Privacy Policy
In short
- We collect only what is needed to run your gym's account: your login, your gym's details, and the member records your gym adds.
- Your gym owns its member data. We store and process it for your gym and use it for nothing else.
- We never sell data and we do not show ads.
- Member payments go straight to the gym's own Razorpay account. We never see card or UPI details.
- You can download all your data at any time, and ask us to delete it.
1. Who we are
GymMunshi (gymmunshi.com) is software that helps gyms collect fees, run the front desk and keep member records. It is a product of Byteflare Technologies, India ("we", "us"). Questions about this policy: [email protected].
2. Two kinds of data, two roles
- Gym owners and their staff (people who sign in to GymMunshi): we decide how this data is used, as described here.
- Gym members (people a gym adds: name, phone, plan, payments, visits): the gym decides what it collects and why. We process it only on the gym's instructions, to provide the service to that gym. Members who have a question about their data should first contact their gym; we will help the gym answer it.
3. What we collect
From gym owners and staff
- Sign-in: your email address. If you sign in with Google, we receive your name, email address and profile picture from Google, and nothing else (no contacts, no Gmail, no Drive).
- Gym details: gym and branch names, address, phone, GST number, billing details for our invoices.
- Security records: sign-in sessions with the device type and IP address, and a log of important actions (for example payments recorded, refunds, settings changed) so the owner can see who did what.
- Our billing: the plan you buy and payment references from Razorpay. We do not receive your card or UPI details.
- Website enquiries: what you type in the early access form on gymmunshi.com (name, gym, phone, email, city, message).
Member data a gym adds
- Name, mobile number, email, gender, date of birth, address, emergency contact, photo, and any extra fields the gym creates.
- Plans, orders, payments, invoices, refunds, visits (check-ins), and messages sent to the member.
- The member's consent to receive reminders and receipts, with the date and the text that was shown.
4. How we use it
- To provide GymMunshi: sign-in, member records, sales, invoices, reminders, check-in, reports.
- To send service emails: sign-in codes, staff invitations, and, on the gym's behalf, renewal reminders and receipts to members who agreed to receive them.
- To bill gyms for GymMunshi and keep the accounts that tax law requires.
- To keep the service secure, find faults and give support.
We do not sell or rent data, we do not use it for advertising, and we do not use member data for our own marketing.
5. Support access
To fix a problem, our support team may open a gym's account. Every such visit is recorded in our internal log. During support access we cannot change payment-gateway details, billing or staff logins.
6. Who helps us run GymMunshi
We share data only with providers that help us run the service, only as much as each one needs:
- Cloud hosting and storage (servers, database and backups).
- Cloudflare: website hosting, DNS and protection against attacks.
- Resend: sending emails.
- Razorpay: payments. Members pay into the gym's own Razorpay account; gyms pay us through ours.
- Google: "Sign in with Google", if you choose it.
- HubSpot: our list of early access enquiries from the website.
- Zoho Mail: our support mailbox.
- Meta (WhatsApp): only if a gym turns on automated WhatsApp reminders, to deliver those messages.
Some of these providers process data outside India. We may also share data when the law requires it.
7. How long we keep data
- As long as the gym's account is open.
- When a gym closes its account, we give it time to download its data, then delete it, except invoices and payment records, which we keep as long as Indian tax law requires.
- Sign-in codes expire in 10 minutes. Backups are replaced on a rolling basis.
8. How we protect it
- All traffic uses HTTPS. Each gym's data is separated at the database level, so one gym can never see another's.
- Payment-gateway keys are stored encrypted. Sign-in uses one-time codes or Google, so there are no passwords to leak.
- Staff see only what their role allows, and important actions are logged.
9. Your choices and rights
- Gym owners can download their data (members, payments, invoices) from the app at any time, correct it, or ask us to delete the account.
- Members can ask their gym to see, correct or delete their data, or to stop reminders; the gym can do this in GymMunshi.
- You can withdraw consent at any time. Under India's Digital Personal Data Protection Act, 2023, you may also nominate someone to act for you and complain to the Data Protection Board of India.
Write to [email protected]; we reply within 30 days.
10. Cookies
The app uses only essential cookies: to keep you signed in, to remember your branch, and to remember a member's pass on their own phone. There are no advertising or tracking cookies. The website loads fonts from Google Fonts.
11. Children
GymMunshi accounts are for adults running or working at a gym. If a gym adds a member under 18, the gym is responsible for having a parent's or guardian's consent.
12. Changes
If we change this policy, we will update the date above, and tell gym owners in the app or by email before a significant change takes effect.
13. Contact and grievances
Grievance Officer, GymMunshi · [email protected]