Privacy Policy

Effective date: 3 July 2026

Riyoflow ("Riyoflow", "we", "us") is a mobile application for sports-coaching academies, operated by TAKCTRL, Chennai, India. This policy explains what personal data we collect, why, how it is used and protected, and the rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Riyoflow is the Data Fiduciary for the personal data described here.

1. Who this policy covers

  • Coaches — head coaches who create and run an academy in Riyoflow.
  • Households (parents/guardians) — the account holder for one or more players.
  • Players — the children or adults being coached. Most players are minors; their data is added and controlled by their parent or guardian and their coach.

2. What we collect

CategoryExamplesSource
Account dataPhone number, name, role (coach or household)You, at sign-up
Player dataPlayer name, date of birth, sport, squadParent/guardian and coach
Coaching dataAttendance records, skill ratings (OVR and five attributes), session reports, coach notesCoach, in the app
Payment dataSubscription tier, fee plans, payment status, transaction references. We never see or store card, UPI, or bank credentials — payments are processed by Razorpay (and Apple, for iOS subscriptions).You and our payment partners
Technical dataDevice type, app version, crash and error logsYour device

We do not collect precise location, contacts, or advertising identifiers, and we do not show ads.

3. Children's data and parental consent

Riyoflow is built around coaching children, so we treat minors' data with particular care:

  • A player profile for a minor can only be created or linked by their parent or guardian, who provides verifiable consent inside the app at the time of linking, or by the coach with the guardian's consent captured at sign-up.
  • A minor's personal details are visible only to their own household and their coach — never to other families or academies.
  • We do not use children's data for advertising, profiling beyond the coaching features described here, or any behavioural monitoring.
  • A guardian may withdraw consent at any time (see Your rights); the player's personal data is then erased.

4. Why we process data

  • To run the service — rosters, sessions, attendance, ratings, reports, and household views.
  • To collect fees and subscriptions — creating payment orders with Razorpay or Apple and reconciling their confirmations.
  • AI assistant (coaches only) — when a coach asks the AI assistant a question, relevant squad data is sent to our AI provider to generate the answer. The assistant is available only to coaches, never to households or players, and its answers are grounded in the coach's own academy data.
  • Safety and integrity — authentication, fraud prevention, debugging, and abuse prevention.
  • Legal obligations — tax, accounting, and compliance with Indian law.

We process data on the basis of your consent and, where applicable, for legitimate uses permitted by the DPDP Act. We do not sell personal data and we do not use it for third-party advertising.

5. Who we share data with

  • Within your academy — coaches see their academy's players; households see only their own children.
  • Supabase — our database and backend infrastructure provider.
  • Razorpay — payment processing and, for coaches, fee settlement to the coach's linked account. Razorpay processes your payment data under its own privacy policy.
  • Apple — subscription billing on iOS.
  • AI provider — squad context for coach AI queries, as described above.
  • Authorities — where required by applicable law or valid legal process.

6. How data is protected

  • All traffic is encrypted in transit (TLS); data is encrypted at rest by our infrastructure provider.
  • Access is enforced with database-level row security: every academy's data is tenant-isolated, and money and subscription records can only be written by our servers, never directly by an app.
  • Payment credentials never touch our systems.

7. How long we keep data

  • Account and coaching data is kept while your account is active.
  • When an account is deleted, personal data is erased; anonymised or aggregate records that no longer identify anyone may be retained.
  • Financial transaction records are retained as required by Indian tax and accounting law (typically 8 years), even after account deletion.

8. Your rights

Under the DPDP Act you (and, for a minor, their parent or guardian) can:

  • Access — request a summary of the personal data we hold and how it is used.
  • Correct — have inaccurate or incomplete data corrected (much of this you can edit in-app).
  • Erase — delete your account and personal data from inside the app (Settings → Delete account) or by writing to us. Erasure covers players in your household; financial records are retained as described above.
  • Withdraw consent — at any time, with effect for future processing.
  • Grievance redressal — raise a complaint with our Grievance Officer, and if unresolved, with the Data Protection Board of India.

9. Grievance Officer

Grievance Officer: Sriraam Balaji
TAKCTRL, K.K. Nagar, Chennai, Tamil Nadu 600078, India
Email: support@riyoflow.com

We acknowledge grievances within 48 hours and aim to resolve them within 30 days.

10. Changes to this policy

If we make material changes, we will notify you in the app and update the effective date above. Continued use after the effective date means the updated policy applies.