1. Introduction
Welcome to TheBlueMustard (“we,” “us,” “our,” or “the Platform”), accessible at thebluemustard.com, its subdomains (including creator storefronts at <slug>.thebluemustard.com and the assessments portal at tests.thebluemustard.com). We are committed to protecting your personal information and respecting your right to privacy. This Privacy Policy explains how we collect, use, disclose, store, and safeguard your information when you access or use the Platform.
TheBlueMustard is a combined digital product marketplace, online assessment platform, and subscription billing service. Depending on how you use it, we may act as a data fiduciary for you as a buyer or visitor, as a data processor for a creator when they use us to administer assessments to their own candidates and team members, or both.
This Privacy Policy applies to all users of the Platform, including visitors, registered users, creators (sellers and assessment authors), store staff and team members, buyers, guest purchasers, candidates taking assessments, admins, and grievance officers. By accessing or using the Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with these practices, please discontinue use of the Platform.
This Privacy Policy is published in compliance with the Information Technology Act, 2000 (in particular Section 43A), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020, and the Digital Personal Data Protection Act, 2023 (to the extent notified), together with any other applicable Indian data-protection laws and regulations.
2. Types of Data Collected
2.1 Account & Profile Information
When you register for an account on the Platform (via our authentication provider, Clerk), we may collect the following personal information:
- Full name, first name, last name, and display name
- Email address and, where offered by Clerk, phone number
- Username (unique on the Platform)
- Profile avatar or photograph
- Bio or personal description
- Website URL (optional)
- Social handles — Twitter/X, Instagram, YouTube, LinkedIn, GitHub (all optional)
- Language and timezone preferences, and privacy toggles (whether your profile, sales metrics, follower count, and contact email are publicly visible)
- Whether two-factor authentication is enabled on your account
- Session and device metadata surfaced by Clerk (session identifier, last active time, issuing device fingerprint)
2.2 Creator, Store & Team Information
If you register as a creator, own a store, or are added to a store as a team member, we additionally collect:
- Store name, description, tagline, custom slug, and branding assets (logo, banner, favicon, brand colours, brand theme, support email and support phone)
- Store registration policy (invite-only / public / approval) and any custom registration fields the store owner has configured (for example: employee ID, roll number, department, cohort)
- Store-scoped role assignments (owner, admin, manager, team member, customer, or any custom role a store creates)
- Team invitations that you send or receive, including the invited email, role keys, invitation message, acceptance state, and expiry
- Product listing details (titles, descriptions, pricing, currency, compare-at price, categories, cover image, sample images with alt text and tags)
- Digital product files you upload for sale, together with their filename, MIME type, size, and SHA-256 checksum
- Subscription plans, prices, and coupons that you author, and the subscribers they attract
2.3 Assessment & Candidate Data (Creators as Authors and Assessors)
If you use the Platform to author or administer online assessments, we collect and store — on your behalf and under your direction — the following information about the tests you build and the candidates who take them:
- Test configuration: title, slug, instructions, duration, passing score, maximum attempts, randomization flags, access mode (public, private, invite-only), launch mode (candidate self-serve or supervisor-launched), timer mode (whole-test or section-wise), navigation policy, and any per-test share token or test code
- Question bank content: prompt HTML, options and correct answers, explanations, difficulty, subject, tags, translations, immutable version snapshots, and duplicate fingerprints for de-duplication
- Candidate profile data (per store): name, father’s name, email, mobile number, date of birth, address, photograph, qualification, acquisition source, and work status, plus store-defined custom fields
- Candidate groups, tags, bulk-import spreadsheets you upload for validation, and the outcome report of each import
- Assessment invitations: invited email, attempts allowed, availability window, expiration, delivery status (SES message ID, delivery/bounce/complaint), and open/start/complete timestamps
2.4 Candidate Runtime Data (Candidates Taking a Test)
When you are a candidate taking a test on the Platform (whether via a share link, a test code, or an emailed invitation), we collect the following information for the store that is administering the assessment:
- Name and email you provide at registration (and, if the assigning creator has provided one, a link back to your global Candidate profile)
