CloudFYT ("we", "our", "us") is firmly committed to protecting the privacy and security of your fitness business and your gym members. We do NOT sell, rent, or monetize your personal or member data under any circumstance.
1. Information We Collect
We collect information necessary to deliver, maintain, and support the CloudFYT gym management platform:
- Business Account Information: Gym name, owner/administrator name, business email, phone number, physical gym location, and account login credentials.
- Gym Member Records: Member full name, contact information, emergency contact, date of birth, membership plan, expiry dates, attendance logs, digital passes, and fitness assessment metrics entered by you or your staff.
- Payment & Transaction Data: Subscription fees and in-gym POS transactions processed securely via RBI/PCI-DSS compliant payment gateways (Razorpay, Stripe). We do not store raw credit card numbers or banking PINs on our application servers.
- System & Device Logs: IP address, browser type, operating system, crash analytics, and timestamped audit trails of administrative actions.
2. How We Use Your Information
We use the collected information exclusively to:
- Operate the CloudFYT software, member directory, attendance checkpoints, and front-desk POS.
- Dispatch automated WhatsApp renewal alerts, payment confirmation receipts, and welcome passes on your gym's behalf.
- Generate compliant GST/VAT invoices and revenue accounting dashboards.
- Provide customer assistance, live chat support, and free data migration.
- Ensure platform security, prevent fraud, and maintain system uptime.
3. Strict Third-Party Disclosure Policy
We do not sell personal data. Information is shared solely with trusted technical infrastructure providers required to deliver the Service:
- Payment Processors: Razorpay, Stripe, or bank gateways for secure checkout.
- Cloud Infrastructure: Cloudflare Global Edge Network, ISO 27001 certified data center facilities.
- Messaging Gateways: Meta WhatsApp Cloud API and verified SMS providers for message transmission.
- Legal Compliance: When compelled by valid legal court orders or law enforcement warrants.
4. Data Retention & Deletion
Account and member records are retained throughout your active subscription. You have the right to request permanent deletion of your account and member data at any time by submitting a request to [email protected]. We will process verified data erasure requests within thirty (30) days, except where financial transaction logs must be retained for statutory tax compliance.
5. Security Standards & Encryption
CloudFYT employs state-of-the-art security practices to protect your data against loss, interception, or unauthorized disclosure:
- 256-bit TLS/SSL encryption for all data in transit across public networks.
- AES-256 encryption for sensitive database storage at rest.
- Role-Based Access Control (RBAC) preventing unauthorized staff access.
- Automated redundant cloud backups with zero single points of failure.
6. Mobile App Permissions
The CloudFYT Mobile App for trainers, front-desk staff, and gym members requests only the minimal device permissions necessary to function:
- Camera: Used exclusively to scan member attendance QR passes and upload member profile photos.
- Storage / Photos: Used to attach fitness documents, invoices, or receipts.
- Push Notifications: Used to deliver critical renewal reminders and workout alerts.
7. Your Privacy Rights
Regardless of your gym's physical location, you have the right to request an export of your data, correct inaccurate details, restrict automated processing, or close your account.
8. Privacy Contact Officer
If you have inquiries regarding this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection desk:
CloudFYT Technologies Private Limited
Attn: Data Privacy & Information Security Officer
[email protected]