Privacy Policy
Last updated: 21 September 2026
This policy describes how OnRep (“OnRep”, “we”) collects and uses information in the OnRep website, web app, and Android app. Contact: hi@onrep.in.
The legal entity display name, registered address, governing law and a named grievance officer beyond hi@onrep.in have not been published yet. Until those details are confirmed, use hi@onrep.in for privacy questions.
Who this applies to
OnRep accounts are invite-only for academy staff and parents. Student login is not available in the Android app. The roles that can delete an OnRep account are academy owner, academy admin, coach, parent.
Account and identity information
We collect name, email, phone number, user identifiers, hashed email-password credentials where used, Firebase Authentication identifiers, and session refresh tokens so invited academy members can sign in. Android phone sign-in uses Firebase Authentication one-time codes. We do not store those one-time codes after verification. We store device push tokens to deliver notifications.
Academy memberships and children / student records
Academies store membership roles, invitations, and student roster data needed to run classes. Parent accounts are linked as guardians. Student profiles, attendance, enrolment, fees and safeguarding notes belong to the academy. Deleting a parent account removes guardian access; it does not delete the child’s academy records.
Child attendance, enrolment, fee and safeguarding records remain under the academy’s control while required to provide the service and meet legitimate operational, legal or safeguarding obligations. They are subsequently deleted or anonymized according to the academy’s retention policy.
Attendance, schedules and performance
Coaches record session schedules, rosters and attendance. Coaches may capture race times, fitness or other performance measurements and private coaching notes. Those records stay coach-private unless the academy enables parent performance sharing for that activity and a coach explicitly publishes an update. Unpublished measurements remain coach-private.
Fees, payment references, receipts and uploaded payment evidence
Academies record class fees, payment obligations, payment references (including UTR), receipts, and optional payment screenshots uploaded by parents. Those screenshots are used only as evidence that a class fee was paid to the academy for physical coaching. They do not unlock OnRep app features.
OnRep does not hold or custody academy funds. Where enabled, payments are processed by Razorpay or another identified payment provider and settled according to the academy’s configured payment account. OnRep retains limited fee and transaction information for payment status, receipts, reconciliation, support and applicable recordkeeping obligations.
OnRep platform subscriptions are sold only on the web. The Android app does not sell the OnRep subscription and does not contain an external SaaS checkout link. Razorpay in Android is used only for physical academy or coaching fees where an academy has enabled that collection.
OnRep does not store card numbers, CVV, UPI PINs or bank login credentials. Bank account numbers used for academy payout configuration are encrypted and shown to academy owners only in masked form.
Files, notifications and diagnostics
We may store uploaded files such as payment screenshots or communication attachments, notification history, Firebase Cloud Messaging tokens, server logs, IP addresses and security diagnostics needed to operate and secure the service.
Firebase authentication and notifications
Firebase Authentication verifies phone OTP and issues ID tokens that OnRep exchanges for its own session. Firebase Cloud Messaging delivers push notifications. We do not use Firebase to sell OnRep subscriptions in the Android app.
How we use data
- Operate academy scheduling, attendance, fees and parent communication
- Authenticate users and keep sessions secure
- Send operational notifications (class, fee and academy messages)
- Reconcile academy fee payments and issue receipts
- Meet tax, accounting, fraud-prevention and legal obligations
Subprocessors and location
Service providers process data on our behalf. Processing may occur outside the country where you live, including in facilities operated by those providers.
- Google Firebase — authentication and push notifications (project onrep-academy)
- Neon — application database hosting
- Amazon Web Services — email delivery and file storage for payment evidence
- Razorpay — academy class-fee collection where the academy enables it, and web-only OnRep platform billing
- Cloudflare — website hosting
Security
We use HTTPS in production, access controls, hashed credentials where passwords are used, encrypted academy bank details, and session revocation on deletion. No method of transmission or storage is completely secure.
Retention and deletion
An academy owner, academy admin, coach or parent can delete an account in the app under Account → Delete account, or request deletion at onrep.in/delete. Access is disabled and active sessions are revoked immediately. Personal identity data is then deleted or irreversibly anonymized. External identity-provider deletion may be retried if temporarily unavailable. If you cannot sign in, submit the public request form. We process a verifiable request within 30 days.
We may retain:
- Fee, payment, receipt and tax records may be retained for up to eight years, or for another period required by applicable tax, accounting, fraud-prevention or legal obligations.
- Security and audit logs may be retained for up to two years for investigations, abuse prevention and legal requests.
- Child attendance, enrolment, fee and safeguarding records remain under the academy’s control while required to provide the service and meet legitimate operational, legal or safeguarding obligations. They are subsequently deleted or anonymized according to the academy’s retention policy.
A deleted identity cannot sign back in with the previous OTP or password. Sole owners of an active academy must transfer ownership or explicitly close the academy as part of in-app deletion.
Your rights
You may request access, correction or deletion of personal identity data by using in-app deletion or onrep.in/delete, or by emailing hi@onrep.in. Academy-owned student and fee records are controlled by the academy.
Contact
OnRep · hi@onrep.in
Related: Terms · Delete account