- The test you registered for, the number of attempts, and each attempt’s start, activity, submission, and evaluation timestamps
- Your answers to each question, per-question time spent, and any “flag for review” marks
- Client snapshot metadata (viewport dimensions, user-agent hints, connection details) captured at attempt start
- Client-reported proctoring signals when the creator has enabled them: tab switches, window blur, fullscreen exits, copy/paste attempts, right-clicks, developer-tools openings, together with a running violation count
- Real-time connection presence (connected/disconnected) while an attempt is in progress
- Real-time messages exchanged with the assessor during a live session (see §2.5)
- Section-wise state (pending, active, completed, expired) with server-anchored deadlines, and whether a section was auto-submitted because a timer expired
- Score, maximum score, percentage, pass/fail, and evaluation state (pending, auto-graded, manual review, complete)
- Your test-response and result-share emails and their delivery status
- Language preference at the time you took the test (for reporting in the same language you experienced)
2.5 Live-Session, Messaging & Real-Time Data
Some assessments are launched inside a supervisor-run live session. For those we also collect and store:
- Live-session lifecycle events (waiting, active, ended) and their timestamps
- Messages sent between assessors and candidates (individual and broadcast), including sender, recipients, priority (info/warning/critical), content, and read receipts
- Assessor actions targeted at a candidate (warnings, force-submit, ban with reason)
- Presence and connectivity signals of connected sockets so assessors can see who is currently online
2.6 Financial, Payment & Billing Information
When you make a purchase or subscribe on the Platform, payment information is collected and processed securely by our third-party payment gateway, Razorpay Software Private Limited. This may include:
- Credit or debit card details (card number, expiry date, CVV)
- UPI ID and, for QR-based tip flows, UPI handle
- Net banking credentials
- Digital wallet information
- EMI and BNPL provider details (when offered by Razorpay)
Important: TheBlueMustard does not directly collect, store, or have access to your full credit-card numbers, debit-card numbers, CVV codes, banking PINs, or UPI PINs. All sensitive payment information is processed exclusively by Razorpay in accordance with their PCI-DSS Level 1 compliance standards and their privacy policy. We only receive confirmation of payment status (success or failure), transaction reference identifiers, and the payment method type used.
In addition, for creators who wish to receive payouts and for buyers on subscriptions or business (B2B) invoices, we collect and store:
- Payout preferences: payout provider (for example: Razorpay Route or bank transfer), external account reference, payout currency, payout schedule (daily, weekly, monthly)
- Billing account details: billing email, currency, and Goods and Services Tax Identification Number (GSTIN) for tax-compliant invoicing
- Provider references: Razorpay customer IDs, plan IDs, subscription IDs, and invoice/order/payment IDs (never full instrument data)
2.7 Order, Subscription & Entitlement Data
We collect and store the following transaction-related data on our servers:
- Order ID and order status (Pending, Paid, Fulfilled, Failed, Refunded, Cancelled), currency, and total amount
- Line items (product, test, store or bundle purchased, plan / price snapshots, and price at purchase)
- Razorpay order ID, payment ID, and payment status (Pending, Captured, Failed, Refunded), plus a signature reference
- License key(s) generated for one-time purchases and their download counters and last-download timestamp
- Entitlements (the single source of access-truth), including their resource type, source (one-time, subscription, manual grant, promo, invitation, migration), validity window, and per-metric caps
- Subscription lifecycle (trialing, active, paused, grace, past-due, canceled, expired), current billing period, grace window, and cancel-at-period-end preference
- Invoices (with sequential GST-compliant numbering), invoice lines (subscription, one-time, usage overage, credit pack, discount, tax), tax lines (CGST/SGST/IGST, rate, GSTIN), credit notes, and refunds
- Usage events and per-period usage counters for metered features (for example: tests created, assessments run, candidate invites, candidate attempts, emails sent, API calls, cumulative storage)
- Credit balances and an append-only credit-transaction ledger (purchase, promotional, consumption, refund, adjustment, expiry) with signed amounts and running balances
- Coupon redemptions (including referral coupons) tied to your account or subscription
- An append-only billing audit log that records every finance-grade action (payment captured, order fulfilled, entitlement granted, refund issued, and so on) with before / after state — this log is retained for regulatory and dispute purposes
