Last updated · 10 July 2026
DPDP compliance
The Digital Personal Data Protection Act, 2023 (DPDP) governs how organisations in India process personal data. Rewinity Labs (“Rewinity”) is designed to comply by default — consent before exposure, minimisation of contact data, and rights you can exercise in the app.
Data fiduciary
Rewinity Labs (Bengaluru, India) is the data fiduciary for personal data processed through the Rewinity platform. Contact: [email protected].
We will register with the Data Protection Board and appoint a Data Protection Officer when required by applicable rules. Status updates will be published on this page.
Personal data we process
Categories include (see our privacy policy for detail):
- Identifiers — phone number, account ID, device/session identifiers.
- Profile & professional data — name, city, tags, bio, photos, service area.
- Contact hashes & graph edges — not raw address-book numbers.
- Transaction data — intro payments, wallet, points, redemptions.
- Communications — intro briefs, chat messages, attachments, quick asks (auto-deleted after 24 hours), bounty broadcasts.
- Matrimony data — only for users who opt in.
- Technical & security logs — audit trail, push tokens, consent records, search-query log (rolling purge; deleted on deletion request).
- Device-integrity data — root/jailbreak signals and Google Play Integrity / Apple App Attest verdicts, kept ≤ 90 days, used solely for platform security.
- Crash reports — scrubbed diagnostics (no phone numbers, names, or message content) processed by our error-reporting provider.
Lawful basis: consent
We rely primarily on free, specific, informed, and withdrawable consent, captured per surface:
- Age 18+ — confirmed at signup.
- Terms & privacy — recorded with version
2026-07. - Circle (saved people) — a person is saved to someone’s rolodex only after they accept the request; revocable any time.
- Bounty broadcasts — posting one is explicit consent to reveal your first name and need to its recipients.
- Contact processing — before sync; OS permission for address book.
- Per-contact discoverability — each contact defaults off until you enable it.
- Master searchable toggle & reach — you control whether and how far you appear.
- Per-introduction accept/decline — target must accept before contact details flow.
- Channel choice — target picks phone, WhatsApp, email, and/or in-app chat.
- Matrimony — separate opt-in consent when you enable the feature.
- Push notifications — OS permission; in-app notification preferences.
Withdrawing consent (e.g. pausing presence, turning off discoverability, deleting your account) may limit features but will not require undue effort.
Purpose limitation
Data is used only to operate Rewinity: network search, introductions, chat, payments, points, referrals, matrimony (if enabled), security, and legal compliance. Contact data is never used for advertising or sold to third parties.
Data minimisation
- Address-book numbers are hashed before server storage; raw numbers from your book are not kept.
- Search shows masked cards — not phone numbers or full chain identities.
- Card payments are handled by Razorpay; we do not store card numbers.
- Exports strip other users’ PII from introduction chains (length only).
Data processors
We engage processors under contracts that require appropriate safeguards:
- Twilio — OTP / SMS
- Razorpay — payments
- Tremendous — gift-card fulfilment
- AWS — object storage
- Expo — push delivery
- Sentry — crash/error reporting (scrubbed)
- Google — Play Integrity verification (Android)
- Apple — App Attest verification (iOS)
- SMTP email provider — transactional email
- Infrastructure hosting — databases and caches
Some processing may occur outside India. We limit transfers to what is necessary and apply contractual protections.
Rights of the data principal
| Right | How to exercise |
|---|---|
| Access & portability | Settings → Privacy → Download my data (JSON) |
| Correction | Edit profile and settings in the app |
| Erasure | Settings → Privacy → Delete account (30-day grace; email to cancel) |
| Withdraw consent | Discoverability toggles, pause presence, disable matrimony, delete account |
| Grievance | Email [email protected] |
Retention
- Active data — while the account is active.
- Deletion requests — deactivate immediately; erase/anonymise within 30 days.
- Financial records — retained as required by law, anonymised after erasure where applicable.
- Security logs — ~1 year; error logs — ~30 days; ephemeral data — short TTLs.
Security safeguards
TLS in transit; access-controlled object storage; server-side contact pepper; webhook signature verification; role-restricted production access; rate limiting on abuse-sensitive endpoints. Details in our privacy policy.
Children
Rewinity is not directed at children under 18. We do not knowingly process children’s personal data. If you believe a minor has registered, contact us for removal.
Personal data breach
If we become aware of a personal-data breach likely to affect you, we will notify the Data Protection Board and affected users as required by the DPDP Act and its rules, and describe remedial steps we take.
Grievance officer
Direct grievances to [email protected]. We acknowledge receipt within 24 hours and resolve grievances within 15 days. The named officer’s details will be published here upon appointment.