REVMETIQ OS (“Platform”, “we”, “us”, “our”) is a business-to-business software-as-a-service platform that helps fitness and wellness businesses manage members, track revenue, and automate communications. This Privacy Policy is issued in accordance with Section 5 of the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It governs our handling of personal data in connection with the Platform.
1. Scope & Dual-Role Notice
REVMETIQ OS operates in two legally distinct capacities depending on whose personal data is being processed. This distinction is central to understanding your rights and our obligations.
Our Dual Role Under the DPDPA, 2023
Data Fiduciary — In respect of personal data that Gym Owners provide to us during registration and account use (your business name, owner name, email address, phone number, and billing information), REVMETIQ OS is the Data Fiduciary. We determine the purpose and means of processing this data.
Data Processor— In respect of personal data that Gym Owners upload or generate about their gym members (member names, phone numbers, payment history, etc.), REVMETIQ OS is the Data Processor. The Gym Owner is the Data Fiduciary for their members' data. We process member data strictly on documented instructions from the Gym Owner and for no other purpose.
This policy applies to both capacities. Where provisions differ in their application, this is noted clearly.
2. Data We Collect
2.1 Account & Business Data (Gym Owner Data — Direct Collection)
When a gym owner registers for and uses the Platform, we collect the following categories of personal and business data:
- Full legal name of the authorised gym representative or owner
- Business or gym name
- Email address (used as the primary login identifier)
- Mobile phone number
- Business address
- GSTIN (optional — required only if you wish to receive GST-compliant invoices)
- Country code, preferred currency, display language, and timezone
- Subscription plan tier and plan expiry date
- Payment and billing information — processed and tokenised by Razorpay; REVMETIQ OS never stores raw credit card numbers or bank account credentials
- WhatsApp Business API credentials (Phone Number ID and Access Token), if the gym owner chooses to connect a Meta WhatsApp Business Account
2.2 Member Data (Processed on Behalf of Gym Owners)
The following categories of personal data may be entered into the Platform by Gym Owners or their authorised staff in respect of gym members. REVMETIQ OS processes this data only as instructed by the Gym Owner:
- Full name
- Mobile phone number
- Email address (optional)
- Date of birth (optional)
- Gender (optional)
- Membership plan name, start date, and expiry date
- Payment history: amounts, dates, payment modes (cash, UPI, card, bank transfer), and GST records
- Outstanding dues and total payments collected
- Fitness notes or any free-form text entered by Gym Owner staff
- Member acquisition source (e.g., walk-in, referral, Google)
- Communication preferences (WhatsApp opt-out, preferred language)
- WhatsApp and SMS delivery logs (message type, delivery status, timestamp)
- AI-derived churn-risk scores and predicted lifetime value — computed internally on the Platform; these values are not sourced from any external data broker or third party
We do not collect or process any data categorised as “sensitive personal data” under the IT (SPDI) Rules, 2011 (such as passwords, financial account details, biometric data, health data, or sexual orientation) except as explicitly noted above in the context of payment record-keeping by the Gym Owner.
2.3 Automatically Collected Technical Data
- IP address and browser/device type (for security logging and fraud prevention)
- API request logs including endpoint, HTTP status code, and response time (retained for 30 days; used for monitoring and debugging)
- Session refresh token stored in an HttpOnly, Secure, SameSite=Strict cookie (no PII in readable form)
3. Legal Basis for Processing
REVMETIQ OS processes personal data only where a lawful basis under Section 4 of the DPDPA, 2023 exists:
Contract Performance
Processing Gym Owner account data (name, email, phone, billing information) is necessary to perform the subscription agreement between you and REVMETIQ OS. Without this data, we cannot create or maintain your account or deliver the Platform services.
Consent (for member data via Gym Owner instruction)
When Gym Owners upload or enter member data into the Platform, REVMETIQ OS acts as a Data Processor on the Gym Owner's instruction. The Gym Owner — as Data Fiduciary — is responsible for ensuring a valid lawful basis (typically consent) exists for collecting and sharing their members' personal data with the Platform.
Legitimate Interests
We process certain technical data (IP logs, security events) on the basis of our legitimate interest in maintaining the security, reliability, and integrity of the Platform, provided this interest is not overridden by the rights of the data principal.
Legal Obligation
We retain certain billing and invoice records for up to 7 years to comply with the requirements of the Goods and Services Tax Act, 2017, and the Income Tax Act, 1961.
