Privacy Policy

Talk Over Cookies — operated by The NIFC

Last updated: September 24, 2026

Our commitments — in plain terms

  • We hold school and college data — nothing personal, and nothing of or from students.
  • Students never have accounts on the platform, and we collect nothing about them.
  • We do not ask for or store profile photos, bios, or dates of birth — for anyone.
  • The only personal details we hold are the minimum needed to run an institution’s account: the coordinator’s name, work email, optional phone, and time zone.
  • Sessions are live and encrypted, directly between the two participating classrooms. We never record, transcribe, or store any session’s audio or video, and we cannot access what is said or shown.
  • We store only what is needed to operate memberships, matching, and bookings.

1. Introduction

The NIFC (referred to as “we,” “us,” or “our”) operates Talk Over Cookies (“the Platform”), a school-and-college cultural-exchange platform where classrooms engage in guided, teacher-led conversations to develop life skills.

This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access or use the Platform. It covers institution representatives (coordinators and host teachers) and administrators. Students are not users of the Platform — we do not collect, store, or process any student data.

This policy is designed to comply with applicable privacy laws worldwide, including but not limited to:

  • The General Data Protection Regulation (GDPR) — European Union
  • The California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA) — California, USA
  • The Digital Personal Data Protection Act, 2023 (DPDP Act) — India
  • The Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada
  • The Lei Geral de Proteção de Dados (LGPD) — Brazil
  • The Protection of Personal Information Act (POPIA) — South Africa
  • The Children’s Online Privacy Protection Act (COPPA) — United States

Because the Platform collects no student data, the child-specific obligations of these laws (such as verifiable parental consent) do not arise for any data we process. See Section 16 for our regulatory position.

By using the Platform, you acknowledge the practices described in this policy. If you do not agree, please discontinue use immediately.

2. Information We Collect

We collect only the information needed to operate an institution’s membership, matching, and bookings:

2.1 Information You Provide

  • Institution data: Institution name, institution type (school or college), location (country, state/province, city), time zone, the participating class’s age band (an age range used only for matching, e.g., 10–12), teaching interests, preferred regions, and your weekly availability windows.
  • Coordinator account identity: The coordinator’s name, work email, and an optional phone number.
  • Account role: Institution representative or platform administrator.
  • Program history: Membership details, programs booked, sessions attended, feedback you choose to give, and messages you send through our Contact form.
  • Payment references: Plan, credits, coupon used, and payment order/reference identifiers. We never hold full payment card details.

We do not collect profile photos, bios, or dates of birth, and we do not collect any data about students.

2.2 Information Collected Automatically

  • Aggregate analytics: Page views and feature usage, aggregated for product improvement. This is not used for advertising or for building advertising profiles.
  • Security audit records: Basic records of account actions (who, what, when, and the IP address involved) kept to protect the Platform and its users.
  • Session metadata: The scheduled date and time of a session (in your time zone), its theme, the two participating institutions, and when each side joined. We do not record or store session audio, video, or chat content.

2.3 Information from Third Parties

  • Payment provider — Processes payments. We receive payment status and order references but never see or store full card numbers.
  • Analytics provider — Provides aggregate usage analytics.
  • Email delivery service — Sends transactional emails (booking confirmations, session reminders).
  • Hosting and data-storage providers — Run application deployment and data storage.

Sessions run directly between the two participating classrooms; no third party receives session content.

* The specific third-party providers we use may change over time. This list will be updated accordingly.

4. Purpose of Data Collection

We use the information we collect for the following purposes:

  • To provide and maintain the Platform: Account creation, membership activation, program matching, and session access.
  • To match institutions with cultural-exchange programs: Age band, location, region, interest, and availability-based program recommendations.
  • To process payments: Membership fees collected via a third-party payment provider.
  • To communicate with you: Booking confirmations, session reminders, account notifications, and support responses.
  • To ensure safety and security: Platform monitoring and abuse prevention.
  • To improve the Platform: Aggregate usage analytics and feedback analysis.
  • To comply with legal obligations: Record-keeping, regulatory compliance, and lawful requests from authorities.

