1. Who We Are
GymCRM ("we", "us", "our") is a gym management software platform built for Indian gym owners and fitness businesses, operated by Shashank Kumar. We operate at gymcrm.in.
This Privacy Policy explains how we collect, use, store, and share information when you use our platform — whether you are a gym owner, a staff member, or a gym member accessing the member portal.
Questions? Email us at shashanksingh67567@gmail.com or reach us on WhatsApp at +91 75410 04076.
2. Two Roles: Controller and Processor
For gym owners and staff — GymCRM is the Data Fiduciary (Controller). We decide how your account information (name, email, phone, billing details) is processed.
For gym members — GymCRM is the Data Processor acting on behalf of the gym (the Data Fiduciary). The gym is responsible for the lawful basis on which it collects and holds member data. We only process member data as instructed by the gym.
3. Data We Collect
Gym owners and staff
- Name, email address, and phone number
- Gym name, address, and business details
- Subscription and billing information (processed via Razorpay or Dodo Payments)
- Payment method details (we do not store card numbers — payment processors handle these)
- Login activity and session information
Gym members (collected by the gym, processed by GymCRM)
- Name, email address, and phone number
- Gender (if provided by the gym)
- Profile photo (if uploaded by the gym or member)
- Membership plan, start/end dates, and renewal history
- Payment and invoice records
- Attendance and check-in history
- Class bookings and enrollments
- Workout plans assigned by the gym
- Notes added by gym staff (free-text notes about the member)
- Documents uploaded by the gym (waivers, ID copies, medical forms)
Automatically collected data
- Browser type, device type, and IP address
- Pages visited, features used, and session duration (via PostHog analytics)
- In the Android app: device identifiers, screens viewed, and in-app interactions (via Google Firebase Analytics)
- Page view counts and general traffic data (via Vercel Analytics)
- Error and crash reports, including stack traces (via Sentry)
- Gym account login timestamps and gym name, logged to an internal monitoring channel for operational health and fraud detection purposes
4. Android App Permissions
The GymCRM Android app requests the following device permissions. Each permission is used solely for the core functionality described below and is never used to collect data beyond what is necessary.
- SEND_SMS— Used to send membership reminders, payment due alerts, and renewal notifications directly to gym members via SMS from the gym owner's device SIM. SMS messages are only sent to members whose phone numbers are stored in the gym's own member database. We do not send marketing or promotional SMS to any third party. Gym owners are responsible for ensuring member consent and compliance with TRAI regulations before enabling this feature.
- CAMERA — Used to scan QR codes for member check-in and to capture member profile photos directly within the app.
- READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE — Used to allow gym owners to select profile photos and documents from their device gallery and to save exported reports (CSV, invoices) to their device.
- RECEIVE_BOOT_COMPLETED — Used to restart the scheduled membership expiry and payment reminder background worker after the device reboots, so reminders continue to run without requiring the app to be manually opened.
- INTERNET — Required to sync member data, payments, and attendance records with the GymCRM cloud backend.
You can revoke any permission at any time via Android Settings → Apps → GymCRM → Permissions. Revoking a permission will disable the related feature but will not affect other app functionality.
5. How We Use Your Data
- To create and manage your gym account and provide the GymCRM service
- To process subscription payments and send billing receipts
- To send transactional emails — renewal reminders, invoices, welcome messages (via Resend)
- To send WhatsApp notifications for membership renewals and alerts (via the Meta WhatsApp Business API, using your gym's connected number)
- To send SMS membership reminders from the gym owner's device to their members (Android only, requires explicit opt-in by the gym owner)
- To generate attendance reports, revenue summaries, and daily digests for gym owners
- To monitor platform health and detect unusual login activity through internal operational logging
- To improve the platform — we analyse anonymised usage data to fix bugs and prioritise features
- To respond to support requests you send us
We do not use your data for advertising and we do not sell your data to any third party.
6. Third-Party Services We Use
We use the following third-party services to operate GymCRM. Each receives only the minimum data necessary for their function. By using GymCRM, you acknowledge that your data may be processed by these services, which may be hosted outside India.
- Supabase (Ireland / AWS) — Database, authentication, and file storage. All member and gym data is stored on Supabase infrastructure.
- Vercel(United States) — Web hosting and edge delivery. All web requests pass through Vercel's infrastructure. Vercel Analytics collects anonymised page view data.
- Sentry (United States) — Error monitoring and crash reporting. Stack traces and error context are transmitted to Sentry when exceptions occur. We have disabled screenshot and UI-tree capture to prevent PII from being included in error reports.
- PostHog (United States) — Product analytics. We track feature usage and user flows in anonymised form to improve the platform.
- Google Firebase Analytics (United States) — App usage analytics for the mobile app. Collects device identifiers, screen views, and in-app events to help us understand how the app is used and improve it.
