Privacy Policy
Effective date: 8 September 2026 Last updated: 8 September 2026
RL Apex LLP ("GROWTH", "we", "us") operates the GROWTH service. This policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the choices and rights you have. It applies to the GROWTH website and apps ("Service"). We are the data fiduciary for this data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. Data we collect
You give us
| Data | When | Why |
|---|---|---|
| Mobile number | Sign-up, verification | Account identity, one-time passwords (sent via WhatsApp), optional notifications |
| Email address | Sign-up (email method) or later | Account identity, sign-in, transactional email |
| Password (hashed), PIN (hashed), passkey public keys | When you set them | Authentication on trusted devices |
| Name, username, profile photo, timezone, guide preferences | Onboarding / profile edit | Personalising the app, showing you in the community |
| Identity / KYC documents you upload (e.g. ID images) | KYC step | Verifying your identity where required; regulatory / anti-fraud |
| Billing details — legal name, address, state, GSTIN if you provide one | Before a paid purchase | Issuing a valid tax invoice |
| Goals, habits, check-ins, weekly ratings, affirmations you write, wins | Using the app | Delivering the core product and your progress views |
| Community posts, comments, reactions, reports, uploaded post images | When you post | Running the community |
| Live-session RSVPs and questions | When you RSVP / ask | Managing attendance and Q&A |
| Support messages | When you contact us | Helping you |
Collected automatically
| Data | Why |
|---|---|
| Device and browser info, and an approximate location (city/region/country) derived from your IP when a device is first trusted | Security — so you can recognise your own "trusted devices" and spot a stranger's |
| Log and diagnostic data (IP address, timestamps, pages, errors) | Security, debugging, abuse prevention |
| Web-push subscription tokens | Sending notifications you asked for, to the devices you allowed |
| Cookies / local storage — session tokens, and small preferences (remembered tab, theme, unsent drafts) | Keeping you signed in; remembering choices. We do not use third-party advertising cookies. |
From third parties (only if you connect them)
| Source | Data | Why |
|---|---|---|
| Google Calendar (if you connect it) | An OAuth token, and read/write access to that week's events. We read this week's events and create/update events for your goal tasks, habits, and session RSVPs. We do not read your wider calendar history and nothing in your calendar can create goals or habits. | The two-way weekly sync you enabled |
| Razorpay | Payment status, method type, amounts, and a payment/order id — not your full card or bank number | Confirming payments, fulfilment, invoicing, refunds |
2. How we use your data
- Provide, maintain, and secure the Service and your account.
- Authenticate you and protect against fraud and unauthorised access.
- Process payments, renewals, refunds, and issue tax invoices.
- Send you service messages (verification codes, receipts, security alerts, changes to terms) — these are not optional while you have an account.
- Send you the notifications you chose (session reminders, daily affirmation, community mentions/replies, announcements) over web push, email, and — if you opt in — WhatsApp. You can change these any time in settings.
- Run the community and show your content to the audience you chose.
- Understand feature usage in aggregate to improve the product.
- Comply with law, enforce our Terms, and establish or defend legal claims.
3. Legal bases (DPDP Act)
- Your consent — for optional processing such as marketing/engagement notifications and connecting Google Calendar. You can withdraw consent at any time (see section 7); withdrawal does not affect processing already done.
- Legitimate uses / performance of the service you asked for — creating and running your account, delivering features you use, processing your payments, keeping the Service secure.
- Legal obligation — tax invoicing and record-keeping, responding to lawful requests, retaining KYC records where required.
4. Who we share it with
We do not sell your personal data. We share it only with:
- Service providers (data processors) who run parts of the Service on our
instructions, under contract:
- Supabase — database and file storage (hosted primarily in the Mumbai, India region)
- Vercel — application hosting and delivery
- Razorpay — payment processing
- Meta Platforms — sending WhatsApp one-time passwords and, if you opt in, WhatsApp notifications
- Google — Calendar API, and transactional email
- Other members — content you post in the community, and your public profile fields (name, username, photo), are visible to the audience you posted to.
- Authorities / legal — where required by law, court order, or to protect rights, safety, or the integrity of the Service.
- A successor — if we merge with or are acquired by another entity, your data may transfer, subject to this policy.
Some providers may process data outside India. Where that happens we rely on contractual safeguards and only transfer to jurisdictions permitted under applicable law.
5. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | While your account is active |
| Goals / habits / community content | While your account is active, unless you delete individual items sooner |
| KYC / identity documents | For as long as required for verification and any legal/regulatory retention period, then deleted or anonymised |
| Invoices and payment records | As required by tax law (typically 8 years in India) |
| Security and access logs | 12 months, then deleted or aggregated |
| Backups | Rolling backups are overwritten within 30 days |
When you delete your account, we remove or irreversibly anonymise your personal data within 30 days, except records we must keep by law (e.g. invoices) and minimal data needed to prevent re-abuse.
6. Security
We use industry-standard measures: encryption in transit, hashed passwords/PINs, row-level access controls in the database, private storage buckets for documents, scoped access for staff, and a content-security policy. No system is perfectly secure; we cannot guarantee absolute security. If a breach affects your data we will notify you and the Data Protection Board of India as required by the DPDP Act.
7. Your rights
Subject to the DPDP Act and its exceptions, you can:
- Access the personal data we hold about you and a summary of processing;
- Correct or update inaccurate or incomplete data — much of this you can do yourself in the app;
- Erase your data — delete your account in the app, or ask us;
- Withdraw consent for optional processing (notifications, calendar) — turn it off in settings or ask us;
- Nominate another person to exercise your rights in the event of death or incapacity;
- Grieve / complain — see section 9, and you may escalate to the Data Protection Board of India.
To exercise these, email pc@rlapex.in from your registered email/number. We may need to verify your identity. We will respond within the timeframe required by law.
8. Children
The Service is for adults (18+). We do not knowingly collect data from children. If you believe a child has given us data, contact pc@rlapex.in and we will delete it.
9. Grievance / Data Protection contact
Grievance Officer / Data Protection Contact: Priti More Email: pc@rlapex.in Address: Flat No. 'A' - 802, Sr No. 292/6/1/2/3/5/7, Pride Valencia, Dhankude Wasti, Pune, Maharashtra, 411045 We acknowledge grievances within 48 hours and resolve them within the period required by applicable law.
10. Changes
We may update this policy. Material changes will be notified in-app or by email before they take effect. The "Last updated" date and version at the top always reflect the current version.