Skip to content
InstiPilot
FeaturesContact
Log in

INSTIPILOT / POLICIES

Privacy Policy

How InstiPilot handles information across its website, institute management platform, desktop application, and connected services.

Last updated: 5 October 2026

ON THIS PAGE

Scope of this policyOur role and your institute’s roleInformation we processWhy information is usedAttendance, devices, and desktop useWhatsApp and other integrationsBrowser storage and website linksSharing and service providersStudent and children’s informationSecurity and retentionRequests, concerns, and updates

1. Scope of this policy

InstiPilot is an Institute Operating System for coaching institutes and educational organisations. This policy explains how information is handled when you visit our website, contact us, use the institute management platform or desktop application, or use connected communication and attendance features.

It covers features available to your institute. It does not mean that every integration or feature is enabled for every account. Third-party websites and services have their own privacy policies.

2. Our role and your institute’s role

For demo enquiries, account administration, support, and service security, InstiPilot handles information to operate its own service. For student, guardian, staff, and institute operational records, the institute generally decides what information to collect and how to use it; InstiPilot processes those records to provide the service on its behalf.

If you are a student, parent, guardian, or staff member, contact your institute first about the records it maintains. You can also contact InstiPilot for help directing a privacy request. We verify authority before sharing or changing institute data.

3. Information we process

  • Website and enquiries: information you choose to share when requesting a demo or contacting us, such as your name, institute, phone number, email, and message.
  • Accounts: user identity, contact details, organisation and branch membership, roles, permissions, and authentication-related records.
  • Institute records: enquiries, admissions, enrollments, student and guardian contact details, student photos, batches, classes, attendance, leaves, fee schedules, payments, refunds, concessions, staff records, and inventory where those features are used.
  • Files and communications: institute branding, uploaded documents, templates, attachments, WhatsApp message content and delivery records, and support correspondence.
  • Technical information: browser and device details, IP addresses and request logs where recorded by our infrastructure, application errors, security events, and integration identifiers needed for operation and troubleshooting.

Fee records document institute transactions. Do not enter banking credentials, card security codes, or unrelated sensitive information into notes or uploaded files.

4. Why information is used

Information is used to provide account access, organise institute records, operate attendance and fee workflows, deliver configured communications, respond to enquiries, provide support, investigate errors, maintain service security, and meet applicable legal obligations.

We may review operational information to improve reliability and usability. Access for support or investigation should be limited to the information needed for that purpose. InstiPilot does not sell personal data.

5. Attendance, devices, and desktop use

Where enabled, attendance workflows may process enrollment or staff identifiers, attendance times, NFC card identifiers, device identifiers, student photos, and device event records. Connected biometric devices may also supply user identifiers and attendance events. The information processed depends on the device and configuration; an attendance event is not itself a fingerprint or facial template.

The desktop application connects supported local hardware with the platform. Device configuration and connectivity can affect what information is transmitted. Institutes should explain their attendance practices and obtain any required permissions before using hardware or displaying personal information.

Attendance monitors may display a student’s name, photo, enrollment, and attendance outcome. Institutes should choose a suitable location and configuration to avoid unnecessary exposure of student information.

6. WhatsApp and other integrations

When an institute connects WhatsApp, InstiPilot may process business account and phone-number identifiers, connection credentials, templates, recipients, messages, attachments, and delivery events needed for the integration. Messages are initiated or configured by the institute; the institute is responsible for required recipient permissions and appropriate messaging.

A demo request made through our website opens WhatsApp. Your conversation is handled through WhatsApp and by our team. Meta and WhatsApp govern their own handling of that information. Disconnecting an integration does not automatically erase previous operational or message records; deletion requests are described in our Data Retention Policy.

7. Browser storage and website links

The institute application uses browser storage for functions such as maintaining a signed-in session and remembering login preferences. Shared devices should be signed out or secured when unattended.

This version of the public website does not include advertising pixels or optional analytics scripts. Infrastructure providers may still process technical request information to serve and protect the website. If optional tracking is introduced, this policy and any required choice controls will be updated.

Links to the institute application, WhatsApp, and other external services take you to those services; their own storage and privacy practices may apply.

8. Sharing and service providers

Information may be made available to authorised institute users according to their access permissions. InstiPilot uses infrastructure and service providers to host applications, authenticate users, store records and files, and operate integrations. Current infrastructure includes Supabase and Cloudflare; enabled WhatsApp features use Meta services.

We may disclose relevant information when required by law, to investigate misuse, or to protect the rights and safety of users and the service. Service providers may process information in different locations according to their infrastructure and arrangements. This policy does not promise storage exclusively in India.

9. Student and children’s information

The platform is managed by authorised institute staff. Institutes are responsible for providing appropriate notices to students, parents, guardians, and staff, and obtaining any consent or authorisation required by applicable law, including for children’s information.

Parents or guardians should contact the relevant institute about a child’s records. Please do not send a child’s full record or identity documents in an initial support enquiry; we will explain any information needed for verification.

10. Security and retention

We use access controls and technical safeguards intended to protect information. No service is completely risk-free. Institutes must manage permissions, keep devices and credentials secure, and notify us of suspected unauthorised access.

Information is retained as needed to operate the service and address applicable record-keeping, security, dispute, and legal requirements. Different record types may require different retention periods. Archiving an enrollment or removing a record from a screen is not necessarily permanent deletion.

Deletion may involve removing or anonymising active records. Backups and restricted logs may retain information until their applicable retention or rotation period ends. We explain relevant limitations when handling a verified deletion request.

11. Requests, concerns, and updates

You may contact us to request access, correction, deletion, or help with a privacy concern, subject to verification and applicable law. Where processing depends on consent, you may ask how to withdraw it; this can affect the relevant feature and does not automatically remove records that must be retained.

Email admin@instipilot.com. For records maintained by an institute, identify the institute and your relationship to it. We may need to coordinate with its authorised administrator.

We may revise this policy as the service changes. The date at the top identifies the latest version. See our Data Retention Policy for the request process.

InstiPilot home
Privacy PolicyTerms of ServiceData Retention Policy

Questions? admin@instipilot.com