Table of Contents (8 sections)
1. Scope & Relationship
Rozx provides booking, appointment scheduling, billing, and customer relationship management (CRM) software for service businesses, including salons, spas, clinics, barbershops, and studios.
To ensure clarity, we distinguish between the different ways information is processed on our platform:
- Merchant Account Users: Business owners, managers, receptionist staff, and service professionals who register and use Rozx accounts. Rozx acts as the data controller for account management, billing, and communication purposes regarding these users.
- End Customers & Clients of Merchants: Individuals who book appointments or receive services from businesses using Rozx. Merchants control their client database and determine what information is requested. Rozx processes this customer information strictly on behalf of and under the instruction of the merchant to deliver calendar scheduling, notifications, and POS checkout services.
2. Information We Collect
We collect information necessary to operate the platform, maintain security, and process billing:
- Account & Workspace Information: Name, phone number, email address, business name, GSTIN (where applicable), branch addresses, and staff account details provided during signup or workspace configuration.
- Billing & Subscription Details: Payment transaction identifiers, subscription status, and invoice history. Payment processing is handled directly by verified payment gateways (such as Razorpay). Raw credit card numbers or UPI PINs are never received or stored on Rozx servers.
- Merchant Operating & CRM Data: Service catalogs, pricing, staff schedules, appointment bookings, walk-in records, customer contact information, visit history, notes, and digital intake forms or waivers entered by merchants into their workspace.
- Technical & Usage Log Data: Standard server logs, IP addresses, browser specifications, operating system details, error traces, and anonymous interface navigation logs collected for security audit, troubleshooting, and system performance monitoring.
3. How Information Is Used
Information processed by Rozx is used strictly for legitimate business and operational purposes:
- To provision, maintain, and deliver the Rozx SaaS platform services.
- To manage calendar bookings, prevent appointment conflicts, and process checkout transactions.
- To deliver automated booking confirmations, WhatsApp/SMS appointment alerts, and invoice notifications requested by merchants.
- To process subscription renewals, manage billing accounts, and issue tax invoices.
- To investigate technical errors, prevent unauthorized access, and protect system infrastructure.
- To fulfill legal obligations under applicable Indian laws and regulatory frameworks.
4. Verified Third-Party Service Providers
Rozx engages third-party infrastructure and service providers to support specific platform operations. Data shared with these providers is limited to what is strictly required for function delivery:
| Provider / Technology | Purpose | Data Type Handled |
|---|---|---|
| Razorpay | Payment processing & subscription gateway | Transaction IDs, billing contact info |
| Meta / WhatsApp Cloud API | WhatsApp booking reminders & notifications | Phone numbers, appointment notification text |
| SMS Gateway Providers | Transactional SMS notifications | Recipient phone numbers, SMS message text |
| PostHog | Product usage analytics & performance tracking | Anonymized page views, feature interaction metrics |
| Sentry | Application error logging & crash reporting | Technical stack traces, browser/OS error logs |
| Sanity CMS | Marketing website content delivery | Public blog & case study content |
5. Security & Tenant Data Isolation
Rozx implements technical and organizational safeguards designed to protect workspace information from unauthorized access, loss, or misuse:
- Tenant Isolation: Database queries enforce strict tenant boundary filtering (`tenantId` scoping) to prevent cross-business data leaks.
- Encryption in Transit & Rest: Data transmitted across web connections is encrypted using HTTPS / TLS protocols. Sensitive database credentials and tokens are encrypted at rest.
- Role-Based Access Control (RBAC): Workspace owners can assign specific staff roles (Owner, Manager, Reception, Professional) to restrict access to sensitive business reports and billing data.
6. Data Retention & Account Cancellation
We retain workspace data for as long as your account remains active or as necessary to provide services, resolve billing disputes, and comply with legal or tax obligations.
Upon subscription cancellation or account termination, access to the workspace is disabled at the end of the paid billing period. Operational database backups and inactive workspace records are subject to periodic server cleanup schedules. Merchants desiring a copy of their customer CRM or booking history should export their business records prior to workspace deactivation.
7. Privacy Rights & Indian DPDP Principles
Rozx respects data protection principles aligned with India's Digital Personal Data Protection (DPDP) Act, 2023. Account holders may request access to, correction of, or deletion of their account registration details by contacting us.
If you are an end customer of a salon, spa, or clinic using Rozx and wish to exercise privacy rights regarding your booking or treatment records, please contact the specific business directly, as they maintain control over their customer CRM records.
8. Privacy Contact & Inquiries
If you have any questions regarding this Privacy Policy, wish to update your business contact information, or have privacy inquiries, please contact our team at:
Email: hello@rozx.in
Legal Operator: Rozx
Governing Law: India (Jurisdiction: Courts of New Delhi, India).
For legal notices or data inquiries, reach out to hello@rozx.in.