This policy explains what data we collect when you use gymtech, why, who can access it and how we protect it. We keep it plain because a gym trusts us with its members' data.
Who we are
gymtech is a platform for running gyms from a phone, operated by [Company legal name], [Address] (“we”). It consists of the gym's phone app, the server that stores and syncs the data, and an admin panel used by our team.
What we collect
- The gym, its owner and staff: the gym's name, each user's name and phone number, and passwords stored hashed, never as text.
- Member data the gym enters: name, phone, date of birth, gender, notes, check-ins, subscriptions and payments.
- Member photos stay on the gym's phone only and are not uploaded to our servers.
- Device data needed for sync: a device identifier, and the time and author of each action.
- Logs of messages sent in the gym's name (cards, reminders, receipts): to whom, when, and their status.
Why we use it
We use data only to run the service, and we never sell it:
- Running the app and the server, and syncing the gym's actions across its devices.
- Sending cards, reminders and receipts to the gym's members on WhatsApp or SMS, at the gym's request and according to its settings and plan.
- Billing the gym's platform subscription.
- Support, when the gym asks for it.
Who can access it
- The gym itself: the owner and staff, each within their role's permissions.
- Authorised gymtech staff, through an admin panel that records every action in an audit log.
- The messaging provider (WhatsApp or SMS), only as far as needed to deliver a message.
- The hosting provider our servers run on.
We do not sell, rent or use the data for advertising.
The gym's responsibility for its members
The gym controls its members' data: it decides what is entered and what is sent, and we process it on the gym's behalf to run the service. The gym should tell its members that it uses gymtech to manage their subscriptions and check-ins, and that it may message them on WhatsApp or SMS.
Retention and backups
- We keep a gym's data while its account exists.
- We take an encrypted backup every day; older backups are deleted automatically.
- A local copy stays on the gym's phone so the app works offline; it is deleted on sign-out.
- When an account is closed we delete the gym's data within [30 days], after offering the owner an export.
Security
- All traffic between the app and the server is encrypted over HTTPS.
- Passwords are stored hashed and cannot be read by anyone.
- Each gym's data is isolated: no gym can see another gym's data.
Your rights
A gym owner can ask us to access, correct, export or delete their data by contacting us. A gym member should ask their gym first, since the gym manages their data.
Contact
For any privacy question, message us on WhatsApp: +963958263253.
Changes to this policy
We may update this policy. The new version is published on this page with its effective date, and the gym owner is told about any significant change.