Privacy Policy
How GUINEX collects, uses, stores, and protects your personal information across the academic project marketplace.
Effective Date: August 1, 2026 ยท Last Updated: August 1, 2026
Table of Contents
1. Introduction
GUINEX ("Platform," "we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the GUINEX academic project marketplace at guinex.in.
By using GUINEX, you consent to the data practices described in this policy. If you do not agree with these practices, please discontinue use of the Platform.
2. Information We Collect
2.1 Account Information
- Full name, email address, and password (hashed by Firebase Authentication)
- GUINEX ID (unique username, permanent once set)
- Account role (user, moderator, admin)
- Registration timestamp and last login time
2.2 Profile Information
- Bio/description text
- College/institution name and department
- Avatar image (stored on Cloudinary)
- Social links (GitHub, LinkedIn, Twitter, website) โ voluntarily provided
2.3 Financial Information
- GP wallet balance (current balance, pending earnings, total earned)
- Transaction records (recharges, unlocks, earnings, withdrawals)
- UPI ID (VPA) for withdrawal requests
- UTR reference numbers for recharge verification
- Recharge and withdrawal request amounts and statuses
We do NOT store your UPI PIN, banking passwords, or payment app credentials. Payments are made directly through your UPI app.
2.4 Project Upload Data
- Project titles, descriptions, abstracts, categories, and pricing
- Notebook Editor content (text cells, code blocks, images)
- Gallery images and poster files (stored on Cloudinary)
- Project metadata (approval status, view counts, unlock counts, ratings)
2.5 Community Interaction Data
- Ratings, reviews, and likes submitted by users
- Follower/following relationships
- Challenge waitlist registrations
- Support Chat messages and evidence attachments
2.6 Automatically Collected Data
- Browser type and version
- Theme preference (dark/light mode, stored in localStorage)
- Firebase Authentication session tokens
- IP address and general location (collected by Firebase hosting infrastructure)
3. How We Use Your Information
- Account Management: To create and manage your GUINEX account, authenticate sessions, and maintain your GUINEX ID.
- Marketplace Operations: To process project unlocks, manage the GP wallet, execute atomic transactions, and handle the 72-hour escrow system.
- Communication: To enable Support Chat between buyers and creators, send important account notifications, and respond to support requests.
- Content Moderation: To review uploaded projects, moderate reviews, investigate disputes, and enforce community guidelines.
- Financial Processing: To verify recharge UTRs, process withdrawal requests, and maintain transaction audit trails.
- Platform Improvement: To analyze usage patterns, fix bugs, improve features, and develop new functionality.
- Security: To prevent fraud, detect unauthorized access, enforce Firestore security rules, and protect Platform integrity.
- Legal Compliance: To comply with applicable Indian laws, respond to legal requests, and maintain required financial records.
4. GP Wallet & Transaction Data
The GP Wallet is central to GUINEX's marketplace operations. We handle wallet data with particular care:
- Wallet balances and transaction history are stored in Cloud Firestore with strict security rules limiting access to the account owner and authorized administrators.
- All wallet modifications (recharges, unlocks, earnings, withdrawals) use Firestore Client Transactions (runTransaction) ensuring atomic, consistent operations that prevent double-spending.
- Transaction records include: type, amount, direction (credit/debit), counterparty reference, timestamps, and approval status.
- UTR reference numbers are stored solely for recharge verification and are not shared with third parties.
- Your wallet balance is never visible to other users โ only to you and authorized GUINEX administrators.
5. Support Chat & Dispute Evidence
- Support Chat messages are stored in Cloud Firestore under order-specific chat collections with security rules restricting access to the buyer and creator of that specific order.
- Chat messages are never sold, shared with third parties, or indexed by search engines.
- Evidence attachments (screenshots, logs) uploaded during disputes are stored on Cloudinary and linked to the specific dispute record.
- GUINEX administrators may access Support Chat history solely for the purpose of dispute investigation when either party escalates a formal dispute.
- Chat data is retained for the duration of the order relationship and may be archived for legal compliance purposes.
6. Cookies & Local Storage
GUINEX uses minimal cookies and browser storage:
| Storage Type | Purpose | Source |
|---|---|---|
| localStorage | Theme preference (dark/light mode) | GUINEX |
| sessionStorage | Cached FAQ data, session state | GUINEX |
| Firebase Auth cookies | Session management and authentication state | Firebase (Google) |
| Cloudinary cookies | Image delivery optimization | Cloudinary |
GUINEX does NOT use advertising cookies, behavioral tracking cookies, or third-party analytics tracking pixels.
