1. Introduction
This Privacy Policy explains how KombatOS, a platform operated by Koshaary Ventures LLP ("KombatOS", "we", "us", or "our"), handles personal information when you use our website, the KombatOS Android app, our academy-management and CRM tools, tournament software, and related services (together, the "Platform"). By using the Platform, you agree to the practices described here.
KombatOS is operated by Koshaary Ventures LLP, a limited liability partnership registered in India at C-1184, Ground Floor, Sushant Lok-1, Gurgaon – 122002. We are committed to handling personal data responsibly and in line with applicable laws, including the Digital Personal Data Protection Act, 2023.
2. Our Role: Controller and Processor
For data about your own account (such as your name, email, and login details), KombatOS acts as the data controller.
For data that an academy, club, or coach enters about their members and students (for example, member profiles, attendance, belts, payments, and waivers), the academy is the controller and KombatOS acts as a processor — we process that data on the academy's instructions to provide the Platform. Academies are responsible for having a lawful basis and any necessary consents to upload and manage that data.
3. Information We Collect
We collect the following categories of information:
- Account information you provide — name, email address, phone number, password, role, and profile details (such as a photo, bio, or coaching credentials).
- Member and student data entered by academies — names, contact details, date of birth, gender, address, emergency/guardian contacts, health declarations, attendance, belt and grading records, membership and payment history, and signed waivers and consent forms.
- Tournament data — fighter profiles, registrations, categories, club affiliations, match results, and rankings.
- Photos and media — profile and member photographs, certificates, receipts, and documents uploaded to the Platform. These are stored with our media provider (see Section 7).
- Facial biometric data — where an academy enables face check-in and the member has given explicit consent, a numeric face template used only for attendance. Section 4 describes this in full.
- Payment and billing information — transaction records, invoices (including GST details where applicable), and payment status. Card, UPI, and bank details are handled directly by our payment partner; we do not store full card numbers.
- Communications — emails, WhatsApp messages, in-app notifications, support requests, and messages you send to us. Where an academy enables WhatsApp messaging, member names and phone numbers are shared with our messaging provider so the message can be delivered.
- Usage and device data — log data, IP address, browser and device type, pages viewed, and similar information collected automatically through cookies and similar technologies.
- Device location — only if you tap “Find academies near me” and allow the permission. Your coordinates are used once, in that moment, to work out which nearby cities have academies. We do not store them, and we never track your location in the background.
We do not use advertising trackers or third-party advertising SDKs, and we do not build advertising profiles.
4. Facial Biometric Data (Face Check-In)
Some academies use face check-in so members can mark attendance without a card or a phone. Because this involves biometric data, we hold it to a higher standard than anything else on the Platform.
- Off by default, opt-in per academy. Face recognition is disabled unless an academy deliberately turns it on.
- Explicit consent first. No member is enrolled without their explicit, recorded consent. Where the member is a minor, a parent or legal guardian must consent, and that consent is recorded against the member record with the guardian name and a timestamp.
- What we store is a numeric template, not a photograph of your check-in. When a face is enrolled, the image is converted into a face template — a list of numbers derived from the image — and that template is what we store and match against. The check-in image itself is not kept.
- Where it is processed. Templates are generated by a KombatOS-operated service that holds no member records. It receives an image, returns the template, and retains nothing.
- Temporary scan records auto-delete. Data created during a live check-in scan expires automatically within five minutes.
- Used only for attendance, within one academy. A template is matched only against the enrolled members of the same academy. Templates are never matched across academies, never used to identify anyone outside the Platform, never used for advertising or profiling, and never sold or shared with advertisers or data brokers.
- Withdraw consent and delete at any time. A member, or their guardian, can withdraw consent at any time and ask their academy or KombatOS to delete the stored face template. On deletion the template is erased and the member simply returns to card, PIN, or QR check-in. Nothing else about their membership is affected.
Face templates are retained only while the member remains enrolled in face check-in. They are deleted when consent is withdrawn, when the member requests deletion, or when the member record is deleted. A member photograph uploaded by an academy for an ID card or profile is a separate, ordinary photograph governed by the rest of this Policy, not by this section.
5. How We Use Information
- Provide, operate, and maintain the Platform and its features.
- Create and manage accounts, memberships, tournaments, and academy operations.
- Process payments, generate invoices, and send fee and renewal reminders.
