1. Introduction
GYMpays ("we", "us", "our") operates a refund-backed gym membership platform that lets members earn back a percentage of their gym fee by maintaining consistent attendance at partner gyms. This Privacy Policy explains what information the GYMpays mobile app (package com.gympays.app) and the gympays.com website collect, how we use and share it, how long we keep it, and the choices and controls you have.
By creating a GYMpays account or using the app, you agree to the practices described here. If you do not agree, please do not use the service.
2. Information We Collect
- Account details: your name and email address. We sign you in with a one-time password (OTP) sent to your email — we do not store a password. We store a temporary hash of the OTP and its expiry until it is used.
- Membership data: the partner gym and plan you join, your start and end dates, the fee and service charge you paid, and your membership status.
- Attendance and session data: each daily check-in — the date and time, the gym, the method used (QR code, GPS, or manual/staff verification), your check-out time, and the number of minutes credited toward your attendance goal.
- Location data: GPS latitude, longitude, accuracy and timestamp. This includes location collected while the app is in the background or your screen is locked, during an active gym session only. Section 3 explains this in full.
- Payment and refund details: transaction and order records for your membership fee, processed by Razorpay, and the UPI ID you provide to receive your refund payout. We never see or store your full card number, UPI PIN, CVV, or bank credentials — those are handled entirely by Razorpay.
- Device and technical data: a randomly generated device identifier created on first launch and stored on your device, plus your app version and operating system version. We use this to tie a session to one device and detect duplicate or shared-account use.
- Integrity signals: whether your device reports a mock or spoofed GPS provider and whether Android Developer Options are enabled. We check these only to prevent attendance fraud, and we record the outcome of the check, not the contents of your device.
- Analytics and usage data:in the app, Google Firebase Analytics records screen views and in-app events. On the website, Google Analytics 4 and Microsoft Clarity record page views, referral source, approximate region, and — in Clarity's case — anonymised session recordings and heatmaps of clicks and scrolls on our public pages.
- Support correspondence: the content of emails or messages you send us, so we can respond and keep a record of the issue.
We do not collect your contacts, photos, camera roll, SMS, call logs, health or fitness sensor data, or biometric data. The app does not use advertising identifiers and shows no ads.
3. Location Data During Gym Sessions
Foreground location("while using the app") is used for two things:
- Showing how far each partner gym is from you on the gym list, so you can sort by nearest.
- Confirming, at the moment you check in by GPS, that you are within the required radius of your gym's entrance (currently 150 metres).
Session location is used for one thing only: proving you actually stayed at the gym for the minimum session length. Because your phone screen will usually be locked or you will be using another app while you train, the session can only be verified if the app can read your location while it is not on screen. Specifically:
- Session tracking starts only after you tap check in and confirm the disclosure shown in the app. It never runs before you check in.
- While a session is active, the app records your coordinates, accuracy and timestamp at a short interval (currently about every 60 seconds) and sends them to our server, which records only whether that point was inside your gym's radius and credits the time accordingly.
- Tracking runs as an Android foreground servicewith a persistent notification that stays visible the entire time, so you always know when it is active. GYMpays uses the standard "while using the app" location permission — it does not ask for, and cannot use, "allow all the time" access.
- Collection stops automatically when your session completes, when you check out, or when the session expires. It does not resume until your next check-in.
- If location is switched off or permission is withdrawn mid-session, the app records a "location unavailable" marker with no coordinates, purely so a later dispute about missing time can be resolved fairly.
We never sell your location data, use it for advertising or profiling, share it with data brokers, or track your movements outside an active gym session.
You can withdraw location permission at any time in your device settings (Settings → Apps → GYMpays → Permissions → Location). Withdrawing it does not delete your account, but GPS check-in and automatic session verification will stop working, and you will need to use QR-code or staff-verified check-in instead.
4. How We Use Your Information
- To create your account, sign you in by email OTP, and manage your membership.
- To verify your attendance, count qualifying gym days, and track your progress toward your refund goal.
- To process your membership payment and, once you qualify, your refund payout via UPI.
- To detect and prevent attendance fraud — for example spoofed GPS, shared accounts, or check-ins made away from the gym.
- To send you check-in reminders, milestone updates, and service notices about your membership or refund.
