Legal
Privacy Policy
Last updated: 29 June 2026
Vantor is software for coaching institutes, operated by NOESIS TECHNOLOGY(Udyam Reg. No. UDYAM-JK-07-0090332), Jammu, Jammu & Kashmir, India. This policy explains, in plain terms, what personal data passes through Vantor, why, who else touches it, how long we keep it, and the rights you have under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
1.Who we are.
“Vantor”, “we”, “us” and “our” mean NOESIS TECHNOLOGY operating the Vantor platform at vantorapp.com and its institute subdomains (yourinstitute.vantorapp.com). Registered office: Opp. House No. 188, Sanjay Nagar, Ext. 4, Near BBN Public School, Jammu, Jammu & Kashmir, District Jammu – PIN 180010, India.
2.The two roles — read this first.
- The institute is our customer. For an institute’s own signup and billing data, we are the Data Fiduciary.
- Students and parents are the institute’s people. Everything an institute enters about its students, parents and teachers is decided and controlled by the institute. For that data, the institute is the Data Fiduciary and Vantor is only the Data Processor — we store and process it strictly on the institute’s instructions, never for our own purposes.
- If you are a parent or student: your relationship is with the institute. To access, correct or delete your data, contact the institute first; we will help them honour your request.
3.What we collect, and why.
- About the institute & team (we are the Fiduciary): institute name, subdomain and city; owner and staff name, email and phone; password (stored only as a one-way hash — we never see it); subscription, plan and payment status; and basic technical logs (request id, time, route, error, signed-in user id). We never log passwords, message contents, request bodies, or secrets.
- About students, parents & teachers (the institute is the Fiduciary; we only process): student and parents’ names, parent phone number(s) and home address, class/section/batch, subjects, enrolment and dropout dates, fee structure and payment records, attendance, test and board-exam marks, student photographs, teacher contact details, staff notes, and — where the institute uses WhatsApp — the consent record, opt-out status, and the messages exchanged with parents.
4.What we never do.
- We do not sell personal data.
- We do not advertise to students or build behavioural profiles of children.
- We run no analytics, advertising, or third-party tracking scripts anywhere in the product — this is verifiable in our code, not just a promise.
- Messaging is utility only (fee reminders, attendance, report cards), sent by the institute through its own WhatsApp account. There are never marketing messages to children.
5.Cookies and tracking.
Vantor uses only essential cookies needed to keep you securely signed in. We use no analytics cookies, no advertising cookies, and no cross-site trackers. See our Cookie Policy for details.
6.Who we share data with.
We share data only with the infrastructure providers needed to run Vantor, each under its own terms, and only as far as the service requires:
- Supabase (database, authentication, file storage) — stores all application data with per-institute row-level isolation. Hosting region: Mumbai, India (ap-south-1).
- Vercel (hosting) — serves the website and app.
- Razorpay (payments) — receives the institute owner’s name, email and phone to create the subscription. We never receive or store card or bank-account numbers.
- Meta / WhatsApp (Cloud API) — delivers the messages an institute sends to parents; the institute connects its own WhatsApp Business account and is billed by Meta directly.
- Google (optional “Continue with Google” sign-in) — receives your Google-verified email only if you choose that login.
We also disclose data where the law requires it. We keep this list current.
7.Where data lives and how we protect it.
Data is stored with the providers above. We protect it with per-institute isolation enforced in the database (one institute can never read another’s data), encryption in transit (HTTPS), encryption at rest for the most sensitive secrets (WhatsApp access credentials are stored as AES-256-GCM ciphertext, never in plain text), role-based access (only an institute’s owner — not its assistants — can see its WhatsApp credentials), and redacted logging that excludes passwords, message bodies, and secrets. Our operator can see institute-level account and billing information to run the business, but does not have a routine way to view individual students’ personal details; any exceptional, support-driven access is logged.
8.Report links and student photos.
- Parent report links are created by the institute and let anyone holding the link view that one child’s progress until the link expires (30 days). Treat the link like a key.
- Student photos uploaded by the institute are stored under unguessable addresses; keep photo sharing within the institute.
9.How long we keep data.
We keep an institute’s data while its subscription is active, and we keep it safely even after a subscription ends — cancelling never deletes your data, and you can reactivate at any time to pick up right where you left off. Data is only permanently erased when an institute owner explicitly requests deletion of their account, and that request can be undone for a short window before it takes effect (an export is available first). Some records (e.g. tax and payment records) may be retained longer where law requires.
10.Your rights (DPDP Act).
You may access a summary of your data, correct or complete it, request erasure, nominate someone to exercise your rights, and raise a grievance. You may withdraw consent as easily as you gave it. Institute owners and staff: email us. Parents and students: contact your institute first; we will assist them.
11.Children’s data.
Many students are minors. The institute is responsible for having the right to hold that data — including any verifiable parental consent the law requires — and for using it only for genuine educational and child-safety purposes. As processor, we store the institute’s WhatsApp consent evidence and enforce opt-outs. We do not profile children, serve them ads, or track their behaviour.
12.Grievance Officer.
For any privacy question, complaint, or to exercise your rights, contact our Grievance Officer (full details on the Grievance Redressal page): Kanishk Mahajan · contact@vantorapp.com · +91 78895 24600. We acknowledge complaints within 24 hours and aim to resolve within 15 days (IT Rules, 2021); DPDP requests are answered within the statutory timeline.
13.Changes.
We may update this policy; the “Last updated” date will change and we will tell you about material changes through the app or by email before they take effect.
14.Contact.
NOESIS TECHNOLOGY (Vantor) · Opp. House No. 188, Sanjay Nagar, Ext. 4, Near BBN Public School, Jammu, Jammu & Kashmir, District Jammu – PIN 180010, India · contact@vantorapp.com · +91 78895 24600.