Privacy Policy
Last updated: 19 September 2026
Bring Back is a loyalty platform for restaurants, cafés and gyms. This policy explains what personal data we collect, why, and the rights you have. It is written to meet India's Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and its SPDI Rules, and, where they apply, the GDPR (EU/UK) and US state privacy laws such as the CCPA/CPRA.
1. Who is who
Business customers (the restaurants, cafés and gyms that use Bring Back) decide why and how their own customers' data is used. For that data, the business is the "data fiduciary" / "controller" and Bring Back acts as its "data processor".
For our own website, business accounts, billing and security, Bring Back is the fiduciary / controller.
If you are a diner or gym member and have a question about a business's loyalty programme, please contact that business first. We will also help you directly at hello@bringback.com.
2. Data we collect
- Business account data: name, email, phone, business name, branding, staff details, and plan and billing information.
- Loyalty programme data (on behalf of businesses): a customer's name, mobile number, optional email, visit and reward history, and scratch-card / spin-wheel plays.
- Verification data: mobile numbers used for one-time passwords (OTP).
- Technical data: device and browser type, IP address, log data and basic usage analytics.
- Payment data: handled by our payment partners. We do not store full card, UPI or bank details.
3. Why we use it (legal basis)
- To provide the service: run campaigns, issue and redeem rewards, send OTPs. (Performance of a contract / consent)
- To take payments, issue GST invoices and keep tax records. (Contract and legal obligation)
- To keep the platform secure and prevent fraud. (Legitimate interest / legitimate use)
- To send service messages, and marketing only where you have opted in. (Consent)
4. Consent and children
Where we rely on consent, it is free, specific and informed, and you can withdraw it at any time as easily as you gave it. Withdrawing does not affect earlier lawful use.
Bring Back is not intended for children under 18. Under the DPDP Act we do not knowingly process a child's data without verifiable parental consent. If you believe a child has signed up, contact us and we will delete the data.
5. Who we share data with
We do not sell personal data. We share it only with service providers who help us run Bring Back, under contracts that require them to protect it:
- Cloud hosting and database (Supabase, Vercel)
- Payment processing (such as Cashfree, Razorpay, Stripe)
- Email and SMS delivery (such as Resend and SMS providers)
- Analytics (Vercel Analytics)
We may also disclose data where the law, a court or a government authority requires it, or to protect rights and safety, or in a merger or sale of the business (with notice to you).
6. International transfers
Our providers may process data outside your country, including in India, the EU and the USA. Where required, we use safeguards such as Standard Contractual Clauses, and we only transfer personal data outside India to countries not restricted by the Government of India.
7. How long we keep data
We keep data only as long as needed for the purposes above. Business accounts and their programme data are deleted or anonymised within 90 days of account closure, unless the law requires longer (for example, tax and invoice records for up to 8 years). Backups roll off within 35 days.
8. Security
We use encryption in transit, access controls, row-level data isolation between businesses and monitoring. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority (including the Data Protection Board of India and, for EU/UK users, the supervisory authority) as the law requires.
9. Your rights
- India (DPDP Act): access a summary of your data, correct and update it, erase it, nominate someone to exercise your rights if you die or are incapacitated, and get your grievance addressed.
- EU/UK (GDPR): access, rectification, erasure, restriction, portability and objection, plus the right to complain to your supervisory authority. See our GDPR page.
- California and other US states: know, access, delete, correct, and opt out of the "sale" or "sharing" of personal data. We do not sell or share personal data for cross-context advertising. We will not discriminate against you for using these rights.
To use any right, email hello@bringback.com. We respond within 30 days (sooner where the law requires). We may need to verify your identity first.
10. Marketing messages
We send promotional email or SMS only with your consent, in line with CAN-SPAM, the TCPA and India's TRAI/DLT rules. Every message has a clear way to opt out (unsubscribe link or reply STOP). Service messages such as OTPs and receipts are not marketing.
11. Grievance Officer (India)
As required by the IT Act and DPDP Act, you can raise complaints with our Grievance Officer at hello@bringback.com (subject: "Grievance"). We acknowledge within 48 hours and resolve within 15 days. If unresolved, you may approach the Data Protection Board of India.
12. Changes to this policy
We may update this policy. If the change is material we will tell you by email or in the product before it takes effect. The date at the top shows the latest version.