Privacy Policy
Last updated: June 30, 2026
1. What We Collect
When you enroll in a Sariro cohort, we collect:
- Account info: email, full name, phone number, password (hashed)
- OAuth data: profile photo, verified email (from Google/GitHub)
- Payment info: processed by Razorpay — we never see or store your card details
- Cohort activity: attendance, project submissions, mentor feedback
- Chat history: messages you send to the Sariro assistant (stored encrypted)
- Usage analytics: pages visited, feature usage — anonymized
2. How We Use Your Data
We use your data to:
- Run your cohort — attendance, feedback, certificates
- Notify you about cohort starts, schedule changes, and important updates
- Improve our courses, FAQ knowledge base, and AI assistant
- Detect and prevent fraud, abuse, and academic dishonesty
- Comply with legal obligations (tax records, etc.)
We never sell your data to third parties. We never share your contact info with marketing partners.
3. Cookies & Tracking
We use essential cookies to keep you logged in and remember your preferences. We use optional analytics cookies (only with your consent — see the cookie banner) to understand which pages are most useful. We do not use cookies for cross-site advertising tracking. You can manage cookies anytime via the banner or your browser settings.
4. Data Sharing
We share data only with these trusted processors (all under strict data processing agreements):
- Supabase — authentication and database hosting
- Razorpay — payment processing (PCI-DSS compliant)
- Google — Google One Tap sign-in (only if you choose it)
- GitHub — GitHub OAuth sign-in (only if you choose it)
- Resend — transactional email delivery
We never share your data with any other third party without your explicit consent. Law enforcement requests are honored only when legally compelled, and we'll notify you unless prohibited.
5. Your Rights (GDPR / CCPA)
You have the right to:
- Access — request a copy of all data we hold about you
- Correct — fix inaccurate personal data
- Delete — request erasure of your data ("right to be forgotten")
- Export — receive your data in a portable JSON format
- Object — opt out of certain processing activities
- Withdraw consent — for any processing based on your consent
To exercise any of these rights, email contact@sariro.com with the subject "Data request." We respond within 30 days.
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we erase your personal data within 30 days, except where we're legally required to retain it (e.g., tax records for 7 years). Anonymized analytics data may be retained indefinitely.
7. Security
We use industry-standard security: TLS encryption in transit, AES-256 at rest, row-level security on all database tables, and regular security audits. Payment data never touches our servers — it goes directly to Razorpay's PCI-DSS-compliant infrastructure. Despite our best efforts, no system is 100% secure; if a breach occurs, we'll notify affected users within 72 hours per GDPR Article 34.
8. Children's Privacy
Sariro cohorts are open to students aged 14+. For students aged 14–17, we require parental consent at enrollment. We do not knowingly collect data from children under 14. School partnership programs for younger learners are governed by separate contracts that comply with COPPA, FERPA, and applicable local laws.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to enrolled students at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
10. Contact
Privacy questions? Email contact@sariro.com or write to us at San Francisco · Remote-first · Worldwide. We reply within 24 hours, Monday through Friday.