Privacy Policy
Last updated: July 17, 2026Status: DRAFT — not yet published. Placeholder fields below must be completed and reviewed by qualified legal counsel before this page goes live.
1. Introduction
This Privacy Policy explains how ⚠ TODO: legal entity name operating
Y&A 10X Club ('Y&A 10X Club', 'Y&A', 'we', 'us', or 'our') collects,
uses, stores, shares, and protects personal data when you visit our
website, apply for membership, create an account, join events, use the
member dashboard, interact with the member directory, participate in
founder matching, or communicate with us.
Y&A 10X Club is a premium, curated founder network. Because the platform
handles business, membership, event, payment, profile, and verification
information, privacy is central to the trust of the community.
2. Scope
This Policy applies to:
- the Y&A 10X Club website and landing pages;
- membership application and onboarding forms;
- login, account, dashboard, member profile, founder matching, member directory, renewal, coupon, event, and notification features;
- online and offline events, retreats, masterclasses, meetups, funding days, and other special formats;
- email, WhatsApp, phone, social media, and other communications with us.
This Policy does not apply to third-party websites, platforms, payment
gateways, social networks, or tools that have their own privacy
policies.
3. Data Controller / Data Fiduciary
| Topic | Details |
|---|---|
| Operator | ⚠ TODO: legal entity name operating Y&A 10X Club |
| Registered office | ⚠ TODO: registered office address |
| Support / legal contact | ⚠ TODO: official support/legal email |
| Grievance Officer / Privacy Contact | ⚠ TODO: Grievance Officer name and email |
For applicable Indian data protection law, the operator of Y&A 10X Club
will generally act as the Data Fiduciary for personal data collected and
processed through the platform, unless a separate arrangement states
otherwise.
4. Personal Data We Collect
4.1 Information You Provide Directly
| Topic | Details |
|---|---|
| Account and login data | Name, email ID, phone/WhatsApp number, password or authentication method, Google login identifier where used. |
| Founder and profile data | Photo, first name, last name, role/designation, city, company name, website, domain/sector, business model, revenue range, team size, business description, products/services, strengths, bottlenecks, social links. |
| Application and eligibility data | Membership application answers, business age, scalable business model response, source of reference, referrer details, consent confirmations, internal review status. |
| Verification documents | Revenue proof documents such as audited balance sheet first page, GSTR-3B summary, bank statement summary, CA-certified revenue certificate, or other authorized documents submitted by you. |
| Payment and transaction data | Membership fee, renewal fee, event fee, coupon use, transaction status, receipt details, payment processor confirmation. We do not intend to store full card details. |
| Event data | Event registrations, ticket type, guest/additional attendee details where allowed, attendance, event feedback, photo/video participation where applicable. |
| Communications data | Emails, WhatsApp messages, support requests, feedback, survey responses, complaints, and correspondence with Y&A. |
4.2 Information Collected Automatically
- device and browser information;
- IP address and approximate location;
- pages viewed, links clicked, session duration, referral source, campaign attribution;
- login activity, security events, audit logs, error logs, performance diagnostics;
- cookie, pixel, and similar tracking information as described in the Cookies Policy.
4.3 Information From Other Sources
- referrals from members, partners, invitees, or event hosts;
- public business sources such as company websites, LinkedIn, MCA/GST or similar public business records where relevant and lawful;
- payment gateways and service providers confirming payment or transaction status;
- event partners, sponsors, or co-hosts where you consent or where needed to administer a specific event.
5. Why We Use Personal Data
| Topic | Details |
|---|---|
| Membership application review | To assess eligibility, perform due diligence, review documents, approve/reject applications, and request more information. |
| Account and platform access | To create accounts, verify login, provide dashboards, control paid/unpaid access, and manage security. |
| Member directory and founder matching | To help active members discover relevant founders based on profile fields, strengths, bottlenecks, sector, city, stage, and other matching tags. |
| Events and community operations | To manage registrations, payments, attendance, reminders, passes, coupons, feedback, photos, videos, and post-event communication. |
| Payments, renewals, and coupons | To process payments, issue receipts, manage renewals, payment reminders, coupon allocation, and usage tracking. |
| Notifications and communication | To send service messages, application updates, event updates, renewal reminders, admin announcements, WhatsApp group updates, and community information. |
| Security and abuse prevention | To prevent fraud, misuse, spam, unauthorized access, security incidents, and violations of our policies. |
| Legal and compliance | To comply with legal, tax, accounting, dispute resolution, audit, law enforcement, and regulatory requirements. |
6. Legal Basis / Grounds for Processing
Depending on the activity and applicable law, we process data based on
one or more of the following grounds:
- your consent, including for WhatsApp group addition, certain marketing communications, non-essential cookies, and optional public visibility choices;
- performance of a contract or steps taken before entering into a contract, such as processing applications, membership, payments, renewals, and events;
- legitimate interests such as platform security, member verification, service improvement, fraud prevention, and community quality control;
- compliance with legal obligations such as taxation, accounting, lawful requests, and dispute handling.
