A working draft for BeanWise and its lawyer to review. It is not in force yet, and anything marked CLIENT TO CONFIRM is still an open question.
Privacy notice
Last updated 24 Sep 2026 · DraftWhat we collect when you book a class or write to us, why we need it, who else sees it, how long we keep it, and how to ask us to show, correct or delete it. There are no accounts, no passwords and no advertising trackers.
On this page
Who we are
[CLIENT TO CONFIRM: registered legal name of the business that sells these classes] runs beanwiseacademy.com and decides how your personal data is used. Under India's Digital Personal Data Protection Act, 2023, that makes us the Data Fiduciary for it.
Questions about your data, and requests to use your rights, go to [CLIENT TO CONFIRM: name and email of the person who answers questions about personal data, if not the grievance officer]. Complaints go to our grievance officer, [CLIENT TO CONFIRM: grievance officer's name, designation, email and phone].
The short version
- To book a seat we need your name, email address and mobile number, and a name for every seat. A company GSTIN is optional
- We use them to hold your seats, send your ticket, put names on the roll, reach you about the class and keep the records tax law requires
- You pay on Razorpay. We never see your card, UPI or bank details
- There are no accounts and no passwords. You sign in with a six digit code we email you
- A few small cookies make sign-in and tickets work. There are no advertising or analytics trackers
- After a class, your ticket asks how it went. Your answer goes to the office, and the office can choose to show your first name and your words on the course page
- You can ask to see, correct or delete your data, or complain, by writing to us
What we collect, and why
| What | When | Why |
|---|---|---|
| Your name, email address and mobile number | When you book a seat | To hold your booking, send your ticket email, which shows what you paid, and reach you about your class: a reminder the day before, and a note if it moves or is cancelled |
| The name for every seat | When you book a seat | To put the right names on the roll and on your ticket |
| A company GSTIN, if you add one | When you book a seat | To apply the right GST and show it on your tax documents |
| Your booking: the class, the seats, what you paid and the GST in it, and Razorpay's order and payment references | When you book and pay | To confirm your payment, run the class, handle changes and refunds, and keep the accounts the law requires |
| What you type into a form: your name, email address, WhatsApp number, city, the course you ask about and your message | When you use the contact form, a waitlist or newsletter box, or Can't make it? on a ticket | To reply to you, and for a waitlist or newsletter box, to email you when a new class opens |
| Your email address and a scrambled copy of your sign-in code | When you ask for a sign-in code | To check the code you type, so you can see your bookings. We never store the code itself |
| Your IP address, and signals about your browser | When you use a form, check out or sign in | To stop spam and abuse: we limit repeated attempts from one address, and Google reCAPTCHA checks that a person is using the form |
| The same booking details, typed in by the office, and a note of how you paid | If you book through the office, by phone, bank transfer or another shop | To give you a seat and a ticket, exactly as if you had booked online |
| Your answer about a class you came to, anything you add, and your first name | When you answer the question on your ticket after a class | To tell the office how the class went. The office can choose to show your first name, your answer, your words and the month of the class on that course's page. [CLIENT TO CONFIRM: that reviews can be shown on the course page with the writer's first name, and whether the writer must be told this where they write it] |
- Your name, email address and mobile number
- WhenWhen you book a seat
- WhyTo hold your booking, send your ticket email, which shows what you paid, and reach you about your class: a reminder the day before, and a note if it moves or is cancelled
- The name for every seat
- WhenWhen you book a seat
- WhyTo put the right names on the roll and on your ticket
- A company GSTIN, if you add one
- WhenWhen you book a seat
- WhyTo apply the right GST and show it on your tax documents
- Your booking: the class, the seats, what you paid and the GST in it, and Razorpay's order and payment references
- WhenWhen you book and pay
- WhyTo confirm your payment, run the class, handle changes and refunds, and keep the accounts the law requires
- What you type into a form: your name, email address, WhatsApp number, city, the course you ask about and your message
- WhenWhen you use the contact form, a waitlist or newsletter box, or Can't make it? on a ticket
- WhyTo reply to you, and for a waitlist or newsletter box, to email you when a new class opens
- Your email address and a scrambled copy of your sign-in code
- WhenWhen you ask for a sign-in code
- WhyTo check the code you type, so you can see your bookings. We never store the code itself
- Your IP address, and signals about your browser
- WhenWhen you use a form, check out or sign in
- WhyTo stop spam and abuse: we limit repeated attempts from one address, and Google reCAPTCHA checks that a person is using the form
- The same booking details, typed in by the office, and a note of how you paid
- WhenIf you book through the office, by phone, bank transfer or another shop
- WhyTo give you a seat and a ticket, exactly as if you had booked online
- Your answer about a class you came to, anything you add, and your first name
- WhenWhen you answer the question on your ticket after a class
- WhyTo tell the office how the class went. The office can choose to show your first name, your answer, your words and the month of the class on that course's page. [CLIENT TO CONFIRM: that reviews can be shown on the course page with the writer's first name, and whether the writer must be told this where they write it]
We don't ask for or store your card number, UPI PIN or bank login. We don't sell your data and we don't use it for advertising.
