PRIVACY POLICY
Last updated – 10th March, 2025
Introduction
Thank you for choosing to be a part of the Tavasyam Mind and Body LLP (“Tavasyam,” “we,” “us,” or “our”) community. We are committed to safeguarding your personal information and maintaining your trust in our data privacy practices. This Privacy Policy explains how we collect, use, disclose, and secure your personal data when you interact with our platform, including the Tavasyam Website ([www.tavasyam.life]), Mobile Application, and all related services, products, and content (collectively, the “Platform”).
We recognize the importance of your privacy and take data protection very seriously. If you have any questions or concerns regarding this Privacy Policy or our data practices, you may contact us at support@tavasyam.com
The use of our Platform, including accessing services, features, and tools provided by Tavasyam, may involve the collection and processing of personal information. This policy is designed to comply with the requirements of the Information Technology Act, 2000, Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, General Data Protection Regulation (GDPR), and any other applicable laws and regulations concerning the collection, use, and protection of personal data.
We provide full transparency regarding the scope, nature, and purpose of data collection. In certain cases, where there is no statutory basis for the processing of your personal information, we will seek your explicit consent before collecting or processing your data. This includes, but is not limited to, data required for personalizing services, offering tailored fitness programs, and tracking your progress toward health and wellness goals.
When you visit our Website, Mobile Application, or engage with our services, you entrust us with your personal information. In this Privacy Policy, we aim to explain in a clear and detailed manner:
- The types of information we collect and why.
- How your personal information is used and protected.
- The rights you have regarding your personal information.
If you do not agree with any part of this Privacy Policy, we kindly request that you discontinue the use of the Platform and our Services.
This Privacy Policy applies to all data collected through our Website, Mobile Application, chat applications (e.g., WhatsApp), social media accounts, marketing events, and any related platforms. We encourage you to read this policy carefully to make informed decisions regarding the sharing of your personal information with us.
Table of Contents
- What Information Do We Collect?
- How Do We Use Your Information?
- Will Your Information Be Shared, and With Whom?
- Do We Use Cookies and Other Tracking Technologies?
- Do We Use Google Maps or Location Services?
- How Do We Handle Your Social Logins?
- Is Your Information Transferred Internationally?
- How Long Do We Keep Your Information?
- How Do We Keep Your Information Safe?
- Do We Collect Information From Minors?
- What Are Your Privacy Rights?
- Controls for Do-Not-Track Features
- Do We Make Updates to This Policy?
- How Can You Contact Us About This Policy?
WHAT INFORMATION DO WE COLLECT?
In Short: We collect both personal information and non-personal information to provide, maintain, and improve our Services, ensure security, and deliver a personalized user experience. Below is an overview of the types of information we collect:
Information You Provide
We collect personal information that is necessary to provide our services when you create an account, interact with the Platform, or communicate with us.
- Account Registration Information:
- Name, email address, phone number, birth date, gender, and mailing address.
- Health and Fitness Information:
- Weight, height, food preferences, lifestyle details, medical conditions, health goals, and fitness-related data, including workouts, physical activity, nutrition data, body metrics, sleep patterns, steps etc.
- Contributions:
- Content and information you share, such as text, photos, videos, comments, questions, or suggestions submitted through posts, contact forums, or recipe logging.
- Messages:
- We store messages, photos, videos, and documents shared through our services for accessibility across your devices. This data is encrypted, and our developers do not access it.
- Payment Data:
- Data required for processing payments, including payment instrument details (e.g., credit card number and security code).
- Payment data is securely stored and processed by third-party providers, such as Cashfree, and PayPal.
Information Automatically Collected
Some data is automatically collected during your interaction with our Platform, including device and usage information.
- Device and Usage Data:
- IP address, browser type, device model, operating system, language preferences, location data, referring URLs, and time spent on our Platform.
- This information is necessary for maintaining the security and performance of our Platform and for internal analytics and reporting.
- Cookies and Tracking Technologies:
- We use cookies and similar technologies to improve user experience, analyse site usage, and enhance service functionality. For details, refer to our Cookie Policy.
