Preparing your experience
We take your privacy seriously. This policy explains what data we collect, how we use it, and the rights you have.
Last updated: June 9, 2026
Table of Contents
When you register for GMS, we collect your name, email address, phone number, gym name, and subdomain. This information is required to create and manage your account.
As a gym owner, you may input member profiles including names, contact details, membership plans, attendance records, and payment history. This data is stored securely and accessible only to authorized users within your gym account.
We collect payment records entered by gym staff (amount, method, date). We do not store full credit/debit card numbers. Payment processing for GMS subscriptions is handled by third-party processors who comply with PCI-DSS standards.
We automatically collect information about how you use our platform — pages visited, features used, browser type, IP address, and device identifiers — to improve our service and ensure security.
Your data powers the GMS features you use — creating member profiles, processing payments, sending WhatsApp reminders, generating attendance reports. Without it, the platform cannot function.
We use your contact details to send you billing notifications, product updates, and security alerts relevant to your account. If you opt into our newsletter, we may also share gym-growth tips. You can opt out of promotional messages at any time from your account settings.
Aggregated, anonymised usage patterns help us understand which features gym owners rely on most, where users get stuck, and what to build next. This analysis never identifies you personally.
Where Indian law or a valid legal order requires us to act on data — for example, a court order or government request — we will do so. We will notify you when legally permitted.
We do not sell, license, or broker your personal information or your gym members' data. Full stop. Monetising your data is not part of our business model — our revenue comes from your subscription.
GMS runs on cloud infrastructure, so some data necessarily passes through the servers that host our platform. We also use tools for transactional email and error tracking. All such partners are vetted and operate under strict data handling agreements that prohibit them from using your data for anything other than delivering our service.
When you turn on WhatsApp reminders, your members' phone numbers are passed to the messaging integration only to deliver the message you configured. The number is not stored, profiled, or reused by the provider after delivery.
If we receive a lawful request from an Indian government authority or court that compels disclosure of specific data, we will comply. Where the law allows, we will inform the affected account holder before disclosing.
GMS is built as a strict multi-tenant platform. Every piece of data — members, payments, attendance, staff — is scoped to your gym's unique account. No two gyms share a data boundary, and no gym can ever view or interact with another gym's records.
Data moving between your browser and our servers is protected with TLS transport security. Data stored on our servers uses strong encryption at rest. Account passwords are run through a one-way hashing process and the original value is never retained anywhere in our system.
GMS enforces permission tiers across all account roles. A receptionist can check in members but cannot edit pricing. A trainer sees only their assigned clients. Branch managers see only their branch. The gym owner holds full access. Every sensitive action is recorded in an audit trail.
Should a security incident occur that affects your data, our team will assess its scope and impact, notify affected account holders promptly, and take swift action to contain the situation. We aim to communicate within 72 hours of confirmed discovery as a guiding target, consistent with responsible disclosure standards.
You can view and export almost all your data directly from the GMS dashboard at any time. If you need a full structured export of everything we hold, email us at info@workflowgym.com and we will prepare it within 7 business days.
Wrong email on your account? Old gym name? Update it directly in Settings. If something is stuck or you cannot change it yourself, our support team will correct it for you — usually the same day.
You can close your GMS account at any time from Settings → Account. When you do, we permanently remove all your gym data — members, payments, attendance, everything — within 30 days. There is no recovery after that window, so export first if you want a copy.
You can ask us to stop using your data for optional purposes like product improvement analytics. We will honour that request. For uses that are essential to running your account (like processing payments), we cannot opt you out — but you can close the account entirely if you prefer.
We keep your data for as long as your GMS account is open. The moment you close it, the deletion process begins.
Personal data — names, emails, payment records, member profiles — is wiped within 30 days of account closure. Anonymised, aggregated usage statistics (such as "how many check-ins happened this month") contain no personally identifiable information and may be retained to inform platform improvements.
Indian tax and financial regulations may require us to hold certain billing records for up to 7 years. In those cases, only the minimum required records are kept and they are not used for any other purpose.
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact our team. We will respond within 5 business days.
For privacy-related enquiries, reach us at:
© 2026 WFG — WorkflowGym. All rights reserved.