Back to GymProTrust & Legal

Privacy Policy

This policy explains the information GymPro processes to provide its website and connected gym-management service.

Last updated:

Scope of this policy

This policy explains how GymPro handles information through the website and GymPro application. It applies to prospective customers, gym owners, authorized staff and people who contact GymPro. A gym using GymPro remains responsible for the member and staff information it enters and for giving any notices or obtaining any permissions required for its own operations.

Information provided by gym owners and staff

GymPro may process information supplied when an owner creates or activates an account and when authorized users operate the service, including:

  • Name, email address, phone number and account role.
  • Gym name, contact information and business address details.
  • Configuration, receipt and membership settings.
  • Actions taken through authorized product workflows.

Member data processed on behalf of gyms

Gym owners may store member names, phone numbers, photos, member numbers, plan assignments, membership dates, status, optional service selections and related operational notes. GymPro processes this information to provide the service to the relevant gym. Gym owners must collect and use member information lawfully.

Authentication and account information

Firebase Authentication is used for account sign-in, email verification and account-security workflows. GymPro receives account identifiers and authentication state needed to protect the service. Password credentials are handled by Firebase Authentication; GymPro application records do not store plaintext passwords.

Membership and plan information

The service stores plan details, membership dates, renewals, joining or reactivation settings, service selections and membership status so the gym can administer access and dues.

Attendance information

GymPro processes check-in records, attendance dates, attendance method and related member references. Depending on the gym’s configuration, attendance may be recorded manually, through a fixed QR flow or through a configured biometric-device integration. GymPro does not claim that every attendance method is enabled for every gym.

Lead and enquiry information

Enquiry records may include a prospect’s name, phone number, goal, interest status, follow-up date and conversation notes. Gyms use this information to follow up with prospects and, when appropriate, convert an enquiry into a member record.

Staff information

The service may process trainer or authorized-user names, phone numbers, status, role, compensation settings, personal-training assignments and access-related records needed for supported staff workflows.

Payment and transaction references

GymPro stores operational payment and expense records entered by a gym, such as amount, payment method, date, receipt reference, category and adjustment history. The current public website does not provide self-service subscription checkout, and the repository does not contain a public card-processing integration. GymPro should not be used to store full card numbers, banking passwords or payment credentials in free-text fields.

Contact and support communications

When you email GymPro, we receive the address, message and attachments you choose to send. We use that information to understand and respond to the request, maintain appropriate support or security records, and protect the service. Do not send passwords, access tokens or unnecessary member information.

Technical and usage data

GymPro may process device, browser, platform, session, release, error, operation and diagnostic information needed to authenticate users, prevent conflicting sessions, troubleshoot failures and operate the service. No third-party advertising analytics SDK or independent behavioral analytics integration was identified in the current application repository.

Cookies, local state and analytics

Authentication and application functionality may use browser storage or similar technologies to maintain secure session and interface state. The progressive web application may use a service worker for application delivery. GymPro does not currently describe an advertising-cookie program because none is implemented in the reviewed code. This policy will be updated before materially different analytics or advertising technologies are introduced.

Purposes for processing

Information is processed to:

  • Provide, secure and maintain GymPro.
  • Authenticate users and enforce gym-scoped access.
  • Run the member, attendance, enquiry, staff and financial-record workflows requested by a gym.
  • Generate receipts, reports and supported exports.
  • Investigate errors, abuse and security reports.
  • Communicate about access, support, privacy, security and billing questions.
  • Meet applicable contractual and legal obligations.

Service providers and subprocessors

The reviewed product uses Google Firebase services, including Firebase Authentication, Cloud Firestore, Cloud Functions and Cloud Storage, to provide authentication, database, server-side and file-storage functions. These providers may process information for GymPro under their applicable service terms.

No separate third-party advertising-analytics, AI-processing, email-delivery, error-monitoring or public payment-gateway integration was identified in the current application code. GymPro will update this policy before relying on additional processors in ways that materially affect personal information.

Data retention

GymPro retains information while it is needed to provide the service and for appropriate operational, contractual, security, recovery and legal purposes. A single fixed retention period has not been published because retention depends on the record type, the gym’s account status, technical safeguards and applicable obligations. Retention rules will be refined as commercial and legal requirements are confirmed.

Data security

GymPro uses safeguards appropriate to its current stage, including Firebase Authentication, Firestore and Storage rules, tenant-scoped records, trusted server-side authorization for sensitive commands, input validation and controlled secret configuration. No internet service can guarantee absolute security.

Data access, correction and deletion requests

Gym owners should first handle requests relating to member data they control. Account holders and other requesters may contact founder@gympro.in for assistance with access, correction or deletion. GymPro may need to verify identity, authority and the relevant gym before acting. Some information may be retained where reasonably required for security, dispute handling, recovery or legal obligations.

Children’s information

GymPro owner accounts are intended for adults acting for a fitness business. The service is not directed to children creating owner accounts. A gym may hold information about younger members where lawful and appropriate; the gym is responsible for obtaining any required parent or guardian permission and using that information responsibly.

International processing

Cloud service providers may process information in locations where they or their infrastructure operate. GymPro does not publish a fixed data-residency commitment at this stage. Where international processing applies, it is subject to the provider’s safeguards and applicable legal requirements.

Changes to this policy

GymPro may update this policy when the product, providers or legal requirements change. The “Last updated” date identifies the current published version. Material changes will be communicated through an appropriate channel when required.

Contact information

Privacy questions and requests may be sent to founder@gympro.in. The official website is https://gympro.in.