This Privacy Policy explains how Gymnast ("Gymnast," "the App," "we," "us," or "our") collects, uses, discloses, and protects information when a gym, studio, or fitness business (a "Gym") and its owners, managers, trainers, receptionists, and members (collectively, "Users," "you") use the Gymnast mobile and web application and related services (the "Service").
Gymnast is a multi-tenant gym-management platform. A Gym signs up as a customer and invites staff and members to use the same App under that Gym’s own private workspace. Because of this structure, some information is provided directly by you, and other information is provided about you by the Gym you belong to — for example, when a receptionist creates your member profile. Section 3 explains these roles in more detail.
By creating an account, being added to a Gym as a staff member or member, or otherwise using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service.
Gymnast is developed and operated by an independent developer. For any question, request, or complaint about this Policy or your personal data, contact:
Email: debajyotiupadhayaya@gmail.com
We aim to respond to all privacy-related requests within 30 days, or sooner where local law requires a shorter period.
To understand who controls your data, it helps to know the roles the App supports:
• Super Admin — platform-level administrator (us) with the technical access needed to operate and support the Service.
• Gym Owner — the individual or business that creates a Gym workspace, subscribes to a plan, and is the primary customer.
• Manager, Trainer, Reception — staff accounts the Gym Owner invites, with day-to-day operational access scoped by role.
• Member — an individual enrolled at a Gym. A Member’s profile is usually created by Gym staff, though a Member may also self-register or link their own login to that profile.
For information Gym staff enter about Members (for example, contact details, health notes, or payments recorded in person), the Gym acts as the data controller and we act as its data processor / service provider — we process that data only to provide the Service, on the Gym’s instructions. For account-level information tied to your own login (your email, password, device tokens, app usage) and for our own business operations, we act as the data controller. If you are a Member with questions about data a Gym holds about you, we encourage you to contact that Gym directly, as well as us.
We collect the following categories of information:
When anyone creates a login (Gym Owner, staff, or Member), we collect: name, email address, phone number (for phone/OTP sign-in), and a password, which is stored in hashed form by Firebase Authentication — we never see or store plain-text passwords. We also collect your profile photo and Google account identifiers if you sign in with Google, and we record your role, account status, account creation date, and last login date.
Gym staff can create and maintain profiles for each Member, which may include: full name, email, phone number, profile photo, date of birth, gender, home address, membership plan, membership status and dates, payment totals and outstanding balance, assigned trainer, loyalty/rewards points, and an emergency contact’s name and phone number.
The Service lets Gym staff and trainers record health-related details to support safe training, including: injury or medical condition notes ("health notes"); body measurements such as weight, body-fat percentage, and chest/waist/arm measurements; workout logs, training milestones, and challenge or gamification activity; and personalized nutrition or diet plans (meals, food items, calorie targets) assigned by a trainer. This information is treated as sensitive and is visible only to the Member it belongs to and to Gym staff with a legitimate reason to see it, such as their assigned trainer. Because this data is entered by Gym staff about a Member, the Gym is responsible for obtaining any consent required by law before recording it, and we process it strictly on the Gym’s behalf.
For Gym employees, the Gym Owner or Manager may record: name, email, phone number, role, specialization (for example, "Yoga" or "Weight Training"), profile photo, employment status, join date, and salary. Salary and other employment details are visible only to authorized roles within that Gym (typically Owner/Manager) and are never used by us beyond what is necessary to operate the database.
Gyms can track prospective members (“leads”) they are trying to convert into Members, including: name, phone, email, how the lead was sourced (for example, walk-in, referral, Instagram, WhatsApp, or a QR poster), fitness goals, budget, preferred training time, follow-up notes, and which staff member is assigned to them.
When a payment is recorded in person (cash or cheque) by Gym staff, we store the amount, method, status, description, date, receipt number, and which staff member collected it — but not payment-card details. When a payment is made online (for example, a Member paying for a “Go” subscription, or a Gym Owner paying their subscription), the transaction is processed by Razorpay, a third-party, RBI-authorized payment gateway. Razorpay collects your card, UPI, or net-banking details directly — we do not receive or store your full card number, CVV, or bank credentials. We receive only a transaction/order ID and a cryptographically signed confirmation that the payment succeeded.
With your permission, the App uses your device’s GPS location for gym self-check-in: when you scan a Gym’s check-in poster, we briefly check that your device is within a distance the Gym Owner has configured (25 m to 5 km) of the check-in spot, to confirm you are actually at the Gym. A Gym Owner’s device also records a location when they set up a check-in poster. We do not track or store a continuous location history — only the location reading needed at the moment of a check-in or poster setup. You can decline location permission; check-in will then rely on the QR code alone, if the Gym allows it.
The App requests camera access to scan check-in QR codes, and photo-library or camera access to let you set a profile photo for yourself, a Member, or a staff record. We do not access your camera or photos other than when you actively choose to scan a code or select or take a picture.
We automatically collect limited technical information via Firebase, including app usage events and screens viewed (Firebase Analytics), crash reports and stack traces (Firebase Crashlytics), and push-notification delivery tokens (Firebase Cloud Messaging) and app-install identifiers, so that we can send you notifications — such as membership-expiry reminders — and diagnose problems.
Gym Owners can bulk-import Member records from a spreadsheet (Excel/CSV) and export Member lists, payment records, and reports as CSV, Excel, or PDF files. Files you import or export are processed on your device and are used only to create or export your Gym’s own records — we do not use imported files for any other purpose.
A Gym Owner may choose to publish a public profile (for example, gym name, description, address, and photos) so prospective Members can find the Gym and request to join. Information in a public profile is, by definition, visible to anyone browsing gym listings in the App.
