1. Who We Are
GetQi ("GetQi", "we", "us", "our") is a B2B corporate wellness platform operated by GetQi Pvt. Ltd., registered in Bengaluru, Karnataka, India. We connect corporate employers, their employees, and fitness facility partners through a technology platform available at getqi.in and the GetQi mobile application.
For privacy-related queries, contact us at: [email protected]
2. Scope
This Privacy Policy applies to:
- Employees and individuals who use the GetQi app or web platform ("Users")
- HR administrators who manage corporate wellness accounts ("HR Admins")
- Facility owners and staff who use the partner portal ("Facility Partners")
- Personal trainers registered on the platform
- Visitors to getqi.in
This policy does not apply to third-party websites or services linked from our platform.
3. Information We Collect
3.1 Information You Provide
- Google Account Information: When you sign in via Google, we receive your name, email address, and Google profile photo. We do not receive your Google password.
- Work Email: If you verify your employer through our OTP flow, we store your work email address and the timestamp of verification.
- Profile Information: Name, phone number, and other profile fields you choose to complete.
- Contact Form Submissions: Name, email, phone, and message content submitted via our contact or partner inquiry forms.
- Facility Partner Information: For facility owners: legal name, GST number, bank account details, IFSC, UPI ID, contact person, and phone number.
- Trainer Information: Bio, photo, specialisations, and experience details for personal trainers.
- Reviews: Rating scores and written comments you submit for facilities or trainers.
3.2 Information Generated Through Platform Use
- Check-in Records: Date, time, facility visited, pass or wallet used, check-in status.
- QR Token Data: Generated tokens and their usage status (used, expired, cancelled).
- Wallet Transactions: Top-up amounts, spend amounts, refunds, and transaction types across your personal and/or company wallet.
- Pass and Membership Records: Pass type purchased, sessions remaining, expiry dates.
- Group Class Bookings: Sessions booked, attendance, cancellations, no-show status.
- Payment Records: Transaction IDs, amounts, payment status (via Razorpay). We do not store card numbers or UPI credentials — these are handled entirely by Razorpay.
3.3 Information Collected Automatically
- Authentication Cookie: A refresh token is stored as an HTTP cookie (
getqi_refresh) on your browser for up to 30 days to keep you signed in. This is a session management cookie, not a tracking cookie. It is also mirrored in localStorage under the same key. - Log Data: Server logs may include IP address, browser type, operating system, and pages visited for security and debugging purposes.
4. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Authenticating you and maintaining your session | Contract (providing the service) |
| Matching you to your employer's corporate wellness account | Contract |
| Processing wallet top-ups and check-in payments via Razorpay | Contract |
| Generating QR codes and recording check-ins at facilities | Contract |
| Sending transactional emails (invitations, OTPs, notifications) via Resend | Contract |
| Enabling facility partners to validate check-ins | Contract |
| Displaying your usage data to your employer's HR administrator (utilisation reports) | Contract / Legitimate Interest |
| Moderating reviews you submit | Legitimate Interest |
| Platform security, fraud prevention, and debugging | Legitimate Interest |
| Complying with legal obligations | Legal Obligation |
We do not use your data for advertising or sell it to third parties.
5. Information Shared with Third Parties
We share data only where necessary:
- Razorpay: Payment processing. Razorpay handles card and UPI data directly. We share order amounts and receive confirmation of payment status. Razorpay's privacy policy applies to payment data.
- Google (Google Sign-In): Authentication. Google returns your name and email to us upon sign-in.
- Resend: Transactional email delivery (OTPs, invitations, welcome emails).
- Your Employer (HR Admin): If you are an employee on a corporate account, your HR administrator can see aggregated and individual utilisation data — i.e., how frequently you use the platform and your wallet balance. This is a core function of the corporate wellness product.
- Facility Partners: When you check in, the facility's staff can see your name and check-in confirmation via their portal. They do not see your payment details or wallet balance.
- Law Enforcement: We may disclose information if required by Indian law, court order, or government authority.
We do not share your data with advertisers, data brokers, or analytics platforms.
6. Cookies
GetQi uses a single functional cookie:
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
getqi_refresh | Stores your refresh token to keep you signed in across sessions. Used by our server middleware to protect authenticated routes. | 30 days (or until you log out) | Functional / Essential |
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can clear this cookie at any time by logging out, which explicitly removes it.
7. Data Retention
- Account data: Retained while your account is active. If your account is deactivated, data is retained for a reasonable period for compliance and dispute resolution purposes.
- Transaction and check-in records: Retained for 7 years to comply with Indian accounting and GST requirements.
- OTP codes: Automatically expire after 10 minutes and are not retained beyond that.
- Log data: Retained for up to 90 days.
- Reviews: Soft-deleted reviews are retained in our database but not shown publicly.
8. Your Rights
You have the right to:
- Access: Request a copy of personal data we hold about you.
- Correction: Update your profile information via the Settings page, or request corrections for data you cannot update yourself.
- Deletion: Request deletion of your account and associated personal data, subject to legal retention requirements.
- Portability: Request an export of your transaction and check-in history.
To exercise these rights, email us at [email protected]. We will respond within 30 days.
Note: Employees on corporate accounts should be aware that their employer may have independent data retention obligations. Requests for data deletion should also be communicated to your HR administrator.
9. Security
- All communication is encrypted in transit via HTTPS/TLS.
- JWT access tokens are short-lived. Refresh tokens are stored as HttpOnly-capable cookies with SameSite=Lax.
- Security headers are enforced: HSTS, X-Frame-Options, CSP, X-Content-Type-Options.
- Razorpay webhook requests are validated via HMAC-SHA256 signature before processing.
- Role-based access control: each user role (Employee, HR Admin, Facility Owner, Super Admin) can only access data relevant to their function.
- Admin and Swagger endpoints are disabled in production.
Despite these measures, no internet-based service can guarantee 100% security. Please notify us immediately at [email protected] if you suspect any security issue.
10. Children's Privacy
GetQi is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or a prominent notice on the platform. Continued use of the platform after changes are posted constitutes acceptance of the revised policy.
12. Governing Law
This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka.
13. Contact
For any privacy-related questions, data requests, or concerns:
GetQi Pvt. Ltd.Bengaluru, Karnataka, India
[email protected]
getqi.in