1Introduction
mymocktest ("we", "us", "our", "Company") is committed to protecting the privacy and confidentiality of users of the website mymocktest.com and the mymocktest mobile application (collectively, the "Platform").
This Privacy Policy ("Policy") describes the types of personal and non-personal information we collect when you interact with the Platform, the manner in which we collect, use, store, share, and protect such information, and the rights and choices available to you in respect of your personal information.
This Policy is published in accordance with the requirements of:
- The Information Technology Act, 2000 and the rules made thereunder;
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules");
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
- The Digital Personal Data Protection Act, 2023 ("DPDP Act"), to the extent applicable;
- Other Applicable Laws relating to the protection of personal data.
2Scope & Applicability
This Policy applies to all visitors, registered Users, paying subscribers, and other persons who access or use any part of the Platform, irrespective of the device used.
This Policy does not apply to information collected by any third-party websites, services, or applications that are linked to from, or used in connection with, the Platform. We strongly encourage you to review the privacy policies of such third parties before sharing your personal information with them.
By accessing or using the Platform, you signify your acknowledgment of this Policy and your consent to the collection, use, and disclosure of your information as described herein.
3Information We Collect
We collect different categories of information depending on how you interact with the Platform.
3.1 Information you provide directly
| Category | Examples |
|---|---|
| Account information | Full name, mobile number, email address, password (stored as a one-way hash), profile photo (optional) |
| Profile & preferences | Target examination(s), state, city, gender (optional), date of birth (optional), educational background (optional), language preferences |
| Test & learning data | Mock test attempts, responses to questions, time spent per question, scores, rank, percentile, bookmarks, saved questions, revision lists, performance history |
| Communications | Messages, queries, support tickets, feedback, reviews, and any other content you submit through contact forms or email |
3.2 Information collected automatically
| Category | Examples |
|---|---|
| Device information | Device type, model, operating system and version, mobile network information, unique device identifiers, screen resolution, browser type and version |
| Usage data | Pages visited, features used, time and duration of visits, click streams, navigation paths, referring URLs, exit pages |
| Log data | IP address, access times, error reports, crash logs, session identifiers |
| Location | Approximate location inferred from IP address. We do not collect precise GPS location. |
| Cookies & identifiers | Cookies, web beacons, pixel tags, local storage identifiers (see Clause 9) |
3.3 Information received from third parties
- Payment confirmations from our payment gateway providers (transaction ID, payment status, masked card details or UPI handle, amount, time);
- Authentication providers if you choose to sign in via OTP services or social login (limited to information you authorise);
- Analytics providers (aggregated, non-identifying behavioural data).
3.4 Sensitive personal data
To the extent any information we collect qualifies as "sensitive personal data or information" under the SPDI Rules (e.g., password, financial information), we treat such information with the highest standard of care, store it in encrypted form where applicable, and access it only on a strict need-to-know basis.
4How We Collect Information
We collect information through the following means:
- Directly from you when you sign up, create or update your profile, attempt tests, make payments, or communicate with us;
- Automatically through cookies, web beacons, server logs, software development kits (SDKs), and similar technologies when you use the Platform;
- From third-party service providers such as payment gateways, authentication providers, and analytics tools;
- From publicly available sources, where relevant and legally permissible.
5Purpose of Collection & Use
We use the information collected for the following purposes:
5.1 Providing and operating the Platform
- Creating and managing your Account;
- Authenticating your identity and securing your sessions;
- Delivering mock tests, content, analytics, ranks, and personalised recommendations;
- Saving your bookmarks, revision lists, and attempt history;
- Processing payments and activating Subscriptions.
5.2 Improving our Services
- Understanding how Users interact with features so we can improve usability and content quality;
- Diagnosing technical issues, monitoring performance, and fixing bugs;
- Conducting research and statistical analysis on aggregated, anonymised data;
- Developing new features and product offerings.
5.3 Communication
- Sending transactional communications (OTPs, payment confirmations, subscription expiry alerts, password resets);
- Responding to your queries, complaints, and grievances;
- Sending important notices about changes to our Platform, Terms, or this Policy;
- Sending promotional offers, newsletters, and product updates — only where you have consented or as permitted by law (see Clause 16).
5.4 Security & fraud prevention
- Detecting, investigating, and preventing fraudulent activity, account misuse, content piracy, security breaches, and other harmful activities;
- Enforcing our Terms and Conditions and other policies;
- Protecting the rights, property, and safety of mymocktest, our Users, and the public.
5.5 Legal compliance
- Complying with Applicable Laws, court orders, and lawful requests from government authorities;
- Maintaining financial records as required under tax and accounting laws;
- Responding to legal claims and exercising or defending legal rights.
6Legal Basis for Processing
We process your personal information on one or more of the following legal bases:
- Consent: You provide consent at the time of registration, while making a purchase, or for specific purposes such as marketing communications. You may withdraw such consent at any time;
- Performance of contract: Processing is necessary to provide the Services you have requested and to perform our obligations under our Terms and Conditions;
- Legal obligation: Processing is necessary to comply with Applicable Law;
- Legitimate interest: Processing is necessary for our legitimate business interests, such as improving our Services, securing our Platform, and preventing fraud, balanced against your privacy rights.
8Payment Information
Payments on the Platform are processed exclusively by third-party payment gateway service providers that are certified as PCI-DSS (Payment Card Industry Data Security Standard) compliant. When you make a payment:
- You are redirected to the payment gateway's secure interface to enter your payment details;
- Your card number, CVV, UPI PIN, net banking credentials, and other sensitive payment credentials are entered, processed, and stored by the payment gateway, not by mymocktest;
- We receive only the transaction confirmation, including the transaction ID, amount, status, payment method type (card, UPI, netbanking, wallet), and masked details (e.g., last 4 digits of card) for our records.
