Who this applies to
Everyone who touches the service: the gym that holds the account, its staff, its members using the self-service portal, and anyone using our API. It forms part of the terms of service, so breaking it breaks the contract.
Member data
- Collect only what your gym actually needs, and tell members what you hold.
- Take written consent before biometric enrolment, and always offer a card or PIN alternative.
- Never enrol a member’s biometrics without them present and willing.
- Do not upload identity documents, Aadhaar numbers, health reports or photographs of minors.
- Do not export a member list to sell, rent or share with another business.
- Do not use attendance data to harass, shame or publicly rank members.
Messaging
FynGym sends transactional messages to your own members: renewals, dues, receipts, class changes. That is what the templates and credits are for.
- No unsolicited marketing to numbers that did not opt in.
- No messages to purchased or scraped lists.
- Honour every opt-out immediately; we enforce it at platform level.
- Respect TRAI rules on commercial communication, including quiet hours.
- No misleading sender names, fake offers or content unrelated to your gym.
Spam complaints above the network threshold will suspend your messaging credits while we investigate, even before we hear from you.
Security
- No probing, scanning or load-testing our systems without written permission.
- No attempting to reach another gym’s workspace, or to bypass roles and permissions.
- No sharing logins between people, and no leaving a front-desk session signed in unattended.
- No uploading malware, or files intended to break parsers or browsers.
- No circumventing rate limits, or running more than 20 API requests a second without an agreed quota.
Responsible disclosure is welcome and rewarded. Email security@fyngym.com before you test anything.
Fair use of the platform
Plans are sized for a gym, not a data warehouse. Do not resell access, run another product on top of our API, mine the platform for a competing dataset, or use automation to create thousands of fake member records.
If your legitimate usage grows past your plan’s limits we will tell you and offer the right plan. We do not throttle you without warning.
Content
Announcements, class descriptions, member notes and uploaded files must not contain unlawful, obscene, defamatory or hateful material, must not infringe copyright, and must not impersonate anyone. Internal staff notes are not private from the member they describe — write them accordingly.
How we enforce it
Most issues are a misunderstanding, so our first step is an email explaining what we saw. From there:
| Situation | What we do |
|---|---|
| Minor or first-time issue | Notice, with 15 days to fix it |
| Repeat or unresolved issue | Feature suspension, such as messaging |
| Serious risk to members or the platform | Immediate suspension, then investigation |
| Unlawful use | Termination and, where required, report to authorities |
Suspension for breach does not earn a refund. If we got it wrong, we restore access and say so.
Reporting abuse
If you are a member and your gym is misusing your data, or you see something on the platform that should not be there, write to abuse@fyngym.com. We acknowledge within one working day and investigate confidentially.
Questions about this document?
Write to privacy@fyngym.com or post to the Grievance Officer, Webspace IN Private Limited, 4th floor, Pride Icon, Kharadi, Pune, Maharashtra 411014. We answer legal and data requests within seven working days.