Legal

Privacy Policy

Last updated 1 October 2026AlsoTerms of ServiceCookie Policy
Contents · 16 sections

Staffcoder (“Staffcoder”, “we”, “us”, “our”) operates a framework-first engineering practice platform where developers write, run, and submit code inside a browser-based development environment. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. It applies to our website, applications, and related services (collectively, the “Service”).

The data controller, and under the Digital Personal Data Protection Act, 2023 the Data Fiduciary, is SHASTACK INDIA TECHNOLOGIES (OPC) PRIVATE LIMITED, CIN U62010UP2025OPC218177, of B-174 Sector 20, Gautam Buddha Nagar, Noida, Uttar Pradesh, India - 201301.

When you create an account, we ask you to confirm that you have read this policy. This policy is available in other Indian languages on request.

Information you provide

  • Account information: your name, email address, and password (stored only as a secure hash). If you sign in with Google, GitHub, or LinkedIn, that provider sends us your name and verified email address.
  • Profile details, all optional: your date of birth, gender, city, country, a one-line headline, and links to your profiles on other sites, such as GitHub or LinkedIn.
  • Onboarding answers, all optional: whether you are studying or working and the name of your college or company, the areas you want to focus on, your goal, and your level of experience.
  • Code and submissions: the source code, solutions, and other content you write or upload while completing challenges.
  • AI prompts: anything you type into an AI feature, and the code and challenge context sent with it.
  • Billing details: if you buy a paid plan, your legal name or company name, billing email, phone number, and billing address. These are required to issue a GST-compliant invoice. Card details are entered with our payment processor and never reach us.
  • Communications: messages you send us through support, contact forms, feedback, or email.

Information we collect automatically

  • Usage data: challenges viewed and attempted, submissions, scores, progress, session activity, and feature interactions.
  • Device and log data: IP address, browser type, operating system, referring pages, timestamps, and diagnostic logs.
  • Timezone: read from your browser when you sign up, so dates and streaks follow your local day.
  • Country: the country your connection comes from, as reported by our content delivery network. If the country in your profile is empty, we fill it in from this when you save your profile. You can change or remove it.
  • Consent records: when you accept our terms or make a cookie choice, we record the date, the policy version, your choice, and your browser’s user-agent string.
  • Cookies and similar technologies: used to keep you signed in, remember preferences, and understand how the Service is used.

Session environments

When you start a session, we provision a containerised development environment for you. Code you write inside it is transmitted to us when you submit or when the environment syncs. The environment itself is ephemeral and is destroyed when the session ends.

We use the information we collect to:

  • provide, operate, and maintain the Service, including running your code and grading submissions;
  • create and secure your account and authenticate your sessions;
  • personalise your practice experience and track your progress;
  • provide AI-assisted features where your plan and the challenge include them;
  • process payments, manage subscriptions, and issue invoices;
  • respond to your requests and provide customer support;
  • send the emails described in clause 12;
  • monitor, analyse, and improve performance, reliability, and features;
  • detect, prevent, and address fraud, abuse, and security incidents; and
  • comply with legal obligations and enforce our terms.

We do not sell your personal information, and we do not use your code or submissions to train our own machine-learning models.

Some plans and challenges include AI-assisted features: an in-editor assistant and, where a challenge enables it, an AI interface your own code can call.

Your content leaves our systems here

When you use an AI feature, the content you provide to it, which may include your code, the challenge you are working on, and anything you type into the assistant, is transmitted through our AI gateway to third-party large-language-model providers, who process it to generate a response. Do not enter confidential or personal information into an AI feature.

What this means for you:

  • Those providers process your content under their own terms and privacy practices. We select them and pass your content to them, but we do not control their models.
  • Content sent to an AI feature may be processed outside India, mainly in the United States.
  • We do not ask model providers to use your content to train their models.
  • We record metering data about your AI usage, the volume and cost against your plan’s budget, in order to enforce that budget.

If you would rather your code and prompts were not sent to a model provider, do not use the AI features. The rest of the Service works without them. Your rights in this content are described in the Terms of Service.

We use strictly necessary cookies to keep you signed in, to protect forms against cross-site request forgery, and to run the practice environment. Settings such as your appearance preference and your collapsed sidebar are kept on your own device, in local storage and in one cookie.

The only optional technology we use is Google Analytics 4, and it is off until you accept it. If you refuse, Google’s code is never loaded. You can accept or withdraw at any time from the Cookie settings link in our footer, and withdrawing deletes the analytics cookies.

Every cookie we set, what it is for and how long it lasts, is listed in our Cookie Policy.

We do not sell your personal information. We share it only as follows.

