1. Introduction & Scope
At MentorTechz ("we", "our", "us"), protecting the privacy and personal data of our visitors, internship applicants, enrolled candidates, and partners is an essential priority. This Privacy Policy outlines our verified practices regarding the collection, processing, storage, and protection of information obtained through our website (https://mentortechz.sbs), candidate portal, and administrative document workflows.
This policy applies to all personal information submitted via online application forms, imported candidate records, candidate dashboard profiles, project assignment submissions, payment verification receipts, and contact inquiries.
2. Information We Collect
We only collect information directly relevant to evaluating candidate applications, administering project tracks, delivering mentorship, and issuing verifiable completion credentials:
A. Identification & Contact Details
- Full Legal Name: Used for candidate identification, account profiles, and official certificate issuance.
- Contact Channels: Email address (used for password setup, notifications, and portal authentication) and phone/WhatsApp number (used for candidate communication and onboarding).
- Geographic Information: City, country, and time zone (used to schedule mentor sessions and compute submission deadlines accurately).
- Profile Images: Candidate-uploaded profile avatars or photos displayed within the candidate portal dashboard.
B. Academic, Experience & Application Details
- Education Background: Educational qualification, university or college name, current semester, or graduation year.
- Technical Proficiencies: Programming languages, frameworks, development tools, and selected internship domains (e.g., Web Development, Mobile Apps, UI/UX).
- External Profiles: URLs to GitHub repositories, LinkedIn profiles, or live web portfolios submitted for evaluation.
- Resumes & CVs: Candidate-uploaded resume files, stored with original file names, MIME types, and encoded formats for administrative review.
C. Candidate Portal Activity & Project Submissions
- Authentication Data: Cryptographically hashed passwords (using industry-standard bcrypt hashing). We never store plain-text passwords.
- Security Tokens: Cryptographically generated one-time tokens for initial password setup and SHA-256 hashed tokens for secure password resets with strict expiration limits.
- Session & Liveness Tracking: Secure session cookies (
candidate_session) and periodic activity timestamps (lastSeenAtheartbeat) used to monitor portal engagement and account activity. - Project Submissions: Code repository links, deployment URLs, submission notes, uploaded code files, zip archives, and task artifacts.
- Evaluation Records: Project review statuses (Approved, Under Review, Changes Requested), mentor feedback, rubric scores, and preliminary automated code assessments.
D. Payment Confirmations & Document Issuance Data
- Payment Method Selected: Easypaisa, JazzCash, or PayPal.
- Transaction Proof: Candidate-submitted payment receipt screenshots or documents (validated up to 5MB) and candidate-provided transaction reference IDs or notes.
- Verification Timestamps: Exact dates and times when payment was submitted, verified by administration, or rejected with logged administrative reasons.
- Issued Document Records: Generated Certificate of Completion and Letter of Recommendation PDF records, issuance timestamps, and unique reference codes (e.g.,
MT/CERT/...andMT/REC/...).
3. How We Use Your Information
The personal data collected is utilized solely for lawful educational, developmental, and administrative purposes, specifically:
- Application Evaluation: Assessing candidate eligibility, programming familiarity, and cohort placement;
- Portal Management: Authenticating candidate logins, enabling dashboard features, tracking assigned project tasks, and recording submission milestones;
- Feedback & Mentorship: Reviewing submitted code, providing technical critique, and communicating project revision guidance;
- Payment Auditing: Manually cross-referencing candidate payment proofs with financial account statements for document processing fees;
- Credential Generation: Generating tamper-resistant digital Certificates and personalized Letters of Recommendation with verifiable reference identifiers;
- System Security: Detecting and mitigating unauthorized portal access, duplicate accounts, or fraudulent submissions.
4. Data Security & Storage Controls
We implement technical, architectural, and procedural safeguards verified in our production software stack:
Password Security
All candidate passwords are cryptographically salted and hashed using bcrypt before database insertion. Plain-text passwords are never saved or visible to administrative staff.
Hashed Reset Tokens
Password reset links rely on one-time raw tokens whose SHA-256 hashes are validated against the database with strict expiry windows, preventing unauthorized interception.
Secure Session Cookies
Authenticated candidate portal access is enforced via secure, HTTP-only session cookies with role-based permission checks at every endpoint.
Strict File Validation
File uploads (including payment proof screenshots and code deliverables) enforce a strict 5MB file size limit and type inspection to protect against malicious payloads.
Our database layer utilizes Prisma ORM with parameterized queries, preventing SQL injection vulnerabilities. Access to the administrative dashboard is restricted to authorized personnel with authenticated admin credentials.
5. Data Retention Policy
We retain candidate records in accordance with operational necessity:
- Active Candidate Accounts: Data remains active throughout the duration of the internship and project evaluation cycle.
- Issued Credential Records: Certificate reference IDs, recipient names, dates, and issuing records are retained permanently in our secure database archive to enable lifetime credential verification by potential employers or educational institutions.
- Payment Proof Artifacts: Payment verification screenshots are retained during the verification window and auditing period, after which access is limited to administrative ledger archives.
- Inactive or Rejected Applications: Applications not accepted or abandoned candidate accounts may be purged periodically following administrative review.
6. Your Rights & Deletion Requests
Candidates have clear rights regarding the personal information held by MentorTechz:
- Access & Review: You can view and edit your personal information, contact number, and profile picture at any time through the Candidate Portal Dashboard.
- Correction: If any recorded detail (such as spelling of your legal name for certification) is inaccurate, you may request a correction prior to document issuance.
- Data Deletion Request: You may request the deactivation of your portal account and deletion of your profile data by emailing our administrative team at softwarehousementor@gmail.com. Upon receiving your verified request, we will remove your active portal account and associated personal artifacts, subject to preserving legally required ledger records and already-issued certificate verification entries.
7. Third-Party Services & External Links
The MentorTechz platform may contain links to external third-party platforms (including GitHub, LinkedIn, WhatsApp, Facebook, and payment providers like Easypaisa, JazzCash, or PayPal). Please note that MentorTechz does not control the privacy practices or content of external platforms. We encourage candidates to review the privacy policies of any third-party website they visit.
8. Privacy Inquiries & Contact
For questions, privacy concerns, or data deletion requests, please contact our designated website administrator:
MentorTechz Privacy Administration
Email: softwarehousementor@gmail.com
Phone / WhatsApp: +92 331 9109875
Headquarters: Islamabad, Pakistan