We only email you about your bookings and the things you asked for. We send news about new classes only if you asked for it, by typing your email into a box that says so. Booking a class never signs you up.
[CLIENT TO CONFIRM: whether we send one email the day after a class asking how it went]
Other people's names
When you book seats for other people, you give us their names. Please only give us the names of people who know you are booking for them.
We use those names for the roll, the ticket and the class itself, and nothing else. Anyone with your booking code can see them on the ticket, so share it only with the people coming.
Who else sees it
| Who | What they do | What they get |
|---|---|---|
| Razorpay | Processes your payment and any refund | Your name, email address and mobile number, the amount and your booking code |
| Amazon Web Services | Hosts this website and its database, and sends our emails. [CLIENT TO CONFIRM: that the booking database is hosted in AWS's Mumbai region] | The data described on this page, stored on servers in India |
| Google (reCAPTCHA) | Checks that forms and the checkout are used by people rather than bots | Information about your browser and how you use the page |
| Our office email inbox, run by [CLIENT TO CONFIRM: the office's email provider] | Receives a copy of every booking and every form, so a person can act on it | Your booking or form details |
| WhatsApp (Meta) | Only if you choose to message us on WhatsApp | Whatever you send in that chat |
- Razorpay
- What they doProcesses your payment and any refund
- What they getYour name, email address and mobile number, the amount and your booking code
- Amazon Web Services
- What they doHosts this website and its database, and sends our emails. [CLIENT TO CONFIRM: that the booking database is hosted in AWS's Mumbai region]
- What they getThe data described on this page, stored on servers in India
- Google (reCAPTCHA)
- What they doChecks that forms and the checkout are used by people rather than bots
- What they getInformation about your browser and how you use the page
- Our office email inbox, run by [CLIENT TO CONFIRM: the office's email provider]
- What they doReceives a copy of every booking and every form, so a person can act on it
- What they getYour booking or form details
- WhatsApp (Meta)
- What they doOnly if you choose to message us on WhatsApp
- What they getWhatever you send in that chat
Reviews the office chooses to show are public. Anyone can read the first name, the answer, the words and the month on the course page.
We may also share data where the law requires it, for example with tax authorities or in answer to a lawful request.
Cookies
| Cookie | What it's for | How long |
|---|---|---|
| bw_otp | Ties a sign-in code to the browser that asked for it, so nobody else can use up your code | 15 minutes |
| bw_session | Keeps you signed in on this browser after you type a sign-in code, so you can see your bookings, see your next class at the top of the site, and skip retyping your details at checkout | 30 days |
| bw_seen | Remembers that this browser has signed in with a code before, so the ticket door can welcome you back | 1 year, or until you sign out |
| bw_ticket_ok | Set after you pay. Lists the booking codes this browser was given, so My ticket and the bar at the top of the site can take you straight to your ticket, and so those tickets still open when our limit on repeated ticket lookups kicks in | 24 hours |
| bw_studio | Signs BeanWise office staff in to the office's booking tool. Visitors never get this one | 12 hours |
| bw_preview | Set only when you open a draft link from the BeanWise office, so you can see an unpublished page (the site framework sets its own preview cookie with it) | up to 7 days |
| _GRECAPTCHA (Google) | Part of reCAPTCHA's check that you are a person. Set by Google on its own domain | Up to six months |
| Razorpay's cookies | Set by Razorpay on its own domain when you open the payment window, to process and protect the payment | Set by Razorpay |
- bw_otp
- What it's forTies a sign-in code to the browser that asked for it, so nobody else can use up your code
- How long15 minutes
- bw_session
- What it's forKeeps you signed in on this browser after you type a sign-in code, so you can see your bookings, see your next class at the top of the site, and skip retyping your details at checkout
- How long30 days
- bw_seen
- What it's forRemembers that this browser has signed in with a code before, so the ticket door can welcome you back
- How long1 year, or until you sign out
- bw_ticket_ok
