Privacy Policy
Last updated: July 10, 2026
Fitchakra ("we", "us", or "our") operates a gym and fitness center management platform (the "Service"). This Privacy Policy explains what personal data we collect, how we use and share it, and the rights and choices available to you. By using the Service, you agree to the practices described in this policy.
1. Information We Collect
Information you provide
- Account and profile data: name, email address, phone number, date of birth, gender, address, emergency contact details, and profile photo.
- Membership and health data: membership plan details, fitness goals, and health notes you or your gym choose to record (e.g., injuries or medical conditions relevant to training).
- Payment data: billing details and transaction history. Card and bank details are collected and processed directly by our payment providers (e.g., Razorpay); we store only payment references and tokens, never full card numbers.
Information collected automatically
- Attendance and access data: check-in and check-out records, including the method used (QR code, biometric device, or facial recognition). Where biometric check-in is used, we store only irreversibly hashed templates — never raw biometric images or fingerprints.
- Usage and device data: log data, IP address, browser type, and pages visited, used for security and to improve the Service.
- Cookies: we use cookies and similar technologies for authentication and session management.
2. How We Use Your Information
- To create and manage your account and membership;
- To process payments, generate invoices, and manage recurring billing;
- To schedule classes and appointments and manage attendance and facility access;
- To send transactional and service notifications (renewals, invoices, class and appointment reminders) via email, SMS, and WhatsApp, where you have opted in;
- To provide customer support;
- To analyze usage and generate aggregated reports for the fitness business you are a member of;
- To protect the security and integrity of the Service and comply with legal obligations.
3. WhatsApp Business Platform
We use the WhatsApp Business Platform, provided by Meta Platforms, Inc. ("Meta"), to send service-related messages such as membership renewal reminders, invoice notifications, and class or appointment reminders, and to respond to messages you send us on WhatsApp.
- We only send you WhatsApp messages if you have provided your phone number and opted in to receive them.
- When we communicate with you on WhatsApp, your phone number and the content of those messages are processed by Meta in accordance with the WhatsApp Privacy Policy.
- You can opt out of WhatsApp communications at any time by replying "STOP" to any of our messages or by contacting us at the address below. Opting out does not affect your membership.
- We do not use WhatsApp conversation data for third-party advertising and we do not sell it.
4. How We Share Your Information
We do not sell your personal data. We share it only in the following circumstances:
- With the fitness business you are a member of: your gym and its authorized staff can access your profile, membership, attendance, and billing data to operate their business.
- Service providers: we use trusted third parties to operate the Service, including Meta (WhatsApp Business Platform), Twilio (SMS), Razorpay (payments), Amazon Web Services (hosting and storage), and Cloudflare (network security). These providers process data only as needed to provide their services to us.
- Legal requirements: when required by law, court order, or governmental authority, or to protect our rights and the safety of our users.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. After account deletion, we remove or anonymize your personal data within 90 days, except for records we are legally required to retain (such as tax and billing records) and limited data needed to resolve disputes or enforce our agreements. Activity logs are automatically purged on a rolling basis.
6. Data Security
- Data is encrypted in transit using TLS;
- Passwords are stored using strong one-way hashing (bcrypt);
- Biometric check-in data is stored only as irreversible hashed templates;
- Access to personal data is restricted by role-based access controls and limited to staff who need it;
- Payment card data is handled entirely by PCI-compliant payment providers.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent (for example, to WhatsApp or SMS communications) at any time. To exercise any of these rights, contact us at support@fitchakra.com or follow the steps on our Data Deletion page. We respond to verified requests within 30 days.
8. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Minors may only be registered as members by a parent or legal guardian in accordance with the policies of the fitness business.
9. International Data Transfers
Your data may be processed on servers located outside your country of residence, including by the service providers listed above. Where required, we use appropriate safeguards for such transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the "Last updated" date. Material changes will be communicated through the Service or by email.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at support@fitchakra.com.