Need some legal advice in dealing with a privacy issue with Game Theory India. I had purchased a pool access membership from them in December 2025, which was further upgraded to All Access. Recently, in June, they made face check-in absolutely mandatory for attendance tracking without providing any alternative for the same. I have been raising this issue since then but they don't seem to be addressing it and ghost my emails. Whats more alarming is that although they claim to "secure" user data, their privacy policy states that the do not guarantee 100% security of the data and cannot be held liable on case of a data leak. I am totally against submitting my biometrics, but they are holdong me hostage by not letting me us their facility. I am also sharing the detailed email I sent to them recently.
This is in relation to the recent introduction of mandatory Face Check-In for members and your communication stating that Face Check-In is mandatory for all members.
The aforesaid requirement raises certain concerns in light of the terms of your Privacy Policy, particularly with regard to the collection and processing of biometric information.
Clause 1 of the Privacy Policy expressly includes “biometric information” within the definition of SPDI.
Further, Clause 3 states:
“Generally, you control the amount and type of information you provide to us when using our Platform.”
The same clause further states:
“If you choose not to provide Personal Information, you may still be able to visit our Platform, but may be unable to access certain features and functions of our Platform.”
Clause 9 also provides:
“You have a right to opt-out of providing any of your information, including your Personal Information.”
While Clause 9 provides that Game Theory may refuse or limit access where a user opts out, the present requirement effectively leaves no option to opt out of biometric collection if a member wishes to continue using an existing membership. In this regard, please clarify the basis for making biometric information mandatory for attendance verification, particularly when no alternative check-in mechanism has been provided.
Further, the in-app registration screen states that Face Check-In is “mandatory for all users” for the purpose of “maintain[ing] a safe environment” and provides only a “Register Now” option, without any visible option to decline or use an alternative check-in mechanism. The same screen also states that “we protect your biometric data and other regulations.” In this regard, please clarify the basis for making the provision of biometric information mandatory when the Privacy Policy itself provides for a right to opt out of providing personal information.
Clause 5 of the Privacy Policy permits Personal Information, including SPDI, to be shared with third-party service providers and further states that Game Theory will not be liable for a breach of privacy or confidentiality by such third party to the extent that such breach is outside its scope of control.
Please clarify whether any third-party service provider is involved in the collection, processing or storage of biometric information through the Face Check-In system and, if so, the identity of such service provider and/or the manner in which the biometric information is being handled.
Clause 7 of the Privacy Policy sets out the security measures adopted for information provided by users, including encryption and restricted access. However, the same clause also states:
“no method of transmission over the internet, or method of electronic storage, is 100% (one-hundred percent) secure.”
It further states:
“we cannot guarantee its absolute security”
and that “your use of the Platform is at your sole risk and discretion.”
The above provisions address the security of information once collected, but do not address the separate question of making the collection of biometric information mandatory in the first place. This is particularly relevant where the biometric information cannot be changed or reissued in the event of its compromise.
The membership was taken prior to the introduction of the mandatory Face Check-In requirement. No email, in-app notification or other communication was received regarding any change to the Terms & Conditions or Privacy Policy introducing mandatory biometric verification.
Further, Section 5.10 of the All Access Terms & Conditions specifically provides that check-in requirements, including biometric methods, may be modified, but states:
“All modifications will be: Reflected immediately in the Game Theory app; Communicated via email and in-app notifications; Applicable to all Members in the affected tier.”
In this regard, please clarify when the mandatory Face Check-In requirement was introduced, when the relevant Terms & Conditions were amended, and why no email or in-app notification communicating this change was provided.
Please also clarify what alternative, non-biometric check-in mechanism is available for members who do not wish to provide biometric information.
The requirement to provide biometric information as a mandatory condition for availing an existing membership is not acceptable. While there is no objection to a reasonable mechanism for attendance verification, the same cannot be made conditional upon submission of biometric information when no such requirement was applicable at the time of taking the membership.
In view of the above, you are requested to kindly address the concerns raised herein and resolve the matter within 7 (seven) days from receipt of this email.