Privacy Policy
This policy explains what Zenstu does with personal data: yours if you are a yoga teacher or studio using our software, and your students' if you store their details on our platform.
1. Who we are
Zenstu is a software platform operated by iGenius Global. In this policy, "Zenstu", "we" and "us" mean that company. "You" means whoever is reading it: a teacher, a studio, or a student of one of them.
You can reach us at support@zenstu.com.
2. Two different roles we play
This distinction matters, so it comes early.
For teachers and studios, we are the Data Fiduciary. When you sign up, we decide what we collect and why, and we are answerable to you for it under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
For students, we are usually a Data Processor. When a teacher adds a student's name, phone number or health notes to Zenstu, the teacher decides what to collect and why. We only store and process it on the teacher's instructions. The teacher is the Data Fiduciary for that information and is responsible for having a lawful basis to collect it.
There is one exception. When a student creates their own login, pays a fee, or sends an enquiry through a teacher's website, we also handle some of that data for our own purposes, such as running payments securely and preventing fraud. For those limited purposes we are a Data Fiduciary too.
3. What we collect
From teachers and studios
- Account details: name, brand or studio name, mobile number, email address, city, password (stored only as a cryptographic hash, never in readable form).
- Profile and website content: your biography, photographs, logo, certificates you upload, class descriptions, prices and timings, and anything else you choose to publish on your Zenstu website. Anything you publish is public by design.
- Business details for payouts: bank account details, PAN, GSTIN where provided, and KYC documents. These are collected and verified by our payment partner; we see only limited confirmation data.
- Billing records: plan, invoices, payment status, GST details. We do not store your card number, CVV or UPI PIN at any point.
- Usage data: log-in times, pages used, device and browser type, IP address, error logs.
- Support messages you send us by email, WhatsApp or phone.
From students
- Entered by their teacher: name, mobile number, email, class enrolled in, fee amount, payment and attendance records, and any notes the teacher adds, which may include health information such as injuries or pregnancy.
- Entered by the student: enquiry form submissions, profile details, and payment records if they pay online.
- Automatically: basic usage and device data when they visit a teacher's Zenstu website or student portal.
If you sign in with Google
When you choose "Continue with Google", Google shares your name, email address and profile photo with us (through the basic sign-in / profile and email scopes) so we can create and log you into your Zenstu account. We do not request, and cannot access, your Gmail, Google Drive, Calendar or any other Google service. This information is used only to run your account as described in this policy; it is never sold, used for advertising, or used to train AI models, and we only share it as described in section 5.
4. Why we use it
| What we do | Why |
|---|---|
| Create and run your account | To provide the service you signed up for |
| Build and host your website | Core function of the product |
| Send OTPs and log you in | Security and account access |
| Send fee reminders and receipts to students | On the teacher's instruction, as part of the service |
| Process subscription payments and student fees | To perform our contract with you and meet legal and tax obligations |
| Provide support | To answer your questions and fix faults |
| Detect fraud and abuse, keep logs | Security, and legal obligations including retention requirements |
| Improve the product using aggregated statistics | Product development, using data that does not identify anyone |
| Send service announcements | To tell you about changes that affect your account |
| Send marketing emails | Only with your consent, and you can withdraw it at any time |
We do not sell personal data. We do not show third-party advertising in Zenstu, and we do not share your students' details with other teachers or with anyone for marketing.
5. Who we share it with
We share data only with service providers who help us run Zenstu, and only as much as they need. These include providers who help us with payments, hosting and databases, messaging, email delivery, and analytics and error tracking.
We also disclose data where the law requires it, such as a valid order from a court, tax authority or law enforcement agency. If Zenstu is ever sold or merged, account data may transfer to the buyer, who would remain bound by this policy or give you notice of any change.
6. Where it is stored
Personal data is stored on servers located in India. Some of our providers may process limited data outside India. Where that happens, we transfer data only to countries not restricted by the Central Government under the DPDP Act, and we require the provider to protect it to a comparable standard.
7. How long we keep it
- While your account is active, we keep your data so the service works.
- After you cancel, your account is paused, not deleted. You can export your data or reactivate for 90 days. After that we delete or irreversibly anonymise it, except where we must keep it.
- Invoices, payment records and tax documents are kept for 8 years, as required by Indian tax law.
- Security and access logs are kept for at least one year, in line with the DPDP Rules.
- Student data is deleted when the teacher deletes it, or when the teacher's account is deleted, whichever is earlier.
8. Your rights
Under the DPDP Act you may:
- Access a summary of the personal data we hold about you and who we have shared it with.
- Correct anything inaccurate, incomplete or out of date.
- Erase your data where we no longer need it and no law requires us to keep it.
- Withdraw consent at any time, as easily as you gave it. Withdrawing consent does not undo what we did lawfully beforehand.
- Nominate another person to exercise these rights if you die or become incapacitated.
- Complain to us, and then to the Data Protection Board of India if you are not satisfied.
Most of this you can do yourself inside Zenstu, under Account. Otherwise write to our Grievance Officer (section 14). We will acknowledge within 3 working days and resolve within 30 days, and in any case within the maximum period the DPDP Rules allow.
If you are a student, the data about you mostly belongs to your teacher's records. Ask your teacher first. If they cannot help, or you cannot reach them, write to us and we will assist.
9. Students' data and teachers' duties
If you are a teacher using Zenstu, you are responsible for the student data you put into it. By using Zenstu you confirm that:
- You have told your students what you collect and why, and have their consent where the law requires it.
- You collect only what you need. Health notes should be limited to what affects safe teaching.
- You will not upload data you have no right to hold, and will not use Zenstu to send messages students have not agreed to receive.
- You will pass on any request from a student to access, correct or delete their data, and act on it.
- You will tell us promptly if you become aware of any unauthorised access to your account.
We act on your instructions for this data. We will help you meet a student's request, but we cannot decide on your behalf whether to grant it.
10. Children
Zenstu accounts are for people aged 18 and over. We do not knowingly let a child open a teacher or studio account.
Teachers do sometimes teach children. If a student is under 18, the teacher must obtain verifiable consent from a parent or legal guardian before entering that child's details into Zenstu, and must not use Zenstu to track that child behaviourally or to target advertising at them. If we learn that a child's data has been collected without proper consent, we will delete it.
11. Security
We take reasonable security safeguards, including: encryption in transit (HTTPS) and at rest, passwords stored only as hashes, one-time passwords for login, database-level separation so one teacher can never see another's data, restricted internal access on a need-to-know basis, access logging, and regular backups.
No system is perfectly secure. Choose a password you do not use elsewhere, do not share OTPs with anyone, and tell us at once if you think your account has been accessed by someone else.
12. Data breaches
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person without delay, in the manner and within the timelines required by the DPDP Rules. Our notice will describe what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.
13. Cookies
We use cookies and similar storage for a small number of things:
- Essential: keeping you logged in and keeping the site secure. These cannot be switched off.
- Preferences: remembering settings such as which studio you last opened.
- Analytics: understanding which features are used, so we can improve them.
Teacher websites built on Zenstu may load analytics that the teacher has added themselves, such as Google Analytics or Meta Pixel. Those are the teacher's responsibility, and their own privacy notice should cover them.
14. Grievance Officer
For any question or complaint about your data, contact:
Zenstu Support Team, Grievance Officer
support@zenstu.com
We acknowledge complaints within 3 working days and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
15. Changes to this policy
If we change this policy in a way that materially affects you, we will email you and show a notice inside Zenstu at least 15 days before it takes effect. Smaller corrections will simply be published here with a new "last updated" date. Previous versions are available on request.
© 2026 Zenstu. zenstu.com
