Back to BiPeer
Get Support
Transparency & Data Trust

Privacy Policy

Your privacy and academic data sovereignty are fundamental to BiPeer. This Privacy Policy details the exact data we collect, how it is processed, third-party disclosures including Google AdSense and Safepay, and your statutory data rights.

Effective Date: September 1, 2026•Last Updated: 2026-09-01•Operator: BiPeer (Pakistan)

1. Introduction & Overview

BiPeer ("BiPeer," "we," "our," or "us") operates the higher education ecosystem, student networking, career discovery, and Pathfinder platform available at https://bipeer.com.

BiPeer operates with primary infrastructure and engineering teams based in Pakistan, serving verified university students, educators, recruiters, creators, and organizational partners domestically and globally.

This policy applies to all registered and visiting users across our web applications, mobile interfaces, APIs, and associated digital services. By accessing or registering for BiPeer, you acknowledge the data handling practices described in this document.

2. Information We Collect

We adhere to strict data-minimization principles. The personal data we collect depends on your account type (Student, Individual, University, Company, Club, NGO, or Creator) and platform usage:

A. Account Credentials & Direct Registration Data

Full name, unique username, primary account email address, sparse phone number (where voluntarily provided), cryptographic salted password hashes (bcrypt), and optional Google OAuth profile identifiers.

B. Academic & Institutional Verification Data

Enrolled university, academic department, discipline, degree level (BS, MS, PhD, MBBS, BBA, etc.), graduation year, student status, and verified institutional email addresses (e.g. .edu.pk addresses verified via SHA-256 hashed one-time verification tokens).

C. Career & Talent Profile

Curriculum Vitae / Resume documents (stored securely in private AWS S3 storage), listed technical skills, work experience, portfolio links, GitHub/LinkedIn URLs, desired roles, and salary expectations (where made discoverable to employers).

D. User-Generated Content (UGC)

Posts published to the university feed, attached images/documents (uploaded directly to private AWS S3 buckets with direct presigned URLs), comments, event creations, scholarship listings, job applications, bookmarks, and private direct messages.

E. Automatically Collected Device & Telemetry Data

Device identifiers, browser user-agent strings, coarse approximate IP geolocation (city/country level for security sessions and regional load balancing), session timestamps, operating system version, and server logs. BiPeer never tracks or collects continuous background GPS coordinates.

3. How We Use Your Data

We process your personal information strictly for legitimate operational purposes:

  • Authentication & Security: Verifying credentials, managing multi-factor authentication (TOTP), revoking active sessions, and protecting against brute-force attacks.
  • Institutional Proof: Confirming institutional affiliation so verified students can access campus-exclusive discussions, voting, and student guide opportunities.
  • Opportunity Discovery: Matching students with verified scholarships, campus hackathons, and employer postings based on department and listed skills.
  • Platform Communications: Sending critical security notifications, verification codes, application updates, and support communications via our transactional mail gateway.
  • Fraud Prevention & Abuse Moderation: Enforcing our Community Guidelines, preventing scam jobs or fake scholarships, and investigating reported content.

4. Artificial Intelligence & Automated Processing

BiPeer integrates optional AI-powered advisory features, including Pathfinder Career AI and Job Fit Candidate Analysis.

Service Providers: AI queries are processed through authorized enterprise APIs provided by Google Cloud (Gemini) and OpenRouter.

Data Shared with AI Models: When you initiate an AI fit analysis or ask Pathfinder a question, only the relevant excerpt (such as the target job description and your listed public skills or anonymized career interest prompt) is sent for analysis. Passwords, payment data, and private messages are never passed to AI inference models.

Advisory Nature: AI analysis outputs (including match scores and skills gap advice) are automated estimations intended solely for educational guidance. They do not constitute guaranteed admission, employment offers, or professional career endorsements.

5. Google AdSense & Advertising Disclosures

BiPeer displays advertisements on select public discovery pages (such as `/opportunities`, `/scholarships`, `/events`, and public articles) to fund free academic tools and platform infrastructure.

Mandatory Google Publisher Disclosures

We partner with Google AdSense (Publisher ID: ca-pub-4783681911433771) to serve commercial advertising on designated sections of BiPeer.

  • Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to BiPeer or other websites on the Internet.
  • Google's use of advertising cookies (including the DoubleClick cookie) enables it and its partners to serve ads to users based on their visit to BiPeer and/or other sites on the Internet.
  • Users may opt out of personalized advertising by visiting Google Ads Settings. Alternatively, users may opt out of third-party vendor cookies for personalized advertising by visiting aboutads.info.
  • Consent for Users in the EEA/UK: Visitors located in the European Economic Area (EEA), the United Kingdom, and Switzerland are served advertising in compliance with the IAB Europe Transparency and Consent Framework (TCF) and Google certified Consent Management Platforms (CMP).
  • Ad-Free Entitlement: BiPeer strictly suppresses display advertising for verified Premium subscribers holding the AD_FREE entitlement, as well as on private student dashboards, checkout flows, and direct messaging workspaces.

6. Cookies & Browser Storage

We use strictly necessary session cookies, functional storage, and third-party advertising cookies. For complete technical definitions of every cookie name, duration, and purpose, please consult our dedicated Cookie Policy.

  • Strictly Necessary: accessToken, refreshToken, and csrfToken HTTP-only cookies required for session security.
  • Functional Storage: theme preference and sidebar state in browser localStorage.
  • Advertising: Third-party advertising cookies managed by Google AdSense on eligible public pages.

7. Payments & Billing via Safepay

BiPeer processes digital subscription and event payments using Safepay (https://getsafepay.com), a licensed payment gateway operating in Pakistan.

No Raw Card Storage: When making a payment, your credit/debit card details, mobile wallet accounts, or banking credentials are submitted directly to Safepay's PCI-DSS compliant secure checkout environment. BiPeer never collects, processes, or stores your raw card numbers or CVV codes on our servers.

Transaction Metadata: BiPeer retains only transaction metadata necessary for billing reconciliation, invoice delivery, and account provisioning (order ID, tracker token, transaction status, amount paid, currency PKR, and timestamp).

8. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. Personal information is only disclosed to:

  • Cloud Infrastructure & Storage: AWS S3 (secure media asset storage) and MongoDB Atlas (encrypted database cluster).
  • Transactional Email: Hostinger Mail API for verification codes and account notifications.
  • Payment Gateway: Safepay for processing payment authorization and refunds.
  • Advertising Partners: Google AdSense for serving display ads on public pages.
  • Law Enforcement & Legal Process: When compelled by valid, binding legal orders from competent courts or regulatory bodies in Pakistan.

9. Public vs. Private Information

BiPeer is an academic and networking community. It is critical to understand what other members can see:

  • Public to Members: Your name, username, enrolled university, profile photo, headline, and posts you submit to public feeds.
  • Configurable Audience: In your Settings > Privacy, you can restrict whether your email, phone, or resume downloads are visible to everyone, connections only, or nobody.
  • Private: Direct messages, password hashes, payment receipts, draft content, and support tickets are private and visible only to you and authorized platform staff.

10. Data Retention & Cryptographic Security

We employ industry-standard technical safeguards, including TLS 1.3 encryption in transit, strict Content Security Policies (CSP) with dynamic nonces, salted bcrypt password hashing, and role-based access control.

We retain personal data for the duration of your active account lifecycle. Financial transaction records are retained for statutory accounting periods mandated under Pakistani commercial law.

11. Your Rights: Export & Deletion

We provide automated self-service data management tools inside your account:

Self-Service Data Export

Export your profile, preferences, and activity in standard JSON format anytime via Settings > Data & Privacy.

30-Day Scheduled Deletion

Schedule permanent account deletion with a 30-day grace period. During this window, you may cancel deletion by logging back in.

12. Age & Children's Privacy

BiPeer is designed for university applicants, undergraduate scholars, graduate researchers, and adult professionals. Users must be at least 16 years of age (or the minimum legal age of digital consent in their jurisdiction) to create an account.

We do not knowingly collect personal data from individuals under 16. If we become aware that an account belongs to a child under 16, we will promptly terminate the account and purge associated data.

13. International Access & Cross-Border Transfers

BiPeer is accessible worldwide. If you access the platform from the European Union, United Kingdom, United States, or other international regions, your information will be transferred to and processed in secure cloud facilities located in Pakistan and AWS global regions. We ensure appropriate technical safeguards protect cross-border transfers.

14. Contact Our Privacy Officer

For privacy inquiries, rights requests, or data protection questions, you may contact our dedicated privacy officer:

Email: privacy@bipeer.com / support@bipeer.com

Questions, Legal Inquiries, or Disputes

If you have questions regarding this policy, please reach out to our legal and support team:

General Supportsupport@bipeer.com
Legal & Privacy Desklegal@bipeer.com