Information Collected Through Our Mobile Application
We may collect information from your mobile device to provide and enhance the services offered through our App.
- Geo-Location Information:
- We may request permission to access your location to provide location-based services, such as tagging your location on a post. You can modify this permission in your device settings.
- Mobile Device Access:
- We may request access to features on your mobile device, including:
- Storage: To read and write images, videos, and documents.
- Contacts: To help you find and connect with other users.
- Camera and Microphone: To capture images, record videos, and stream live sessions.
- Social Media Accounts: For login and integration with our services.
- Health Data: For fitness tracking via third-party services (e.g., Apple Health, Google Fit, Google Health Connect).
- We may request access to features on your mobile device, including:
We comply with Apple’s HealthKit development guidelines. To view Apple’s HealthKit developer guidelines, go to https://developer.apple.com/app-store/review/guidelines/#health-and-health-research.
We handle Google Fit data in accordance with Google Fit Terms of Service. To view Google Fit Terms of Service go to https://developers.google.com/fit/terms.
We comply with Google’s Health Connect Permissions policy. To view Google’s Health Connect Permissions policy go to https://support.google.com/googleplay/android-developer/answer/12991134?hl=en.
We ensure that your health data is not shared with third parties for marketing or advertising. Access to health data can be managed through your device’s settings. However, revoking the access may prevent you from using all or some of our services.
- Mobile Device Data:
- Device ID, model, manufacturer, operating system, and version information, as well as IP address, may be collected automatically for security and performance monitoring.
- Push Notifications:
- We may request permission to send you push notifications related to your account and services. You can manage these notifications through your device settings.
- Messages via Chat Applications:
- We may request permission to send you notifications or updates via messaging apps like WhatsApp. You can opt out by declining the request when prompted or modifying your notification preferences.
HOW DO WE USE YOUR INFORMATION?
In Short: We process your information based on legitimate business interests, contractual obligations, legal requirements, and/or your consent.
We use the information we collect to provide, improve, and support our Services and to meet our business and legal responsibilities. The following outlines the purposes for which we use your personal information, along with the relevant legal basis for each purpose:
1. To Facilitate Account Creation and Login
- We use your personal information, such as name and email address, to set up and manage your account on the Platform.
- If you link your account through a third-party provider (e.g., Google or Apple login), we process the information you have authorized to facilitate this integration.
(Legal Basis: Contractual necessity and consent.)
2. To Deliver Our Services
- We process your data to provide customized fitness and wellness programs, including nutrition tracking, progress monitoring, and coaching services.
(Legal Basis: Contractual necessity.)
3. To Send Administrative Information
- We may use your contact information to notify you about changes to our Services, terms, policies, or updates related to your account.
(Legal Basis: Contractual necessity and legal compliance.)
4. To Support Marketing and Promotional Activities
- With your explicit consent, we may use your personal information to send marketing emails, promotional offers, and updates about our services and features.
- We may also use user-generated content, including your name, photos, testimonials, and other contributions, for marketing and publicity purposes across various media channels.
(Legal Basis: Consent.)
5. To Manage Orders and Payments
- We use your payment data to process orders and manage billings.
(Legal Basis: Contractual necessity.)
6. To Track and Analyse Fitness Progress
- Our coaches use your health and fitness data, including workout history, photos, body measurements, and nutrition intake, to develop personalized plans and evaluate your progress toward health goals.
(Legal Basis: Contractual necessity and consent.)
7. To Enable User-Generated Content
- If you contribute posts, photos, or other user-generated content on our Platform, we may use this information to support community engagement and related activities.
(Legal Basis: Consent and legitimate business interests.)
8. To Post Testimonials
- With your permission, we may publish your name and testimonial on our Platform and marketing materials. You can request to update or remove your testimonial by contacting us.
(Legal Basis: Consent.)
9. To Conduct Surveys and Collect Feedback
- We may contact you to request feedback on your experience with our Services, helping us improve and enhance the Platform.
(Legal Basis: Legitimate business interests.)
