1. Who we are
The services at oneroadmap.io (the “Services”) are operated by GHAI TECHNOLOGIES PRIVATE LIMITED, a company incorporated in India, operating under the brand OneRoadmap™. We are a DPIIT-recognized Startup (DIPP ID: 197615) and a registered MSME.
For the purposes of the EU/UK General Data Protection Regulation we are the data controller, and for the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the data fiduciary, for the personal data described in this policy.
Privacy / Grievance Officer: Gaurav Ghai - gauravghai@htmlhints.com.
2. What this policy covers
This policy covers personal data we process when you visit our websites, create an account, take a certification assessment, enroll in a job simulation, book a session or event, make a payment, or contact us. It does not cover third-party websites or services we link to - their own policies apply.
By using the Services you acknowledge this policy. Where the law requires consent (for example for non-essential cookies, marketing, or processing under the DPDP Act), we rely on the consent you give us, which you can withdraw at any time as described below. Your use of the Services is also governed by our Terms of Service.
3. Data we collect
Data you give us
- Account data. Name, email address and profile photo - either entered directly or received from Google when you sign in with Google. We use one-time email codes (OTP) instead of storing passwords.
- Assessment & simulation data. Your answers, scores, timings, uploaded work files (for example cleaned datasets and memos in job simulations), retry counts and leaderboard results.
- Certificate data. The name shown on your certificate, the credential earned, score, percentile, issue date and certificate ID.
- Resume & career data. If you use resume or career tools, the resume content you create, import or upload.
- Payment data. Payments are processed by Razorpay. We receive the order reference, amount, status and your email - we never receive or store your full card number, UPI PIN or banking credentials.
- Communications. Messages, feedback, reviews and support requests you send us.
Data collected automatically
- IP address, approximate location derived from it, device and browser type, pages visited, referring URLs and interaction events - collected through server logs and cookies (see Section 6).
- Assessment-integrity signals during timed tests and simulations (for example tab switches, submission timing and unusually fast completion) used to keep results fair and credible.
4. How we use data & our legal bases
Where GDPR / UK GDPR applies, every use of your data rests on a legal basis; the DPDP Act, CCPA/CPRA and UAE PDPL impose similar purpose limitations. We use personal data to:
- Provide the Services (contract). Create and manage your account, run assessments and simulations, grade submissions (including with AI-assisted review), issue and host certificates, maintain leaderboards, and process payments.
- Communicate with you (contract / legitimate interests). Send OTP codes, results, receipts, deadline reminders and other service messages.
- Keep results credible (legitimate interests). Detect cheating, fraud, multiple accounts and abuse, and revoke credentials where our integrity rules are violated.
- Improve the Services (legitimate interests / consent). Analyse aggregated usage to improve content and features. Analytics cookies run only if you accept them.
- Marketing (consent). Send product updates and offers where you have opted in - you can unsubscribe at any time.
- Comply with law (legal obligation). Tax, accounting, and responding to lawful requests from authorities.
We do not use your personal data for automated decisions that produce legal or similarly significant effects without human oversight; AI-assisted grading is reviewable - you can contest any result via the contact below.
5. Talent Graph, connected accounts & AI processing
Our "Get Verified" feature builds a Talent Graph - a structured, evidence-backed view of what you have demonstrated for a target role. It only runs when you start it, and only on data you provide or connect. Before any evidence is processed we ask for your explicit agreement to these terms and this policy, and we record when you gave it.
What we collect for it
- Profile & onboarding details. Username, who you are (student / fresher / professional), education or work details, target role, goals, and companies you are interested in.
- Resume data. A resume you upload or sync from The Perfect Resume. We store the file and a structured version (work history, education, skills, projects, certifications). Contact details are removed before any text is sent to an AI model.
- Connected accounts (only when you connect them). GitHub (via GitHub's own authorization; we read only the repositories you grant), LinkedIn (via LinkedIn sign-in for identity and, if you choose, posting; your public profile is fetched from the URL you provide), and public activity on Credly, Hugging Face, LeetCode and HackerRankfor the usernames you enter. We never ask for your passwords.
- Simulation & interview results. Your OneRoadmap job-simulation results and, when enabled, contextual-interview answers.
How the AI is used - and what it is not allowed to do
AI models (currently Google Gemini) read the evidence above and produce observations against a fixed, published competency rubric - for example, "implemented input validation" with a reference to the file or answer that shows it. Every observation is validated against the rubric and stored with the prompt and model version used. The AI never sets a score, level or verification status. Those are computed by OneRoadmap's own deterministic rules from the validated observations, and every result stores the exact evidence, configuration versions and rules that produced it, so it can be audited and re-evaluated.
Security of connected-account data
Access tokens for connected accounts are stored encrypted at rest (AES-256-GCM) and used only to read the data described above. Your Kaggle-style API keys or platform passwords are never stored. You can disconnect any account at any time from the Get Verified page, which revokes our access and deletes the stored token.
What is public
Nothing from the Talent Graph is public unless you make your profile public. Your public profile shows your verification status, competency levels (never raw scores), certificates, projects and the accounts you connected - you control each section's visibility and can set the whole profile to private.
Retention & your choices
Evidence and graph versions are kept while your account is active so results stay auditable; deleting your account deletes them, along with stored resume files and connected-account tokens. You can replace your resume (the previous file is deleted), remove projects and certifications, and re-run the evaluation at any time. If you are in the EEA/UK, the legal basis for this processing is your consent (Art. 6(1)(a) GDPR), which you can withdraw by disconnecting sources or deleting your account.
Ori, the OneRoadmap Chrome extension
Ori is our optional Chrome extension. It works only on the tab where you open its side panel, on sites you have allowed, and everything it sends to OneRoadmap is covered by this policy.
