Legal
Privacy Policy
Effective date: 18 July 2026
This Privacy Policy explains how REAP FITNESS (Proprietorship of Aparna Mahesh) collects, uses, stores, and shares personal data when you use www.reapfitness.in, our member app, and studio services. We aim to process data fairly, for clear purposes, and in line with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act) as it applies to us.
1. Who we are
Data fiduciary / business: REAP FITNESS, Proprietorship of Aparna Mahesh.
Address: 2nd Floor, No.1, Janaki Avenue 4th Street, Abiramapuram, Alwarpet, Chennai - 600018, Tamil Nadu, India.
Privacy contact: move@reapfitness.com · +91 98402 98336.
2. Data we collect
- Identity & contact: name, phone number, email, date of birth, and account identifiers.
- Authentication: Google sign-in tokens (we do not store your Google password).
- Health & safety: waiver acceptances, health declarations, injury notes you choose to share, and related acknowledgements.
- Bookings & membership: sessions booked, waitlists, check-ins, credits, orders, cancellations, no-shows, and strike/lock status.
- Payments: order amounts, status, and payment references from Razorpay (card/UPI details are processed by Razorpay; we do not store full card numbers).
- Device & usage: app/browser type, approximate logs needed for security and debugging, and notification tokens.
- Communications: messages you send us and records of transactional notifications.
- CCTV: video footage from studio premises (excluding toilets/changing areas).
- Optional media: photos/videos only if you opt in to media consent.
3. How we collect data
- Directly from you (account, booking, waiver, contact forms).
- Automatically via cookies/SDKs on the website and app (see Cookie Policy).
- From payment partners (Razorpay) for payment confirmation.
- From authentication providers (e.g. Firebase/Google) for sign-in.
- From CCTV systems on premises.
4. Why we use data
- Provide accounts, bookings, credits, waitlists, QR check-in, and customer support.
- Process payments and issue receipts.
- Manage safety: waivers, medical disclosures you provide, pregnancy clearance workflows, and incident response.
- Enforce studio rules, cancellation/no-show policies, and booking limits.
- Send transactional reminders (e.g. class reminders, waitlist offers) via WhatsApp, SMS, email, or push.
- Send marketing only with consent where required; you may withdraw marketing consent anytime.
- Secure our systems, prevent fraud/abuse, and comply with law.
- Improve products using aggregated or de-identified insights where practicable.
- Studio security via CCTV.
5. Legal bases / consents (DPDP)
Depending on the processing, we rely on: (a) consent (e.g. marketing, optional media); (b) performance of a contract / requested service (account, booking, payment); (c) employment/legitimate operational needs for security and fraud prevention where permitted; and (d) compliance with legal obligations.
You may withdraw consent for consent-based processing without affecting processing that is necessary to provide services you requested, subject to law.
7. Cross-border processing
Some providers (for example authentication or cloud tools) may process data on servers outside India. Where this occurs, we take steps consistent with applicable law and provider terms. By using our services, you acknowledge that such processing may be necessary to operate the website and app.
8. Retention
- Account & booking records: while your account is active and for a reasonable period afterward for disputes, accounting, and legal compliance.
- Payment records: as required for tax and financial record-keeping.
- Waiver/health acknowledgements: for the period needed for safety and legal defence.
- CCTV: typically for a limited security window, unless retained longer for an incident or legal request.
- Marketing preferences: until you opt out or your account is deleted.
9. Security
We use reasonable technical and organisational measures (access controls, encrypted transport where applicable, least-privilege staff access). No method of transmission or storage is perfectly secure; please protect your devices and login credentials.
10. Children
Our services are available from age 12. For users under 18, a parent/guardian must provide required consents. We do not knowingly market to young children. If you believe a child under 12 provided data, contact move@reapfitness.com so we can delete it.
11. Your rights
Subject to applicable law, you may request access, correction, or erasure of your personal data, withdraw consent, or raise a grievance. Contact move@reapfitness.com. We may need to verify your identity and may retain certain records where legally required (for example completed payments or waivers).
Account deletion: email move@reapfitness.com from your registered address (or use in-app controls if available) requesting deletion. We will delete or anonymise personal data that is no longer needed, except records we must keep for law, accounting, fraud prevention, or dispute resolution.
13. Updates
We may update this Policy from time to time. The effective date at the top will change when we do. Significant changes may also be notified in-app or by email where appropriate.
REAP FITNESS
Proprietorship of Aparna Mahesh
2nd Floor, No.1, Janaki Avenue 4th Street, Abiramapuram, Alwarpet, Chennai - 600018, Tamil Nadu, India