Skip to content
RewinityRewinity
Legal

Plain language, real commitments

Privacy policy, terms of service, and DPDP compliance — aligned with how Rewinity works today.

Last updated · 10 July 2026

DPDP compliance

The Digital Personal Data Protection Act, 2023 (DPDP) governs how organisations in India process personal data. Rewinity Labs (“Rewinity”) is designed to comply by default — consent before exposure, minimisation of contact data, and rights you can exercise in the app.

Data fiduciary

Rewinity Labs (Bengaluru, India) is the data fiduciary for personal data processed through the Rewinity platform. Contact: [email protected].

We will register with the Data Protection Board and appoint a Data Protection Officer when required by applicable rules. Status updates will be published on this page.

Personal data we process

Categories include (see our privacy policy for detail):

  • Identifiers — phone number, account ID, device/session identifiers.
  • Profile & professional data — name, city, tags, bio, photos, service area.
  • Contact hashes & graph edges — not raw address-book numbers.
  • Transaction data — intro payments, wallet, points, redemptions.
  • Communications — intro briefs, chat messages, attachments, quick asks (auto-deleted after 24 hours), bounty broadcasts.
  • Matrimony data — only for users who opt in.
  • Technical & security logs — audit trail, push tokens, consent records, search-query log (rolling purge; deleted on deletion request).
  • Device-integrity data — root/jailbreak signals and Google Play Integrity / Apple App Attest verdicts, kept ≤ 90 days, used solely for platform security.
  • Crash reports — scrubbed diagnostics (no phone numbers, names, or message content) processed by our error-reporting provider.

Lawful basis: consent

We rely primarily on free, specific, informed, and withdrawable consent, captured per surface:

  • Age 18+ — confirmed at signup.
  • Terms & privacy — recorded with version 2026-07.
  • Circle (saved people) — a person is saved to someone’s rolodex only after they accept the request; revocable any time.
  • Bounty broadcasts — posting one is explicit consent to reveal your first name and need to its recipients.
  • Contact processing — before sync; OS permission for address book.
  • Per-contact discoverability — each contact defaults off until you enable it.
  • Master searchable toggle & reach — you control whether and how far you appear.
  • Per-introduction accept/decline — target must accept before contact details flow.
  • Channel choice — target picks phone, WhatsApp, email, and/or in-app chat.
  • Matrimony — separate opt-in consent when you enable the feature.
  • Push notifications — OS permission; in-app notification preferences.

Withdrawing consent (e.g. pausing presence, turning off discoverability, deleting your account) may limit features but will not require undue effort.

Purpose limitation

Data is used only to operate Rewinity: network search, introductions, chat, payments, points, referrals, matrimony (if enabled), security, and legal compliance. Contact data is never used for advertising or sold to third parties.

Data minimisation

  • Address-book numbers are hashed before server storage; raw numbers from your book are not kept.
  • Search shows masked cards — not phone numbers or full chain identities.
  • Card payments are handled by Razorpay; we do not store card numbers.
  • Exports strip other users’ PII from introduction chains (length only).

Data processors

We engage processors under contracts that require appropriate safeguards:

  • Twilio — OTP / SMS
  • Razorpay — payments
  • Tremendous — gift-card fulfilment
  • AWS — object storage
  • Expo — push delivery
  • Sentry — crash/error reporting (scrubbed)
  • Google — Play Integrity verification (Android)
  • Apple — App Attest verification (iOS)
  • SMTP email provider — transactional email
  • Infrastructure hosting — databases and caches

Some processing may occur outside India. We limit transfers to what is necessary and apply contractual protections.

Rights of the data principal

RightHow to exercise
Access & portabilitySettings → Privacy → Download my data (JSON)
CorrectionEdit profile and settings in the app
ErasureSettings → Privacy → Delete account (30-day grace; email to cancel)
Withdraw consentDiscoverability toggles, pause presence, disable matrimony, delete account
GrievanceEmail [email protected]

Retention

  • Active data — while the account is active.
  • Deletion requests — deactivate immediately; erase/anonymise within 30 days.
  • Financial records — retained as required by law, anonymised after erasure where applicable.
  • Security logs — ~1 year; error logs — ~30 days; ephemeral data — short TTLs.

Security safeguards

TLS in transit; access-controlled object storage; server-side contact pepper; webhook signature verification; role-restricted production access; rate limiting on abuse-sensitive endpoints. Details in our privacy policy.

Children

Rewinity is not directed at children under 18. We do not knowingly process children’s personal data. If you believe a minor has registered, contact us for removal.

Personal data breach

If we become aware of a personal-data breach likely to affect you, we will notify the Data Protection Board and affected users as required by the DPDP Act and its rules, and describe remedial steps we take.

Grievance officer

Direct grievances to [email protected]. We acknowledge receipt within 24 hours and resolve grievances within 15 days. The named officer’s details will be published here upon appointment.

Related documents

Questions? Contact us or email [email protected]

Your network awaits

The people you need are already connected to you.

Download Rewinity — illuminate the golden threads in your graph. Consent at both ends. Rewards for everyone who bridges.

Phone-verified · Default-off discoverability · No ads