1. Who we are
Sprout & Roots (the Sprout & Roots app for Android and iPhone, the Sprout & Roots web app and this website) is run by Scholastiq Innovations Pvt Ltd, Concorde , Electronic City, Bangalore, Karnataka, 560100, Bengaluru, Karnataka 560100 (“Sprout & Roots”, “we”, “us”).
Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) we are the Data Fiduciary for the personal data described here, and this policy is also our privacy policy under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Questions: contact@scholastiqinnovations.com or our Grievance Officer (section 14).
2. Who this policy covers
This policy covers parents and guardians who use Sprout & Roots, the children whose plan they follow, people who buy a gift subscription, and anyone who writes to us through the contact form.
Sprout & Roots is a service for adults: you must be 18 or older and the child’s parent or lawful guardian to create an account. Staff of partner schools who use our partner portal are covered by their agreement with us.
3. What we collect and why
We collect the following, mostly directly from you in the app:
| What | Details | Why we need it |
|---|---|---|
| Mobile number | Your Indian mobile number. | To sign you in with a one-time SMS code and to identify your account. One number is one child’s account. If you turn on the weekly WhatsApp report, also to send it to this number. |
| Child profile | Your child’s first name, age band (for example 2.5–3.5 years) and, if you choose one, an animal avatar. | To pick the right plan and personalise the app, certificates and monthly reports. |
| Activity progress | For each activity and plan day: introduced, practising or mastered, and when you recorded it. Badges earned; monthly report summaries. | To show progress, unlock badges and certificates, and create monthly reports. |
| Preferences | App language, a daily screen-time limit and reminder time; your time zone (India Standard Time by default). | To show the app in your language and unlock each day at your local midnight. |
| Billing details (optional) | Name for the invoice, billing address, state and GSTIN if you enter them. | To issue correct GST invoices (the state decides CGST + SGST or IGST). |
| Subscription and payment records | Plan, billing period, amounts, GST, invoice numbers, payment status and the payment reference from Razorpay, Apple or Google. | To give you access, issue invoices and credit notes, process refunds and meet tax and accounting law. |
| Feedback | Ratings you give an activity, monthly check-ins, and your reason when you cancel. | To improve the activities and the service. |
| Codes and invitations | Referral codes you use or share, gift codes (with the recipient’s first name and your message), school, doctor, hospital, employer or other partner codes. | To apply rewards, longer trials and discounts, deliver gifts and credit partners. |
| Live sessions | Whether you reserved a place in a live group session. | To manage places and send you a reminder. |
| WhatsApp report choice | Whether you turned the weekly WhatsApp progress report on or off, and when. Which weeks a report was sent. | To send the report only if you asked for it, and only once a week. It is off until you turn it on, and you can turn it off in Account at any time. |
| Device and notifications | A push notification token and the platform (Android, iOS or web). | To send notices, kit-shipping updates and reminders. |
| Materials kit delivery | The recipient name, a phone number for the courier, delivery address (with an optional landmark), PIN code, city and state you enter in the app, and the courier tracking number, for kit orders. | To deliver your kit (see the shipping policy). |
| Contact form | Your name, phone and/or email, topic, message, and the internet (IP) address it came from. | To answer you, and to stop spam and abuse. |
| Security logs | The internet (IP) address used to request a sign-in code, and standard server logs. | To limit abuse of SMS codes and keep the service secure. |
We do not collect photos or videos of your child, your child’s date of birth, your contacts, location, microphone or camera. There are no advertising or analytics trackers in the app or on this website.
4. Children’s information
Sprout & Roots is used by parents, for their children. The parent creates and controls the account; children do not sign in, chat or share anything. By creating a child profile you confirm that you are the child’s parent or lawful guardian and consent to us processing the child’s data described here, for the purposes described here.
- We keep child data to a minimum: first name, age band, optional animal avatar and activity progress.
- We do not track children, show them advertising, or build profiles of their behaviour for any purpose other than showing you their progress.
- Children never see comparisons or rankings with other children.
- Payments and links that open outside the app are behind a parental gate (a question for grown-ups).
- Certificates and monthly reports show your child’s first name; they are only available to you through time-limited links.
5. How we use it, and our legal basis
We use personal data only to:
- provide the service you signed up for: sign-in, your child’s daily plan, progress, badges, reports, notices and live sessions;
- take payments, issue GST invoices and credit notes, give refunds and apply gift, referral and school codes;
- deliver materials kits;
- answer your questions and complaints;
- keep the service safe (for example limiting how many SMS codes can be requested) and improve it using feedback;
- comply with law, including tax and accounting law and lawful requests from authorities.
We process your data on the basis of your consent, which you give when you sign up and use the app, and for the legitimate uses allowed by section 7 of the DPDP Act (for example where you have voluntarily given us data for a purpose, or where law requires us to keep records). You can withdraw consent at any time (section 10); we will then stop the service and delete your data, except what we must keep by law.
