Preparing your page
Preparing your page
Legal
Effective Date: March 10, 2026
HELTHOFIT PRIVATE LIMITED and its subsidiaries ("Paybycal", "Company", "we", "us", or "our") are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy is an electronic record under the Information Technology Act, 2000, and is designed in alignment with the underlying principles of the Digital Personal Data Protection Act (DPDPA), 2023.
This Privacy Policy must be read in conjunction with our Terms of Use. By downloading, registering, or using the Paybycal mobile application (the "App") or our platform at www.paybycal.com, you provide your explicit, informed, and unconditional consent to the collection, storage, processing, and sharing of your data as described in this document. If you do not agree with these practices, you must immediately cease using the platform.
To provide total transparency and ensure the security of your information, Paybycal legally and operationally bifurcates the data we collect into distinct categories:
We collect data through three primary channels to power the Calcoin reward ecosystem, facilitate marketplace transactions, and optimize our proprietary algorithms.
With your explicit device-level permission, Paybycal integrates with Apple HealthKit (iOS) and Google Health Connect / Google Fit (Android).
When you use the App, we automatically collect App Telemetry Data. We utilize SDKs, cookies, web beacons, and analytical tools to track how you navigate the platform. This data allows us to detect bugs, monitor server latency, and understand user preferences to enhance the user interface (UI) and user experience (UX).
We utilize your data to operate, maintain, and legally protect the Paybycal ecosystem.
Paybycal is not a data broker. We only share your data under the following strictly defined operational contexts:
When you interact with the Marketplace or book a diagnostic test, we must share specific data (Name, Phone number, Address, Email Address, and context-specific health requirements) with the respective third-party vendor, laboratory (e.g., Healthians), or logistics provider for the creation of orders and to be able to provide you services as may be necessary. These entities act as Co-Data Fiduciaries or Data Processors. Their use of your data is governed by their independent privacy policies once the data is transferred for service fulfillment. Paybycal assumes no liability for the data practices of these independent third parties.
If you enroll in specialized, high-risk programs (such as the Water Fasting regimen), relevant fitness profile data may be shared with the independent, third-party instructors guiding those programs to ensure your safety and suitability for the regimen.
We reserve the absolute right to disclose any category of your data if requested by law enforcement, judicial authorities, or government agencies under a valid legal mandate. We will also disclose data to enforce our Terms of Use, investigate fraud (including Calcoin manipulation), or protect the rights, property, or physical safety of Paybycal, our users, or the public.
In the event of a merger, acquisition, restructuring, bankruptcy, or sale of all or a portion of our assets, your data will be securely transferred to the acquiring entity as a core business asset, subject to the continuity of this Privacy Policy.
Paybycal utilizes state-of-the-art, globally recognized cloud infrastructure to host the platform. While we prioritize the localization of data within the territory of India in compliance with emerging regulations, you explicitly acknowledge and consent that your data may be routed, processed, or stored on secure servers located in other global jurisdictions as required for operational efficiency, redundancy, and disaster recovery.
We implement commercially reasonable, industry-standard cryptographic and administrative safeguards to protect your data. However, transmitting data over the internet is inherently risky. Paybycal makes no absolute guarantee of data security. We expressly disclaim liability for any unauthorized access, cyber-attacks, ransomware, or data exfiltration events perpetrated by malicious third parties that are beyond our reasonable, direct control.
Paybycal retains your Personal Data, Health Data, and App Telemetry Data for as long as your account remains active, or as long as necessary to fulfill the purposes outlined in this Policy. We also retain data indefinitely as required by Indian law to resolve disputes, prevent fraud, enforce our agreements, and comply with tax and audit requirements regarding your e-commerce and Calcoin transactions.
We do not automatically delete your data upon mere app uninstallation or prolonged inactivity. If you wish to exercise your right to erasure, you must submit an explicit data deletion request via the App settings or by contacting our Grievance Officer. Upon verification of your identity, we will sever your access to the platform, instantly void your accrued Calcoins, and securely purge your primary Health Data, retaining only the minimal transaction logs required by law.
Subject to the notification and full enforcement of the respective provisions of the Digital Personal Data Protection Act, 2023, you are entitled to the following rights regarding your data:
The Paybycal ecosystem is strictly age-gated. We do not knowingly collect, solicit, or process personal data from individuals under the age of eighteen (18). If we become aware that a minor has provided us with personal data, we will take immediate steps to terminate the account and purge the information.
Paybycal reserves the unilateral right to update, modify, or amend this Privacy Policy at any time to reflect changes in our operational practices, new API integrations, or evolving legal frameworks (such as the imminent enforcement of the DPDPA 2023 rules). We will notify you of material changes via an App notification or email. Your continued use of the platform after such modifications constitutes your binding acceptance of the updated Policy.
In strict compliance with the Information Technology Rules, 2021, and the DPDPA, 2023, if you have any questions, concerns, or grievances regarding our data processing practices, please contact our designated Grievance / Data Protection Officer:
Our Grievance Officer is mandated to acknowledge your concern within twenty-four (24) hours and will endeavor to resolve data-related disputes within fifteen (15) working days.