- Date and time of each transaction and each billing event received from the payment provider (with an idempotency ledger that prevents duplicate processing of redelivered webhooks)
2.8 Technical, Device & Usage Data
We automatically collect certain technical and usage data when you access the Platform, including:
- IP address (and, when relevant, the IP recorded for a specific download or attempt)
- Browser type, version, and language settings
- Operating system and device type
- Pages visited, features used, search terms, and navigation patterns
- Date, time, and duration of visits
- Referring website or URL
- Download history, including the file, license, timestamp, IP address, and (for guests) the email associated with the download
- User-agent string
- Request identifiers and correlation identifiers that the server attaches to each request for distributed tracing and debugging (never used for cross-site tracking)
- Rate-limiting and abuse signals attached to a request (per-IP quotas by 1 s / 10 s / 60 s buckets)
2.9 Engagement, Community & Discovery Data
The following additional signals are collected when you interact with the marketplace and community features:
- Wishlist entries you add or remove
- Product views (a naive lifetime counter per product)
- Product reviews (rating 1–5, optional title and body, whether the reviewer is a verified purchaser, and moderation state)
- “Helpful” votes on reviews
- Follows (of a store or a creator)
- Content reports (subject type — product, store, or creator — reason, optional note, and moderation status). Anonymous reports without a signed-in user are permitted
- Recently viewed history maintained in your browser
- Read / dismissed state for in-app UI messages, tips, banners, and announcements
2.10 Guest Purchase & Guest Access Data
If you interact with the Platform as a guest (without creating an account), we collect only what is required to fulfil your action:
- Guest purchases: your email address, optionally a phone number, a one-shot secure download token, and its expiration (default 30 days), together with the transaction data listed above
- Guest OTP authentication: a hash of a 6-digit one-time password sent to your email, the number of verification attempts, and the expiry timestamp. The OTP itself is stored only as a hash and is discarded after use or expiry (default expiry: 3 minutes; default max attempts: 3)
- Guest session token: a short-lived signed JWT (default lifetime 15 minutes) that lets you list and download the purchases tied to a verified email without registering an account
2.11 Support, Communications & In-App Messaging Data
When you contact us or use in-app communication features, we may collect and retain:
- The name, email, subject category, and message content you submit through the Contact form
- Emails, replies, and threaded correspondence exchanged with our support team
- Email lifecycle events (sent, delivered, bounced, complaint) surfaced by our email providers via SES/SNS or Resend webhooks — used to suppress deliveries to invalid or complaining addresses
- Read/dismissed state for platform-driven UI messages and banners
2.12 Administrative & Audit Data
For accountability, security, and dispute resolution we maintain the following internal records. Most of these fields are visible only to the Grievance Officer and authorised platform-owner personnel:
- Audit log: an immutable log of security-relevant actions taken on the Platform (actor, action, resource, before/after state, IP, user-agent, request and correlation identifiers, status, and any reason)
- Activity log: a retained log of operational events (imports, bulk jobs, moderation, imports/exports, and similar)
- Impersonation sessions: when a platform-owner administrator uses the Super Admin console to impersonate an account for support purposes, the session, reason, target, IP, and start / end timestamps are recorded and remain visible to the impersonated user on request
- Kill switches, feature flags and system settings: the flags and settings applied to your account or store at a given time, together with their version history
- Bulk jobs: the parameters, status, and per-item outcomes for bulk-import and bulk-administrative jobs you run
3. How Data is Collected
We collect your data through the following means:
- Account Registration: personal information provided by you during sign-up through our authentication provider, Clerk (email/password, one-tap, or social sign-in as supported by Clerk).
- Profile, Store & Team Setup: information you voluntarily provide when setting up your user profile, creator profile, store branding, or when accepting a team invitation to another creator’s store.
- Product & Test Authoring: information and files you upload when listing digital products for sale, building tests, importing questions or candidates in bulk, and exporting question banks.
- Assessment Participation: information you provide when registering for a test (email, name, optional store-defined fields), while taking an attempt (answers, per-question timing, flags, client-reported proctoring events), and during live-session messaging.
