top of page

FinLab Privacy Policy

Effective Date: 14 August 2026
Last Updated: 14 August 2026

FinLab respects the privacy of its users and is committed to protecting personal information collected and processed through the FinLab application.

FinLab is operated by Unnayan Educational Services Pvt. Ltd. under its CforCommerce educational initiative.

This Privacy Policy explains what information FinLab collects, why it is collected, how it is used and protected, when it may be shared, and the choices available to users regarding their personal information.

1. About FinLab

FinLab is an educational and programme-management application designed to support financial literacy, commerce education and related learning programmes.

FinLab may be used by students, teachers, facilitators, Lab Administrators, schools, educational institutions, programme administrators and authorised institutional or government stakeholders.

Some users may create their own FinLab accounts. Student accounts may also be created or administered by authorised Lab Administrators for participation in FinLab programmes.

2. Information We Collect

The information collected depends upon the user's role and the FinLab features being used.

A. Identity and Profile Information

FinLab may collect:

  • Name

  • School or educational institution

  • Class or grade

  • Age and/or date of birth

  • Gender

  • Email address

  • Mobile number

  • User identification information

  • User role, such as student, teacher, facilitator or administrator

  • Other information reasonably required to administer the user's participation in a FinLab programme

B. Learning and Programme Information

FinLab may collect, generate or maintain information relating to participation and learning, including:

  • Attendance

  • Check-in records

  • Sessions attended

  • Activities or modules undertaken

  • Module progress

  • Module completion

  • Quiz and assessment responses

  • Assessment scores and outcomes

  • Certificates earned, issued or eligible to be issued

  • Programme completion information

  • Feedback and responses submitted through FinLab

This information is primarily used for educational delivery, attendance management, programme monitoring, assessment, certification and reporting.

3. Camera Access

FinLab may request access to the device camera when a user chooses to use the QR-code scanning functionality.

Camera access is used for scanning QR codes required for FinLab programme functions.

FinLab does not require access to the camera for continuous recording.

Camera access is activated when the user uses a feature requiring QR-code scanning and is subject to the permissions provided through the user's device.

4. Approximate Location for Attendance

FinLab may request access to the user's approximate location only when the user performs an attendance or check-in function.

Approximate location is used to support verification of attendance at the relevant FinLab programme or activity location.

FinLab:

  • Does not require precise location for attendance;

  • Does not require background location access for this purpose; and

  • Does not use location for continuous tracking.

Location access is associated with the attendance/check-in functionality and is subject to the permission provided by the user through the device.

If location permission is not granted, location-dependent attendance functionality may not operate as intended.

5. Notifications

FinLab may send device notifications relating to:

  • Learning progress

  • Programme or session reminders

  • Pending or completed modules

  • Module completion

  • Certificates

  • Other important FinLab programme communications

Users may manage notification permissions through their device settings.

6. Device Permissions FinLab Does Not Require

FinLab's current functionality does not require access to:

  • Microphone

  • Bluetooth devices

  • Contacts

  • Photos

  • Photo library

  • User files

  • Precise location

FinLab intends to request only those device permissions reasonably necessary for the functionality being used.

7. Technical and Usage Information

FinLab may automatically process limited technical and application-usage information required to operate, secure, troubleshoot and improve the application.

This may include information such as:

  • Device type

  • Operating system

  • Application version

  • IP address

  • Login and authentication events

  • Technical identifiers

  • Application interactions

  • Error information

  • Diagnostic information

  • Application performance information

8. Google Analytics

FinLab uses Google Analytics to help understand how the application is being used and to improve application functionality, reliability and user experience.

Google Analytics may process application-usage and technical information in accordance with Google's applicable privacy and data-processing terms.

FinLab does not use Google Analytics to provide targeted advertising to students.

FinLab does not use student personal information for advertising purposes.

Where required for users who are children, analytics functionality may be restricted, configured or disabled as appropriate to comply with applicable privacy and platform requirements.

9. How We Use Information

Information collected or processed through FinLab may be used to:

  • Create and manage user accounts

  • Authenticate users

  • Enrol students and other authorised users

  • Deliver educational programmes

  • Record and verify attendance

  • Facilitate QR-based programme functionality

  • Record module participation

  • Track learning progress

  • Conduct quizzes and assessments

  • Record assessment results

  • Determine programme or module completion

  • Issue and verify certificates

  • Generate educational and programme reports

  • Provide authorised programme dashboards

  • Communicate programme information

  • Send progress, programme and certificate notifications

  • Provide technical and user support

  • Maintain application and account security

  • Detect unauthorised access or misuse

  • Diagnose technical issues

  • Improve FinLab functionality and programme delivery

  • Meet contractual, regulatory or legal requirements

Personal information is intended to be processed only for legitimate educational, administrative, programme, technical, security or legal purposes.

10. Students and Children's Privacy

FinLab is an educational application and may process personal information relating to users below the age of 18.

We recognise that children's personal information requires additional care and protection.

Student accounts may be created and managed by authorised Lab Administrators as part of a school, district or other authorised educational programme.

Where parental, guardian, institutional or other consent or authorisation is required under applicable law, FinLab and/or the relevant participating institution will follow the applicable consent and authorisation requirements.