10. To Administer Prize Draws and Competitions
- We may use your information to organize and manage contests or prize draws in which you participate.
(Legal Basis: Consent.)
11. To Enhance Security and Fraud Prevention
- We process data to monitor and prevent unauthorized access, fraud, and security threats to the Platform.
(Legal Basis: Legitimate business interests and legal compliance.)
12. To Enable User-to-User Communication
- With your consent, we may facilitate communications between users for features such as community posts and challenges on the Platform.
(Legal Basis: Consent and contractual necessity.)
13. To Comply with Legal Requests and Prevent Harm
- In the event of legal obligations (e.g., subpoenas or regulatory inquiries), we may inspect and provide relevant data to authorities as required.
(Legal Basis: Legal compliance.)
14. To Manage User Accounts
- We maintain your account and related settings to ensure the continuity and functionality of the Services.
(Legal Basis: Contractual necessity.)
15. To Respond to Inquiries and Offer Support
- We use your information to provide technical assistance, resolve issues, and respond to any inquiries you submit.
(Legal Basis: Contractual necessity.)
16. To Analyze and Improve Our Services
- We analyze aggregated, anonymized data to identify trends, measure the effectiveness of marketing campaigns, and enhance the overall user experience.
(Legal Basis: Legitimate business interests.)
These processing activities are designed to ensure that you receive a seamless and personalized experience on the Tavasyam Platform while maintaining legal and regulatory compliance.
Tavasyam or authorized third parties may store, display, reproduce, publish, distribute, or otherwise use user-generated content both online and offline in any media or format (existing or future) and may or may not attribute it to the user. Other users and third parties may have access to this user-generated content and may share or further distribute it. Therefore, you should carefully consider the type of information you choose to share publicly, including personal information, as public postings are not confidential. Tavasyam does not control or monitor who may access publicly available user content and cannot guarantee that such individuals or third parties will respect your privacy or ensure the security of the information. Tavasyam is not responsible for the privacy, accuracy, use, or misuse of any information you voluntarily share on the Platform, nor for how third parties handle that information once shared on our Website, Mobile Application, or related services.
Additionally, we may process your information for various business purposes, including data analysis, identifying usage patterns, evaluating the effectiveness of promotional campaigns, and enhancing our services, products, and user experience. This data may be stored and used in an aggregated and anonymized form that does not identify individual users. We will not use any personally identifiable information for these purposes without your explicit consent.
WILL YOUR INFORMATION BE SHARED, AND WITH WHOM?
In Short: We only share your information with your consent, to comply with laws, to fulfil business needs, protect your rights, or under other legitimate conditions.
We may share or disclose your personal information under the following legal grounds:
- Consent: If you have explicitly granted us permission to use your data for specific purposes, we will process and share your information as per your consent.
- Legitimate Interests: We may share your information where it is necessary for the business operations of Tavasyam and does not override your privacy rights.
- Performance of a Contract: When you engage with our services, your data may be shared to fulfil the terms of that contract, such as delivering services or handling payments.
- Legal Obligations: We may disclose your information to comply with legal or regulatory obligations, such as court orders, subpoenas, or government requests.
- Vital Interests: Your information may be shared to investigate or prevent activities that threaten personal safety, security, or property, or to comply with legal defences in litigation.
Situations Where Information May Be Shared
- Vendors, Consultants, and Service Providers:
We work with third-party vendors who provide services such as payment processing, data hosting, analytics, email delivery, and customer support. These service providers may need access to personal data to perform their functions but are bound by strict contractual obligations to safeguard your information and use it only for authorized purposes. - User Interactions and Public Content:
When you engage with the Platform (e.g., posting in the community or sharing content), your contributions may be publicly accessible and visible to other users. This includes your profile photo, name, and any content you post. Public content may also be distributed outside the Platform and persist in the public domain. Please exercise caution and avoid sharing sensitive personal data in public forums. - Business Transfers:
In the event of a business transaction, such as a merger, acquisition, or sale of company assets, your information may be transferred to a third party as part of the business deal. - Third-Party Advertising:
We may use third-party advertising services that use cookies and tracking technologies to display relevant advertisements based on your browsing activity. These advertisements may appear on the Platform or external websites. - Offer Wall:
If the Platform includes an offer wall for redeeming rewards (e.g., KarmaCredits), we may share your name, address, and phone number with the third-party provider to fulfill product deliveries. - Third-Party Websites and External Services:
The Platform may contain links to third-party websites and services. Tavasyam does not control these external platforms, and their privacy policies and practices may differ from ours. We are not responsible for the security, content, or privacy practices of third-party websites. Users should review the privacy policies of these websites before sharing any personal information.
