Privacy policy
A plain reading of how the platform handles member and payment data. No legalese where a sentence will do.
1. Scope
This policy applies to the Coressssfitzaa9 platform and the websites that describe it. It covers information a gym owner, a trainer, a front-desk operator or a member provides to the platform, plus anything the platform records as those users work.
2. Data we collect
Account and profile
Name, contact details, membership type, cycle, city, gym affiliation and role - as needed to identify a person on the platform.
Payments
Method, amount, cycle, date and receipt reference. Card numbers, CVV and bank credentials never touch our servers - they stay with the payment provider.
Attendance and workouts
Check-in timestamps and workout session logs - only for the gym the member is enrolled with.
Website usage
Standard log data - IP, browser type, pages visited - used to keep the site working, in aggregate. No behavioural profiles are built or sold.
3. How we use it
- To run the platform - member profiles, fee tracking, attendance, workout plans and analytics.
- To generate personalised workout plans for members whose account is enabled for that.
- To send transactional notifications - renewal reminders, receipts and account-related updates.
- To improve reliability and performance, using aggregated, non-identifying signals.
We do not sell personal data. We do not use member data to train models outside the scope of the account it belongs to.
4. Who sees it
Access to a gym's data is scoped by role. Owner, trainer, front desk and branch roles each see a defined subset - member data is not exposed across gyms or across branches beyond the roles you configure.
We use vetted third parties for payment processing, email delivery and SMS delivery. Each receives only the data needed to perform its function.
5. Retention
Active member records stay for the duration of the membership. Archived records are retained for up to twenty-four months to allow reactivation. On explicit request, personal identifiers can be removed while preserving aggregate history for analytics.
6. Your rights
- Access - You can request an export of the personal data linked to you.
- Correction - Incorrect data can be corrected through the account holder or, directly, through us.
- Deletion - Personal identifiers can be removed on request, subject to lawful retention requirements.
- Withdrawal of consent - Where processing is based on consent, you can withdraw it and processing stops.
7. Security
Data at rest is encrypted. Data in transit uses TLS. Access is scoped by role and every write is audit-logged. Reasonable safeguards are in place - no service, ours or anyone else's, can guarantee absolute security.
8. Changes
If this policy changes materially, the account holder for a gym is notified through the platform and by email. Continued use of the platform after a change constitutes acceptance of the updated policy.