For specific terms relating to payment processing, please refer to the privacy policy and terms of the relevant payment gateway provider.
10Third-Party Services
The Platform may use or integrate with third-party services to enable certain functionality. These third parties may collect and process information independently in accordance with their own privacy policies. Examples include:
- Hosting infrastructure (Hostinger VPS / cloud providers);
- Object storage (Amazon Web Services S3);
- Payment processing (Razorpay, Cashfree);
- Analytics (Google Analytics or similar);
- Communication services (email service providers, SMS gateways);
- Push notification services (Firebase Cloud Messaging).
We are not responsible for the privacy practices of these third parties. You are encouraged to review their privacy policies separately.
11Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of providing the Services, complying with our legal obligations, resolving disputes, and enforcing our agreements.
Specifically:
- Active Accounts: Personal data is retained for the duration that your Account remains active;
- Inactive Accounts: Accounts inactive for more than 24 (twenty-four) consecutive months may be deleted or anonymised, after providing reasonable notice (where contact details are valid);
- Transaction records: Retained for at least 8 (eight) years from the date of transaction to comply with tax and accounting laws;
- Communication records: Support tickets and related communications retained for up to 3 (three) years;
- Legal holds: Information may be retained for a longer period if required by law or for the establishment, exercise, or defence of legal claims.
Upon expiry of the retention period, personal data is either securely deleted, destroyed, or anonymised such that it can no longer be associated with you.
12Data Security
We implement reasonable and appropriate technical, administrative, and physical security measures designed to protect your personal information from unauthorised access, alteration, disclosure, or destruction. These measures include, among others:
- Encryption: HTTPS/TLS encryption for all communications between your device and our servers; encryption of sensitive data at rest;
- Access controls: Role-based access controls restricting access to personal data to authorised personnel on a strict need-to-know basis;
- Password protection: Passwords are stored as one-way salted hashes; we never store plain-text passwords;
- Server security: Firewalls, intrusion detection, regular security patches, and hardening of servers;
- Audit logs: Maintenance of audit logs for security-sensitive operations;
- Vendor security: Engaging only reputed service providers with adequate security certifications.
Notwithstanding the foregoing, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
In the unlikely event of a data breach affecting your personal information, we shall notify you and the appropriate authorities as required by Applicable Law.
13Your Rights
Subject to Applicable Law, you have the following rights in respect of your personal information:
- Right to access: You may request a copy of the personal information we hold about you;
- Right to correction: You may request correction of inaccurate or incomplete personal information. Most profile information can be edited directly through your Account settings;
- Right to deletion / erasure: You may request deletion of your personal information, subject to certain exceptions (e.g., information we are required to retain by law);
- Right to withdraw consent: Where processing is based on consent, you may withdraw such consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal;
- Right to object: You may object to processing of your personal information for direct marketing purposes;
- Right to data portability: Where applicable, you may request a copy of your personal information in a structured, commonly used format;
- Right to grievance redressal: You may submit a complaint to our Grievance Officer (see Clause 18).
To exercise any of these rights, please write to us at privacy@mymocktest.com from the email address associated with your Account. We may require verification of your identity before processing your request. We shall endeavour to respond to your request within 30 (thirty) days.
Please note that exercising certain rights, in particular the right to deletion, may result in your inability to use some or all features of the Platform.
14Children's Privacy
The Platform is intended for users aged 13 years and above. We do not knowingly collect personal information from children below the age of 13 years.
For users between the ages of 13 and 18, use of the Platform should be under the supervision of a parent or legal guardian, who shall be deemed to have provided consent for the collection and processing of the minor's personal information.
If you believe that a child under the age of 13 has provided personal information to us without parental consent, please contact us at privacy@mymocktest.com and we shall take prompt steps to delete such information.
15Data Transfers & Storage Location
Your personal information is primarily stored and processed on servers located in India. Some of our service providers may operate servers in other jurisdictions; in such cases, we ensure that adequate safeguards are in place to protect your information in accordance with Applicable Law and this Policy.
By using the Platform, you consent to such transfer, storage, and processing of your information in locations as described above.
16Communications & Marketing
We may send you transactional communications relating to your Account, payments, subscriptions, and Platform updates. These communications are integral to providing the Services and cannot be opted out of while your Account remains active.
We may also send you promotional communications, newsletters, special offers, and product updates. You may opt out of such marketing communications at any time by:
- Clicking the "unsubscribe" link in any promotional email;
- Updating your communication preferences in your Account settings;
- Writing to us at privacy@mymocktest.com.
17Updates to this Policy
We may update this Policy from time to time to reflect changes in our practices, legal requirements, or features of the Platform. Material changes will be notified through the Platform or by email (where reasonably possible). The "Last updated" date at the top of this Policy indicates when it was last revised.
Your continued use of the Platform after the effective date of the updated Policy shall constitute acceptance of such updates. We encourage you to review this Policy periodically.
18Contact & Grievance Officer
If you have any questions, concerns, requests, or grievances relating to this Policy or to our handling of your personal information, please contact us using the details below.
Email: privacy@mymocktest.com
General Support: support@mymocktest.com
Website: https://mymocktest.com
Name: Mr. Manish
Designation: Grievance Officer, mymocktest
Email: grievance@mymocktest.com
Address: Jaipur, Rajasthan, India
Hours: Monday to Friday, 10:00 AM to 6:00 PM IST (excluding public holidays)
The Grievance Officer shall acknowledge complaints within 24 (twenty-four) hours and shall endeavour to redress the same within 15 (fifteen) days, in accordance with Applicable Law.
We take your privacy seriously. If anything in this Policy is unclear, please don't hesitate to reach out.
© 2026 mymocktest. All rights reserved.