Privacy Policy
This policy explains what personal data Rush4Rush collects when you use this website, why we collect it, who else sees it, and what you can ask us to do with it.
Last updated 19 August 2026
01Who controls your data
School of AI and future technologies, Universal AI University, organiser of Rush4Rush, is the data fiduciary responsible for the personal data collected through this website. We handle it in line with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made under it.
Universal AI UniversityKushiwali, PO Gaurkamath, VadapKarjat, Maharashtra 410201India02What we collect
Information you give us
- Your name and email address, collected when you sign in with a one-time code.
- Your phone number, so we can reach you about schedule changes or a problem with your registration.
- Your college or institution, and for students of the university, verification that your email uses the official college domain.
- Details specific to an event you enter — for example a team name, teammate names, a performance category, or a submission you upload.
- Where you pay by direct UPI transfer, the screenshot or reference you upload as proof.
Information created by using the site
- Your registrations, order history and payment status.
- Your ticket records and the time and gate at which a QR code was scanned.
- Basic technical logs — IP address, browser type, pages requested and timestamps — kept for security and troubleshooting.
Information we deliberately do not collect
We never receive or store your card number, CVV, expiry date, UPI PIN, netbanking password or any other payment credential. Those are entered directly with our payment gateway and never reach our servers. What we receive back is limited to a payment identifier, an amount, and whether the payment succeeded or failed.
We also do not ask for your date of birth, government ID number, caste, religion, health records or biometric data through this website.
03Why we use it
- To create your account and sign you in without a password.
- To take payment, issue a ticket, and prove at the gate that you paid.
- To work out which entry pass rate applies to you, based on your email domain.
- To give each club a list of who registered for its own events, so it can run them.
- To email you confirmations, tickets, reminders and changes to the programme.
- To manage venue capacity, attendance and safety.
- To detect fraud, duplicate tickets and misuse of the site.
- To produce aggregate footfall and participation figures for the university. These are counts, not lists of names.
We do not sell your data, rent it, or use it for advertising, and we do not send you marketing email unless you ask us to.
04The basis we rely on
For most of the above, we rely on your consent, given when you create an account and complete a registration. For issuing tickets and taking payment, we rely on the necessity of performing the contract you enter into when you buy a pass. For fraud prevention, security logs and record-keeping, we rely on our legitimate interest in running the festival safely.
You may withdraw consent at any time by writing to us. Withdrawing consent does not undo processing already carried out, and it may mean we can no longer honour a ticket you have bought.
05Who else sees it
We share the minimum necessary with the following, each of which is bound to use it only to provide their service to us:
- Razorpay Software Private Limited — our payment gateway. Receives your name, email and phone to process a payment and to handle refunds or disputes. Governed by Razorpay’s own privacy policy.
- Supabase — our database and authentication provider. Stores your account and registration records.
- Resend — our transactional email provider. Receives your email address in order to deliver one-time codes, confirmations and tickets.
- Vercel — our hosting provider, which serves this website and keeps standard access logs.
- Club administrators and volunteers — student organisers, who see the registration list for the specific clubs they are assigned to and nothing beyond that.
- University administration — which receives participation records and aggregate figures for the festival.
We will also disclose data where we are required to by law, by a court, or by a lawful request from a government authority or the police.
06Where it is stored
Our database is hosted in the Mumbai (ap-south-1) region, so your account and registration records are stored in India. Some of our service providers — in particular our email and hosting providers — operate infrastructure outside India, which means limited data such as your email address and access logs may be processed abroad. Where that happens, it is done under those providers’ contractual data protection commitments.
07How long we keep it
- Account details: until you ask us to delete them, or up to 12 months after the festival, whichever is sooner.
- Registration, ticket and payment records: retained for the period required for accounting, audit and tax purposes — ordinarily eight financial years — because they are financial records.
- Manual UPI payment proof: deleted once the payment is verified and reconciled.
- Technical and access logs: up to 90 days.
After these periods, data is deleted or reduced to anonymous statistics that cannot be traced back to you.
08How we protect it
- All traffic to this site is encrypted over HTTPS.
- Sign-in uses one-time codes sent to your email, so there is no password of yours for us to lose.
- Database access is restricted by row-level security rules, so club administrators can only read records belonging to their own clubs.
- Ticket QR codes are cryptographically signed, so a forged or altered code fails validation at the gate.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the Data Protection Board of India as required under the DPDP Act.
09Your rights
You can ask us to:
- Tell you what data we hold about you and who we have shared it with.
- Correct anything inaccurate or incomplete.
- Delete your data, where we are not required to keep it for accounting or legal reasons.
- Stop processing your data by withdrawing your consent.
- Nominate someone to exercise these rights on your behalf if you die or become incapacitated.
Write to Rush4Rush@universalai.in from the email address on your account. We will respond within 30 days. There is no charge for a reasonable request.
10Cookies
We use a small number of strictly necessary cookies. These keep you signed in after you enter your one-time code and protect forms against cross-site request forgery. We do not use advertising cookies or third-party tracking pixels. Blocking these cookies in your browser will stop you from being able to sign in.
11Children
This website is not intended for children under 16, and we do not knowingly collect their data. Where a registrant is between 16 and 18, we rely on consent given by a parent or guardian as required by the DPDP Act. If you believe a child has registered without that consent, contact us and we will delete the account.
12Changes to this policy
We will update this page when our practices change, and the date at the top will change with it. Where a change materially affects how we use your data, we will tell you by email.
13Grievance Officer
If you are unhappy with how we have handled your data, you can raise it with our Grievance Officer, appointed under the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines) Rules:
Yash PardeshiRush4Rush HeadRush4Rush@universalai.in
We acknowledge grievances within 48 hours and aim to resolve them within 30 days. If you remain dissatisfied, you may escalate to the Data Protection Board of India. See also our Contact Us page.