- To respond to your support requests and resolve disputes about credited attendance.
- To understand how the app and website are used in aggregate so we can fix problems and improve the product.
- To meet our legal, tax, accounting, and audit obligations.
5. Data Sharing
We do not sell your personal information to third parties. We share the minimum data necessary with the following categories of recipients:
- Partner gyms: your name and your attendance record at that gym, so they can confirm your membership and verify your visits. Partner gyms do not receive your raw GPS coordinates, your email address, or your payment details.
- Razorpay (payment gateway): the information needed to take your membership payment and send your refund. Razorpay processes this as an independent controller under its own privacy policy.
- Google (Firebase Analytics, Google Analytics 4): app and website usage events, used to measure product performance.
- Microsoft (Clarity): website interaction data and anonymised session recordings of our public pages.
- Infrastructure providers: our hosting, database, and email delivery providers, who process data on our instructions to run the service.
- Legal and safety: regulators, law enforcement, or professional advisers where we are legally required to disclose information, or where disclosure is necessary to establish, exercise, or defend a legal claim.
- Business transfer: if GYMpays is involved in a merger, acquisition, or sale of assets, your data may transfer to the successor entity, which will remain bound by this policy.
6. Data Retention
We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires us to. Retention periods by category:
| Data | How long we keep it |
|---|---|
| Account details (name, email address) | Until you delete your account. Deleted immediately on request. |
| One-time password (OTP) hash | Until the OTP is used or expires — a matter of minutes. |
| Membership and subscription records | For the life of the membership, then 12 months after it ends, to handle late refund claims and disputes. |
| Attendance and check-in records | For the life of the membership, then 12 months after it ends. These are the evidence of your refund entitlement. |
| Raw GPS location pings (session coordinates) | For the life of the membership, then 12 months after it ends, after which they are deleted. Kept this long so any dispute over credited attendance during your 240-day goal can be independently verified. |
| Device identifier and integrity signals | For the life of the membership, then 12 months after it ends, as part of the fraud-prevention record. |
| Payment, order, and refund records (including UPI ID) | 8 years from the end of the relevant financial year, as required for books of account under section 128 of the Companies Act, 2013 and applicable tax law. This applies even if you delete your account. |
| Support correspondence | 24 months from the date the issue is closed. |
| App and website analytics | Retained in aggregated or pseudonymised form under the default retention settings of Firebase Analytics, Google Analytics 4, and Microsoft Clarity (currently up to 14 months for Google, 30 days for Clarity recordings). |
When a retention period ends, we delete the data or irreversibly anonymise it so it can no longer be linked back to you. Backups are overwritten on a rolling cycle, so data deleted from our live systems may persist in encrypted backups for a short period before being purged.
7. Data Security
We use reasonable technical and organisational measures to protect your data against unauthorised access, alteration, or loss. These include encryption of data in transit (HTTPS/TLS), token-based authentication, access controls restricting staff access to production data, and processing card and UPI credentials exclusively through our PCI-DSS compliant payment gateway rather than on our own systems. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Please keep access to your email inbox secure, since that is how you sign in.
8. Your Rights and Choices
You can, at any time:
- Access and correct the personal data we hold about you, by contacting us at infogympays@gmail.com.
- Delete your account and data from within the app — open Profile → Delete Account. This permanently deletes your account, membership, attendance records, and location pings from our servers, subject only to the financial records we are legally required to keep (see section 6). You can also request deletion by emailing infogympays@gmail.com from your registered email address.
- Withdraw location permission in your device settings, as described in section 3.
- Opt out of analyticsby using your browser's do-not-track or script-blocking settings on our website.
- Complain to the relevant data protection authority if you believe we have mishandled your data.
9. Children's Privacy
GYMpays is not directed at individuals under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us at infogympays@gmail.com and we will delete it.
10. Where Your Data Is Stored
GYMpays operates in India and our systems are hosted with cloud providers whose infrastructure may be located outside India. Our analytics and payment providers may also process data outside India. Where data is transferred internationally, we rely on the contractual protections offered by those providers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and — where the change materially affects how we use your data — by notifying you in the app before the change takes effect.
12. Contact Us
Questions about this policy, your data, or a deletion request can be sent to infogympays@gmail.com. We aim to respond within one business day and to resolve data requests within 30 days.