Third Parties with Whom We Share Data
To provide a transparent overview, below are examples of categories of third parties Tavasyam may share your data with:
- Cloud Services: Amazon Web Services (AWS)
- Communication Platforms: WhatsApp, Zendesk Chat
- Payment Processing Services: CashFree, PayPal, Stripe, Paytm
- Email and Bulk Mailing Services: Mailchimp, Mailgun, Sendy
- Social Login Providers: Google, Apple, Facebook Login
- Web Analytics: Google Analytics, CleverTap
- App Development and Testing: TestFlight, Google Play Console
- Health Data Partners: Registered Medical Practitioners, Nutrition and Fitness Plan Support Providers
These third parties are bound by data protection agreements and are required to handle your data in compliance with applicable privacy laws and regulations.
If you have provided consent for data sharing but later wish to revoke it, you can contact us via the details provided in the How Can You Contact Us About This Policy section.
DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
In Short: Yes, we may use cookies and similar tracking technologies to collect and store your information to improve your experience and analyse how the Platform is used.
Cookies and Web Beacons
You can access our Website without providing personal information. However, we may use cookies, web beacons, tracking pixels, Google Analytics, and similar technologies to customize and enhance your experience on the Platform. These tracking technologies help us analyse user activity and monitor website performance by collecting anonymous traffic data. We do not collect personal details such as your name, age, or gender unless you create an account and provide this information directly by accessing our Mobile Application.
Cookies are small files stored on your device that allow us to remember your preferences and improve the functionality of the Platform. You may prevent cookies from being set by adjusting your browser settings. Additionally, you can delete cookies from your browser at any time. Please note, however, that disabling cookies may affect the functionality and usability of certain features on the Platform.
For more information on how we use cookies, please refer to our Cookie Policy incorporated into this Privacy Policy. By using our Website or Mobile Application, you agree to be bound by our Cookie Policy.
Website Analytics
We may partner with third-party vendors such as Google Analytics to allow tracking technologies and remarketing services on the Platform. These technologies use both first-party and third-party cookies to analyse user behaviour, track online activities, and determine the popularity of certain content. This helps us better understand how users interact with the Platform and improve the overall user experience.
These third-party services may collect and process usage data. While they do not receive your personal information, such as your name or contact details, they may collect non-personal technical data related to your activity on the Platform. For details on how Google Analytics collects and processes your data, please review their Privacy Policy here. You can also learn more about opting out of Google Analytics tracking here.
If you do not wish to be tracked by cookies or tracking technologies, you may also use the Network Advertising Initiative Opt-Out Tool or the Digital Advertising Alliance Opt-Out Tool to control your preferences.
Please note that if you install a new browser, update your current browser, or clear your cookies, you may need to reset your opt-out preferences.
DO WE USE GOOGLE MAPS OR LOCATION SERVICES?
In Short: Yes, we use Google Maps APIs to enhance your experience and provide better services.
Our Website and Mobile Application integrate Google Maps APIs to offer location-based services and features, such as activity tracking, tagging your location in posts, and providing relevant services based on your geographic area. By using the Platform’s Maps features, you agree to be bound by Google’s Terms of Service, which govern the use of Google Maps APIs.
You can view the Google Maps APIs Terms of Service here and Google’s Privacy Policy here.
If you wish to disable location services, you may adjust your device’s settings at any time. However, please note that disabling location access may limit or prevent you from using certain location-based features on our Platform.