- What it reads. When you ask Ori to read a job or an application form, the extension sends that page's address, the job posting text and the structure of the form (field labels and types - never what you or the employer typed into it) to OneRoadmap, so we can identify the job and prepare your application.
- What it writes. Only when you press Autofill, it writes your own saved details or the answers you approved into that form. It never submits an application, never fills legal, identity or self-identification questions, and never overwrites what you typed.
- Sign-in. You sign in through a OneRoadmap window. The extension keeps a short-lived session token on your device and never sees your password; signing out or uninstalling removes it.
- Tracking. When you tell Ori that you submitted an application, we record that on your application in OneRoadmap, with the time you confirmed it and whether you used autofill. Jobs you analyse are added to OneRoadmap's job catalogue as public job facts only; nothing about you or your application is attached to them.
6. Certificates are public by design
If you want a certificate page unpublished or your leaderboard entry anonymised, email gauravghai@htmlhints.com and we will action it within 30 days. Note that unpublishing a verification page makes the credential unverifiable.
9. International transfers
We are based in India and use cloud infrastructure that may store or process data in other countries (including the United States). When we transfer personal data across borders we protect it as required by the law that applies to you:
- EEA / UK. Transfers rely on adequacy decisions where available, or the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), plus supplementary safeguards.
- India (DPDP Act). We transfer personal data outside India only to countries not restricted by the Central Government, and our processors are bound by contract to equivalent protections.
- UAE (PDPL). Transfers are made to jurisdictions with adequate protection or under appropriate contractual safeguards and, where required, your consent.
10. How long we keep data
- Account data: for as long as your account exists, then deleted or anonymised within 90 days of a verified deletion request.
- Certificates & verification records: retained while the credential remains valid, because employers rely on the verification page - unless you ask us to unpublish it (Section 5).
- Assessment submissions: kept while relevant for grading, integrity review and your reports; work files are routinely purged after the review window.
- Payment & tax records: kept for the period required by Indian tax and company law (typically 8 years).
- Server logs: short-lived and rotated automatically.
When data is no longer needed for the purpose it was collected (or when consent is withdrawn and no other lawful basis applies, as the DPDP Act requires), we delete or irreversibly anonymise it.
11. Security
We use encryption in transit (HTTPS/TLS), encrypted storage with our cloud providers, OTP-based sign-in instead of stored passwords, scoped access controls, and payment processing that keeps card data with a PCI-DSS-compliant processor. No system is perfectly secure - if we learn of a breach affecting your personal data we will notify you and the relevant authority (for example a supervisory authority, the Data Protection Board of India, or your state regulator) within the timelines the law requires.
12. Your rights by region
You can exercise any of these rights by emailing gauravghai@htmlhints.com from your registered email address (we may verify your identity). We respond within 30 days, or the shorter period your local law sets, and we will never discriminate against you for exercising a privacy right. Many actions - editing your name, or deleting your account - are also available in Dashboard → Account Settings. Step-by-step deletion instructions, including for data you shared over WhatsApp, are at Delete your data.
European Economic Area & United Kingdom (GDPR / UK GDPR)
- Right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection (including to legitimate-interests processing and to any direct marketing).
- Right to withdraw consent at any time without affecting prior processing.
- Right to lodge a complaint with your supervisory authority - in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority of your member state.
India (Digital Personal Data Protection Act, 2023)
- Right to access a summary of your personal data and the processing activities; right to correction, completion, updating and erasure.
- Right to withdraw consent as easily as it was given; right to grievance redressal through our Grievance Officer (details in Section 1 and the footer below), who responds within the timelines prescribed under the DPDP Act and IT Rules.
- Right to nominate another individual to exercise your rights in the event of death or incapacity, and the right to approach the Data Protection Board of India if unsatisfied with our response.
United States - California (CCPA/CPRA) and other state laws
- Right to know/access the personal information we collect, use and disclose; right to correct and to delete; right to data portability.
- Right to opt out of “sale” or “sharing” of personal information - we do not sell or share personal information as those terms are defined in the CPRA, and we do not use or disclose sensitive personal information beyond what the law permits.
- Right to non-discrimination, and to use an authorized agent to submit requests. Residents of Virginia, Colorado, Connecticut, Utah and other states with comprehensive privacy laws have equivalent rights, which we honor through the same contact.
United Arab Emirates (Federal Decree-Law No. 45 of 2021 - PDPL)
- Right to access and receive a copy of your personal data, and to request correction or erasure of inaccurate data.
- Right to restrict or object to processing, including for direct marketing, and to withdraw consent.
- Right to complain to the UAE Data Office if you believe your data has been processed in violation of the PDPL.
13. Children
The Services are intended for users aged 16 and over. If you are under 18 and located in India, you may use the Services only with the verifiable consent of a parent or guardian, as the DPDP Act requires - and we do not use children's data for tracking, behavioural monitoring or targeted advertising. We do not knowingly collect data from children under 13 anywhere; if you believe a child has provided us personal data, contact gauravghai@htmlhints.com and we will delete it promptly.
14. Marketing choices
We send marketing emails only with your consent or as otherwise permitted by law, and every marketing email includes an unsubscribe link that works immediately. Service messages (OTP codes, results, receipts, deadline warnings) are not marketing and continue while you hold an account.
15. Changes to this policy
When we make material changes we will update the “Last updated” date above and notify you by email and/or an in-app notice before the changes take effect; where the change requires fresh consent under your local law, we will ask for it. Earlier versions are available on request.
Questions, requests or complaints
GHAI TECHNOLOGIES PRIVATE LIMITED (OneRoadmap™) · Grievance / Privacy Officer: Gaurav Ghai · gauravghai@htmlhints.com · Support: support@oneroadmap.in. We acknowledge requests promptly and aim to resolve them within 30 days (or sooner where local law requires).