- Record attendance, including by face check-in where the academy has enabled it and the member has consented.
- Suggest academies near you, if you ask us to and allow the location permission.
- Communicate with you about your account, updates, security, and support, and send the academy notifications you or your academy have enabled (email, WhatsApp, and in-app).
- Improve and develop the Platform, including troubleshooting and analytics.
- Protect against fraud, abuse, and security threats, and comply with legal obligations.
We do not use personal data to serve advertising, and we do not sell personal data.
6. Children's and Minors' Data
Martial arts academies often enrol minors. The Platform is intended for account-holding adults — academy owners, staff, coaches, parents, and adult members — and is not directed at children.
Where an academy stores information about a child on the Platform, the academy is responsible for obtaining verifiable consent from a parent or legal guardian as required by law, and for limiting the data to what is necessary. Face check-in for a minor requires recorded guardian consent before enrolment, as described in Section 4. KombatOS does not knowingly collect personal data directly from children without such consent. If you believe a child's data has been provided without appropriate consent, please contact us so we can address it.
7. How We Share Information
We do not sell personal data and we do not share it for advertising. We share information only as needed to run the Platform, with the following categories of recipient:
- Within your academy — staff and roles you authorise (owners, managers, coaches, front desk) can access member data according to their permissions.
- Service providers (processors) — named below. They may process data only on our instructions and for the purpose described.
- Legal and safety reasons — where required by law, regulation, legal process, or to protect the rights, safety, and security of users and the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
The service providers we rely on, and what each one receives:
- Razorpay — payment processing for membership fees, belt-test fees, tournament entries, and subscriptions. Receives the payer name, contact details, and transaction amount, and handles card, UPI, and bank details directly.
- Cloudinary — storage and delivery of uploaded images and documents, such as profile photographs, certificates, and receipts.
- Resend — delivery of transactional and notification emails. Receives recipient name and email address.
- AiSensy, a WhatsApp Business Solution Provider delivering through the WhatsApp Business Platform operated by Meta — delivery of WhatsApp messages where an academy has enabled them. Receives the recipient name and phone number and the message content.
- Google — sign-in, where you choose to sign in with a Google account.
- MongoDB Atlas and Railway — database hosting and application hosting for the Platform.
Facial biometric templates are not shared with any of these providers. They are processed only by KombatOS-operated services and stored in our own database, as described in Section 4.
8. Data Retention
We retain personal data for as long as needed to provide the Platform, comply with our legal and tax obligations, resolve disputes, and enforce our agreements. Academies can update or remove member records, and we will delete or anonymise data when it is no longer required, subject to legal retention requirements (for example, financial and invoice records).
Specific periods: temporary face-scan records expire automatically within five minutes; face templates are kept only while the member remains enrolled in face check-in and are deleted on withdrawal of consent or on request; account and member records are deleted within 30 days of a verified deletion request, except where a record must be retained to meet a legal obligation.
9. Data Security
We use reasonable technical and organisational measures to protect personal data, including encryption in transit, access controls, and role-based permissions. Face templates are stored separately from member profiles and are scoped to a single academy. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident.
10. Your Rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you and request a copy.
- Correct inaccurate or incomplete data.
- Request deletion of your data, where there is no overriding legal reason to retain it.
- Withdraw consent where processing is based on consent — including consent to face check-in, which can be withdrawn at any time without affecting the rest of your membership.
- Raise a grievance about how your data is handled.
If your data is managed by an academy (as controller), please direct member-data requests to that academy; we will support them as their processor. To exercise rights regarding your KombatOS account, contact us using the details below.
To delete your account and personal data, visit kombatos.com/delete-account (also reachable from Account settings on the web and in the Android app). We complete deletion within 30 days, except where records must be retained to meet a legal obligation.
11. Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Platform is used. You can control cookies through your browser settings; disabling some cookies may affect how the Platform works.
12. International Processing
The Platform and our service providers may process and store data on servers located in or outside India. Where data is transferred across borders, we take steps to ensure it remains protected consistent with this Policy and applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Platform after changes take effect means you accept the updated Policy.
14. Contact Us
If you have questions, requests, or grievances about this Privacy Policy or your personal data, contact us at [email protected].
Koshaary Ventures LLP
C-1184, Ground Floor, Sushant Lok-1, Gurgaon – 122002, India