HOW DO WE HANDLE YOUR SOCIAL MEDIA SHARING?
In Short: We provide users the ability to share their activities from our Platform to social media platforms such as Instagram, Facebook, and WhatsApp.
Our Mobile Application allow you to share your activity, progress, or achievements on various social media platforms. To enable this feature, you may be required to link your social media accounts (e.g., Instagram, Facebook, or WhatsApp) with the Tavasyam app. When you choose to do this, the social media platform may collect certain information about your activity on Tavasyam, such as shared progress updates or achievements.
Please note that Tavasyam does not control the privacy practices of these third-party social platforms. We recommend reviewing the privacy policies of each social media service to understand how they collect, use, and share your data, as well as how to manage your privacy settings on their platforms.
If you wish to unlink your social media account from our Platform, you can do so at any time by adjusting your device’s settings or the settings on the respective social media platform.
IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We retain your information for as long as necessary to provide services, meet legal obligations, and fulfil the purposes outlined in this Privacy Policy.
When you use our services, Tavasyam collects and stores your personal data to facilitate account management, service delivery, and other business needs. We retain your personal information only for as long as your account remains active or for as long as necessary to fulfill the purposes described in this Privacy Policy. In certain cases, we may retain data for a longer period to comply with legal, tax, regulatory, or other statutory obligations.
If you choose to delete your account through the Delete Account option on our Mobile Application, the following process applies:
- Account Deletion: Upon your request, we will remove your personal information from our active systems and databases.
- Legal Obligations: Certain data may be retained if required to comply with legal, regulatory, or business obligations (e.g., for recordkeeping, tax, or legal claims).
- Backup Data: Data stored in secure backups may not be immediately deleted. However, it will remain inaccessible for further processing and will be deleted in accordance with our regular data purge cycles.
Once your personal data is no longer required for any legitimate business or legal purpose, it will either be permanently deleted, anonymized, or securely stored until deletion becomes feasible.
HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We implement organizational and technical security measures to protect your personal information.
At Tavasyam, we have adopted a security framework designed to safeguard any personal information we collect and process. Our measures are aligned with industry best practices to mitigate risks, including unauthorized access and data breaches. Our security efforts include:
- Regular monitoring and threat detection
- Periodic vulnerability assessments and security audits
- Implementation of access controls and data encryption
While we take these precautions to secure your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage users to take additional safety measures, such as accessing our services through secure connections. Sharing information online is done at your own risk, and we recommend using trusted, secure networks for access.
DO WE COLLECT INFORMATION FROM MINORS?
In Short: We comply with regional laws that govern data collection from individuals under the age of majority. For minors aged 13 to 18, we require parental or guardian consent where applicable.
Tavasyam provides services designed primarily for adult users but also permits access to minors, typically aged 14 and above, with parental or legal guardian consent. By accessing or using our Services or Mobile Application, you confirm that you are either at least 18 years old or are the parent or guardian providing consent for a minor dependent’s use of the Services.
Depending on the region, the following policies apply:
- United States: In compliance with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect data from children under 13 without verified parental consent.
- European Union: In accordance with GDPR, we require parental consent for the collection and processing of data for minors under the age of 16 (or lower where permitted by local law, such as 13 in certain EU countries).
- India: We comply with the provisions of the Digital Personal Data Protection Act and require parental consent for minors under 18 years of age.
If we become aware of any data collection from minors without appropriate consent, we will take steps to secure parental approval or delete the information as required by the applicable law. Parents or guardians who believe their child has provided personal information without consent are encouraged to contact us so we can take appropriate action.
WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your region, such as the United States, European Economic Area (EEA), or India, you may have rights that provide greater access to and control over your personal information. These rights include the ability to review, update, delete, or restrict the processing of your personal data and withdraw consent where applicable.
Rights for Different Regions:
- European Economic Area (EEA)
Under the General Data Protection Regulation (GDPR), users in the EEA have the right to:- Access, update, or delete personal data.
- Restrict or object to data processing.