5. Data Sharing and Disclosure

We do not sell user data, and we do not share it for marketing. We may share data only in the following circumstances:

5.1 Service Providers

We share necessary data with the service providers that run the Platform on our behalf, under contractual obligations:

  • Payment provider — Payment processing (we do not see or store your full card number)
  • Analytics provider — Aggregate usage analytics
  • Email delivery service — Transactional email delivery
  • Hosting and data-storage providers — Application hosting and data storage

* The specific third-party providers we use may change over time. This list will be updated accordingly.

5.2 Session presence

Session presence information (which two institutions are meeting and when) is shared only with those two institutions and with our administrators for safety and support purposes. Session content is never shared because it is never stored.

5.3 Legal Requirements and Business Transfers

We may disclose information if required to do so by law, regulation, or legal process (e.g., court order, government agency request). In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; you will be notified of any change in ownership.

6. Data Retention

We keep information only as long as it serves the purposes described in this policy:

  • Account, institution, and matching data: Kept while the institution’s account is active. You may request deletion at any time; on deletion we remove the account, institution profile, and matching data.
  • Financial and audit records: Kept for as long as required by tax, financial, and legal obligations, and to resolve disputes and protect the Platform.
  • Security audit records: Kept as needed for security and legal purposes.

There is no session content to retain: sessions are live, are never recorded or transcribed, and we do not store session audio, video, or chat.

When information is no longer needed for these purposes, we delete or anonymize it. If you would like your data deleted, see Section 8.

7. Data Security

We apply appropriate technical and organizational measures to protect the information we hold:

  • Encryption in transit: Communications with our servers are encrypted using TLS 1.2 or later.
  • Encryption at rest: Stored data is encrypted at rest.
  • Access controls: Data access is limited to the platform administrators who need it to operate the service.
  • Payment security: Payments are processed by a PCI-DSS Level 1 compliant provider (Razorpay). We never see or store your full card number, CVV, or similar credentials.
  • Authentication: Email-based sign-in with hashed passwords where passwords are used.
  • Periodic review: We review our security practices periodically and update them as needed.

While we take reasonable measures to protect information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you have the following rights regarding information we hold about you. We respond to all legitimate requests within the timeframes required by applicable law (typically 30 days).

GDPR Rights (EU/EEA)

  • Right of Access — Request a copy of your data.
  • Right to Rectification — Correct inaccurate or incomplete data.
  • Right to Erasure — Request deletion of your data.
  • Right to Restriction — Limit how we process your data.
  • Right to Data Portability — Receive your data in a structured, machine-readable format.
  • Right to Object — Object to processing based on legitimate interests.

CCPA/CPRA Rights (California)

  • Right to Know — Request details about the personal information we collect, use, and share.
  • Right to Delete — Request deletion of your personal information.
  • Right to Correct — Request correction of inaccurate information.
  • Right to Opt-Out — We do not sell your personal information. No opt-out is needed.
  • Right to Non-Discrimination — We will not discriminate against you for exercising any CCPA right.

DPDP Act Rights (India)

  • Right to Notice — Receive clear information about data collection and processing.
  • Right to Consent — Give, manage, and withdraw consent for data processing.
  • Right to Access — Obtain a summary of your data and processing activities.
  • Right to Correction and Erasure — Update or delete your data.
  • Right to Grievance Redressal — Lodge complaints regarding data processing.
  • Right to Nominate — Nominate a person to exercise your rights in the event of incapacity or death.

How to Exercise Your Rights

To exercise any of your rights, email us at hi@talkovercookies.com. We may need to verify your identity before processing your request. You may also designate an authorized agent to make requests on your behalf.

9. Children, Students & Schools

Students are not users of the Platform. They never create accounts, and we collect no names, ages, photos, contact details, or any other data of or from students.

