1. Introduction
Welcome to MemberFlow. We are a Software-as-a-Service (SaaS) platform designed to help businesses manage memberships, subscriptions, and client relationships. Our platform serves various industries including fitness, sports, education, arts, wellness, professional services, recreation, health, and niche membership organizations.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web services (the "Service").
Please read this privacy policy carefully. By accessing or using MemberFlow, you acknowledge that you have read and understood this policy.
2. Important Notice: Roles and Data Responsibility
MemberFlow operates as a multi-tenant platform. It is crucial to understand the distinction between our users:
- Business Owners (Tenants): Entities (e.g., Gym Owners, School Administrators, Studio Managers) who subscribe to MemberFlow to manage their business. They are the Data Controllers for their client information.
- Staff: Employees of the Business Owner (Managers, Receptionists, Trainers, Instructors) who access the system to perform duties.
- Members (End Clients): Individuals whose records are managed by the Business Owner (e.g., Gym Members, Students, Clients). Members do not have direct login accounts with MemberFlow. Their data is entered by the Business Owner or Staff.
Your responsibility: If you are a Business Owner, you are responsible for obtaining necessary consent from your Members before uploading their personal data to MemberFlow. MemberFlow acts as the Data Processor for Member data.
3. Information We Collect
3.1 Information Provided by Business Owners & Staff
When you register as a Business Owner or Staff, we collect:
- Personal identification: Full Name, Phone Number, Email Address, Gender, Profile Photo.
- Authentication data: Credentials managed via Supabase Auth (Google, Apple, or Phone Number + Invite Code).
- Business details: Organization Name, Address, Postal Code, Facilities/Services Offered, Logo.
- Financial data: Billing address and transaction history for SaaS subscription payments.
3.2 Member Data (Processed on Behalf of Business Owners)
We store data entered by Business Owners regarding their Members. This may include:
- Name, Phone Number, Address, Gender, Profile Photo.
- Membership Plans, Subscription Status, Payment Due Dates.
- Assignment Records (e.g., assigned Trainer, Instructor, or Mentor).
Note: We do not collect sensitive financial data (credit card numbers) of Members. Payment records stored are limited to status (Paid/Unpaid) and amounts.
3.3 Payment Information
We use Razorpay as our payment gateway for SaaS subscription billing.
- We do not store sensitive credit card details, bank account numbers, or CVV codes on our servers.
- All payment transactions are processed directly by Razorpay in compliance with PCI-DSS (Payment Card Industry Data Security Standards).
- We retain only transaction IDs, payment status, timestamps, and invoice records for billing and analytics.
3.4 Automatically Collected Data
- Device information: Device type, OS version, Unique Device Identifiers (for notifications).
- Usage data: Login timestamps, feature usage, crash logs.
- Advertising data: Ad views and click interactions (see Section 7).
- Location data: Postal Code provided during registration (used for Moderator assignment and regional analytics).
4. How We Use Your Information
We use the collected data for the following purposes:
- Service provision: To enable membership management, staff coordination, and billing operations.
- Authentication: To verify user identity via Google, Apple, or Phone Number + Invite Code.
- Billing & subscriptions: To manage SaaS subscription plans, renewals, and generate invoices via Razorpay.
- Notifications: - In-app: For alerts on dues, staff invites, and system updates. - WhatsApp: For sending Invite Codes, Payment Reminders, and Subscription Alerts via WhatsApp API (requires explicit phone number consent). - Push notifications: Via Firebase Cloud Messaging (FCM).
- Advertising: To display relevant third-party advertisements within the dashboard (see Section 7).
- Security & compliance: To monitor for fraud, enforce Role-Based Access Control (RBAC), and maintain data isolation between businesses.
5. Data Sharing and Disclosure
We do not sell your personal data. We share data only in the following circumstances:
5.1 Third-Party Service Providers
We share data with trusted vendors to operate the Service:
- Supabase: For database hosting, authentication, and backend infrastructure.
- Razorpay: For payment processing and fraud detection.
- Firebase (Google): For Push Notifications (FCM) and Analytics.
- WhatsApp API Provider: For delivering transactional messages and invites.
- Cloud Storage: For storing profile pictures and business logos.
5.2 Legal Requirements
We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
5.3 Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, you will be notified via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.
6. Data Security
We implement robust security measures designed to protect your information:
- Encryption: Data is encrypted in transit (SSL/TLS) and at rest via Supabase.
- Multi-tenancy: Strict Row Level Security (RLS) policies ensure Business Owners can only access their own organization's data.
- Access control: Role-Based Access Control (RBAC) limits staff access based on their role (Owner, Manager, Receptionist, Staff).
- Payment security: All payments are processed via Razorpay, which is PCI-DSS compliant. We never handle raw card data.
- Soft delete: Deleted records are marked as
isDeleted = trueand retained temporarily for recovery before permanent purging, preventing accidental data loss.
7. Advertising and Tracking
Our Service includes an advertising system to support platform operations.
- Ad display: We display third-party advertisements on dashboards.
- Tracking: We track ad views and clicks to measure performance.
- Cooldown logic: To prevent accidental inflation of click data, we use a local cooldown mechanism (e.g., repeated clicks from the same device within 3 hours may not be counted as unique clicks).
- Control: Business Owners cannot disable mandatory system ads, but we ensure ads do not interfere with critical operational features.
8. Data Retention
- Active data: Retained as long as your Business Owner account is active and subscribed.
- Soft-deleted data: When a record (Member, Staff, Business) is deleted, it is soft-deleted (marked inactive) and retained for a period defined in our backup policy before permanent deletion.
- Terminated accounts: If a Business Owner's subscription is terminated due to non-payment (Suspended > 30 days), data may be archived or deleted according to our Terms of Service.
- Financial records: Transaction logs are retained for tax and auditing purposes as required by law (typically 5–8 years).
9. Children's Privacy
Our Service is not intended for users under the age of 13.
- Business Owners: If you operate a business involving children (e.g., Kids Sports, Tutoring), you are responsible for ensuring compliance with local laws regarding children's data (e.g., COPPA, DPDP Act).
- MemberFlow: We do not knowingly collect personally identifiable information from children under 13 directly. If we discover that a child under 13 has provided us with personal information directly, we will immediately delete this from our servers.
10. Your Data Protection Rights
Depending on your location, you may have the following rights:
- Access: Request copies of your personal data (for Business Owners/Staff).
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your data (subject to legal retention requirements).
- Withdraw consent: Opt out of marketing communications.
- Data portability: Request transfer of your data to another service.
For Members (End Clients): Since Members are clients of the Business Owner, requests regarding Member data (access, deletion) should be directed to the respective Business Owner. MemberFlow acts as the data processor in this relationship.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date." You are advised to review this Privacy Policy periodically for any changes.
12. Contact Us & Grievance Redressal
If you have any questions about this Privacy Policy, or if you wish to report a grievance regarding data usage or payment issues, please contact us:
- Support email: memberflow@ctoryteller.com
- Phone / WhatsApp: +91-9970983661
- Website: www.ctoryteller.com
- Registered address: Ctoryteller, Shalpora Dangerpora. 193201. J&K, India
- Grievance Officer: Faroze War, grievance@ctoryteller.com
- Business hours: Monday–Saturday, 10:00 AM – 6:00 PM IST
- Response time: Within 2 business days (general); 15 business days (formal grievances)
For payment disputes processed via Razorpay:
- Razorpay support: support@razorpay.com
- Razorpay dispute portal: https://dashboard.razorpay.com/app/disputes