- Request data portability.
- Withdraw consent at any time without affecting the lawfulness of prior processing.
- File a complaint with their local data protection authority.
Contact details for EEA data protection authorities can be found here.
- United States (California)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:- Know what personal data is collected, how it is used, and with whom it is shared.
- Request access to and obtain a copy of their data.
- Request the deletion of personal information.
- Opt out of the sale of personal data.
- Not face discrimination for exercising their privacy rights.
To submit a CCPA request, please contact us using the details provided in the “How Can You Contact Us About This Policy?” section.
Please Note: Tavasyam does not sell personal data, but we may share it with vendors and service providers as described in this policy.
For more details on your rights under the CCPA, visit the California Attorney General’s website at https://oag.ca.gov/privacy/ccpa
- India
Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, users in India have the right to:- Review and amend sensitive personal data or information.
- Withdraw consent for data processing at any time.
Tavasyam is committed to handling user data according to these rules, ensuring privacy and data security.
Account Information
You can review, update, or terminate your account by:
- Logging into your account settings and updating your profile information.
- Contacting us using the contact details provided below.
Upon account termination, we will deactivate or delete your information from active databases. However, certain data may be retained to comply with legal obligations, prevent fraud, resolve disputes, troubleshoot issues, or enforce our Terms of Use.
Cookies and Tracking Technologies
You can manage cookie preferences through your web browser. Disabling cookies may limit your experience on the Platform. For details on managing cookies, visit http://www.aboutads.info/choices/.
Opting Out of Marketing Communications
You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in our emails or contacting us. However, we may still send you essential service-related emails. To manage marketing preferences, you can also update your account settings or contact us directly.
Google Forms and Surveys
We collect data through Google Forms to improve our services. While these surveys are designed to be anonymous, respondents should avoid sharing personally identifiable information unless necessary.
Only authorized personnel within Tavasyam have access to survey data, which is handled per our data protection policies. For more details on Google’s privacy practices, visit Google Privacy & Terms.
If you wish to exercise your privacy rights, please contact us through the “How Can You Contact Us About This Policy?” section.
CONTROLS FOR DO-NOT-TRACK FEATURES
In Short: We currently do not respond to Do-Not-Track (DNT) signals or other mechanisms that automatically communicate your tracking preferences.
Many web browsers and some mobile operating systems offer a Do-Not-Track (DNT) feature that allows you to express your preference not to have your online activities monitored. However, there is no industry-standard technology or regulatory requirement in place for recognizing and honouring DNT signals.
As such, Tavasyam does not currently respond to DNT browser signals or similar mechanisms. If a standardized DNT protocol is established and recognized in the future, we will update our practices and inform you through a revised version of this privacy policy.
For further details on your privacy preferences and tracking technologies, please refer to the Cookies and Tracking Technologies section of this policy.
DO WE MAKE UPDATES TO THIS POLICY?
In Short: Yes, we will update this policy as necessary to remain compliant with relevant laws and to reflect any changes to our practices.
We may revise this privacy policy from time to time to stay aligned with legal requirements, business operations, or industry standards. Any updates will be indicated by an updated “Last Revised” date at the top of this document. The revised policy will take effect as soon as it is made available on our Website or Mobile Application.
If material changes are made to this policy, we may notify you by:
- Posting a prominent notice of such changes on the Platform; or
- Sending you a direct notification through email or other communication methods.
We encourage you to periodically review this privacy policy to stay informed about how we collect, use, and safeguard your personal information. Your continued use of our services after updates signifies your acceptance of the revised policy.
HOW CAN YOU CONTACT US ABOUT THIS POLICY?
If you have any questions, concerns, or comments about this privacy policy, you may contact us by email or postal mail at the following address:
Tavasyam Mind and Body LLP
The Lofts, Blueridge Township,
Phase-1, Rajiv Gandhi IT Park,
Hinjewadi, Pune, Maharashtra – 411057
India
Email: support@tavasyam.life
We are committed to addressing your queries promptly and ensuring that your privacy concerns are handled with the utmost priority.