FinLab does not:

  • Sell children's personal information;

  • Use children's personal information for targeted advertising; or

  • Use children's personal information for commercial behavioural advertising.

Information relating to students is intended to be used primarily for educational delivery, attendance, learning assessment, certification, programme monitoring and related administration.

11. Who Can Access Personal Information

Access to personal information is restricted according to authorised roles and programme requirements.

At present, authorised personnel of CforCommerce / Unnayan Educational Services Pvt. Ltd. may access student-level and programme information where required for:

  • Programme administration

  • User support

  • Attendance and programme monitoring

  • Assessment

  • Certification

  • Reporting

  • Technical support

  • Security and compliance

Where FinLab is implemented as part of a district or government-supported programme, relevant information may also be made available to an authorised District Administration or other authorised government/programme authority where required for authentication or verification of programme reports, implementation, outcomes or related programme purposes.

Access will be limited to information reasonably required for the relevant authorised purpose.

Where practical, aggregated or non-identifiable information may be used for general programme and impact reporting.

12. Third-Party Service Providers

FinLab uses third-party technology service providers that assist in operating and supporting the application.

These currently include:

Supabase

FinLab uses Supabase for database, backend and related application infrastructure services.

Personal information processed through FinLab may therefore be stored or processed using infrastructure supporting the FinLab Supabase environment.

Google Analytics

FinLab uses Google Analytics for application analytics and improvement.

Third-party service providers process information in accordance with their applicable contractual, security and privacy terms and the configuration used by FinLab.

FinLab may use additional service providers in future where reasonably necessary to operate, secure or improve the application. This Privacy Policy will be updated where a material change affects the processing of personal information.

13. Advertising and Sale of Personal Information

FinLab does not contain third-party advertising.

FinLab does not sell or rent personal information.

FinLab does not use student personal information for targeted advertising.

14. Data Security

FinLab uses reasonable administrative, organisational and technical measures designed to protect personal information against:

  • Unauthorised access

  • Unauthorised disclosure

  • Misuse

  • Alteration

  • Accidental loss

  • Destruction

Measures may include authentication, access controls, secure communications, restricted administrative access, database security, monitoring and other appropriate safeguards.

While reasonable safeguards are used, no electronic transmission, application or storage system can be guaranteed to be completely secure.

15. Data Retention

Personal information is retained only for as long as reasonably required for the purposes for which it was collected or subsequently legitimately processed.

This may include retention required for:

  • Programme participation

  • Attendance records

  • Assessment records

  • Learning progress

  • Certification and certificate verification

  • Programme reporting

  • Institutional or contractual requirements

  • Security

  • Grievance handling

  • Legal or regulatory requirements

Where personal information is no longer required, it may be deleted, anonymised or otherwise securely disposed of in accordance with applicable requirements.

16. User Rights and Requests

Subject to applicable law and appropriate verification, a user, parent, lawful guardian or authorised representative may request:

  • Access to relevant personal information;

  • Correction of inaccurate or incomplete information;

  • Updating of personal information;

  • Deletion or erasure of personal information;

  • Withdrawal of consent where processing is based upon consent; and

  • Information concerning the processing of personal information.

We may request information reasonably necessary to verify the identity or authority of the person making a request.

Certain information may continue to be retained where retention is necessary for an authorised programme purpose or required by applicable law.

17. Account and Data Deletion

Users who create a FinLab account may request deletion of their account and associated personal information.

A deletion request may be initiated:

  • Through the account-deletion functionality or request mechanism provided within FinLab; or

  • Through the FinLab Account & Data Deletion facility available on the CforCommerce website.

Where a student's account has been created or administered by a Lab Administrator, school, district programme or other authorised institution, the deletion request may require verification and, where appropriate, coordination with the relevant authorised administrator or institution.

Upon a valid deletion request, the account and associated personal information will be deleted except for information that must or may legitimately be retained for purposes including legal compliance, security, certification, programme records or other applicable requirements.

18. Withdrawal of Permissions

Users may withdraw device permissions through their device settings.

Withdrawal of a device permission may prevent functionality dependent upon that permission from operating.

For example:

  • Disabling camera access may prevent QR-code scanning.

  • Disabling location access may prevent location-supported attendance verification.

  • Disabling notifications may prevent FinLab notifications from being displayed on the device.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • FinLab functionality

  • Information collected or processed

  • Technology or service providers

  • Programme requirements

  • Legal or regulatory requirements

  • Privacy and security practices

The most recent version will be published on the CforCommerce website with its effective or last-updated date.

Where appropriate, material changes may also be communicated through the FinLab application or other suitable means.

20. Contact and Privacy Grievances

For questions concerning this Privacy Policy, personal information processed through FinLab, correction requests, account or data deletion requests, or privacy-related grievances, please contact:

Unnayan Educational Services Pvt. Ltd.
CforCommerce / FinLab

Email: info@cforcommerce.com

Corporate Office:
Suite 558, 715-A Spencer Plaza
Mount Road
Chennai - 600 002
Tamilnadu, India

Please mention “FinLab Privacy” in the subject line of your communication and provide sufficient information to enable us to identify and respond to the relevant request.

©2022 by C for Commerce.

bottom of page