OneRoadmap · Legal

Privacy Policy

We build career credentials, so trust is our product. This policy explains - in plain language - what personal data we collect, why, who we share it with, and the rights you have wherever you live, including under the EU/UK GDPR, India's DPDP Act 2023, California's CCPA/CPRA and the UAE PDPL.

Last updated: 26 August 2026 · GHAI TECHNOLOGIES PRIVATE LIMITED (operating as OneRoadmap™) · DPIIT-recognized Startup (DIPP ID: 197615)

1. Who we are

The services at oneroadmap.io (the “Services”) are operated by GHAI TECHNOLOGIES PRIVATE LIMITED, a company incorporated in India, operating under the brand OneRoadmap™. We are a DPIIT-recognized Startup (DIPP ID: 197615) and a registered MSME.

For the purposes of the EU/UK General Data Protection Regulation we are the data controller, and for the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the data fiduciary, for the personal data described in this policy.

Privacy / Grievance Officer: Gaurav Ghai - gauravghai@htmlhints.com.

2. What this policy covers

This policy covers personal data we process when you visit our websites, create an account, take a certification assessment, enroll in a job simulation, book a session or event, make a payment, or contact us. It does not cover third-party websites or services we link to - their own policies apply.

By using the Services you acknowledge this policy. Where the law requires consent (for example for non-essential cookies, marketing, or processing under the DPDP Act), we rely on the consent you give us, which you can withdraw at any time as described below. Your use of the Services is also governed by our Terms of Service.

3. Data we collect

Data you give us

  • Account data. Name, email address and profile photo - either entered directly or received from Google when you sign in with Google. We use one-time email codes (OTP) instead of storing passwords.
  • Assessment & simulation data. Your answers, scores, timings, uploaded work files (for example cleaned datasets and memos in job simulations), retry counts and leaderboard results.
  • Certificate data. The name shown on your certificate, the credential earned, score, percentile, issue date and certificate ID.
  • Resume & career data. If you use resume or career tools, the resume content you create, import or upload.
  • Payment data. Payments are processed by Razorpay. We receive the order reference, amount, status and your email - we never receive or store your full card number, UPI PIN or banking credentials.
  • Communications. Messages, feedback, reviews and support requests you send us.

Data collected automatically

  • IP address, approximate location derived from it, device and browser type, pages visited, referring URLs and interaction events - collected through server logs and cookies (see Section 6).
  • Assessment-integrity signals during timed tests and simulations (for example tab switches, submission timing and unusually fast completion) used to keep results fair and credible.

4. How we use data & our legal bases

Where GDPR / UK GDPR applies, every use of your data rests on a legal basis; the DPDP Act, CCPA/CPRA and UAE PDPL impose similar purpose limitations. We use personal data to:

  • Provide the Services (contract). Create and manage your account, run assessments and simulations, grade submissions (including with AI-assisted review), issue and host certificates, maintain leaderboards, and process payments.
  • Communicate with you (contract / legitimate interests). Send OTP codes, results, receipts, deadline reminders and other service messages.
  • Keep results credible (legitimate interests). Detect cheating, fraud, multiple accounts and abuse, and revoke credentials where our integrity rules are violated.
  • Improve the Services (legitimate interests / consent). Analyse aggregated usage to improve content and features. Analytics cookies run only if you accept them.
  • Marketing (consent). Send product updates and offers where you have opted in - you can unsubscribe at any time.
  • Comply with law (legal obligation). Tax, accounting, and responding to lawful requests from authorities.

We do not use your personal data for automated decisions that produce legal or similarly significant effects without human oversight; AI-assisted grading is reviewable - you can contest any result via the contact below.

5. Talent Graph, connected accounts & AI processing

Our "Get Verified" feature builds a Talent Graph - a structured, evidence-backed view of what you have demonstrated for a target role. It only runs when you start it, and only on data you provide or connect. Before any evidence is processed we ask for your explicit agreement to these terms and this policy, and we record when you gave it.

What we collect for it

  • Profile & onboarding details. Username, who you are (student / fresher / professional), education or work details, target role, goals, and companies you are interested in.
  • Resume data. A resume you upload or sync from The Perfect Resume. We store the file and a structured version (work history, education, skills, projects, certifications). Contact details are removed before any text is sent to an AI model.
  • Connected accounts (only when you connect them). GitHub (via GitHub's own authorization; we read only the repositories you grant), LinkedIn (via LinkedIn sign-in for identity and, if you choose, posting; your public profile is fetched from the URL you provide), and public activity on Credly, Hugging Face, LeetCode and HackerRankfor the usernames you enter. We never ask for your passwords.
  • Simulation & interview results. Your OneRoadmap job-simulation results and, when enabled, contextual-interview answers.

