Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Spurrin ("we") collects, uses, and safeguards information when institutions and their users use Exper Attend (the "Service").
1. Information We Collect
- Institution & staff data: college name, admin/faculty names, emails, phone numbers, and roles.
- Student data: name, roll number, email, phone, department, and optional parent contact details.
- Attendance data: session records, timestamps, and (where enabled) coarse geolocation used solely to validate presence.
- Billing data: processed by our payment partner, Razorpay. We do not store card details on our servers.
2. How We Use Data
We use data to operate the Service: generate rotating QR codes, validate check-ins, produce reports, send transactional emails (attendance summaries, defaulter alerts, exam eligibility notices), and provide support.
3. Data Ownership
Each institution owns its data. Administrators can export attendance and student rosters and may request account deletion at any time by emailing support@spurrin.com.
4. Security
Data is stored on managed cloud infrastructure with row-level security, encryption in transit (TLS), and encryption at rest. QR tokens rotate every 30 seconds and are signed with HMAC-SHA256 to prevent sharing.
5. Sharing
We do not sell personal data. We share data only with sub-processors necessary to run the Service (hosting, email delivery, payments) and when required by law.
6. Retention
Attendance records are retained for the duration of the subscription plus 90 days after cancellation, unless earlier deletion is requested.
7. Your Rights
Users may request access, correction, or deletion of their personal data through their institution's administrator or by contacting us directly.
8. Contact
Data protection queries: support@spurrin.com.