4. How We Use Your Data
4.1 Gym Owner Data
- Creating and authenticating your account
- Delivering the subscription services described at revmetiqos.com
- Processing subscription payments and generating GST-compliant invoices via Razorpay
- Sending transactional communications (account activation, password reset, subscription renewal reminders, service alerts)
- Responding to support requests submitted by you
- Improving Platform features based on aggregate, anonymised usage patterns
- Enforcing these Terms of Service and our legal rights
4.2 Member Data (on behalf of the Gym Owner)
- Displaying member profiles, payment history, and plan details on the Gym Owner's dashboard
- Calculating membership expiry dates, outstanding dues, and GST-inclusive payment breakdowns
- Computing AI-generated churn-risk scores and predicted lifetime value using on-Platform algorithms (no data is sent to external AI models without separate disclosure)
- Automatically dispatching WhatsApp messages, SMS, and email reminders as configured by the Gym Owner (e.g., payment reminders, expiry alerts, birthday greetings)
- Generating downloadable PDF payment receipts
- Producing revenue analytics and forecasts visible only to the Gym Owner
No secondary use of member data.Member data is processed exclusively to provide the services contracted by the Gym Owner. REVMETIQ OS does not use member data for its own marketing, profiling, or any purpose beyond delivering the Platform's stated features.
5. Data Sharing — We Do Not Sell Your Data
REVMETIQ OS does not sell, rent, licence, or commercially disclose the personal data of Gym Owners or their gym members to any third party for marketing, advertising, data-brokering, or audience-profiling purposes. This is an absolute commitment.
We share data only in the following limited circumstances, and strictly to the extent necessary:
Infrastructure & Hosting Sub-processors
- Supabase (managed PostgreSQL database hosting) — stores all Platform data
- Upstash (managed Redis) — job queuing for automation tasks; no PII is stored permanently in Redis
- Railway (cloud deployment) — runs the API and background workers
- Cloudinary (media storage) — stores gym logo images
Each infrastructure provider processes data solely on our instructions under confidentiality obligations.
Communication Delivery Providers
- Meta Platforms Inc. (WhatsApp Business API) — receives member phone numbers and message content to deliver messages configured by the Gym Owner
- Twilio Inc. (SMS) — receives member phone numbers and SMS message content for SMS-fallback delivery
- Resend Inc. (transactional email) — receives member email addresses for sending automated emails configured by the Gym Owner
Payment Processor
- Razorpay Financial Solutions Pvt. Ltd. — processes subscription fees charged to Gym Owners. Razorpay is PCI DSS compliant. REVMETIQ OS does not store raw card or bank account data.
Legal or Regulatory Obligation
We may disclose personal data if required by applicable Indian law, a court order of competent jurisdiction, or a demand from a competent governmental or regulatory authority. Where legally permissible, we will notify the affected Gym Owner before disclosure.
Business Transfer
In the event of a merger, acquisition, corporate restructuring, or sale of the Platform, personal data may be transferred to the acquirer as part of that transaction. We will notify Gym Owners by email at least 30 days before any such transfer and will require the acquirer to honour the commitments in this policy.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| Active account data (Gym Owner + Member Data) | Duration of active subscription |
| All data post-account termination or deletion request | 90 calendar days — then permanently and irreversibly deleted from production database and all backups |
| WhatsApp / SMS / email delivery logs | 12 months from message date — then automatically purged |
| GST invoices and billing records | 7 years — as required under the GST Act, 2017, and Income Tax Act, 1961 |
| API request logs (IP, endpoint, status) | 30 days from log creation — then purged |
| Security event logs (failed login attempts, anomalous access) | 90 days — then purged |
The 90-day post-deletion window is maintained to allow for error recovery, pending support disputes, and data export. During this period, data is not accessible through the Platform UI. After 90 days, permanent deletion is executed automatically and irreversibly — no recovery is possible.