- Resend (United States) — Transactional email delivery for account verification, invoices, and membership reminders.
- Razorpay (India) — Payment processing for gym subscription payments within India.
- Dodo Payments — Subscription billing and management for GymCRM Pro plans.
- Meta WhatsApp Business API (United States) — Used to send membership renewal reminders and alerts to gym members on behalf of gym owners who have connected their WhatsApp Business number.
- Telegram — Used internally to receive operational alerts such as new gym account logins (gym name and timestamp only). No member data is transmitted to Telegram.
7. Data Storage and Security
All data is stored on Supabase with Row-Level Security (RLS) enabled. Every query is scoped to the authenticated user's gym — no gym can access another gym's data.
All data in transit is encrypted via HTTPS/TLS. Passwords are never stored in plain text — authentication is handled by Supabase Auth. Sensitive credentials (Razorpay keys, WhatsApp tokens) are stored in encrypted server-side environment variables and are never exposed to the client.
Member profile photos are stored in a private storage bucket and are only accessible via short-lived signed URLs generated for authenticated users. Photos are never publicly accessible.
While we take reasonable technical measures to protect your data, no system is completely secure. Please contact us immediately at shashanksingh67567@gmail.com if you suspect unauthorised access.
8. Cross-Border Data Transfers
GymCRM uses services hosted outside India (Supabase on AWS, Vercel, Sentry, PostHog, Google Firebase Analytics, Resend). By using GymCRM, you acknowledge that your data may be transferred to and processed in countries outside India, including the United States.
We ensure that all third-party processors have adequate data protection measures in place through their respective data processing agreements and privacy frameworks. We will comply with any cross-border transfer restrictions notified by MeitY under the DPDP Act 2023 as and when they come into effect.
9. Data Retention
- Active accounts — Data is retained for as long as the gym account remains active.
- After cancellation — We retain data for 30 days after subscription cancellation. You can export all your data (members, payments, invoices) as CSV during this window.
- After 30 days — Data is permanently deleted from our systems. Deleted data may persist in encrypted backups for up to 7 days before being purged from backup storage.
- Billing records — We may retain transaction records for up to 8 years as required under Indian tax and accounting laws (Income Tax Act, 1961).
- Consent records — Records of consent given at signup are retained for 3 years from the date of withdrawal or account deletion.
10. SMS Reminders
GymCRM's Android app includes an optional SMS reminder feature that allows gym owners to send membership renewal reminders directly from their device's SIM card to their members' phone numbers.
- SMS messages are sent from the gym owner's personal phone number, not from GymCRM's infrastructure
- This feature must be explicitly enabled by the gym owner in the app settings
- Gym owners are solely responsible for obtaining member consent before enabling SMS reminders
- Gym owners are responsible for compliance with TRAI regulations, including DLT registration where required
- Members may opt out of SMS reminders by replying STOP to any reminder message
- GymCRM does not access, read, or store the content of SMS messages sent through this feature
11. Your Rights Under the DPDP Act 2023
Under India's Digital Personal Data Protection Act 2023, you have the following rights regarding your personal data:
- Right to access — Request a copy of the personal data we hold about you.
- Right to correction — Ask us to correct inaccurate or incomplete data.
- Right to erasure — Request deletion of your personal data (subject to legal retention obligations).
- Right to data portability — Export your gym data (members, invoices, payments) as CSV at any time from your account settings.
- Right to grievance redressal — Raise a complaint with our Grievance Officer (details below).
- Right to nominate — Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, contact us at shashanksingh67567@gmail.com. We will respond within 30 days.
Gym members wishing to exercise these rights should contact their gym directly, as the gym is the Data Fiduciary for member data. Gym owners and staff should contact us directly.
12. Cookies
GymCRM uses cookies and similar technologies for:
- Authentication — Keeping you logged in to the platform (Supabase session cookies)
- Analytics — Understanding how the platform is used (PostHog, Vercel Analytics)
We do not use advertising cookies or tracking pixels. You can disable cookies in your browser settings, but this will prevent you from staying logged in to the platform.
13. Children's Privacy
GymCRM is not directed at children under 18. We do not knowingly collect personal data from anyone under 18 without parental or guardian consent. Gym owners who enroll members under 18 must obtain appropriate consent from the member's parent or legal guardian before entering their data into GymCRM.
If you believe a minor's data has been submitted without appropriate consent, please contact us and we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered gym owners via email and update the "Last updated" date at the top of this page. Continued use of GymCRM after the effective date constitutes acceptance of the updated policy.
15. Grievance Officer
In accordance with the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023, you may contact our Grievance Officer for any data-related concerns:
Grievance Officer — GymCRM
Name: Shashank Kumar
Email: shashanksingh67567@gmail.com
WhatsApp: +91 75410 04076
Response time: within 72 hours on business days