Skip to content
BHIMS Ventures

Privacy Policy

Your data, plainly.

Last updated 5 September 2026

This policy explains what we collect when you use the BHIMS Ventures website and the member app, why we collect it, who we share it with and the choices you have. We have tried to write it the way we would explain it at the front desk.

Who we are

BHIMS operates BHIMS Ventures, the club in Patiala, Punjab that brings together the Arena Gym, padel and pickleball courts, Le Petit Café and the nutrition hub. When this policy says “we” or “BHIMS”, it means BHIMS.

Under the Digital Personal Data Protection Act, 2023 we are what the law calls a data fiduciary. In plain terms: we decide why and how your personal data is used, and we are responsible for looking after it. Questions about anything here can go to info@bhimsventures.com.

What we collect on the website

The website is for browsing and enquiries. Nothing is bought or sold on it, so it collects very little.

  • Membership enquiry form: your name, email address, phone number, what brings you to BHIMS, your message and how you prefer to be contacted. We use this to reply to you and nothing else.
  • Server logs: when a page is requested our hosting provider records the IP address, browser type, page and time. These logs help us keep the site running and spot abuse, and are kept only for a short period.
  • Analytics: we use Vercel Analytics, a privacy-friendly service that counts page views in aggregate. It sets no cookies and does not follow you across other websites.

The public pages of the website do not set tracking or advertising cookies.

What we collect in the member app

The member app is where membership, access, orders and rewards live, so it needs more from you.

  • Your phone number. It is your identity in the app. You prove it is yours by entering a one-time code we send by SMS. We store the number and when it was verified.
  • Your device. The app ties your account to the first phone you sign in on, using an identifier for that device. A different handset is refused until a staff member resets the binding for you. This stops someone else signing in as you.
  • Your membership: the plan you hold, its dates, its status and the payments made against it.
  • Attendance and gate check-ins: each time you enter through the gate we record the time, the entrance and whether you used the QR code or Bluetooth. This is how we know who is in the building and how we investigate access problems.
  • Café and nutrition orders: what you ordered, when, the amount, and the pickup status.
  • Reward points: your balance and every credit or debit, with the reason for each.
  • Payment status: the amount, the receipt reference and whether a payment succeeded, failed or was refunded. Card, UPI and net-banking details are entered directly with Razorpay, our payment processor. We never see or store your card number, UPI PIN or bank credentials.
  • Anything you tell us when you ask for help, request a refund or report a problem.
  • Health data, only if you choose to connect Apple Health or Health Connect in the app. We then receive daily totals for steps, active energy and active minutes, and your workout sessions (type, start and end time, energy). We never receive heart rate, sleep, body measurements or any medical record, and the app cannot write to your health app. You can disconnect at any time from the Activity screen, which deletes the health data we hold immediately.

Why we use it

We use your data for the reasons you would expect from a club you have joined, and we ask for your consent when you sign up and when you submit a form. Specifically, we use it to:

  • Run your membership and let you through the gate.
  • Prepare and hand over the orders you place, and take payment for them.
  • Issue refunds and keep an accurate record of money in and out.
  • Award, track and redeem reward points under the rules shown in the app.
  • Reply to enquiries and support requests.
  • Keep the club and your account safe: for example by limiting repeated sign-in attempts and keeping an audit trail of staff actions.
  • Meet our legal duties, such as keeping tax and accounting records.
  • Understand, in aggregate, how the club and the app are used so we can improve them.

We do not sell your personal data. We do not build advertising profiles or share your data with advertisers.

Who we share it with

We share personal data only with providers that help us run the club, and only what each one needs.

  • Razorpay processes payments and refunds. They receive the amount, a receipt reference and your contact details, and they handle your card or UPI details directly under their own privacy policy.
  • Vonage delivers the one-time SMS codes. They receive your phone number and the text of the message.
  • Hosting and infrastructure providers run our website, our app backend and our database. They store data on our behalf and act only on our instructions.
  • Court bookings for padel and pickleball are made on Project Play. When you follow a booking link you deal with Project Play directly, under their terms and privacy policy. We do not pass your app data to them.
  • The map on our website is embedded from Google Maps. When it loads, Google receives your IP address and may set its own cookies, under Google's privacy policy. The address and directions are also written out in plain text, so you can skip the map.

Authorised staff see the parts of your data their role needs, and sensitive actions such as refunds and access resets are recorded. We may also disclose data when the law requires it, for example to a court or a tax authority. Some of our providers run servers outside India; we only use providers that commit by contract to protect your data.

How long we keep it

We keep personal data for as long as we need it for the purpose it was collected, and then delete or anonymise it. As a guide:

  • One-time SMS codes are deleted as soon as they are used or expire.
  • Server logs are kept for a short period, normally no more than 90 days.
  • Website enquiries are kept for up to 12 months after our last contact with you, unless you become a member.
  • Membership, order, payment and refund records are kept while you are a member and afterwards for as long as tax and accounting law requires.
  • Gate check-ins are kept for up to 12 months for safety and dispute resolution.
  • Reward point history is kept while your account exists, because every balance has to be explainable.
  • Health data is kept only while you stay connected. Disconnecting deletes it straight away; it is never used for advertising, never sold, and never used to decide reward points.

Your rights

The Digital Personal Data Protection Act, 2023 gives you rights over your personal data. This is how they work with us:

  • Access: ask us for a summary of the personal data we hold about you and how we use it.
  • Correction: ask us to fix anything that is wrong or out of date.
  • Deletion: ask us to delete your data. We will do so unless we are required to keep it, for example payment records for tax purposes.
  • Withdrawing consent: you can stop using the app and ask us to close your account at any time. Some services, such as gate access, cannot work without the data they depend on.
  • Nomination: you can name someone to exercise these rights on your behalf if you are unable to.
  • Grievances: write to us first at info@bhimsventures.com. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.

Phone numbers change hands. If you give up your number, tell us so we can release it from your account. Once released, the next person to hold that number cannot sign in as you. If you get a new number, tell a staff member at the venue; we will verify who you are before moving your account to it.

How we protect it

Sign-in tokens are stored only as one-way hashes, repeated attempts at a one-time code are limited, a new app sign-in ends any earlier session, staff access is restricted by role, and sensitive staff actions are logged. Payments are handled by Razorpay so that card and UPI details never reach our systems. No system is perfectly secure, and if a breach affects your data we will tell you and the authorities as the law requires.

Children

The club is not intended for anyone under 18 without a parent or guardian. If a child joins, the parent or guardian applies for the membership, gives consent for the data described here and is responsible for the account. If you believe we hold a child’s data without a guardian’s consent, contact us and we will remove it.

Contact

For anything about your privacy, write to info@bhimsventures.com or speak to a staff member at Factory Area, Main Road, Patiala, Punjab. You can also contact us through the details on our contact page.

Changes to this policy

When we change this policy we will post the new version here and update the date at the top. If a change matters to how we use your data, we will also tell you in the app or by SMS or email before it takes effect.