Privacy Policy
Last updated: 25 June 2026
1. Who We Are
Mobinsons Ventures Private Limited (“we”, “us”, “our”) operates the ROR mobile application and website. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA).
2. Data We Collect
| Category | Data | Purpose |
|---|---|---|
| Account | Name, email, phone number | Authentication, communication |
| Waitlist | Email; optional name, phone number, role, and WhatsApp opt-in; a referral code (and the code of whoever invited you) | Launch & early-access updates, personalised emails, and the founding-runner referral program (marketing only with your consent) |
| Profile | Username, city, bio, avatar | Social features, leaderboards |
| Location | GPS coordinates during active runs only | Route tracking, realm claims, zone captures |
| Activity | Run distance, duration, pace, calories | Stats, XP, challenges, leaderboards |
| Payment | Transaction ID (no card data stored) | Subscription management |
| Device | OS, app version, push token | Notifications, bug fixes |
| Usage | Feature interactions, crash logs | Product improvement |
| Technical | IP address, device identifiers | Security, rate-limiting, fraud & abuse prevention |
3. How We Use Your Data & Marketing Communications
- To provide and operate the ROR service (tracking, realms, squads, leaderboards).
- To process payments via Razorpay (India) or Stripe (international).
- To send transactional notifications (run summaries, realm updates, squad invites).
- To send launch and early-access updates to waitlist members, and—only if you opt in—marketing messages on WhatsApp (founding-runner news, your invite when we go live).
- To improve the app through aggregated, anonymised analytics.
- To enforce our Terms of Service and prevent abuse.
Withdrawing consent is as easy as giving it. You can opt out of WhatsApp messages anytime by replying STOP, using the unsubscribe link in any email, or emailing [email protected]. Withdrawal does not affect transactional or service messages you still need to use ROR.
4. Data Storage & Security
- Your data is stored on encrypted servers in Singapore (AWS ap-southeast-1), co-located for low latency to Indian users. Cross-border transfers are made in accordance with the DPDPA, 2023 (§16); we do not transfer your data to any country restricted by the Central Government of India.
- Database access is restricted to authorised personnel with role-based access control.
- Passwords are hashed with bcrypt (never stored in plain text).
- JWT tokens are signed with HS256 and expire within configured timeframes.
- All API communication uses HTTPS/TLS 1.3 encryption.
- We conduct regular security audits of our infrastructure.
- Data-breach notification: in the event of a personal-data breach, we will notify the Data Protection Board of India and affected users without undue delay, as required by the DPDPA, 2023.
- Security researchers: see our Security & Vulnerability Disclosure Policy for the responsible disclosure process and safe-harbor terms.
5. Data Sharing
Data is shared only with:
- Payment providers (Razorpay / Stripe) — strictly for processing transactions.
- Infrastructure providers (cloud hosting, CDN) — for operating the service.
- Analytics (Cloudflare Web Analytics; we may also use Plausible Analytics) — privacy-friendly, cookieless, aggregate-only usage stats. No personal data is shared, no cross-site tracking, no profiling.
- Communication providers — email (AWS SES), WhatsApp (via an authorised WhatsApp Business Solution Provider such as AiSensy, on Meta Platforms' infrastructure), SMS (msg91 / Twilio), and push notifications (Expo) — only to deliver messages you've opted into.
- Maps (Mapbox) — to render maps and route geometry.
- Law enforcement — only when required by valid legal process under Indian law.
Some of these providers process data outside India (e.g. Singapore, the United States, or the European Union). Such transfers are made in accordance with the DPDPA, 2023, and only to countries not restricted by the Central Government of India.
6. Your Rights (under DPDPA 2023)
- Right to access — Request a copy of your personal data.
- Right to correction — Update inaccurate or incomplete data.
- Right to erasure — Request permanent deletion of your account and all data.
- Right to withdraw consent — Withdraw consent for data processing at any time.
- Right to nominate — Nominate another person to exercise your rights in case of death or incapacity.
To exercise any of these rights, email [email protected]. We respond within 72 hours.
7. GPS & Location Data
- GPS data is collected only during active run recording (never in background without your action).
- Location data is coarsened before long-term storage to protect your privacy.
- You can disable location permissions at any time via your device settings.
- Location data is never used for targeted advertising.
8. Cookies & Local Storage
- The web app uses cookies only for authentication (JWT session token) and UI preferences.
- No third-party tracking, advertising, or remarketing cookies are used.
- Local storage is used for UI preferences (sidebar state, theme, onboarding progress).
- Our analytics (Cloudflare Web Analytics; we may also use Plausible) is cookieless — it sets no cookies and collects only aggregate, anonymous usage data.
For full details on what cookies we use, how long they last, and how to manage them, see our Cookie Policy.
9. Data Retention
- Account data is retained while your account is active.
- Upon account deletion, all personal data is permanently removed within 30 days.
- Anonymised, aggregated data (e.g. total runs in a zone) may be retained indefinitely.
- Payment records are retained for 8 years as required by Indian tax law.
10. Children's Privacy (DPDPA §9)
In accordance with the Digital Personal Data Protection Act, 2023 §9, a “child” is any person under 18 years of age. ROR is not intended for children under 18and we do not knowingly collect, process, or store personal data of any user under 18.
If you believe a child under 18 has provided us personal data, please contact [email protected] immediately and we will delete the account and all associated data within 72 hours, in compliance with DPDPA §9(3).
11. Grievance Officer
In accordance with IT (Intermediary Guidelines) Rules, 2021:
Grievance Officer
Mobinsons Ventures Private Limited
CIN: U62011OD2026PTC053747
Registered Office: Banspani, Joda, Kendujhar — 758034, Odisha, India
Email: [email protected]
Response: within 24 hours · Resolution: within 15 days
12. Changes to This Policy
We may update this policy periodically. Material changes will be notified via email or in-app notification at least 30 days in advance.
13. Contact
Questions about privacy? Email [email protected].