7. Data Security
REVMETIQ OS applies the following technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction:
- All data in transit is encrypted using TLS 1.3
- Data at rest is encrypted using AES-256 at the infrastructure layer (Supabase)
- Authentication uses JSON Web Tokens (JWT): short-lived access tokens (15 minutes) and HttpOnly, Secure, SameSite=Strict refresh cookies — preventing XSS-based token theft
- Webhook payloads from Razorpay and Meta are verified using HMAC-SHA256 signature validation before processing
- Row-Level Security (RLS) policies enforced at the PostgreSQL layer ensure that each Gym Owner can only access their own gym's data — even if the application layer is bypassed
- Role-based access control: staff accounts are restricted to permissions explicitly granted by the gym owner
- All direct database connections require SSL and use scoped, least-privilege credentials
- Automated dependency scanning and security patch management
- No production debugging — all testing occurs on local or staging environments
No security system is perfect. In the event of a confirmed personal data breach that is likely to result in risk to individuals, REVMETIQ OS will notify affected Gym Owners within 72 hours of becoming aware of the breach, consistent with applicable law, and will take immediate steps to contain and investigate the incident.
8. Your Rights Under DPDPA 2023
Under Chapter III of the Digital Personal Data Protection Act, 2023, Data Principals have the following rights in respect of their personal data:
Right to Access (Section 11, DPDPA)
You have the right to obtain a summary of the personal data we hold about you and information about how it has been processed. Email privacy@revmetiqos.com with subject line “Data Access Request”. We will respond within 30 calendar days.
Right to Correction and Erasure (Section 12, DPDPA)
You may update your business information directly within the Platform dashboard under Settings → Gym Profile. To request permanent deletion of your account and all associated data, email privacy@revmetiqos.com with subject line “Account Deletion Request”. Deletion will be processed within 30 days. The 90-day post-deletion retention window applies before data is permanently and irreversibly erased.
Right to Grievance Redressal (Section 13, DPDPA)
You have the right to raise a grievance about the processing of your personal data. See Section 12 of this policy (Grievance Officer) for contact details. We acknowledge all grievances within 48 hours and aim to resolve them within 30 days.
Right to Nominate (Section 14, DPDPA)
You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. Submit a nomination in writing to privacy@revmetiqos.com.
For Gym Members: If you are a gym member whose data has been entered into the Platform by a gym owner, please note that the Gym Owner is your primary point of contact as the Data Fiduciary for your data. Please contact your gym directly with requests relating to your personal information. If you forward us a request from a gym member, we will cooperate promptly.
10. Cross-Border Data Transfers
Our primary database (Supabase) is hosted in a region consistent with DPDPA guidelines. However, certain third-party sub-processors — including Meta Platforms (WhatsApp), Twilio (SMS), Cloudinary (media storage), and Upstash (Redis) — operate global infrastructure and may process data outside India as part of their service delivery.
REVMETIQ OS maintains contractual data processing agreements with all such providers requiring them to apply an adequate level of data protection. We will update this section as guidance under the DPDPA cross-border transfer framework (Section 16 of the Act) becomes formally notified.
11. Children's Data
The Platform is designed for adult business operators (18 years and older) running fitness and wellness establishments. REVMETIQ OS does not knowingly collect personal data directly from individuals under the age of 18 through the Platform itself.
Where Gym Owners enter data about gym members who are minors (for example, a junior sports training programme), the Gym Owner is solely responsible for ensuring that the requisite parental or guardian consent has been obtained under Section 9 of the DPDPA, 2023, before uploading such data.
If you believe that personal data of a person under 18 has been inadvertently submitted to the Platform without proper authorisation, please contact us immediately at privacy@revmetiqos.com.
12. Grievance Officer
In accordance with Section 13 of the Digital Personal Data Protection Act, 2023, and Rule 5 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, REVMETIQ OS has designated the following Grievance Officer:
Grievance Officer
REVMETIQ OS
West Bengal, India
Email: privacy@revmetiqos.com
Acknowledgement: within 48 hours of receipt | Resolution target: 30 days
Note: This record will be updated with the designated officer's name and designation upon company incorporation.
If you are not satisfied with the resolution provided by our Grievance Officer, you may approach the Data Protection Board of India once it is constituted under the DPDPA, 2023.
13. Amendments to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will:
- Post the revised policy at revmetiqos.com/privacy-policy with a new "Last Updated" date
- Send an email notification to all registered Gym Owners at least 7 calendar days before the change takes effect
- Display a prominent in-dashboard notice for 14 days following the effective date of the change
Your continued use of the Platform after the effective date of an amended Privacy Policy constitutes your acceptance of the revised terms. If you do not agree to the revised policy, you may terminate your subscription before the effective date as described in our Terms of Service.
Questions about this Privacy Policy?
We are committed to transparency. If anything in this policy is unclear, reach out and we will respond within 2 business days.
privacy@revmetiqos.com