Last updated: 27 August 2026
FitSync (“FitSync”, “we”, “us”) operates the website fitsync.co.in and the FitSync gym-management application. This policy explains, in plain language, what personal data we handle, why, and what your rights are. It is written to align with India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules under it.
It covers two things separately, because they are different: Part 1 — this marketing website; Part 2 — data inside the FitSync application, which belongs to the gyms that use it.
Part 1 — This website
What we collect
- Details you send us. When you use the contact form, WhatsApp, phone or email, we receive what you choose to share — typically your name, phone/WhatsApp number, gym name, city, gym size, email (optional) and your message. Form submissions are stored in our website’s admin system.
- Server logs. Like most websites, our servers keep standard access logs (IP address, browser type, pages requested, timestamps) for security and troubleshooting. Logs are rotated and are not used to profile you.
- Cookies. This website currently sets only the minimal cookies WordPress needs to function. We do not use advertising or cross-site tracking cookies. If we add a website analytics tool (such as Google Analytics) to measure page performance, this policy will be updated to name it.
- Fonts. Our pages load fonts from Google Fonts, which means your browser requests font files from Google’s servers (disclosing your IP address to Google in the process, as with any web request). Google’s privacy policy governs that request.
How we use it
- To respond to enquiries, arrange demos and provide the quote you asked for.
- To operate, secure and improve this website.
- To comply with applicable law.
We do not sell personal data, and we do not send marketing to people who merely enquired and said no.
WhatsApp buttons
Our demo and contact buttons open WhatsApp with a pre-filled message. Your use of WhatsApp is governed by WhatsApp’s own terms and privacy policy. Business messaging from FitSync uses the official WhatsApp Business Cloud API operated by Meta.
Part 2 — Data inside the FitSync application
Gyms use FitSync to manage their members, payments, attendance, follow-ups and staff. For that data, the gym is the data fiduciary (it decides why and how member data is used) and FitSync is a data processor — we process it only to provide the service, on the gym’s instructions. If you are a gym member with a question about your data, your first point of contact is your gym; we assist gyms in meeting such requests.
What the application processes
- Member records: name, phone, email, date of birth, gender, photograph, membership package, validity dates and training type.
- Payment entries: amount, payment mode (cash / card / UPI / bank), date, dues and receipts. FitSync records these as entries made by gym staff — we do not collect, process or store card numbers, UPI PINs or banking credentials.
- Attendance: check-in records (member, time, branch), including check-ins from an optional face-recognition access device.
- Follow-ups and enquiries: call notes, lead details and assignment records.
- Staff records: profiles, attendance, targets, sales attribution and salary records (visible only to owner/super-admin roles).
- WhatsApp messages: receipts, reminders and replies sent or received through the official WhatsApp Business Cloud API, including delivery logs.
Face-recognition attendance
Where a gym uses face-recognition check-in: the face matching itself runs on the access device installed inside the gym’s own network — not in our cloud. FitSync’s servers store the member’s profile photograph and the resulting check-in records, and can push a member’s profile photo to the gym’s own on-site device to enrol them. A member’s face enrolment can be deleted on request to the gym; such deletions are recorded in the application’s activity log. Gyms are responsible for informing members and obtaining any consent required before enrolling them in face-recognition check-in, and manual check-in is always available as an alternative.
Where the data lives
- Hosted on servers located in India (DigitalOcean’s Bengaluru datacenter).
- Encrypted in transit (HTTPS).
- Backed up daily, with backups retained on a 14-day rotation.
Who can see what
Access inside the application is role-based (Super Admin, Owner, Front Desk, Trainer) with per-staff granular permissions and branch-level isolation. Finance and salary data is restricted to owner/super-admin roles. Every data export from the application is logged — who exported, when, and from which branch.
Sub-processors
We use a small number of third-party services to run FitSync:
- DigitalOcean — cloud infrastructure (India region) that hosts the application and this website.
- Meta Platforms (WhatsApp Business Cloud API) — delivery of WhatsApp messages; message content necessarily passes through Meta’s systems for delivery.
- Google — web fonts on this website (see Part 1).
We do not share customer data with advertisers or data brokers, and we do not use gym members’ data to train models, run ads or for any purpose other than providing the service.
Retention and exit
Gyms can export their full data at any time. When a gym stops using FitSync, we provide a complete export on request and delete the gym’s live data within 60 days of termination (sooner on request), after which residual copies age out of the backup rotation. Enquiry correspondence on the website side is kept only as long as needed to serve you and meet legal obligations, then deleted or anonymised.
Your rights
Under the DPDP Act, you have the right to access a summary of your personal data, request correction or erasure, have your grievance heard, and nominate a person to exercise your rights on your behalf. To exercise these rights:
- Website enquiries: contact us directly using the details below.
- Gym members: contact your gym (the data fiduciary); we support gyms in fulfilling these requests, including correction, export and deletion of member records and face enrolments.
Children
Our website and marketing are directed at gym owners and managers, not children. Where a gym enrols a minor as a member, obtaining verifiable parental or guardian consent is the gym’s responsibility as the data fiduciary.
Security
We protect data with HTTPS everywhere, role-based access control, branch isolation, logged exports, hardened servers with restricted access, and daily verified backups. No system is perfectly secure; if we become aware of a personal data breach affecting you or your gym, we will notify affected customers and authorities as required by law.
Grievances
Complaints and grievances go to our Grievance Officer at the contact below. We aim to acknowledge within 48 hours and resolve within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India under the DPDP Act.
Changes to this policy
We may update this policy as the product or law evolves. Material changes will be reflected on this page with a new “last updated” date, and significant changes affecting gym customers will be notified to them directly.
Contact
Grievance Officer, FitSync, New Delhi, India · fitsync.co.in@gmail.com · +91 90349 86123