1. Who we are
Hackemics ("we", "us", "our") is a challenge marketplace that connects college students with company challenges. For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDP Act), the data fiduciary is:
- Legal entity: [LEGAL ENTITY NAME]
- Registered address: [REGISTERED ADDRESS]
- Privacy contact: [PRIVACY CONTACT EMAIL]
This notice explains what personal data we process in the current product. It is written in plain language and is informed by the DPDP Act. It is not a claim of certification or compliance.
2. Information we collect
Depending on your account type, we may process:
Account & profile
- Email address and password (stored as a secure password hash)
- Role (student or company)
- Email verification status and related verification tokens
- Student profile: display name, public slug, university, bio, skills, profile photo URL (https link you provide), XP/level/streak fields maintained by the product
- Optional year or proof links you enter during signup (currently stored as part of bio text where provided)
- Company profile: organisation name, slug, industry, description, logo URL, website and social links you choose to add
- Notification preferences (challenge, submission, feedback, and email toggles)
Challenge activity
- Challenge participation records
- Submissions (including content such as GitHub URL, demo URL, and notes) and related file metadata where used
- Company ratings and feedback (score, feedback text, shortlisted, winner)
- Badge awards and XP events associated with your student profile
Authentication & security
- Session cookies (httpOnly session token used to keep you signed in) and session records
- Password reset tokens when you request a reset
Company challenge assets
- Dataset and submission-template files uploaded by companies for challenges (stored via the product's configured object storage when enabled)
We do not operate a separate analytics SDK or advertising cookie stack in the current MVP codebase. Browser and network logs may be produced by the hosting environment outside this application's control.
3. How we use information
- Create and secure accounts, and keep you signed in
- Operate student and company dashboards
- Enable challenge discovery, joining, submission, and review
- Show company feedback/ratings to the submitting student on their own work
- Support profile completeness, proof-of-work, and portfolio views for the account holder
- Respect notification preferences you save (delivery wiring may evolve over time)
- Process company challenge posting / wallet or payment flows when those features are used
- Respond to support, security, and account-deletion requests
4. Student profiles and proof of work
Student profile fields and submission history are used inside Hackemics so you can manage your work and so participating companies can review submissions on challenges they own. Public company profile pages may show company information and challenge listings; student email addresses are not part of the public company profile response.
5. Challenge participation and submissions
When you join a challenge and submit work, the company that owns that challenge can access your submission content (for example GitHub/demo links and notes) and related student display information needed to review it. Do not submit content you are not entitled to share.
6. Company feedback and ratings
Companies may assign a score, written feedback, shortlist status, and winner status to a submission. That review is associated with the specific submission and is visible to the student who owns it. Students cannot edit company ratings.
7. Authentication and security
Passwords are stored hashed. Sessions use an httpOnly cookie. You can change your password while signed in, and password reset invalidates existing sessions for that account. Keep your credentials confidential and sign out on shared devices.
8. Storage and service providers
Application data is stored in the product database (PostgreSQL). Company sprint assets may be stored using configured object storage (for example Vercel Blob when enabled). Email verification and password-reset links are generated by the application; outbound email delivery depends on the environment configuration and may be logged for development.
Hosting, database, and storage providers process data as needed to run the service. We do not list additional marketing vendors that are not present in the current product.
9. External links
Submissions and profiles may include links to third-party sites (for example GitHub or demo URLs). Those sites have their own privacy practices. Hackemics is not responsible for content or processing on sites we do not control.
10. Retention
We retain account and activity data while your account remains active and as needed to operate the platform, resolve disputes, and meet legal obligations. Specific retention schedules beyond account lifetime are not yet published — contact [PRIVACY CONTACT EMAIL] for questions.
11. Account deletion
Students can delete their account from Settings. Deletion is a hard delete of the user record and related student-owned data via the product's database relationships, including sessions, tokens, notification records, student profile, participations, submissions, ratings on those submissions, badge awards, and XP events.
Important about submissions: Under the current implementation, deleting a student account removes that student's participations and submissions (and related ratings) from the database. Company challenge pages remain, but that student's submission history on those challenges will no longer be available in-app. External files reachable only by URL (for example links you pasted) are not automatically deleted from third-party sites. Company-uploaded challenge assets are not deleted when a student account is deleted.
12. Your rights and requests
Subject to applicable law, you may request access, correction, or erasure of your personal data, or withdraw consent where processing is based on consent. Use in-product settings where available (profile edits, notification preferences, password change, account deletion) or email [PRIVACY CONTACT EMAIL].
13. Consent
Creating an account requires accepting our Terms & Conditions and this Privacy Policy. You may withdraw consent for optional processing (for example turning off notification preferences) where the product allows it. Withdrawal does not affect processing already completed or processing we must continue under law or contract.
14. Grievance / contact
For privacy questions or complaints, contact [PRIVACY CONTACT EMAIL]. We will work to acknowledge and address requests in a reasonable time.
15. Children and students
Hackemics is designed for college students and companies. If you are below the age at which you can lawfully consent to online services in your jurisdiction, you should not create an account without a parent or guardian as required by applicable law. Contact us if you believe we have collected data from a child inappropriately.
16. International processing
The service may be hosted on infrastructure that stores or processes data in locations outside your home country, including facilities used by our hosting and storage providers. By using Hackemics you understand that processing may occur in those locations as needed to provide the service.
17. Changes
We may update this Privacy Policy as the product evolves. The "Last updated" date at the top will change when we do. Continued use after an update means you accept the revised notice, except where applicable law requires additional consent.