- What it's forSet after you pay. Lists the booking codes this browser was given, so My ticket and the bar at the top of the site can take you straight to your ticket, and so those tickets still open when our limit on repeated ticket lookups kicks in
- How long24 hours
- bw_studio
- What it's forSigns BeanWise office staff in to the office's booking tool. Visitors never get this one
- How long12 hours
- bw_preview
- What it's forSet only when you open a draft link from the BeanWise office, so you can see an unpublished page (the site framework sets its own preview cookie with it)
- How longup to 7 days
- _GRECAPTCHA (Google)
- What it's forPart of reCAPTCHA's check that you are a person. Set by Google on its own domain
- How longUp to six months
- Razorpay's cookies
- What it's forSet by Razorpay on its own domain when you open the payment window, to process and protect the payment
- How longSet by Razorpay
Our own cookies, the ones starting bw_, are set by this site, can't be read by scripts on the page, are sent only over a secure connection, and exist only to make sign-in, tickets, draft previews and security work. We don't use analytics, advertising or tracking cookies. If you block cookies you can still browse and book; signing in to My tickets needs them.
This site is protected by reCAPTCHA, and the Google Privacy Policy and Terms of Service apply.
How long we keep it
- Bookings, payments and anything on a tax document: as long as tax law requires. [CLIENT TO CONFIRM: the retention period for booking and tax records, confirmed by the CA; GST law is understood to require at least 72 months after the annual return is due]
- Form messages, and waitlist and newsletter emails: [CLIENT TO CONFIRM: how long form messages and newsletter emails are kept], or until you ask us to stop
- Sign-in codes: a code stops working after ten minutes or five wrong tries. [CLIENT TO CONFIRM: how long the hashed sign-in codes are kept]
- A checkout that was never paid: [CLIENT TO CONFIRM: how long the details of an unpaid checkout are kept]
- Server logs, which can include IP addresses and email addresses: [CLIENT TO CONFIRM: how long server logs are kept, at least one year once the DPDP Rules require it]
- Reviews: [CLIENT TO CONFIRM: how long reviews are kept, and whether one comes off the course page after a time]
To be straight with you: automatic deletion is not switched on yet. Until it is, we delete on request, except where the law requires us to keep a record.
Where it's stored and how we protect it
Your data is stored on servers in India. reCAPTCHA is Google's service and may process data outside India.
Everything travels over an encrypted connection. Sign-in codes are stored scrambled, sign-in cookies are signed so they can't be forged, and only named office staff can open the booking tool, each with a code sent to their own email.
If a breach affects your data, we will tell you and the Data Protection Board of India, as the law requires.
Your rights
Under the Digital Personal Data Protection Act, 2023, you can:
- Ask for a summary of the personal data we hold about you, and who we have shared it with
- Ask us to correct, complete or update it
- Ask us to delete it, unless the law requires us to keep it, as it does for booking and tax records
- Withdraw any consent you gave, for example to news about classes, as easily as you gave it
- Nominate someone to use these rights for you if you die or can no longer use them yourself
- Complain to us, and then to the Data Protection Board of India
How: write to [CLIENT TO CONFIRM: name and email of the person who answers questions about personal data, if not the grievance officer] from the email address you booked with, and include your booking code if you have one. We may email a sign-in code to that address to check it's you. We aim to reply within [CLIENT TO CONFIRM: how many days BeanWise takes to answer a data request], and always within 90 days.
You can't remove a review yourself once it is sent, but you can write to us to have it taken off the course page or deleted. [CLIENT TO CONFIRM: that a writer's request to take down or delete their review is honoured, and how quickly]
If you are not happy with our answer, you can complain to the Data Protection Board of India once it is taking complaints.
Parts of the Act and its Rules come into force in stages up to May 2027. We honour these rights now.
Children
Bookings are made by adults. [CLIENT TO CONFIRM: whether under 18s may attend] If a seat is for someone under 18, the booking must be made by their parent or lawful guardian.
Changes to this notice
When we change this notice we update the date at the top. If a change affects how we use data you have already given us, we will email you first.