- Payment Processing: financial data collected by Razorpay when you initiate a payment transaction or start a subscription.
- Cookies and Session Data: essential cookies set by our authentication system (Clerk) for session management, subdomain routing cookies, and — only when enabled — optional analytics cookies (see §7).
- Automated Collection: technical and usage data collected automatically through server logs, application traces, request-context middleware, and rate-limiting counters when you interact with the Platform.
- Email & Delivery Providers: delivery, bounce, and complaint events reported by Amazon SES (via SNS webhooks) and Resend, so we can maintain deliverability and honour opt-outs.
- Real-Time Gateway: connection presence, room subscriptions, and messaging exchanged over the Platform’s Socket.IO realtime gateway.
- Communications: information you provide when you contact our support team, submit a content report, or reply to any of our transactional emails.
4. Purpose of Data Usage
We use the information we collect for the following lawful purposes:
- Account Management: to create, authenticate, and manage your user account, including enforcing suspend, soft-delete, and account-restoration lifecycles.
- Service Delivery — Marketplace: to enable creators to set up stores, list products, process sales, deliver purchased files, and enable buyers to browse, purchase, download, and access digital products.
- Service Delivery — Assessment Platform: to enable creators to build question banks, author tests, invite and manage candidates, run live proctored sessions, evaluate results, and share reports; and to enable candidates to register, take attempts, receive their submission copies, and (when the creator shares them) their scored reports.
- Payment & Subscription Processing: to facilitate secure transactions through Razorpay, manage recurring subscriptions, generate GST-compliant invoices, and process refunds, credit notes, and coupons where applicable.
- License & Entitlement Management: to generate, manage, and validate license keys for one-time purchases, and to resolve subscription-based entitlements at every access-controlled surface (downloads, test attempts, feature gates).
- Order Fulfilment: to deliver purchased digital products, send order confirmation and receipt emails, provide download-access links and Assessment Codes, and mark orders as fulfilled exactly once.
- Assessment Integrity & Proctoring: to enforce server-anchored timers, log client-reported violations, warn or force-submit candidates who breach configured rules, and give creators the tools to review, ban, or waive violations for their own candidates.
- Communication: to send transactional emails (welcome, creator activation, store created, purchase receipts, sale notifications, store invitations, assessment invitations with test codes, candidate exam-report copies, and scored candidate result emails), respond to support enquiries, and notify you of important account, policy, or billing changes.
- Platform Improvement: to analyse aggregate usage, benchmark performance, troubleshoot technical issues, and improve the Platform’s features, reliability, and user experience.
- Security, Anti-Abuse & Fraud Prevention: to detect, prevent, and address fraud, unauthorised access, quota abuse, spam, content violations, and other harmful activities, including via rate limits, kill switches, and platform-owner moderation tooling.
- Compliance & Enforcement: to comply with applicable laws, regulations, legal process, or enforceable governmental requests, and to enforce our Terms and Conditions.
5. Payment Data Handling
All monetary transactions on the Platform are processed exclusively through Razorpay, a payment gateway authorised by the Reserve Bank of India (RBI) and certified under PCI-DSS Level 1 security standards.
- TheBlueMustard does not store, process, or have access to your full credit-card numbers, debit-card numbers, CVV codes, banking PINs, or UPI PINs at any point.
- Payment data is transmitted directly from your browser or device to Razorpay’s secure servers using industry-standard TLS encryption.
- We receive only payment confirmation details (transaction ID, payment status, and payment-method type) from Razorpay, which are stored on our servers solely for order fulfilment, subscription billing, invoicing, refund processing, and record-keeping.
- For recurring subscriptions we additionally store Razorpay customer, plan, and subscription identifiers so we can reconcile lifecycle events (renewals, dunning, cancellations) with your entitlements. Provider webhooks are recorded once in an idempotency ledger to prevent duplicate processing.
- The optional Support-a-Creator page lets a creator receive voluntary tips on their free products. The creator chooses one or both of two payment surfaces:
- UPI QR & UPI ID (off-Platform): the tip page displays the creator’s personal UPI QR and/or VPA. TheBlueMustard does not process, collect, or hold funds sent this way; they flow directly through your UPI provider to the creator. We record only that a buyer clicked the surface (for the creator’s dashboard analytics) and, if provided, the buyer’s email.