Service providers, acting on our instructions under confidentiality obligations. Who they are, and what each receives:

ProviderWhat they receive
Hosting and infrastructure (Amazon Web Services, Supabase, Vercel)Everything needed to run the Service, including your account data and code
Payment processing (Razorpay)Your billing details and payment instrument; they hold the card data, we do not
AI model providers, via our gatewayPrompts, code, and challenge context you send to an AI feature
Email delivery (Amazon SES)Your email address and the message content
Bot protection (Cloudflare Turnstile)Your IP address and browser signals when you sign in, sign up, or send a form
Rate limiting (Upstash)Your email address and IP address, kept for a short period to block repeated failed sign-ins and abuse
Sign-in providers (Google, GitHub, LinkedIn)Only if you choose to sign in with one: they learn that you use Staffcoder and send us your name and verified email address
Analytics (Google Analytics)Usage and device data, and only if you accept analytics cookies

Legal and safety: when required by law, legal process, or to protect the rights, property, or safety of Staffcoder, our users, or the public.

Business transfers: in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you of any change.

With your direction: when you choose to share content or connect a third-party service.

We retain personal information for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements.

WhatKept for
Account and profileUntil you delete the account
Submissions and progressUntil you delete the account
Diagnostic and security logsAt least one year, then deleted
Invoices and payment recordsAt least six years from the end of the financial year, as law requires
BackupsUp to 30 days

When you ask us to delete your account, it is deactivated straight away and permanently deleted within 30 days. Deleting it removes your profile, submissions, and progress. We cannot delete invoices and payment records on request, even if you delete your account, because Indian tax law requires us to keep them.

We use administrative, technical, and organisational safeguards designed to protect your information, including encryption in transit, encryption at rest for our databases, file storage, and backups, access controls, and hashed passwords. Session environments are isolated from one another. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

We protect your data under India’s DPDP Act and the GDPR. Contact us at support@staffcoder.com for details of our security practices.

Your account data, code, and submissions are stored in India, with Amazon Web Services and Supabase in the Mumbai region. Some processing happens outside India:

  • emails are sent through Amazon SES in the United States;
  • AI features send your content to third-party AI model providers, mainly in the United States;
  • if you accept analytics cookies, Google processes analytics data in the United States and elsewhere; and
  • our website is delivered through Vercel’s global network, and bot protection runs on Cloudflare’s.

Where we transfer personal data out of India or the European Economic Area, we rely on Standard Contractual Clauses or equivalent safeguards, and on the protections applicable law requires.

Depending on where you are, you may have the right to access, correct, update, or delete your personal information; to object to processing we base on our legitimate interests, or to restrict it; to data portability; and to withdraw consent.

Under the Digital Personal Data Protection Act, 2023, you additionally have the right to obtain a summary of the personal data we process about you and the processing activities undertaken, the right to correction and erasure, the right to nominate another person to exercise your rights in the event of your death or incapacity, and the right to a readily available grievance-redressal mechanism, which is set out in clause 16.

You can request a copy of your data, or the deletion of your account, from Settings. We send your data within 30 days, usually much sooner. An account you ask us to delete is deactivated straight away and deleted within 30 days.

To nominate someone, email us with their name and contact details.

For anything else, contact us at support@staffcoder.com. We respond within 30 days. You also have the right to complain to your local data protection authority, and in India to the Data Protection Board.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you.

We send service emails, such as verification codes, security alerts, billing notices, and messages about your subscription or account, because they are needed to provide the Service. You cannot opt out of them while you hold an account.

After you sign up, we send a few getting-started emails: a welcome note a couple of hours after you join, a reminder about your first challenge a day later, and a note about our paid plans a day after your first practice session. You can unsubscribe from them at any time.

In Settings, under Emails, you choose whether to receive progress emails when you finish a module or path, alerts you asked for with Notify me, and occasional product updates. Every one of these emails carries an unsubscribe link. Registration on India’s National Do Not Call registry covers calls and text messages, not email.

Staffcoder is only for people aged 18 or older. When you create an account, you confirm that you are at least 18. We do not knowingly collect personal data from anyone under 18. If we learn that a user is under 18, we will close the account and delete their data within 30 days. If you believe someone under 18 has given us personal data, contact us at support@staffcoder.com.

We may update this Privacy Policy from time to time. When we make material changes, including any change to how AI features process your content, we will update the “Last updated” date above and notify you through the Service or by email. If a change needs your consent, we will ask for it again.

Privacy questions and requests, and grievances under the Information Technology Act, 2000, the Consumer Protection (E-Commerce) Rules, 2020, and the Digital Personal Data Protection Act, 2023, go to our Grievance Officer, Shashank Sharma, Founder and CEO, at support@staffcoder.com.

What happensWithin
We acknowledge a grievance48 hours
We resolve it, or give a written reason30 days
Entity and grievance details
Legal nameSHASTACK INDIA TECHNOLOGIES (OPC) PRIVATE LIMITED
CINU62010UP2025OPC218177
GSTIN09ABPCS4817A1Z8
Registered addressB-174 Sector 20, Gautam Buddha Nagar, Noida, Uttar Pradesh, India - 201301

Questions about this document, and grievances under the Information Technology Act, 2000, go to support@staffcoder.com.

We use cookies that are necessary to run Staffcoder, and optional analytics cookies to see which pages get used. Analytics stays off unless you accept. Read our Cookie Policy.