How the AI is used - and what it is not allowed to do

AI models (currently Google Gemini) read the evidence above and produce observations against a fixed, published competency rubric - for example, "implemented input validation" with a reference to the file or answer that shows it. Every observation is validated against the rubric and stored with the prompt and model version used. The AI never sets a score, level or verification status. Those are computed by OneRoadmap's own deterministic rules from the validated observations, and every result stores the exact evidence, configuration versions and rules that produced it, so it can be audited and re-evaluated.

Security of connected-account data

Access tokens for connected accounts are stored encrypted at rest (AES-256-GCM) and used only to read the data described above. Your Kaggle-style API keys or platform passwords are never stored. You can disconnect any account at any time from the Get Verified page, which revokes our access and deletes the stored token.

What is public

Nothing from the Talent Graph is public unless you make your profile public. Your public profile shows your verification status, competency levels (never raw scores), certificates, projects and the accounts you connected - you control each section's visibility and can set the whole profile to private.

Retention & your choices

Evidence and graph versions are kept while your account is active so results stay auditable; deleting your account deletes them, along with stored resume files and connected-account tokens. You can replace your resume (the previous file is deleted), remove projects and certifications, and re-run the evaluation at any time. If you are in the EEA/UK, the legal basis for this processing is your consent (Art. 6(1)(a) GDPR), which you can withdraw by disconnecting sources or deleting your account.

Ori, the OneRoadmap Chrome extension

Ori is our optional Chrome extension. It works only on the tab where you open its side panel, on sites you have allowed, and everything it sends to OneRoadmap is covered by this policy.

  • What it reads. When you ask Ori to read a job or an application form, the extension sends that page's address, the job posting text and the structure of the form (field labels and types - never what you or the employer typed into it) to OneRoadmap, so we can identify the job and prepare your application.
  • What it writes. Only when you press Autofill, it writes your own saved details or the answers you approved into that form. It never submits an application, never fills legal, identity or self-identification questions, and never overwrites what you typed.
  • Sign-in. You sign in through a OneRoadmap window. The extension keeps a short-lived session token on your device and never sees your password; signing out or uninstalling removes it.
  • Tracking. When you tell Ori that you submitted an application, we record that on your application in OneRoadmap, with the time you confirmed it and whether you used autofill. Jobs you analyse are added to OneRoadmap's job catalogue as public job facts only; nothing about you or your application is attached to them.

6. Certificates are public by design

Verification is the point of a OneRoadmap credential. When you earn a certificate, a public verification page is created at a unique URL showing your certificate name, the credential, score/percentile, issue date, certificate ID and - where applicable - your weekly leaderboard rank. Anyone with the link (for example a recruiter) can view it. Leaderboards similarly display your first name/display name and photo.

If you want a certificate page unpublished or your leaderboard entry anonymised, email gauravghai@htmlhints.com and we will action it within 30 days. Note that unpublishing a verification page makes the credential unverifiable.

7. Cookies & consent

We use a small number of cookies and similar technologies:

  • Essential cookies. Sign-in sessions, security and remembering your cookie choice. These are required for the Services to work and don't need consent.
  • Analytics cookies. Help us understand aggregate usage. These load only after you click “Accept” on our cookie banner; clicking “Decline” keeps them off without affecting your use of the Services.

You can change your choice at any time by clearing cookies for oneroadmap.io (the banner will reappear) or via your browser settings. We do not use third-party advertising cookies and we honor the choice you make in the banner across the site.

8. How we share data

We do not sell or rent your personal data, and we do not share it with third parties for their own advertising. We share data only with:

  • Service providers (processors). Companies that help us run the Services under contract and only on our instructions: payment processing (Razorpay), cloud hosting and databases, email delivery, error monitoring/analytics, and AI model providers used to grade submissions and generate feedback. AI providers are not permitted to use your submissions to train their models under our agreements.
  • People you choose to share with. Public certificate pages, leaderboard entries and anything you post publicly or share to LinkedIn.
  • Legal and safety. Authorities or parties where required by law, court order, or to protect the rights, property or safety of OneRoadmap, our users or the public.
  • Business transfers. If we are involved in a merger, acquisition or asset sale, personal data may transfer as part of that transaction - we will notify you and this policy will continue to apply until amended.