- Razorpay Checkout (on-Platform): tips paid via Razorpay flow through the same PCI-DSS Level 1 gateway that handles regular purchases (see above). We store the tip amount, the tipping user or email, and the Razorpay order and payment identifiers for reconciliation and dispute handling; no license or invoice is generated for a tip. Tip settlement to the creator follows their standard payout arrangement.
- Razorpay’s handling of your payment data is governed by their own privacy policy and terms of service. We encourage you to review Razorpay’s privacy policy at razorpay.com/privacy.
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes. We may share your data with the following parties, strictly on a need-to-know basis and for the purposes outlined below:
6.1 Service Providers & Processors
- Clerk (Clerk Inc.): our authentication and identity-management provider. Clerk processes your login credentials, manages your authentication sessions, and (via webhooks signed with the svix protocol) mirrors profile changes into our database. Clerk’s handling of your data is governed by their own privacy policy.
- Razorpay: our payment gateway. Razorpay processes your payment and recurring-subscription information securely in accordance with PCI-DSS standards and their privacy policy, and returns transaction and lifecycle events to us via signed webhooks.
- Amazon Web Services (AWS): our cloud-infrastructure provider. AWS hosts our servers, databases, and file storage (Amazon S3). Digital product files, product cover images, candidate photographs (when uploaded), and bulk-import spreadsheets are stored in S3 with private access controls, server-side encryption, and short-lived signed URLs.
- Amazon Simple Email Service (SES) and/or Resend: our transactional email providers. One or both is used to send account, order, subscription, invitation, assessment, candidate report, and result emails. Amazon SNS is used to surface SES delivery, bounce, and complaint events back to the Platform so we can keep our sender reputation and suppression list current.
- Redis / BullMQ: deployed alongside our infrastructure to run background jobs (bulk imports, exports, invitation emails, report emails, result emails), realtime pub/sub for the Socket.IO gateway across multiple instances, and in-memory rate limiting. Redis holds transient queue state and short-lived presence data.
- Google Analytics 4 and Meta Pixel (optional, opt-in): analytics scripts that may be enabled per environment via server configuration. They run only when the corresponding measurement or pixel identifier is configured; when unconfigured the scripts are not loaded at all. GA4 is configured with anonymize_ip. Where and when either provider is enabled, this section is updated and, where required, consent is obtained.
6.2 Creators, Stores & Store Team Members
When you purchase a product from a creator’s store, register as a candidate for a creator’s test, or accept an invitation into a store, the creator (and store team members authorised through their store roles) will receive the information they need to fulfil the interaction. This may include:
- Your name and email address
- The product(s) purchased, the amount, and download / license status
- For candidates: your assessment answers, attempt timings, per-section state, scores, proctoring violations, and any messages you exchanged with the assessor during a live session
- For team members: your role assignments in the store, the store-specific profile fields the store owner has configured, and your last-active timestamp
Creators act as an independent data fiduciary for the store data, candidate data, and assessment content they collect and store on the Platform. Their treatment of that data is additionally governed by their own privacy notice and internal policies. Any store-specific fields collected at candidate or team registration (for example: a university roll number or an employer’s employee ID) live only inside that store’s scope and are never promoted to your global profile.
6.3 Legal and Regulatory Compliance
We may disclose your information if required to do so by law, regulation, legal process, or enforceable governmental request, or if we believe in good faith that such disclosure is necessary to:
- Comply with applicable laws, regulations, or legal processes.
- Enforce our Terms and Conditions.
- Protect the rights, property, or safety of TheBlueMustard, its users, or the public.
- Detect, prevent, or address fraud, security, or technical issues.
7. Cookies and Tracking Technologies
7.1 Essential Cookies We Use
We use essential cookies for the following purposes:
- Authentication cookies set by Clerk to manage your login session and keep you securely authenticated as you navigate the Platform.