We do not sell or rent personal data, and we do not use it for advertising.
7. Where your data is stored
Our servers and database are in India (Amazon Web Services, Mumbai region, ap-south-1). A few providers necessarily process small amounts of data outside India: push notifications pass through Expo, Google and Apple, and in-app purchases are handled by Apple, Google and RevenueCat. Transfers outside India are made only as permitted under the DPDP Act.
8. Payment information
Card, UPI and bank details are entered on Razorpay’s secure checkout or in Apple’s or Google’s payment screens, never on our servers. We never see or store full card numbers, CVV, UPI PINs or bank passwords. From Razorpay we receive the confirmation of your payment (payment ID, amount, status and method, and the email, phone or UPI ID you gave Razorpay); we keep it with your payment record. Razorpay, Apple and Google handle payment data under their own privacy policies and the Reserve Bank of India’s rules.
9. How long we keep it
| Data | How long |
|---|---|
| Account, child profile, progress, preferences | While you have an account. Deleted at once when you delete your account in the app or on the delete account page, or within 30 days of a request by email. |
| Feedback | While you have an account. When you delete it, ratings and cancellation reasons are kept without your name, child or any text you wrote. |
| Invoices, payment and refund records | 8 years from the end of the financial year, as required by Indian tax and company law (GST Act, Companies Act, Income-tax Act). Kept after you delete your account, exactly as issued (with the billing name and address on each invoice), and used for nothing else. |
| Kit delivery details | With the kit order while you have an account. When you delete it, the name, address and phone are removed; the order number and status stay with the payment records. |
| Gift codes you bought | A paid code nobody has used yet stays valid for the person you gave it to after you delete your account (with the first name and message you wrote for them). Other gift details are removed. |
| Record of the deletion | The date, how it was requested and what was cancelled or refunded, with no personal data: kept with the payment records. |
| SMS sign-in codes | Stored only as a secure hash, valid for 10 minutes, deleted once used. |
| Sign-in request log (number and IP address) | Automatically deleted after about a day. |
| Contact form messages | Up to 2 years, to follow up on your request. |
| Backups | Deleted data can remain in encrypted backups until they expire, within 35 days. |
10. Your rights and choices
Under the DPDP Act you have the right to:
- access a summary of the personal data we hold about you and your child, and of the processing;
- correct, complete or update it (you can change your child’s avatar, the app language and your billing details in the app yourself; for anything else, write to us);
- erase it, and withdraw your consent, which closes your account;
- nominate another person to exercise your rights if you die or become unable to;
- grievance redressal through our Grievance Officer (section 14), and then the Data Protection Board of India.
When you delete your account:
- your plan is cancelled at once and web AutoPay renewals stop; if you are within the refund window you get a refund under our refund policy;
- your number, name, city and billing details, your child’s profile, progress, badges, certificates and reports, notices, live-session places, notification tokens and friend codes are deleted, and pending friend-code rewards are dropped;
- we keep invoices and payment records for 8 years as the law requires, and a paid gift code nobody has used yet stays valid for its recipient (see section 9);
- you can sign up again with the same number, as a new account with no history.
Cancelling a subscription does not delete your account. Deleting your account cannot stop an App Store or Google Play subscription: cancel it in your iPhone Settings (your name → Subscriptions) or in the Google Play app (profile → Payments & subscriptions → Subscriptions). You can stop push notifications in your phone’s settings, and the weekly WhatsApp report in the app (Account → Weekly WhatsApp report), at any time.
12. How we protect it
- All connections use HTTPS (TLS); the database is not reachable from the internet and only our servers can connect to it.
- Each parent can read only their own family’s data, enforced by the database itself (row-level security).
- Sign-in codes are stored only as hashes, expire after 10 minutes and are rate-limited; staff passwords are hashed.
- Invoices, certificates and reports are shared only through signed links that expire.
- Staff access is limited by role, and every change staff make is recorded in an audit log.
13. If something goes wrong
If a personal data breach affects you, we will inform you and the Data Protection Board of India as the DPDP Act and its rules require, and CERT-In where applicable, with what happened, what it means for you and what we are doing about it.
14. Grievance Officer
For any concern about your personal data or this policy, contact our Grievance Officer:
- Name
- Officer
- contact@scholastiqinnovations.com
- Address
- Scholastiq Innovations Pvt Ltd, Concorde , Electronic City, Bangalore, Karnataka, 560100, Bengaluru, Karnataka 560100
We acknowledge grievances within 48 hours and resolve them within 30 days of receipt. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
15. Changes to this policy
We will update this page when our practices change and change the “Last updated” date above. If a change materially affects how we use your data, we will tell you in the app before it takes effect and, where the law requires, ask for your consent again.