Gym Pro Max

Privacy Policy

Last Updated: 14 August 2026

At Gym Pro Max, operated by SF WebSolutions Private Limited, we are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, share, and protect your personal data in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and other applicable data protection laws in India, including provisions inspired by international best practices such as GDPR.

By using our Platform, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this policy, please do not use our services.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when:

  • Registering an Account: Gym name, owner name, email address, phone number, business address, state, city, pincode, website URL.
  • Creating Member Records: Member names, email addresses, phone numbers, date of birth, gender, addresses, emergency contacts, medical conditions, fitness goals, membership details, biometric identifiers (if applicable).
  • Managing Staff: Staff names, email addresses, phone numbers, roles, permissions, employment details.
  • Processing Payments: Payment method details (processed securely through third-party payment gateways), transaction history, billing addresses.
  • Contacting Support: Your name, email, phone number, and any information you provide in support requests.

1.2 Automatically Collected Information

When you use our Platform, we automatically collect:

  • Usage Data: Pages visited, features used, time spent on the Platform, click patterns, and navigation paths.
  • Device Information: IP address, browser type and version, device type, operating system, screen resolution.
  • Log Data: Access logs, error logs, security events, and system performance data.
  • Location Data: General location information derived from IP address (city/state level, not precise location).

1.3 Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Maintain your login session and preferences.
  • Analyze Platform usage and improve user experience.
  • Remember your settings and preferences.
  • Provide security features and prevent fraud.

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Platform.

2. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve the Platform and its features.
  • Account Management: To create and manage your account, process subscriptions, and handle billing.
  • Communication: To send you service-related notifications, updates, security alerts, and support responses.
  • Member Management: To enable Gym Owners to manage member records, memberships, attendance, and payments.
  • Security: To detect, prevent, and address security threats, fraud, and unauthorized access.
  • Analytics: To analyze usage patterns, improve Platform performance, and develop new features.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.
  • Business Operations: To conduct business analytics, generate reports, and make data-driven decisions.

3. Sensitive Personal Data

Under Indian law, "Sensitive Personal Data" includes passwords, financial information, biometric data, medical records, and sexual orientation. We handle such data with enhanced security measures:

  • Biometric Data: We store only biometric identifiers (references/IDs), not actual biometric templates. This data is encrypted and used solely for access control purposes.
  • Financial Information: Payment card details are processed through PCI-DSS compliant payment gateways. We do not store full card numbers on our servers.
  • Medical Information: Medical conditions and fitness goals provided by members are stored securely and accessible only to authorized Gym Owner staff.
  • Passwords: Passwords are hashed using industry-standard algorithms and never stored in plain text.

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your data only in the following circumstances:

4.1 Service Providers

We share data with trusted third-party service providers who assist us in:

  • Payment Processing: Payment gateways (Razorpay, Stripe, etc.) to process subscription and transaction payments.
  • Email Services: Email service providers (SendGrid, AWS SES, Nodemailer) to send transactional and marketing emails.
  • Cloud Infrastructure: Cloud hosting providers (AWS, MongoDB Atlas) to store and process data securely.
  • Analytics: Analytics services to understand Platform usage (data is anonymized where possible).
  • Biometric Devices: Device manufacturers and integration services to sync biometric access control (only identifiers, not templates).

All service providers are contractually obligated to protect your data and use it only for specified purposes.

4.2 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, including:

  • Compliance with the Information Technology Act, 2000, and related rules.
  • Response to lawful requests from government authorities.
  • Protection of our rights, property, or safety, or that of our users.
  • Enforcement of our Terms & Conditions or other agreements.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections.

5. Data Storage and Security

5.1 Data Storage

Your data is stored on secure servers located in India and/or other jurisdictions as required by our cloud infrastructure providers. We implement appropriate technical and organizational measures to protect your data.

5.2 Security Measures

We employ industry-standard security measures, including:

  • Encryption: Data in transit (HTTPS/TLS) and data at rest (AES-256 encryption).
  • Access Controls: Role-based access control (RBAC) to limit data access to authorized personnel only.
  • Authentication: Strong password requirements, multi-factor authentication (where available), and secure session management.
  • Network Security: Firewalls, intrusion detection, and regular security audits.
  • Regular Backups: Automated backups to prevent data loss.
  • Security Monitoring: Continuous monitoring for security threats and vulnerabilities.

5.3 Data Retention

We retain your data for as long as necessary to provide the Service and comply with legal obligations. Specifically:

  • Active Accounts: Data is retained while your account is active and for 30 days after cancellation.
  • Inactive Accounts: Data may be deleted after 90 days of inactivity, subject to legal retention requirements.
  • Legal Requirements: Financial and audit records may be retained for up to 7 years as required by Indian law.
  • Backup Data: Backup copies may be retained for up to 90 days after account deletion.

6. Your Rights and Choices

Under Indian law and as a best practice, you have the following rights regarding your personal data:

6.1 Right to Access

You can request access to your personal data held by us. We will provide a copy of your data in a structured, commonly used format within 30 days of your request.

6.2 Right to Correction

You can update your account information at any time through your account settings. For corrections to other data, please contact support.

6.3 Right to Deletion

You can request deletion of your personal data, subject to legal retention requirements. We will delete your data within 30 days, except where we are required to retain it by law.

6.4 Right to Withdraw Consent

You can withdraw consent for data processing at any time. However, withdrawal may affect your ability to use certain features of the Platform.

6.5 Right to Data Portability

You can request an export of your data in a machine-readable format (JSON, CSV) for transfer to another service.

6.6 Right to Grievance

If you have concerns about how we handle your data, you can file a grievance with our Grievance Officer (contact details below) or with the appropriate regulatory authority.

7. Third-Party Integrations

The Platform integrates with third-party services that may collect and process your data:

  • Payment Gateways: When processing payments, your payment information is shared with payment processors. Please review their privacy policies.
  • Email Services: Email addresses and content are processed by email service providers for delivery of transactional and marketing emails.
  • Biometric Devices: Biometric identifiers may be synced to third-party biometric access control devices as configured by Gym Owners.
  • Analytics Services: Usage data may be shared with analytics providers (anonymized where possible).

We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies.

8. Children's Privacy

The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete such information.

9. Data Breach Notification

In the event of a data breach that compromises your personal or sensitive personal data, we will:

  • Notify affected users within 72 hours of becoming aware of the breach, as required by Indian law.
  • Report the breach to the appropriate regulatory authority if required.
  • Take immediate steps to contain and remediate the breach.
  • Provide information about the nature of the breach, data affected, and steps taken to address it.

10. International Data Transfers

Your data may be transferred to and stored in servers located outside India as part of our cloud infrastructure. We ensure that such transfers comply with applicable data protection laws and that adequate safeguards are in place to protect your data.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated via email or through a prominent notice on the Platform at least 30 days before they take effect.

Your continued use of the Platform after such notice constitutes acceptance of the updated Privacy Policy.

12. Grievance Officer

In accordance with the Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer to address your privacy concerns:

Grievance Officer

SF WebSolutions Private Limited

10-3-282/2, Humayun Nagar, Mehdipatnam

Hyderabad, Telangana, India

Email: [email protected]

Phone: +91 91103 92332

Response Time: Within 30 days of receiving your grievance

13. Contact Us

For privacy-related questions, requests, or concerns, please contact us at:

SF WebSolutions Private Limited

10-3-282/2, Humayun Nagar, Mehdipatnam

Hyderabad, Telangana, India

Email: [email protected]

Phone: +91 91103 92332

Questions About This Policy?

If you have any questions or concerns about this policy, please contact our support team.