- Storefront routing cookie (
_bm_store): a same-site session cookie that pins the storefront slug you opted into so that navigating between <slug>.thebluemustard.com and the apex site keeps you inside the storefront experience you chose. - Tests portal cookie (
_bm_portal): a same-site session cookie that keeps you inside the dedicated assessments portal at tests.thebluemustard.com after you opt in. - Session and preference storage (via cookies and browser storage) to maintain your session state, cart contents, recently viewed items, dismissed banners, and locally saved search history.
7.2 Optional Analytics Cookies
When configured for a deployment, the Platform may load Google Analytics 4 and/or Meta Pixel scripts (see §6.1). Both are opt-in at the deployment level and no-op when unconfigured. Where they run, GA4 is initialised with anonymize_ip and Meta Pixel is initialised with a PageView event only. If the deployment you are using enables either provider and applicable law requires consent, we will surface a consent notice and honour your choice.
7.3 Managing Cookies
You can control and manage cookies through your browser settings. Disabling essential cookies may impair the functionality of the Platform, including your ability to log in, make purchases, receive live-session updates, or take a test.
8. Data Retention Policy
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law:
- Account Data: retained for as long as your account is active. Upon account deletion or deactivation, your personal data is removed from our active systems within 30 days, subject to any legal retention obligations. A soft-delete record with the deletion reason may be retained for dispute-resolution purposes.
- Transaction & Tax Records: retained for a minimum of 8 years from the date of the transaction, as required under Indian tax and financial regulations (including the Income Tax Act, 1961 and the Central Goods and Services Tax Act, 2017). This covers orders, payments, invoices, invoice lines, credit notes, refunds, and the billing audit log.
- Subscription & Entitlement Records: retained for the life of the subscription plus the tax retention period above. Usage events and per-period counters are retained for at least 24 months to support billing reconciliation.
- Digital Product Files: creator-uploaded product files are retained for as long as the product listing is active. Upon deletion of a product or store, the associated files are removed from our storage systems within a reasonable timeframe.
- Assessment & Candidate Data: tests, question banks, question versions, candidates, invitations, attempts, answers, results, and live-session messages are retained for as long as the owning store keeps them. Immutable question versions and results survive individual edits so historical reports stay reproducible. Soft-deleted tests and candidates remain in the recycle bin until the store owner permanently deletes them or a scheduled purge runs.
- Guest Purchase Data: email addresses and transaction records from guest purchases are retained for the duration required to fulfil download access (default 30 days for the download token) and to comply with legal and tax retention requirements. Once verified, a guest may create an account to permanently associate past guest purchases with a login.
- Guest OTP Records: the 6-digit code is stored only as a hash and is discarded on verification, expiry (default 3 minutes), or attempt-limit exceeded (default 3 attempts). Guest JWTs are short-lived (default 15 minutes) and are not stored server-side after issuance.
- Email Events, Bounces & Complaints: delivery, bounce, and complaint events are retained for up to 24 months so we can maintain a suppression list and protect deliverability.
- Audit, Activity & Billing Audit Logs: the audit log is append-only and retained indefinitely as a security and regulatory record. Activity logs are retained for up to 24 months. Impersonation-session records are retained for at least 24 months.
- Technical Logs: server logs and usage data are retained for up to 12 months for security, analytics, and troubleshooting purposes, after which they are anonymised or deleted.
9. Data Security Measures
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit: all data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS/HTTPS). Realtime traffic uses Secure WebSockets (WSS).
- Encryption at rest: data stored in our managed PostgreSQL database and file storage systems is encrypted at rest using industry-standard algorithms.
- Secure authentication: user authentication is handled by Clerk, which implements multi-factor authentication (opt-in), secure password hashing, and brute-force protection. Server-side session verification runs on every authenticated request.
- Guest OTP security: guest one-time passwords are stored only as hashes, are single-use, expire quickly, and are rate-limited per identifier.
- Access controls: access to personal data is restricted to authorised personnel on a need-to-know basis. The Platform implements a layered RBAC model with platform-owner emails, admin roles / permissions, and per-store roles for team members. Every sensitive administrative action passes through the immutable audit log.
- Signed URLs: digital product files, cover images, sample images, candidate photographs, and bulk-import spreadsheets on Amazon S3 are protected with private access controls and time-boxed pre-signed URLs (default 15-minute expiry) so files are downloadable only by authorised users during a short window.
