Privacy Policy

What we collect, why we collect it, and who else sees it. A gym owner handing us their members' details is entitled to a straight answer to all three.

In effect from 28 September 2026.

1.Who is responsible for what

There are two kinds of data here and they are not governed the same way, so it is worth separating them at the top.

Your account. Your name, email, phone and gym details, and what you do in the app. We decide what is collected and why — we are the controller, and this policy covers it.

Your members’ records. Their names, contact details, memberships, payments and attendance. You decide what to collect and why; we hold it on your instructions and do nothing else with it. You are the controller, we are the processor. Your own privacy notice is what governs it, not this one.

2.What we collect

From gym owners and staff: name, email address, phone number, a hashed password, the gym’s name, city, contact details and branding, and the plan you bought. We record when you last signed in.

From members, entered by their gym: name, member code, and optionally email, phone, date of birth and gender. Attendance is recorded when they scan the gym’s code or the desk checks them in. Memberships, prices and payments the gym records are stored against them.

Automatically: the ordinary technical data any web service sees — request logs and error reports produced by our host. We do not run advertising trackers, we do not use third-party analytics, and we do not build profiles for marketing.

We never see card details. Payment is handled by our provider as merchant of record; card numbers go to them and never touch our servers or our database.

3.Why we hold it

To run the product you are paying for: to sign you in, to show a gym its own members, to record attendance and money, to work out who is due to renew, and to put a listed gym on the public directory. To take payment and keep a record of it, which we are also required to do for tax. To reply when you contact support. To keep the service secure and to investigate misuse.

Our basis is the contract between us for your account, our legitimate interest in keeping the service working and secure, and legal obligation for financial records. For member records, your gym’s basis applies, not ours.

4.What is public, and what is not

A listed gym’s profile is deliberately public: its name, city, coordinates, opening hours, the links it chose to publish and — only where the gym has switched it on — its prices. That is the point of the directory.

No member is ever public. No member name, contact detail, attendance record or payment appears on the directory, on a gym’s public page, or anywhere reachable without signing in.

5.Who else sees it

Only the providers we need to run the service. Each is named here rather than hidden behind “service providers”, because a list you cannot read is not disclosure.

  • Vercel

    Hosting and delivery of the application

    United States and global edge network

  • Neon

    The PostgreSQL database that stores everything in the product

    United States

  • Dodo Payments

    Taking subscription payments as merchant of record. They receive the buyer's payment and billing details directly — those never reach our servers.

    Global

  • OpenStreetMap (Nominatim)

    Turning a typed city into map coordinates when our offline table does not know it. Only the city text is sent — never a name, a number or an account.

    European Union

We do not sell personal data, and we do not share it for anyone else’s marketing. We would disclose data if the law required it, and would tell you unless forbidden from doing so.

These providers are outside India, so running the service involves transferring data internationally. We rely on each provider’s own safeguards for that.

6.How long we keep it

Account and gym data is stored to provide the service. Archiving a gym suspends access and hides its public listing; it does not erase its records. Contact us to request deletion or anonymisation. We will explain what can be removed and any records that must be retained.

Member and payment history may need to remain available to the gym after a membership ends. Removing access to an account is separate from deleting its history. Please contact your gym about member data requests, or contact us for help coordinating the request.

7.How it is protected

Passwords are stored hashed with bcrypt and are never recoverable in plain text — not by us either. Sessions ride in a signed, http-only cookie. Every query for gym data is scoped to the gym that owns it on the server, and that boundary is covered by an automated test suite that runs before anything ships. Traffic is encrypted in transit.

No system is perfectly safe. If a breach affects your data we will tell you and the relevant authority within the time the law requires, and we will tell you what actually happened rather than the least alarming version of it.

8.Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to support@beongym.com and we will respond within 30 days.

If you are a gym member, ask your gym first. They hold your record and they control it; we cannot hand over or delete it without their instruction. Tell us and we will point you to them and help them act.

9.Children

BeOnGym is sold to gyms, not to individuals, and we do not knowingly collect data directly from children. A gym may have members under 18, and it is the gym’s responsibility to have the consent that requires where they operate.

10.Changes, and reaching us

If this policy changes in substance we will update the date at the top and, where the change matters, tell you in the app or by email. Questions go to support@beongym.com, or see the contact page.