7. Third-Party Services
GUINEX integrates the following third-party services, each with their own privacy policies:
Firebase (Google Cloud)
Authentication, Cloud Firestore database, and Firebase Hosting. Data is processed per Google Cloud's privacy terms. Data centers may be located outside India.
Cloudinary
Image and media hosting for avatars, project galleries, poster images, and chat evidence attachments. Images are automatically optimized for fast delivery.
Google Fonts
Web fonts (Inter, JetBrains Mono) loaded from Google's CDN. Google may collect usage metadata per their privacy policy.
CDN Libraries
Tailwind CSS, Lucide Icons, SweetAlert2, and other libraries loaded from cdn.jsdelivr.net and cdnjs.cloudflare.com.
8. Data Security
We employ multiple layers of security to protect your data:
- Transport Encryption: All data is transferred over HTTPS with TLS encryption. HSTS headers enforce secure connections.
- Password Security: Passwords are hashed and managed by Firebase Authentication โ never stored in plain text.
- Database Security: Cloud Firestore security rules implement role-based access control (RBAC), ensuring users can only access their own data. Wallet modifications are validated server-side.
- Atomic Transactions: All financial operations use Firestore Client Transactions (runTransaction) preventing race conditions, double-spending, and data inconsistency.
- HTTP Security Headers: Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers are configured on all pages.
- Admin Access Control: Admin and moderator roles are enforced both client-side and server-side via Firestore security rules. Role escalation requires Firestore-level verification.
9. Data Storage & Retention
- Primary Database: Cloud Firestore (Google Cloud Platform). Data may be stored in Google's global data center network, which may include servers outside India.
- Media Storage: Cloudinary CDN for images and media files.
- Active Account Data: Retained as long as your account remains active.
- Transaction Records: Financial transaction data is retained indefinitely for audit, compliance, and dispute resolution purposes, even after account deletion.
- Support Chat History: Retained for the duration of the relevant order relationship. May be archived for legal compliance.
- Deleted Accounts: Upon account deletion, profile data and authentication credentials are removed. Transaction records and projects purchased by other users may be retained as described above.
10. Account Deletion & Data Rights
- You may request account deletion by emailing guinexadmin@gmail.com with your registered email address.
- Upon deletion, we remove: your profile information, authentication credentials, bio, avatar, and social links.
- We retain: transaction records (for legal/financial compliance), projects already purchased by other users (buyers keep access), and anonymized aggregated data.
- Deletion is typically processed within 30 days of request verification.
11. Children's Privacy
GUINEX is designed for engineering students and is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided personal information to GUINEX, please contact guinexadmin@gmail.com so we can take appropriate action.
12. International Users
GUINEX is based in India and primarily serves Indian users. If you access the Platform from outside India, your data may be transferred to and processed in India and other countries where our service providers (Firebase, Cloudinary) maintain data centers. By using GUINEX, you consent to the transfer and processing of your data in these jurisdictions.
13. Your Rights (DPDP Act Compliance)
Under India's Digital Personal Data Protection Act (DPDP Act) and related regulations, you have the following rights:
- Right to Access: Request information about the personal data we hold about you.
- Right to Correction: Update or correct inaccurate personal data through your Profile page or by contacting support.
- Right to Erasure: Request deletion of your account and associated personal data (subject to retention requirements described in Section 10).
- Right to Grievance Redressal: Submit grievances about data handling to guinexadmin@gmail.com.
- Right to Withdraw Consent: You may withdraw consent for data processing by deleting your account. Note that withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.
14. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our data practices, technology, or legal requirements. Material changes will be communicated via platform announcements or email notification. The "Last Updated" date at the top of this page indicates when this policy was most recently revised.
Continued use of GUINEX after updates constitutes acceptance of the revised Privacy Policy. We recommend reviewing this page periodically.
15. Contact for Privacy Inquiries
For any questions, concerns, or requests related to this Privacy Policy or your personal data:
- Email: guinexadmin@gmail.com
- Contact Page: guinex.in/contact.html
- Subject Line: Include "Privacy Inquiry" in your email subject for faster routing.