9. International transfers

We are based in India and use cloud infrastructure that may store or process data in other countries (including the United States). When we transfer personal data across borders we protect it as required by the law that applies to you:

  • EEA / UK. Transfers rely on adequacy decisions where available, or the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), plus supplementary safeguards.
  • India (DPDP Act). We transfer personal data outside India only to countries not restricted by the Central Government, and our processors are bound by contract to equivalent protections.
  • UAE (PDPL). Transfers are made to jurisdictions with adequate protection or under appropriate contractual safeguards and, where required, your consent.

10. How long we keep data

  • Account data: for as long as your account exists, then deleted or anonymised within 90 days of a verified deletion request.
  • Certificates & verification records: retained while the credential remains valid, because employers rely on the verification page - unless you ask us to unpublish it (Section 5).
  • Assessment submissions: kept while relevant for grading, integrity review and your reports; work files are routinely purged after the review window.
  • Payment & tax records: kept for the period required by Indian tax and company law (typically 8 years).
  • Server logs: short-lived and rotated automatically.

When data is no longer needed for the purpose it was collected (or when consent is withdrawn and no other lawful basis applies, as the DPDP Act requires), we delete or irreversibly anonymise it.

11. Security

We use encryption in transit (HTTPS/TLS), encrypted storage with our cloud providers, OTP-based sign-in instead of stored passwords, scoped access controls, and payment processing that keeps card data with a PCI-DSS-compliant processor. No system is perfectly secure - if we learn of a breach affecting your personal data we will notify you and the relevant authority (for example a supervisory authority, the Data Protection Board of India, or your state regulator) within the timelines the law requires.

12. Your rights by region

You can exercise any of these rights by emailing gauravghai@htmlhints.com from your registered email address (we may verify your identity). We respond within 30 days, or the shorter period your local law sets, and we will never discriminate against you for exercising a privacy right. Many actions - editing your name, or deleting your account - are also available in Dashboard → Account Settings. Step-by-step deletion instructions, including for data you shared over WhatsApp, are at Delete your data.

European Economic Area & United Kingdom (GDPR / UK GDPR)

  • Right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection (including to legitimate-interests processing and to any direct marketing).
  • Right to withdraw consent at any time without affecting prior processing.
  • Right to lodge a complaint with your supervisory authority - in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority of your member state.

India (Digital Personal Data Protection Act, 2023)

  • Right to access a summary of your personal data and the processing activities; right to correction, completion, updating and erasure.
  • Right to withdraw consent as easily as it was given; right to grievance redressal through our Grievance Officer (details in Section 1 and the footer below), who responds within the timelines prescribed under the DPDP Act and IT Rules.
  • Right to nominate another individual to exercise your rights in the event of death or incapacity, and the right to approach the Data Protection Board of India if unsatisfied with our response.

United States - California (CCPA/CPRA) and other state laws

  • Right to know/access the personal information we collect, use and disclose; right to correct and to delete; right to data portability.
  • Right to opt out of “sale” or “sharing” of personal information - we do not sell or share personal information as those terms are defined in the CPRA, and we do not use or disclose sensitive personal information beyond what the law permits.
  • Right to non-discrimination, and to use an authorized agent to submit requests. Residents of Virginia, Colorado, Connecticut, Utah and other states with comprehensive privacy laws have equivalent rights, which we honor through the same contact.

United Arab Emirates (Federal Decree-Law No. 45 of 2021 - PDPL)

  • Right to access and receive a copy of your personal data, and to request correction or erasure of inaccurate data.
  • Right to restrict or object to processing, including for direct marketing, and to withdraw consent.
  • Right to complain to the UAE Data Office if you believe your data has been processed in violation of the PDPL.

13. Children

The Services are intended for users aged 16 and over. If you are under 18 and located in India, you may use the Services only with the verifiable consent of a parent or guardian, as the DPDP Act requires - and we do not use children's data for tracking, behavioural monitoring or targeted advertising. We do not knowingly collect data from children under 13 anywhere; if you believe a child has provided us personal data, contact gauravghai@htmlhints.com and we will delete it promptly.

14. Marketing choices

We send marketing emails only with your consent or as otherwise permitted by law, and every marketing email includes an unsubscribe link that works immediately. Service messages (OTP codes, results, receipts, deadline warnings) are not marketing and continue while you hold an account.

15. Changes to this policy

When we make material changes we will update the “Last updated” date above and notify you by email and/or an in-app notice before the changes take effect; where the change requires fresh consent under your local law, we will ask for it. Earlier versions are available on request.

Questions, requests or complaints

GHAI TECHNOLOGIES PRIVATE LIMITED (OneRoadmap™) · Grievance / Privacy Officer: Gaurav Ghai · gauravghai@htmlhints.com · Support: support@oneroadmap.in. We acknowledge requests promptly and aim to resolve them within 30 days (or sooner where local law requires).