  • Only institutions and their authorized coordinators and host teachers have accounts.
  • The Platform does not condition student participation on any disclosure of information to us.
  • Classroom participation, including parental consent and safeguarding under each school’s own policies, is the responsibility of the participating school.
  • We do not engage in behavioral advertising, and we never show ads on the Platform — including to children.
  • Sessions are live and encrypted classroom-to-classroom, led by each school’s own host teachers; platform administrators can monitor sessions and every session is covered by an audit record.

If a school believes a student’s data has been captured by our systems, they may contact us at hi@talkovercookies.com and we will investigate and delete it promptly.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your own, exclusively as needed to operate the Platform:

  • Hosting and data-storage providers — Data is stored on cloud infrastructure that may span multiple regions.
  • Payment provider — Payment processing.
  • Email delivery service — Transactional email delivery.

Where cross-border transfer is regulated, we rely on the safeguards required by the applicable law (including, where relevant, data-processing agreements and the mechanisms recognised by the recipient country’s data-protection law).

By using the Platform, you acknowledge and consent to the transfer of your data as described in this policy.

11. Cookies and Similar Technologies

We use a small number of technologies for the Platform to work:

  • Authentication cookies: Required for session management and secure sign-in.
  • Security cookies: Measures to prevent cross-site request forgery and other abuse.
  • Analytics: We use Google Analytics to understand aggregate usage (which pages are visited and which features are used). This data is aggregated and is not used for advertising or cross-site tracking.
  • Local storage: Your browser may store small preferences locally, such as dismissing the app-install prompt or enabling offline support.

You may configure your browser to restrict cookies or local storage, but this may affect Platform functionality.

For more information about cookies, visit allaboutcookies.org.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to you via email and/or a prominent notice on the Platform. The “Last Updated” date at the top of this page reflects the most recent revision.

Your continued use of the Platform after changes constitutes acceptance of the updated policy. If you do not agree with a change, you may delete your account and discontinue use.

14. Trust & Data FAQ

Do you collect student data?

No. Students never have accounts on the platform, and we collect nothing on or from them. Schools and colleges participate as institutions.

Do you record sessions?

No. Sessions are live and encrypted, directly between the two participating classrooms. We never record, transcribe, or store any session’s audio or video, and we cannot access what is said or shown.

Do you sell or share personal data?

No. We do not sell, rent, or share data for marketing, and we do not build advertising profiles.

Do you show ads?

No. Advertising is not part of the platform, including to children.

Do you store card numbers?

Never. Payments are processed by a PCI-DSS Level 1 provider, and we keep only payment order references.

15. Regulatory Alignment

Because the Platform collects and processes no student data and holds no education records, the child-specific regimes of major privacy laws are not triggered by our operations:

  • United States (COPPA / FERPA): No personal information is collected from children, and no education records are received or held, so the relevant child-privacy and school-record obligations do not arise.
  • India (DPDP Act, 2023): The verifiable-parental-consent provisions for children’s data do not apply to any data we process. The small amount of coordinator data we hold is covered by our notice, consent-management, and grievance-redressal practices.
  • EU/EEA (GDPR): The child-consent requirements do not arise. The limited coordinator data we process is handled on proper legal bases (contract and legitimate interest) with the rights described in Section 8.
  • United Kingdom (Age Appropriate Design Code): The code’s expectations around children’s data are met by design — no child data, no profiling, and no advertising.
  • Globally: Sessions are live-only and never recorded; payments are handled by a PCI-DSS Level 1 provider; and we never sell, rent, or share data for marketing.

These are position statements about how the Platform is designed and operated; we do not claim certification under any framework.

16. Contact Information & Grievance Officer

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

Grievance Officer (India DPDP Act)

In compliance with the Digital Personal Data Protection Act, 2023 of India, we have appointed a Grievance Officer. The officer acknowledges any complaint within 24 hours and resolves it within 45 days.

Grievance Officer

The NIFC

hi@talkovercookies.com

Install App

Get the app for the best experience