Privacy Policy

🛡️

Zylta Privacy Policy

Official Policy Effective Date: August 31, 2026 Version 1.0

Welcome to Zylta ("we", "our", or "us"). We are dedicated to safeguarding your personal data and ensuring complete transparency regarding how your information is collected, processed, used, and protected when you use the Zylta mobile application, website, and related services.

🌐 1. Introduction & Overview

Zylta provides an online venue discovery, court booking, and facility management platform connecting sports enthusiasts with turf venue operators across India. This Privacy Policy governs your use of the Zylta mobile application, the website located at https://zylta.in, and our related backend APIs and services.

By accessing or using Zylta, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our application or services.

👤 2. Information We Collect

We adhere to the principle of data minimization and only collect information strictly necessary to provide and secure our booking platform:

  • Full Name: Collected during profile setup to identify your account, personalize your experience, and generate your booking passes.
  • Mobile Phone Number: Collected as your primary unique account credential. Used to deliver One-Time Passwords (OTP) for secure login, send transactional SMS confirmations, and facilitate customer support.
  • Email Address (Optional): If provided, used for administrative communications and electronic receipts.
  • Selected District: Selected by you from a list of standardized districts to display relevant nearby turf facilities.
Passwordless Architecture: Zylta operates on a passwordless authentication model using secure SMS OTPs. We never ask you to create or store a password.

🏟️ 3. Owner & Turf Facility Information

When a user applies to register as a Turf Owner, we collect facility details necessary to list and manage the venue:

  • Owner Details: Full name and verified mobile phone number.
  • Turf Facility Name & Physical Address: Stored and displayed publicly to players for venue discovery and navigation.
  • Google Maps Location Link: Provided by the turf owner so players can navigate to the physical facility via Google Maps.
  • Sports, Courts & Pricing Configuration: Number of available courts, sports offered (e.g., Football, Cricket, Badminton), operating hours, and day/night pricing configurations.

📜 4. KYC & Verification Documents

To maintain platform integrity and verify legitimate venue ownership before granting administrative access, our backend supports the collection of owner verification documents:

  • PAN Card Information: Permanent Account Number (PAN) and PAN card document (PDF) where provided, used strictly to verify the owner's legal identity and comply with applicable tax obligations.
  • Business Registration Proof: Business proof documents in PDF format (such as Trade License, GSTIN, or Udyam certificate) where submitted to confirm venue registration.

Access Restriction: KYC documents are accessible strictly to authorized administrators for verification review and are never made public to players or third parties.

📋 5. Booking & Attendance Information

When you book a turf court on Zylta, the platform records:

  • Booking Parameters: Date of booking, selected time slots, sport type, and allocated court numbers.
  • Pricing & Status: Total booking amount, platform fees, payment status (Confirmed, Cancelled, Completed), and Zylta Coins utilized.
  • QR Verification Token: A unique cryptographic verification token generated for your booking pass, which is scanned by the turf operator at the venue entrance to confirm your attendance.
  • Check-in Timestamp: The exact time your QR pass is verified at the facility.

💳 6. Payment & Financial Data

All online payments on Zylta are processed through Razorpay (Razorpay Software Pvt. Ltd.), an RBI-authorized and PCI-DSS Level 1 compliant payment gateway.

Important Financial Protection Disclosure:
Zylta DOES NOT collect, receive, or store your credit card numbers, debit card numbers, CVVs, expiration dates, UPI MPINs, or net banking passwords. All sensitive payment instrument details are entered directly inside Razorpay's encrypted, secure checkout interface.

What Zylta Records: We only store transaction reference identifiers generated by Razorpay (Order ID, Payment ID, cryptographic signature, transaction amount in INR, and payment status) for order fulfillment, accounting, and refund processing.