We use the information described above to:
• Provide, operate, and maintain the Service — accounts, check-in, scheduling, billing, and messaging;
• Let Gyms manage their Members, staff, leads, and payments;
• Verify identity and secure accounts, including fraud and abuse prevention;
• Process payments and reconcile subscriptions;
• Send transactional and reminder notifications — for example, membership expiring, payment due, or class reminders;
• Provide customer support;
• Monitor, debug, and improve the Service through crash reports and usage analytics;
• Enforce our terms and comply with legal obligations; and
• Where a Gym enables loyalty, referral, or gamification features, calculate and display points, badges, and leaderboards.
We do not sell your personal information, and we do not use Member health, fitness, or nutrition data for advertising. We also do not use automated decision-making or profiling that produces legal or similarly significant effects on you — features like points, badges, and leaderboards are informational only and do not gate access to the Service.
If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases:
• Performance of a contract — providing the Service you or your Gym signed up for;
• Legitimate interests — securing the Service, preventing fraud, and improving features, balanced against your rights and freedoms;
• Consent — for example, where a Gym or Member opts in to record sensitive health information, or for optional marketing; and
• Legal obligation — for example, financial record-keeping.
We share information only as follows:
• Within your Gym: Member data is visible to the staff roles at that Gym who need it to do their job — for example, a receptionist sees contact and payment info, while a trainer sees their assigned Members’ health notes and workouts. Tenant isolation in our database ensures one Gym cannot see another Gym’s data.
• Service providers (subprocessors): We use Google Firebase (Authentication, Firestore database, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, and App Check) to run the Service, and Razorpay to process online payments. These providers process data on our behalf under their own security and confidentiality commitments.
• Google Sign-In: If you choose to sign in with Google, Google acts as an identity provider and shares your name, email, and profile photo with us, per your Google account settings.
• Legal reasons: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Gymnast, our users, or others.
• Business transfers: If we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction; we will notify affected users.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
We retain personal information for as long as your account or your Gym’s account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations, resolve disputes, and enforce agreements. A Gym Owner can delete individual Member, staff, or lead records at any time through the App; deleting a Gym’s account removes that Gym’s workspace data, subject to any backups retained for a limited period for disaster-recovery purposes and any records we must legally retain, such as payment or tax records.
We apply several layers of protection:
• Role-based access control so each user can only see the data their role permits — for example, a trainer cannot see another trainer’s salary;
• Per-Gym data isolation (“tenant” separation) in our Firestore database, enforced by server-side security rules;
• Encryption in transit (HTTPS/TLS) for all data sent to and from the App;
• Firebase App Check to help ensure requests come from our genuine app; and
• Signature verification (HMAC) for payment confirmations, so payment status cannot be spoofed.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Depending on where you live, you may have some or all of the following rights regarding your personal information:
• Access a copy of the data we, or your Gym via us, hold about you;
• Correct inaccurate or incomplete data;
• Delete your data, subject to legal retention requirements;
• Restrict or object to certain processing;
• Receive your data in a portable format; and
• Withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us at debajyotiupadhayaya@gmail.com. If your data was entered by a Gym (for example, you are a Member), we recommend also contacting that Gym directly, since they control what information is recorded about you; we will assist the Gym in fulfilling your request.
In addition to the rights above, EEA/UK residents have the right to lodge a complaint with their local data protection supervisory authority.
California residents have the right to know what personal information we collect, use, and disclose; to request deletion; to correct inaccurate information; and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as defined by the CCPA/CPRA. You will not be discriminated against for exercising these rights.
If you are located in India, you have the right to access a summary of your personal data and the processing activities we carry out; request correction, completion, updating, or erasure of your personal data; nominate another individual to exercise your rights in the event of death or incapacity; and file a complaint with us and, if unresolved, with the Data Protection Board of India. Our Grievance Officer / privacy contact can be reached at debajyotiupadhayaya@gmail.com.
Our service providers (Google Firebase and Razorpay) may process and store data in data centers located outside your home country, including in the United States and other regions where Google operates infrastructure. Where required, we and our providers rely on appropriate safeguards, such as standard contractual clauses, for international transfers.
Gymnast is intended for use by adults. Gym Owners, Managers, Trainers, and Reception staff must be adults. Many gyms, however, enroll members under the age of 18. Where a Gym enrolls a minor as a Member, the Gym — not us — is responsible for obtaining verifiable consent from the minor’s parent or legal guardian before entering the minor’s personal data into the App, as required by applicable law, including India’s Digital Personal Data Protection Act, 2023, which defines a "child" as anyone under 18.
We do not knowingly allow anyone under 18 to independently create their own Gymnast login without a Gym or guardian's involvement, and we do not use a child’s data for targeted advertising or behavioral tracking — indeed, the App shows no advertising at all. If you are a parent or guardian and believe your child has provided us personal data inappropriately, contact us at debajyotiupadhayaya@gmail.com and we will work with the relevant Gym to address it.
The web version of Gymnast uses essential cookies and local storage required to keep you logged in and to let the app function, and Firebase Analytics may use similar technologies to understand feature usage in aggregate. We do not use third-party advertising cookies.
The App may let staff open links to external services — for example, opening WhatsApp to message a lead, or a payment provider’s page. Those third parties have their own privacy policies, and we are not responsible for their practices.
We may update this Privacy Policy from time to time to reflect changes in the Service or applicable law. We will update the "Last updated" date above and, for material changes, provide reasonable notice within the App.
Questions, requests, or complaints about this Policy or your data can be sent to:
Email: debajyotiupadhayaya@gmail.com