7. Member Directory, Visibility, and Matchmaking
Y&A 10X Club is built around trust-based founder discovery. If you
become an active member, selected profile information may be visible to
other active members through the member directory and founder matching
features.
| Topic | Details |
|---|---|
| May be visible to active members | Name, photo, company, designation, city, domain/sector, business model, profile bio, products/services, selected social links, strengths, bottlenecks, and selected contact preference. |
| Not visible to members | Revenue proof documents, uploaded verification documents, payment records, internal admin notes, audit logs, passwords, security data, detailed bank statement documents, and non-public application review material. |
| Admin-only export | Full profile data download is restricted to authorized admins/super admins and should be used only for operational and compliance purposes. |
Where platform settings allow, you may be able to control or update
certain visible fields in your profile. However, some basic profile data
may be necessary for the directory and matching features to work
properly.
8. Documents and Revenue Proof
Documents uploaded for revenue or eligibility verification are treated
as confidential review materials. They are used only for application
review, due diligence, audit, dispute handling, or legal compliance.
They are not shown in the member directory and are accessible only to
authorized administrators or service providers who need access for
operational reasons.
9. WhatsApp, Email, and Notifications
If you provide consent, we may add you to the official Y&A 10X WhatsApp
group or send WhatsApp communications related to membership, payments,
renewals, events, reminders, and community updates. You may leave the
WhatsApp group or contact us to opt out of non-essential WhatsApp
updates. Transactional and service messages may still be sent where
needed to operate your membership or event registration.
10. Cookies and Similar Technologies
We use cookies, pixels, tags, local storage, and similar technologies
for login sessions, security, preferences, analytics, performance, and
marketing measurement. Please see our Cookies Policy for details.
11. How We Share Personal Data
We do not sell member personal data. We may share data only as needed
for the following purposes:
- with hosting, cloud, database, security, analytics, email, WhatsApp/SMS, support, CRM, CMS, and payment gateway service providers;
- with payment processors for transaction processing and payment status confirmation;
- with event venues, hosts, co-hosts, sponsors, or partners only where needed for event administration or where you consent;
- with active members through the member directory and matching features, as described above;
- with advisors, auditors, accountants, lawyers, insurers, and compliance consultants under confidentiality obligations;
- with authorities, courts, regulators, or law enforcement where legally required or necessary to protect rights and safety;
- in a business transfer, restructuring, merger, acquisition, or similar transaction, subject to appropriate safeguards.
12. Data Retention
| Topic | Details |
|---|---|
| Account and profile data | Retained while your account is active and for a reasonable period after closure for legal, operational, and dispute purposes. |
| Application and review records | Retained for due diligence, audit, dispute, and membership history purposes. |
| Revenue proof documents | Retained only as long as necessary for review, audit, dispute, compliance, or legal requirements. The final period should be confirmed by legal and accounting advisors. |
| Payment and invoice records | Retained as required for tax, accounting, audit, and compliance. |
| Event records | Retained for event administration, attendance history, receipts, photos/videos, and community records. |
| Logs and security records | Retained for security, fraud prevention, investigation, and audit purposes. |
13. Data Security
We aim to use reasonable technical and organizational measures including
access controls, password hashing, secure API access, encryption where
appropriate, role-based permissions, audit logs, rate limiting, and
security monitoring. No internet-based service can be guaranteed to be
fully secure. You are responsible for keeping your login credentials
confidential.
14. Your Rights
Subject to applicable law and verification, you may request to:
- access a summary of your personal data processed by us;
- correct, update, or complete inaccurate personal data;
- delete or erase personal data where applicable and legally permissible;
- withdraw consent for consent-based processing;
- opt out of non-essential marketing or community communications;
- raise a grievance regarding processing of your personal data;
- nominate another individual to exercise your rights in the event of death or incapacity where applicable law provides this right.
To exercise your rights, contact: ⚠ TODO: Grievance Officer name and email. We may need to verify your identity before acting on a request.
15. Children
Y&A 10X Club is designed for founders, business owners, and
professionals who are at least 18 years old. We do not knowingly collect
personal data from children.
16. Cross-Border Processing
Our service providers may store or process data in India or other
countries depending on their infrastructure. Where cross-border
processing applies, we will seek to use appropriate safeguards and
comply with applicable law.
17. Changes to This Policy
We may update this Policy from time to time. The updated version will be
posted on the website with a revised effective date. Material changes
may also be communicated through email, platform notification, or other
reasonable means.
18. Contact
| Topic | Details |
|---|---|
| Operator | ⚠ TODO: legal entity name operating Y&A 10X Club |
| Address | ⚠ TODO: registered office address |
| Support / Legal Email | ⚠ TODO: official support/legal email |
| Grievance Officer / Privacy Contact | ⚠ TODO: Grievance Officer name and email |