Your data, treated like ours.
Last updated: April 30, 2026. We collect the minimum we need to run Ontesta Mini well, and we never sell your data. This policy explains exactly what we keep, why, and how to get rid of it whenever you want.
1. What we collect
- Account info — email, display name, and a hashed password (we never store your raw password).
- Payment info — purchase amount, plan or series ID, transaction reference. Card / UPI / bank details are handled by Razorpay and never reach our servers.
- Usage info — what you've watched and how far through, your bookmarks (My List), and basic device/browser info in our access logs.
- Communications — when you email us or message us on WhatsApp, we keep that conversation so we can help you better next time.
2. What we don't collect
- We don't use third-party advertising trackers.
- We don't sell or rent your personal data to anyone, ever.
- We don't read your private messages or email beyond what you send us directly.
3. How we use it
We use the data above to:
- Authenticate your sessions and keep your account secure.
- Deliver content you've purchased and remember where you left off.
- Show you a sensibly personalised library — "Continue watching", "My List", category recommendations.
- Process payments and prevent fraud.
- Improve the service — debugging, performance, and product decisions based on aggregate trends.
- Send you transactional emails (purchase receipts, password resets). Marketing emails are opt-in.
4. Cookies & local storage
We use a single authentication token in your browser's local storage to keep you signed in. We do not use cross-site tracking cookies. Your browser may set a short-lived cookie via Cloudflare for bot protection — this is not used for advertising.
5. Third parties we share with
We share the minimum required data with carefully chosen vendors:
- Razorpay — to process payments.
- Cloud hosting and CDN providers — to serve the platform and stream videos.
- Email service provider — for transactional and (opt-in) marketing email.
Each vendor is contractually obligated to protect your data and use it only to perform the service we've engaged them for.
6. How long we keep it
- Account info — for as long as your account is active.
- Payment receipts — 7 years (Indian tax law requirement).
- Watch progress & bookmarks — until you delete them or your account.
- Server access logs — 90 days, then anonymised.
7. Your rights
You can, at any time:
- Request a copy of all the data we hold about you.
- Ask us to correct inaccurate information.
- Delete your account and all associated personal data (excluding payment records we are legally required to retain).
- Withdraw consent for marketing emails.
Email privacy@ontestamini.com from your registered address and we'll act within 30 days.
8. Children
Ontesta Mini is suitable for general audiences but is not designed for children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has signed up, please contact us and we'll delete the account.
9. Security
We use bcrypt-hashed passwords, JWT tokens with short expiry, HTTPS everywhere, and routine dependency audits. No system is perfectly secure — if you suspect a breach of your account, please email security@ontestamini.com immediately.
10. Changes to this policy
We'll notify you of meaningful changes via email and a banner on the platform at least 14 days before they take effect.