GymSmart Privacy &
Data Protection Policy
Learn how GymSmart safeguards your fitness business data, member biometric logs, and mobile app health records with bank-grade 256-bit encryption.
1. Introduction & Scope
Welcome to GymSmart (operated by Ajasys Technologies Private Limited). This Privacy Policy explains how we collect, store, process, and protect your information when you access our cloud ERP platform (erp.gymsmart.in), our website (gymsmart.in), and our branded mobile applications across iOS and Android.
By using GymSmart services or installing our applications, you acknowledge and agree to the practices outlined in this policy. We are committed to safeguarding your privacy and ensuring transparency in all aspects of data handling.
2. Information We Collect
To provide our comprehensive gym management, billing, and access control services, we collect the following categories of information:
- Gym Business Profile: Gym name, branch addresses, GSTIN numbers, owner contact numbers, and bank account details for UPI settlement.
- Member Profile Data: Full name, phone number, email address, date of birth, emergency contacts, profile photo, and membership plan details.
- Financial & Billing Records: Fee payment history, outstanding dues, invoice records, and transaction IDs (we do NOT store raw credit/debit card details; all payments are processed through secure PCI-DSS compliant gateways like Razorpay & PhonePe).
- Usage & Device Information: IP address, device model, operating system version, browser type, and system crash logs for app diagnostics.
3. Data Retention and Deletion
We retain data only as long as necessary to deliver our services, fulfill statutory legal requirements, and resolve operational disputes:
- Active Account Data: Maintained for the entire duration of the active subscription to ensure continuous gym operations.
- Account Deletion Requests: When a gym owner or member requests permanent account deletion, all personal data is permanently wiped from our active databases within 30 days.
- Server Logs & Diagnostics: Stored securely for a maximum of 90 days before automated recycling.
- Encrypted Offsite Backups: Retained for a rolling period of up to 30 days before automated cryptographic overwrite.
4. Health and Fitness Data (Member App)
The GymSmart Member Mobile Application allows gym members to track their fitness journey. This sensitive health data is handled with maximum privacy protections:
- Body Measurements: Weight, height, BMI, body fat percentage, and progress photos.
- Workout & Nutrition Plans: Custom exercise sets, repetitions, target calories, and daily diet macro logs assigned by gym trainers.
- Activity Tracking: Step counts and workout durations synced with user permission.
5. Biometric Attendance & Turnstile Logs
GymSmart connects directly with biometric turnstile hardware (eSSL, TimeWatch, ZKTeco) over secure local TCP/IP sockets:
- No Raw Biometric Storage: We do not store raw fingerprint images or raw facial photos on our cloud servers. All biometric verification occurs locally on hardware firmware chips using mathematical template hashes.
- Check-in Logs: Only timestamped entry/exit logs (User ID, Gate ID, and Check-in Time) are synchronized with the cloud dashboard for attendance verification.
- Automated Gate Lock: Biometric turnstiles automatically restrict entry for expired memberships or unpaid dues based on real-time cloud status.
6. How We Use Your Data
Information collected by GymSmart is utilized strictly for legitimate business and operational purposes:
- To provide core ERP operations: membership registrations, batch scheduling, and automated billing.
- To dispatch automated WhatsApp reminders, payment links, and official GST invoice receipts.
- To compute trainer personal training (PT) commissions and staff biometric payroll.
- To generate analytics dashboards on gym revenue, active renewals, and member churn rates.
- To provide fast customer support, hardware troubleshooting, and technical assistance.
8. Bank-Grade Security Measures
GymSmart employs enterprise multi-layer security protocols to ensure that member records and gym financial reports remain 100% confidential:
- 256-bit SSL/TLS Encryption: All data transmitted between browsers, mobile apps, and servers is encrypted in transit using industry-standard TLS 1.3.
- Role-Based Access Control (RBAC): Gym staff can only view information explicitly permitted by the gym owner (e.g. front desk cannot view overall profit reports).
- Automated Daily Backups: Offsite cryptographic backups prevent any accidental data loss.
9. Children's Privacy
Our services are intended for commercial gym businesses and individuals above 13 years of age. For underage gymnastics or martial arts academies, accounts must be created and supervised with verifiable parental/guardian consent.
10. Third-Party Integrations & Links
GymSmart integrates with trusted enterprise partners (such as WhatsApp Official Cloud API, Razorpay Payment Gateway, and Apple Health / Google Fit). These integrations operate under strict end-to-end security compliance and user-granted permissions.
11. Updates to This Policy
We may update this Privacy Policy periodically to reflect technological enhancements or regulatory compliance updates. Any material updates will be clearly reflected with the revised "Last Updated" date at the top of this page.
12. Grievance Officer & Contact Information
If you have any questions, clarifications, or requests regarding this Privacy Policy or your personal data rights, please contact our Data Protection Officer: