vPlan
  • Home
  • About
  • Articles
  • Contact
  • Log in
  • Sign up

Privacy Policy

Effective date: July 25, 2026 · Last revised: July 25, 2026

VTUSync ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the vPlan platform ("Service"). By using the Service, you consent to the practices described herein.

1. Information We Collect

1.1 Account Information. When you register an account, we collect your full name, email address, and a securely hashed version of your password. If you authenticate via a third-party provider (e.g., Google Sign-In), we receive your name, email address, and profile photograph as authorized by you through that provider.

1.2 Institutional Data. The Service is designed to store academic scheduling data, including but not limited to course names and codes, instructor names and designations, room numbers and capacities, section identifiers, meeting time configurations, holiday calendars, and teacher-subject mappings. This data is collectively referred to as "Institutional Data."

1.3 Usage Data. We automatically collect certain information when you access or use the Service, including: IP address, browser type and version, operating system, pages viewed and features used, session duration and timestamps, referring URL, and device identifiers. This data is anonymized and aggregated where possible.

1.4 Communication Data. If you contact us via email, contact form, or other channels, we collect the content of your communication along with your email address and any metadata associated with the communication.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To operate, maintain, and provide the Service, including generating timetables, managing schedules, and delivering PDF and Excel exports.
  • Authentication & Security: To verify your identity, manage your account access, and protect against unauthorized use, fraud, and abuse.
  • Communication: To send you account-related communications (password resets, security alerts, service updates) and, with your opt-in consent, product announcements and newsletters.
  • Analytics & Improvement: To analyze anonymized usage patterns, diagnose technical issues, and improve the Service's features, performance, and user experience.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests.
  • Research: To conduct anonymized, aggregate research on academic scheduling patterns, which may be published in academic or industry contexts. No personally identifiable information will be disclosed in such research.

3. How We Share Your Information

We do not sell, trade, rent, or commercially exploit your personal information or Institutional Data to any third party. We may share information only in the following limited circumstances:

  • With Your Consent: When you explicitly authorize us to share your information with a specific third party.
  • Service Providers: With trusted third-party service providers who assist in operating the Service (e.g., cloud hosting, email delivery, analytics), subject to strict contractual obligations to protect your data and use it only for the purposes we specify.
  • Legal Requirements: When required by applicable law, regulation, subpoena, court order, or other valid legal process.
  • Protection of Rights: When we believe in good faith that disclosure is necessary to protect the rights, property, or safety of VTUSync, our users, or the public, including fraud prevention and security incident response.
  • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and any choices you may have regarding your information.

4. Data Storage, Security & Encryption

4.1 Storage Location. Your data is stored on secure servers operated by our hosting providers. Data may be processed in jurisdictions other than your own. We ensure that appropriate safeguards are in place for any cross-border data transfers.

4.2 Security Measures. We implement industry-standard technical and organizational security measures, including:

  • TLS/HTTPS encryption for all data in transit
  • AES-256 encryption for sensitive data at rest where applicable
  • Bcrypt password hashing with per-user salts
  • HttpOnly, Secure, and SameSite cookie flags on session tokens
  • Cross-Site Scripting (XSS) prevention headers
  • Clickjacking protection via X-Frame-Options: DENY
  • Content Security Policy (CSP) enforcement
  • CSRF token validation on all state-changing requests
  • Regular security audits and dependency updates

4.3 No Absolute Security. While we strive to use commercially acceptable means to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and disclaim liability for breaches resulting from force majeure events or vulnerabilities not reasonably foreseeable at the time of implementation.

5. Cookies & Tracking Technologies

5.1 Essential Cookies. The Service uses strictly necessary cookies for session management, authentication, CSRF protection, and security. These cookies are required for the Service to function and cannot be disabled.

5.2 Analytics Cookies. If analytics are enabled, we may use privacy-respecting tools (e.g., Plausible, Umami) that do not use cookies, do not track users across websites, and comply with GDPR without requiring cookie consent banners.