💰 7. Zylta Coins & In-App Wallet

Zylta features an in-app coin wallet system used for cancellation refunds and platform promotional credits:

  • User Cancellation Refunds: When a user cancels a confirmed booking, eligible refund amounts (based on the turf's cancellation window minus the ₹20 platform charge) are credited as Zylta Coins directly to the user's in-app wallet. Funds are not returned to the original bank account for customer-initiated cancellations.
  • Coin Redemption: Users can redeem their Zylta Coins for up to 50% of the total booking value on future slot reservations.
  • Owner/Conflict Cancellations: If a turf owner cancels a booking or a technical booking conflict occurs, an automated 100% direct gateway refund is returned to the customer's original payment method via Razorpay.

📍 8. Location Information

No GPS Tracking: Zylta DOES NOT access, track, or collect your device's precise GPS location, geographic coordinates (latitude/longitude), or background location. We do not request Android location permissions.

How Location Works on Zylta:

  • User-Selected District: You manually choose your preferred district (e.g., Chennai, Coimbatore, Madurai) from our standardized district picker. This text selection is saved in your profile to display local sports venues.
  • External Map Navigation: Turf listings display outbound Google Maps links submitted by venue owners. Clicking these links opens Google Maps on your device for driving directions.

📱 9. Device & Technical Information

When you interact with our platform, we collect limited technical metadata necessary for communication and security:

  • Device Identifier: A randomly generated UUID stored in local storage to prevent duplicate push notification dispatches across multiple browsers or devices.
  • Platform Category: General device category (mobile, tablet, or desktop) derived from your browser header to optimize screen layouts and notification rendering.
  • IP Address & User Agent: Logged during security-critical events (such as administrative role changes and QR check-in verification) and used in-memory for API rate limiting to protect against automated abuse.
Zero Ad Trackers or Telemetry SDKs: Zylta does NOT include third-party advertising SDKs, advertising identifiers (AAID/IDFA), Google Analytics, Mixpanel, Sentry, or Crashlytics tracking libraries.

🔔 10. Push Notifications

We use Firebase Cloud Messaging (FCM) (provided by Google LLC) to deliver real-time transactional push notifications:

  • Notification Types: Booking confirmations, slot availability alerts ("Notify Me" watches when a booked slot opens up), and venue owner approval notices.
  • Registration Tokens: Your device's FCM registration token is stored on our server (up to 10 active devices per account).
  • Managing Permissions: You can enable or disable push notifications at any time through your device or browser settings.

🔒 11. Authentication & Security Architecture

Your account security is maintained through modern cryptographic and session safeguards:

  • SMS OTP Verification: Login requests generate a cryptographically random 6-digit OTP delivered via SMS, which expires in 5 minutes.
  • JSON Web Tokens (JWT): Successful authentication issues a tamper-proof JWT token signed with HMAC-SHA256, valid for 7 days.
  • Role Audit Logging: Any administrative elevation or status change is permanently audited with timestamps and administrative identity.

📁 12. Uploaded Documents & Storage

Uploaded owner verification documents are subject to strict technical controls:

  • Format Restrictions: Uploads are strictly restricted to PDF documents (application/pdf) with a maximum file size of 10 MB.
  • Storage & Access: Documents are stored on our dedicated backend file storage and are restricted to authorized administrative personnel for verification.

⚙️ 13. How We Use Information

We process your data strictly for legitimate operational purposes:

  • To create and manage your Zylta account via phone OTP verification.
  • To process court slot reservations, temporary concurrency locks, and booking confirmations.
  • To verify entry tickets at sports facilities via secure QR codes.
  • To process digital payments, automated refunds, and in-app Zylta Coin credits.
  • To send essential transactional notifications and slot availability alerts.
  • To verify the identity and credentials of venue facility operators.
  • To maintain platform security, prevent double bookings, and combat fraud.

