CodeForData

Privacy Policy

Effective date: 10 October 2026 · Last updated: 10 October 2026

CodeForData (codefordata.in) is a free website for practising PySpark interview questions. It is operated by Suraj Anand, an individual based in India ("we", "us"). This policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights you have. We act as the Data Fiduciary for your personal data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

In short: you can practise without an account. If you create one, we store your email address, a securely hashed password (or your Google account ID), and your practice progress so it syncs across devices. We also record what signed-in users do on the site, and use Google Analytics and Microsoft Clarity to understand how the site is used. We do not sell your data, show ads, or use advertising cookies.

1. Data we collect

CategoryWhatWhen
Account dataEmail address; password stored only as a bcrypt hash (we never see or store your actual password); whether your email is verified; account creation dateWhen you sign up with email
Google sign-in dataYour Google account's unique ID and verified email address. We do not receive your Google password, contacts, files or other Google data.When you choose "Continue with Google"
Practice dataProblems you have solved or revealed solutions for, code you write in the editor, and your submission history (result, tests passed, run time)When you use the site while logged in. Logged out, this stays only in your browser.
Activity dataSign-ins, sign-outs and sign-ups; problems you open and solve; bookmarks; searches; profile changes; with the time and the page. Your name, if you add one or it comes from Google.When you use the site while logged in
Usage analyticsPages viewed, clicks, scrolling and mouse movement, device and browser type, approximate location derived from your IP address, and pseudonymous cookie identifiers, collected by Google Analytics and Microsoft Clarity. Clarity may record how you interact with pages (session replay); text you type into forms is masked.On every visit, unless your browser sends a Global Privacy Control signal
Technical and security dataIP address, browser type, pages requested and timestamps (in our hosting provider's logs); IP-based counters used to block repeated login attemptsOn every visit
Error reportsTechnical details of errors (error message, the page, browser and OS version, and your internal account number if logged in). Passwords, cookies and form contents are not included.When something breaks
CorrespondenceYour email address and the contents of messages you send usWhen you contact us

We do not knowingly collect sensitive data such as financial, health or government ID information, and you should not include it in your code or messages.

2. Why we use it (purposes)

We process account and practice data on the basis of the consent you give when you create an account, and for the legitimate uses permitted by the DPDP Act (for example, security and compliance with law). You may withdraw consent at any time by deleting your account (see section 7); this does not affect processing that already took place.

3. Cookies and local storage

We use cookies and local storage that the site needs to work, plus analytics cookies set by Google Analytics and Microsoft Clarity. There are no advertising cookies. Visitors whose browser sends a Global Privacy Control signal are not tracked by analytics; you can also block these cookies in your browser settings.

NameTypePurposeDuration
cfd_sessionCookie (HttpOnly, Secure)Keeps you logged in30 days, or until you log out
cfd_oauthCookie (HttpOnly, Secure)Protects the Google sign-in step against forgery10 minutes
cfd:*Browser local storageYour theme choice, code drafts and progress on this deviceUntil you clear it or log out
_ga, _ga_*Cookie (Google Analytics)Counts visits and distinguishes visitorsUp to 2 years
_clck, _clskCookie (Microsoft Clarity)Links page views into a session for usage analyticsUp to 1 year

4. Who we share data with

We share personal data only with service providers who process it on our behalf to run CodeForData, under their data-protection terms:

ProviderPurposeLocation
Vercel Inc.Website hosting and server functions; request logsGlobal edge network; servers in Singapore
Neon (Databricks, Inc.)Database that stores accounts and progressSingapore (AWS ap-southeast-1)
ResendDelivering confirmation and password-reset emailsUnited States
Sentry (Functional Software, Inc.)Error monitoringUnited States / European Union
Google LLC"Sign in with Google", only if you use it; Google Analytics (usage analytics)Global / United States
Microsoft CorporationMicrosoft Clarity (usage analytics and session replay)United States
Cloudflare, Inc.Domain name system (DNS) and forwarding of emails sent to our support addressGlobal

We do not sell or rent personal data. We may disclose data if required by law, a court order or a lawful request from a government authority, or to protect the rights, safety and security of our users and the service.

5. Transfers outside India

Our providers store and process data outside India, mainly in Singapore and the United States. We transfer data only to countries not restricted by the Government of India under the DPDP Act, and rely on providers that apply recognised security standards.

6. How long we keep data

7. Your rights

Under the DPDP Act you have the right to:

To exercise any right, email support@codefordata.in from the address linked to your account. We may ask you to confirm your identity. We aim to acknowledge requests within 7 days and resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

8. Security

All traffic is encrypted with HTTPS (HSTS enforced). Passwords are hashed with bcrypt, session tokens are stored only as hashes, cookies are HttpOnly and Secure, login attempts are rate-limited, and the site applies a strict Content Security Policy. Access to production systems is limited to the operator. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board as required by law.

9. Children

CodeForData accounts are for people aged 18 or over. We do not knowingly process personal data of children (under 18). If you believe a child has created an account, contact us and we will delete it.

10. Your code

Code you write runs in a PySpark emulator inside your own browser; it is not executed on our servers. If you are logged in, your code drafts are stored with your account so you can continue on another device.

11. Changes to this policy

We may update this policy as the service changes. We will change the "Last updated" date above and, for significant changes, notify account holders by email or on the site before they take effect.

12. Contact and Grievance Officer

Grievance Officer: Suraj Anand
Email: support@codefordata.in
Operator: Suraj Anand, India
More ways to reach us: Contact page.