Skip to content

Legal

Privacy Policy

What we collect, why we collect it, who can see it, and what you can ask us to do about it.

Effective from 16 September 2026

In short: we collect what we need to run your account, pay you correctly and meet Indian tax and KYC law — nothing more. We never sell your data. Your upline can see your name, member code and team volume, and nothing else. Your PAN and KYC documents are encrypted, masked in the interface, and every administrative look at them is logged.

01Who we are and what this covers

Nitesh Skill Hub Private Limited Company is the data fiduciary for the personal data described here. This policy covers this website, the member dashboard, our course platform and our support channels.

It is written to meet the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the disclosure obligations that apply to direct selling entities under the Consumer Protection (Direct Selling) Rules, 2021.

02What we collect

Information you give us

  • Account details: full name, username, email address, mobile number, password (stored only as an Argon2id hash — we never hold the password itself).
  • Profile details: date of birth, address, profile photo if you upload one, and your nominee details if you provide them.
  • KYC documents: PAN, a government photo identity document, and bank account details with IFSC. These are sensitive personal data and are handled as described below.
  • Communications: the content of support tickets, contact form submissions and emails you send us.

Information generated by your use of the platform

  • Purchase and payment records: which package, when, the gateway transaction reference, and the invoice.
  • Genealogy data: your sponsor, your placement position, and the structure of your team.
  • Earnings and payout records: ledger entries, wallet balance, payout requests, TDS deducted.
  • Learning activity: courses accessed, lessons completed, progress and certificates issued.
  • Technical data: IP address, device and browser type, and timestamps, recorded for security, fraud prevention and audit.

We do not collect your card number, UPI PIN or net-banking credentials. Those go directly to the payment gateway and never reach our servers.

03Why we use it

We use your data only for these purposes:

  • To create and operate your account, and to give you access to what you have purchased.
  • To process payments, issue invoices, and calculate and pay commission accurately.
  • To verify identity and meet KYC, anti-fraud and tax obligations, including deducting and depositing TDS against your PAN.
  • To place you in the genealogy and compute commission, rank progress and payouts.
  • To provide support and resolve grievances.
  • To send transactional messages — OTPs, payment confirmations, payout updates, policy changes. These are not marketing and you cannot opt out of them while you hold an account.
  • To send marketing or promotional messages only where you have opted in, with an unsubscribe link in every one.
  • To detect and investigate fraud, duplicate accounts and abuse of the compensation plan.
  • To comply with law, and to establish or defend legal claims.

We do not sell your personal data, and we do not share it with third parties for their own marketing.

04What your upline and downline can see

This deserves its own section, because it is the part people are most often surprised by in a direct selling business.

Members in your upline can see your name, member code, joining date, package level, status, and your team volume and counts — because commission is calculated from exactly that. Your downline can see your name and member code as their sponsor or upline.

Other members can never see your email address, phone number, postal address, bank details, PAN, KYC documents, wallet balance, earnings or payout history. If a member asks you for any of those, or claims to need them to “set up” your account, refuse and report it to us.

05Who else we share it with

We share personal data only with these categories of recipient:

  • Our payment gateway, to take payment and to process refunds.
  • Our cloud hosting and object-storage provider, which stores the platform and your uploaded documents.
  • Our email service provider, to deliver transactional email.
  • Professional advisers — auditors, lawyers and chartered accountants — under a duty of confidentiality.
  • Government authorities, where disclosure is required by law, a court order, or a valid request from a law-enforcement or tax authority.
  • An acquirer, in the event of a merger or acquisition, subject to the same protections continuing to apply.

Each processor is bound by contract to use the data only for the service they provide to us, and to protect it to at least the standard set out here.

06How we protect it

Specifically, and not as a generic assurance:

  • All traffic is served over TLS. Session cookies are httpOnly, Secure and SameSite-restricted.
  • Passwords are hashed with Argon2id and are never recoverable — a reset replaces the hash, it does not reveal the old password.
  • A separate transaction password is required to request a payout, so a stolen session alone cannot move money.
  • PAN and Aadhaar numbers are encrypted at rest with AES-256-GCM and are displayed masked everywhere in the interface.
  • KYC documents are stored in a private bucket that is not publicly readable. Access is only ever through a short-lived signed link.
  • An administrator revealing a full identity number is an explicit, audited action recorded against their name.
  • Every administrative action on member data is written to an immutable audit log.
  • Rate limiting and bot protection are applied at the network edge and again in the application.

No system is perfectly secure. If we become aware of a personal data breach that is likely to cause you harm, we will notify you and the Data Protection Board of India as the DPDP Act requires.

07How long we keep it

Account, transaction, commission and payout records are retained for eight years from the end of the relevant financial year, because the Companies Act, 2013 and the Income Tax Act, 1961 require it. KYC records are retained for the period prescribed for tax and anti-money laundering purposes.

Where retention is no longer required, data is deleted or irreversibly anonymised. Genealogy structure is retained after an account closes, because the positions of other members depend on it — but the closed member’s contact details and documents are removed.

08Your rights

Under the Digital Personal Data Protection Act, 2023 you may:

  • Ask for a summary of the personal data we hold about you and how we process it.
  • Ask us to correct or complete anything that is inaccurate or out of date.
  • Ask us to erase data we no longer have a lawful reason to keep.
  • Withdraw consent for anything you consented to — marketing, for example — at any time.
  • Nominate a person to exercise these rights on your behalf if you die or become incapacitated.
  • Complain to us, and then to the Data Protection Board of India if you are not satisfied.

To exercise any of these, write to us using the details on the contact page. We respond within 30 days. We may need to verify your identity first — that protection is for you. Note that we cannot erase records we are legally required to keep, and we will say so plainly if that is the case.

09Cookies and similar technologies

We use a small number of cookies, and only where they earn their place. Strictly necessary cookies keep you signed in, protect forms against cross-site request forgery, and enforce rate limits. These cannot be switched off without breaking the site.

Where we use any analytics, it is limited to aggregate usage measurement and is set only with your consent. We do not run third-party advertising or cross-site tracking cookies. You can clear or block cookies in your browser; strictly necessary ones being blocked will prevent you signing in.

10Children

The platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has registered, tell us and we will delete the account and the associated data.

11Where your data is stored

Our primary infrastructure is located in DATA CENTRE REGION. Some processors we rely on may store or process data outside India. Where that happens, we transfer data only to countries not restricted by the Central Government under the DPDP Act, and only under contractual terms that maintain the protections described in this policy.

12Changes to this policy

We update this policy when our practices change or the law does. The effective date at the top of this page always reflects the current version. Material changes are notified in the dashboard and by email before they take effect.

Questions about this policy?

Write to us at SUPPORT EMAIL, or use the contact form. Our Grievance Officer is named on the contact page and responds within the timelines set by the Consumer Protection (Direct Selling) Rules, 2021.

Related policies

A note on completeness. Anything highlighted in this document is a company-specific detail that Nitesh Skill Hub still has to supply — a registered address, a registration number, a named officer or a specific figure. This page is a working policy, not legal advice; have it reviewed by a qualified Indian advocate before launch.