🤝 14. Third-Party Service Providers & Data Sharing

We do not sell, trade, or rent your personal information. We share limited operational data strictly with the following verified service providers to operate our services:

Service Provider Jurisdiction Purpose in Zylta Data Shared
Razorpay India Payment gateway, payment verification, automated refunds Order amount, currency (INR), customer phone number, Razorpay Order ID
MSG91 India Primary SMS OTP authentication and widget verification Phone number, OTP verification token
Twilio USA Alternative SMS OTP delivery Phone number, 6-digit OTP code
Firebase (FCM) USA Push notification delivery FCM device push token, notification title and message text, platform
Google Fonts USA Web typography CDN (Inter & Outfit fonts) Standard HTTP request headers (IP address, user agent)
Google Maps USA Venue navigation hyperlinks IP address upon clicking external venue links

15. Data Retention & Automated Lifecycles

We retain personal data only for as long as necessary to fulfill platform operations and comply with legal obligations:

  • User Profile & Bookings: Retained for the lifetime of your active account and deleted immediately upon account deletion.
  • In-App Notifications: Automatically deleted after 30 days via automated database expiration routines (TTL).
  • Slot Watches ("Notify Me"): Automatically deleted at midnight UTC of the target booking date.
  • Temporary Slot Locks: Automatically purged after 2 to 5 minutes if checkout is not completed.
  • Financial & Payment Records: Transaction IDs, amounts, and dates are retained indefinitely for statutory accounting and tax compliance, but are completely anonymized (unlinked from your user account) upon account deletion.

🗑️ 16. Self-Service Account Deletion

Zylta provides an instant, self-service account deletion mechanism directly inside the application:

  • How to Delete: Log in to Zylta, navigate to Profile ➔ Account Settings ➔ Delete Account, and follow the verification prompts.
  • Pre-flight Checks: For consumer protection, deletion is blocked if you have active upcoming bookings, in-flight payment locks, or pending gateway refunds until those transactions are concluded.
  • What is Permanently Deleted: Your profile (name, phone number, district, FCM tokens), booking history, wallet coin balance, notifications, slot watches, and audit logs are 100% hard-deleted from our live database.
  • What is Anonymized: Past financial transaction records have personal user identifiers removed (userId set to null) and are retained solely for mandatory tax and accounting audits.

🛡️ 17. Data Security Measures

We implement multiple layers of technical and organizational security controls:

  • Encryption in Transit: All data transmitted between your browser/app and our servers is encrypted using HTTPS / TLS 1.3.
  • Security Headers: We enforce Helmet security headers including Frameguard, XSS protection, and MIME type sniffing prevention.
  • Database Sanitization: All incoming requests pass through NoSQL query sanitization to prevent database injection attacks.
  • API Rate Limiting: Endpoints are protected with rate limiters to prevent brute-force attacks and abuse.
  • Token Masking: Sensitive QR verification tokens and push identifiers are masked in all internal server logs.

⚖️ 18. User Rights & Choices

In accordance with applicable data protection laws, including the Digital Personal Data Protection (DPDP) Act, 2023:

  • Right to Access: You can view your personal profile details, active bookings, and wallet balance directly in the app.
  • Right to Correction: You can update your name and district preferences at any time from your Profile screen.
  • Right to Erasure: You can permanently delete your account and associated personal data using our self-service deletion workflow.
  • Right to Withdraw Consent: You can unsubscribe from slot availability watches or revoke push notification permissions via browser/app settings.

👶 19. Children's Privacy

Zylta is intended for a general audience and is not directed specifically toward children. We do not knowingly collect personal information from children. If we become aware that personal information has been provided by a child in circumstances where its collection is not permitted, we will take reasonable steps to delete that information from our systems.

🔄 20. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect enhancements in our services, technical architecture, or statutory requirements. When changes are made, the "Effective Date" at the top of this page will be updated. We encourage you to review this policy periodically.

📬 21. Contact Us & Grievance Redressal

If you have any questions, concerns, feedback, or grievances regarding this Privacy Policy or our data handling practices, please contact us:

Official Support Contact:
Support Email: support@zylta.in
Platform Website: https://zylta.in
Grievance Redressal: Grievance Officer, Zylta Technologies
Response Time: We endeavor to respond to all legitimate privacy inquiries within 48 to 72 business hours.
↑ Back to Top