This policy explains what personal data MFTC Trading Academy collects, why, and what control you have over it. It is written to comply with India's Digital Personal Data Protection Act, 2023.
Data Fiduciary: Yash Khajania (sole proprietor, trading as MFTC Trading Academy)
Contact: tradingwithyashkhajania@gmail.com
1. What we collect
You give us
- Name, email address, phone number
- Password (stored only as a secure hash — we never see it)
- Timezone and language preference
- Anything you send us by email or in a support message
Collected automatically
- IP address and approximate city
- Device and browser information, and a device identifier
- Sign-in history — time, device, IP, whether it succeeded
- Which lessons you watched and how far through
- Live class attendance
Why we track IP and device. Your account works on one device at a time. To enforce that — and to show you a sign-in history so you can spot an account you don't recognise — we have to record which device and IP signed in and when. It exists to protect your account and to prevent one paid login being shared between several people. We do not use it for advertising or profiling.
Handled by others, not us
We never see or store your card, UPI or bank details. Payments are processed by Razorpay, who handle that data under their own privacy policy and PCI-DSS obligations. We only receive a payment reference and whether it succeeded.
2. Why we use it
| Purpose | Data used |
|---|---|
| Create and run your account | Name, email, password hash |
| Give access to what you paid for | Payment reference, plan, expiry |
| Enforce one-device access | Device ID, IP, session tokens |
| Show your progress and unlock lessons in order | Watch progress, attendance |
| Send account emails — confirmation, password reset, class reminders | Email address |
| Detect suspicious sign-ins | IP, city, device, login history |
We do not sell your data, and we do not share it with advertisers.
3. Who we share it with
We do not sell your data or share it for advertising. We share it only with the service providers who help us run the Academy, and only the minimum each one needs:
- A cloud database and authentication provider, which stores your account and progress records on servers located in India
- A payment gateway, which handles your payment and is the only party that sees your card or banking details
- A video hosting and delivery provider, which streams course lessons to you
- A video conferencing provider, used to run live classes
- An IP geolocation service, used to turn an IP address into an approximate city for sign-in security
Each of these providers is bound by its own contractual and legal obligations to protect your data and may use it only to provide their service to us. If you need the identity of a specific provider — for example to exercise a right under the DPDP Act — write to us and we will tell you.
We may also disclose data where the law requires it.
4. How long we keep it
| Data | Retention |
|---|---|
| Account details | While your account is active, then 24 months |
| Sign-in history | 90 days |
| Session records | 90 days after the session ends |
| Payment records | As required by Indian tax law (currently 8 years) |
| Course progress | While your account is active |
5. Your rights under the DPDP Act
You can:
- Access — ask for a copy of the data we hold about you
- Correct — have inaccurate data fixed
- Erase — ask us to delete your data, where we are not legally required to keep it
- Withdraw consent — though this may mean we can no longer provide the service
- Nominate — appoint someone to exercise these rights if you die or become incapacitated
- Complain — to us first, and to the Data Protection Board of India if unresolved
To exercise any of these, email tradingwithyashkhajania@gmail.com. We will respond within 30 days.
6. Security
- Passwords are stored as salted hashes, never in readable form
- All traffic is encrypted over HTTPS
- Session tokens are stored hashed, and compared in constant time
- Database access is restricted per user by row-level security
- Video links are signed and expire, so they can't be shared
No system is perfectly secure. If a breach affects your data, we will notify you and the Data Protection Board as the DPDP Act requires.
7. Cookies and local storage
We use only what the site needs to function — keeping you signed in, remembering your device, and storing your language and region choice. No advertising or third-party tracking cookies.
8. Children
Our courses are not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.
9. International students
Our servers are in India. If you enrol from outside India, your data will be processed in India, which may have different protections than your own country. By enrolling, you consent to this transfer.
10. Changes
We may update this policy. Material changes will be notified by email or on the site.