- PCI-DSS compliance: payment processing is handled by Razorpay, which is PCI-DSS Level 1 certified, ensuring the highest level of security for payment data.
- Webhook signature verification: incoming Clerk webhooks are verified using svix signatures and incoming Razorpay webhooks are verified using a per-endpoint shared secret before any state change occurs.
- Rate limiting & kill switches: per-IP, per-route rate limits (short/medium/long windows) protect against abuse. Platform-owner kill switches let us pause outbound email, block a compromised store or product, or freeze a specific capability without a code deploy.
- Continuous review: we conduct regular security reviews, dependency audits, and apply timely security patches to our systems.
While we take all reasonable precautions to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents in accordance with applicable laws.
10. User Rights
In accordance with applicable Indian data-protection laws and principles, you have the following rights with respect to your personal data:
- Right to access: you may request access to the personal data we hold about you. You can view and update most of your personal information through your account settings on the Platform, and export a copy of your account and creator data through Settings → Export data.
- Right to correction: you may request correction or updating of any inaccurate or incomplete personal data we hold about you.
- Right to deletion: you may request deletion of your personal data from our systems, subject to any legal or contractual retention obligations. You can deactivate your account from Settings → Delete account, or, for a full deletion request, contact us at support@thebluemustard.com or hi@imanveer.com. Records required to be retained under tax and financial regulations (see §8) will be kept for the mandated period even after account deletion.
- Right to withdraw consent: where we process your data based on your consent, you may withdraw that consent at any time by contacting us. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
- Right to data portability: you may request a copy of your personal data in a structured, commonly used, and machine-readable format. The self-serve data export in Settings covers the majority of this data.
- Right to raise a grievance: if you have any concerns regarding the processing of your personal data, you may raise a grievance with our Grievance Officer (details provided in §14 below).
Candidate-specific rights: if you were assigned an assessment or added as a candidate by a creator, the creator is the primary data fiduciary for that candidate profile. Requests to correct, delete, or export candidate data are normally routed to the owning creator; you may also contact us and we will facilitate the request with the creator on your behalf.
To exercise any of these rights, please contact us at support@thebluemustard.com or hi@imanveer.com. We will respond to your request within 30 days of receipt.
11. Children’s Privacy
The Platform is not intended for use by children under the age of 13 years. We do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete such information from our servers.
Users between the ages of 13 and 18 may use the Platform only with the verifiable consent and supervision of a parent or legal guardian. Creators who use the Platform to assess minors (for example: schools running exams) must obtain the required parental or guardian consent under applicable Indian law before uploading candidate data or administering an assessment, and remain the data fiduciary for that data. If you are a parent or guardian and believe that your child’s personal information is being processed on the Platform without your consent, please contact us immediately at support@thebluemustard.com or hi@imanveer.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make changes:
- The revised Privacy Policy will be posted on this page with an updated “Last updated” date at the top.
- For material changes that significantly affect how we handle your personal data, we will endeavour to notify you via email or a prominent notice on the Platform prior to the changes taking effect.
- Your continued use of the Platform after the updated Privacy Policy is posted constitutes your acceptance of the revised policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. Third-Party Links and Services
The Platform may contain links to third-party websites, services, or resources that are not owned or controlled by TheBlueMustard — including links a creator adds to their store, product page, or assessment instructions. This Privacy Policy applies only to our Platform. We are not responsible for the privacy practices, content, or security of any third-party websites or services. We encourage you to review the privacy policies of any third-party services you access through the Platform.
14. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules framed thereunder, the details of our Grievance Officer are as follows:
- Name: Grievance Officer, TheBlueMustard
- Email: support@thebluemustard.com, hi@imanveer.com
- Response Time: we acknowledge grievances within 24 hours and endeavour to resolve them within 30 days of receipt.
15. Contact Details
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
- Business Name: TheBlueMustard
- Website: thebluemustard.com
- Email: support@thebluemustard.com, hi@imanveer.com
- Response Time: we endeavour to respond to all enquiries within 24–48 hours on business days.
Related: Terms and Conditions, FAQ, Contact Us.