5.3 No Advertising Cookies. We do not use advertising cookies, retargeting pixels, or any tracking technology for the purpose of serving advertisements or building advertising profiles.

5.4 Browser Do Not Track. If your browser sends a "Do Not Track" signal, we honor it by disabling all non-essential data collection.

6. Data Retention

6.1 Active Accounts. Your Account Information and Institutional Data are retained for as long as your account remains active and in use.

6.2 Account Deletion. Upon account deletion, we will permanently remove your personal data (name, email, password hash) within thirty (30) days. Institutional Data will be purged within sixty (60) days. Anonymized, non-identifiable Usage Data may be retained indefinitely for aggregate analytics.

6.3 Legal Hold. We may retain certain data beyond the stated retention periods if required by applicable law, regulation, or pending legal proceedings.

6.4 Backup Deletion. Data removed from active databases may persist in encrypted backups for up to ninety (90) days before permanent deletion.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of all personal data we hold about you, provided in a structured, commonly used, machine-readable format.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to our legal retention obligations.
  • Right to Data Portability: Receive your Institutional Data in a machine-readable format (CSV, JSON, or Excel) for transfer to another service.
  • Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
  • Right to Object: Object to processing of your data for specific purposes, including direct marketing and analytics.
  • Right to Withdraw Consent: Withdraw previously given consent at any time, without affecting the lawfulness of processing conducted prior to withdrawal.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority if you believe your rights have been violated.

To exercise any of these rights, contact our Data Protection contact at support@vtusync.in. We will respond to your request within thirty (30) days.

8. Children's Privacy

The Service is designed for use by educational institutions and their adult faculty and staff. We do not knowingly collect personal information from children under the age of 13 (or the applicable age of consent in your jurisdiction). If we become aware that a child has provided us with personal information without appropriate consent, we will take immediate steps to delete such information. If you believe a minor has provided us with personal data, please contact us at support@vtusync.in.

9. Third-Party Services & Integrations

9.1 Google Sign-In. If you choose to authenticate via Google, we receive your name, email, and profile photo from Google's OAuth 2.0 API. We do not access your Google contacts, calendar, drive, or any other Google data. Google's privacy policy governs the data you share with Google: https://policies.google.com/privacy.

9.2 Analytics Providers. If analytics are enabled, we may use privacy-first analytics tools that process data on our behalf. These providers are contractually bound to keep your data confidential and use it only for the purposes we specify.

9.3 Hosting Providers. Your data is stored on infrastructure provided by our hosting partners, who maintain SOC 2 Type II compliance or equivalent security certifications.

10. International Data Transfers

If you access the Service from outside the country where our servers are located, your information may be transferred to, stored, and processed in a jurisdiction that may have different data protection laws. By using the Service, you consent to such transfers. We ensure that appropriate safeguards (including Standard Contractual Clauses where applicable) are in place for any such transfers.

11. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users within seventy-two (72) hours of becoming aware of the breach.
  • Notify the relevant data protection authority within the time required by applicable law.
  • Provide affected users with information about the nature of the breach, the data affected, and steps we are taking to remediate the situation.
  • Take immediate steps to contain the breach, investigate its cause, and implement measures to prevent recurrence.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated via prominent notice on the Service and by email to registered users at least seven (7) days before the updated policy takes effect. We encourage you to review this policy periodically.

Your continued use of the Service after the effective date of any revised Privacy Policy constitutes your acceptance of the changes.

13. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:

VTUSync — Data Protection
Email: support@vtusync.in
Web: vtusync.in

Make scheduling not painful.

vPlan

Timetable scheduling for VTU colleges. Conflict-free, automated, done.

Product
Pricing How It Works Give Feedback Articles
Legal
Terms of Use Privacy Policy Support VTUSync
Get in touch

Got a question?
support@vtusync.in

© 2026 vPlan · Powered by VTUSync Built Together • Sam × Rahul

Delete Item

Are you sure you want to delete this? This action cannot be undone.

Delete