Privacy Policy
CodeForData (codefordata.in) is a free website for practising PySpark interview questions. It is operated by Suraj Anand, an individual based in India ("we", "us"). This policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights you have. We act as the Data Fiduciary for your personal data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. Data we collect
| Category | What | When |
|---|---|---|
| Account data | Email address; password stored only as a bcrypt hash (we never see or store your actual password); whether your email is verified; account creation date | When you sign up with email |
| Google sign-in data | Your Google account's unique ID and verified email address. We do not receive your Google password, contacts, files or other Google data. | When you choose "Continue with Google" |
| Practice data | Problems you have solved or revealed solutions for, code you write in the editor, and your submission history (result, tests passed, run time) | When you use the site while logged in. Logged out, this stays only in your browser. |
| Activity data | Sign-ins, sign-outs and sign-ups; problems you open and solve; bookmarks; searches; profile changes; with the time and the page. Your name, if you add one or it comes from Google. | When you use the site while logged in |
| Usage analytics | Pages viewed, clicks, scrolling and mouse movement, device and browser type, approximate location derived from your IP address, and pseudonymous cookie identifiers, collected by Google Analytics and Microsoft Clarity. Clarity may record how you interact with pages (session replay); text you type into forms is masked. | On every visit, unless your browser sends a Global Privacy Control signal |
| Technical and security data | IP address, browser type, pages requested and timestamps (in our hosting provider's logs); IP-based counters used to block repeated login attempts | On every visit |
| Error reports | Technical details of errors (error message, the page, browser and OS version, and your internal account number if logged in). Passwords, cookies and form contents are not included. | When something breaks |
| Correspondence | Your email address and the contents of messages you send us | When you contact us |
We do not knowingly collect sensitive data such as financial, health or government ID information, and you should not include it in your code or messages.
2. Why we use it (purposes)
- To provide your account: log you in, keep you logged in, and save and sync your progress across devices.
- To send service emails: email-address confirmation and password-reset links. We do not send marketing email.
- To keep the service secure: rate-limit login attempts, detect abuse, and investigate security incidents.
- To fix problems: diagnose errors and keep the site reliable.
- To understand and improve the service: see which problems and features are used, where people get stuck, and how many people use the site.
- To respond to you when you contact us, and to meet legal obligations.
We process account and practice data on the basis of the consent you give when you create an account, and for the legitimate uses permitted by the DPDP Act (for example, security and compliance with law). You may withdraw consent at any time by deleting your account (see section 7); this does not affect processing that already took place.
3. Cookies and local storage
We use cookies and local storage that the site needs to work, plus analytics cookies set by Google Analytics and Microsoft Clarity. There are no advertising cookies. Visitors whose browser sends a Global Privacy Control signal are not tracked by analytics; you can also block these cookies in your browser settings.
| Name | Type | Purpose | Duration |
|---|---|---|---|
cfd_session | Cookie (HttpOnly, Secure) | Keeps you logged in | 30 days, or until you log out |
cfd_oauth | Cookie (HttpOnly, Secure) | Protects the Google sign-in step against forgery | 10 minutes |
cfd:* | Browser local storage | Your theme choice, code drafts and progress on this device | Until you clear it or log out |
_ga, _ga_* | Cookie (Google Analytics) | Counts visits and distinguishes visitors | Up to 2 years |
_clck, _clsk | Cookie (Microsoft Clarity) | Links page views into a session for usage analytics | Up to 1 year |
4. Who we share data with
We share personal data only with service providers who process it on our behalf to run CodeForData, under their data-protection terms:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting and server functions; request logs | Global edge network; servers in Singapore |
| Neon (Databricks, Inc.) | Database that stores accounts and progress | Singapore (AWS ap-southeast-1) |
| Resend | Delivering confirmation and password-reset emails | United States |
| Sentry (Functional Software, Inc.) | Error monitoring | United States / European Union |
| Google LLC | "Sign in with Google", only if you use it; Google Analytics (usage analytics) | Global / United States |
| Microsoft Corporation | Microsoft Clarity (usage analytics and session replay) | United States |
| Cloudflare, Inc. | Domain name system (DNS) and forwarding of emails sent to our support address | Global |
We do not sell or rent personal data. We may disclose data if required by law, a court order or a lawful request from a government authority, or to protect the rights, safety and security of our users and the service.
5. Transfers outside India
Our providers store and process data outside India, mainly in Singapore and the United States. We transfer data only to countries not restricted by the Government of India under the DPDP Act, and rely on providers that apply recognised security standards.
6. How long we keep data
- Account and practice data: for as long as your account exists. When you ask us to delete your account, we delete it within 30 days; residual copies in database backups expire automatically within a further 30 days.
- Login sessions: 30 days, or until you log out. Password-reset links expire after 1 hour and email-confirmation links after 24 hours.
- Rate-limit records: deleted automatically after 1 hour at most.
- Activity data: deleted automatically after 180 days.
- Usage analytics: kept by Google Analytics for up to 14 months and by Microsoft Clarity for up to 13 months (session recordings for 30 days).
- Hosting logs and error reports: kept by our providers for limited periods (typically up to 90 days) and then deleted.
- Correspondence: up to 2 years after the conversation ends, unless the law requires longer.
7. Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you and how we process it;
- Correct, complete or update your data;
- Erase your data and account, and withdraw your consent;
- Grievance redressal: complain to our Grievance Officer (below) and receive a response;
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
To exercise any right, email support@codefordata.in from the address linked to your account. We may ask you to confirm your identity. We aim to acknowledge requests within 7 days and resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
8. Security
All traffic is encrypted with HTTPS (HSTS enforced). Passwords are hashed with bcrypt, session tokens are stored only as hashes, cookies are HttpOnly and Secure, login attempts are rate-limited, and the site applies a strict Content Security Policy. Access to production systems is limited to the operator. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board as required by law.
9. Children
CodeForData accounts are for people aged 18 or over. We do not knowingly process personal data of children (under 18). If you believe a child has created an account, contact us and we will delete it.
10. Your code
Code you write runs in a PySpark emulator inside your own browser; it is not executed on our servers. If you are logged in, your code drafts are stored with your account so you can continue on another device.
11. Changes to this policy
We may update this policy as the service changes. We will change the "Last updated" date above and, for significant changes, notify account holders by email or on the site before they take effect.
12. Contact and Grievance Officer
Grievance Officer: Suraj Anand
Email: support@codefordata.in
Operator: Suraj Anand, India
More ways to reach us: Contact page.