1. Scope and roles
This Privacy Policy applies to the Gym0 website, account area, and related services. “Gym0”, “we”, “us”, and “our” refer to the operator of the Gym0 service.
Gym owners and their authorised staff decide which member and trainer records they enter into Gym0. For that information, the gym is responsible for giving appropriate notices, obtaining any required consent, and using the information lawfully. Gym0 processes that information to provide the service and follow the authorised gym account’s instructions.
2. Information we process
- Account information: name, email address, profile image, location, sign-in identifiers, and account settings.
- Gym information: gym name, location, capacity, packages, subscription status, and operational records.
- Member and trainer information: contact details, photographs, date of birth, join date, gym assignment, membership details, attendance or roster information, and fitness-related fields such as height, weight, BMI, or exercise preferences when entered by an authorised user.
- Payment information: plan, amount, status, transaction references, payment mode, refunds, and related billing records. Full card, bank-account, or UPI credentials are handled by the payment provider and are not stored by Gym0.
- Support information: messages, issue reports, and other information supplied when requesting assistance.
- Technical information: session cookies, device and browser details, IP address, request logs, security events, and diagnostic information generated while the service is used.
3. How information is used
- Authenticate users and keep accounts secure.
- Operate gym, member, trainer, package, roster, daybook, billing, and payment features.
- Display records to the authorised account that created or manages them.
- Process subscriptions, payment requests, refunds, and transaction reconciliation.
- Respond to support requests and service communications.
- Prevent fraud, misuse, unauthorised access, and technical failures.
- Improve reliability, performance, accessibility, and customer experience.
- Meet legal, regulatory, accounting, and dispute-resolution obligations.
Gym0 does not sell personal data and does not use member or trainer records for targeted advertising.
4. Basis for processing and consent
We process personal data when it is necessary to provide the service requested by an account holder, when consent has been provided, when required to comply with law, or for other lawful uses permitted under applicable data-protection law.
Where processing is based on consent, that consent may be withdrawn by contacting the gym that collected the information or Gym0, as appropriate. Withdrawal does not affect processing already carried out lawfully and may limit features that require the relevant information.
5. Sharing and service providers
Information may be shared only as reasonably necessary with:
- the gym owner and authorised staff responsible for the relevant records;
- service providers supporting hosting, authentication, databases, file storage, communications, security, analytics, customer support, and payments;
- professional advisers, auditors, insurers, or a successor organisation during a legitimate business restructuring; and
- government authorities or other parties when required by law, necessary to protect rights or safety, or needed to investigate misuse.
Service providers are permitted to process information only for the services they provide and subject to appropriate contractual and security obligations.
6. Cookies and sessions
Gym0 uses essential cookies and similar session technologies to keep users signed in, protect forms, remember necessary account state, and maintain security. These technologies are required for the authenticated service to work. Gym0 does not use member or trainer records for cross-site advertising.
7. Data retention
Personal data is retained only for as long as needed to provide the service, maintain the account, meet legal or accounting requirements, resolve disputes, prevent fraud, and enforce agreements. Retention periods depend on the type of record and why it is held.
When an authorised deletion request is completed, information is deleted or anonymised unless continued retention is required or permitted by law. Residual copies may remain temporarily in protected backups and security logs until they are overwritten under normal retention cycles.
8. Security
Gym0 uses reasonable technical and organisational safeguards designed to protect personal data, including access controls, authenticated sessions, encrypted network connections, restricted administrative access, monitoring, and backup or recovery procedures where appropriate.
No online service can guarantee absolute security. Account holders should use trusted devices, protect their sign-in accounts, restrict staff access, and promptly report suspected unauthorised use.
9. Children’s information
Gym0 is intended for use by gym owners and authorised staff, not for children to create administrative accounts. A gym may maintain a minor member’s record only where it has the authority to do so and has obtained verifiable consent from a parent or lawful guardian when required.
Gym0 does not knowingly use children’s information for behavioural monitoring or targeted advertising. A parent or guardian may contact the relevant gym or Gym0 to request review, correction, or deletion.
10. Your rights and choices
Subject to applicable law and verification of the request, an individual may ask to:
- obtain information about the personal data being processed;
- access, correct, complete, update, or erase personal data;
- withdraw consent where consent is the basis for processing;
- raise a grievance about how personal data is handled; and
- nominate another person to exercise applicable rights in the event of death or incapacity.
For member or trainer records entered by a gym, contact that gym first because it controls and verifies those records. Gym0 may coordinate with the authorised gym account before fulfilling a request. We may ask for information needed to verify identity and prevent unauthorised disclosure or deletion.
11. International processing
Service providers may process or store information in locations outside the user’s state or country. Where this occurs, Gym0 uses reasonable safeguards and follows applicable restrictions governing cross-border processing.
12. Changes to this policy
This policy may be updated to reflect changes in the service, security practices, or legal requirements. The revised version will be posted on this page with a new “Last updated” date. Material changes may also be communicated through the service or registered contact details where appropriate.
13. Privacy questions and grievances
For a privacy request, question, or grievance, email Gym0 with the subject “Privacy request – Gym0”. Please do not include passwords, one-time codes, or full payment credentials.