Who we are
FynGym is a product of Webspace IN Private Limited (CIN U62012JH2026PTC028026), a company registered in India with its office at 4th floor, Pride Icon, Kharadi, Pune, Maharashtra 411014. In this policy “we” and “us” mean that company.
We act in two different roles. For the gym owners and staff who hold a FynGym account, we are the data fiduciary. For the member records a gym stores inside its own FynGym workspace, the gym is the data fiduciary and we are the data processor acting on its instructions. That split matters, and section 4 explains it.
What we collect
From account holders: name, gym name, business address, mobile number, email, GSTIN, payment identifiers returned by our gateway, and the IP address and device used to sign in.
From members, on behalf of the gym: name, contact details, date of birth, sex where the gym records it, membership and payment history, attendance timestamps, and — where the gym uses biometric check-in — an encrypted mathematical template derived from a face or fingerprint.
Automatically: log data such as pages visited, actions taken, error traces, device model and browser. On our website, the cookies described in the cookie policy.
We do not collect health records, government identity numbers or caste or religion data, and we ask gyms not to store them in free-text fields.
Biometric data, specifically
We never store photographs or fingerprint images for matching. A reader converts the scan into a one-way numeric template on the device; that template cannot be reversed into a face or a fingerprint. Templates are encrypted at rest with per-gym keys and are never used for anything except check-in for that gym.
A member may refuse biometric enrolment. Gyms must offer an alternative — a card, PIN or manual check-in — and must take written consent before enrolling anyone. When a membership ends, the template is deleted within 30 days.
Gym data versus our data
We do not decide what a gym does with its member list. We do not sell it, mine it for advertising, or use it to train models. We access it only to run the service, fix a fault you report, or where the law requires it — and every such access is written to an audit log the gym can request.
If you are a gym member with a question about your record, contact your gym first: they control it. If they do not respond, write to us and we will route your request.
Why we use it
- To provide the service — check-in, billing, messaging and reporting are the product.
- To take payment — subscription charges, invoices, GST compliance and dunning.
- To support you — answering tickets, diagnosing a device, restoring a backup.
- To keep the platform safe — fraud checks, rate limits, abuse investigation.
- To improve the product — aggregated, de-identified usage counts only.
- To meet legal duties — tax records, statutory notices, lawful requests.
We rely on your consent, on the performance of our contract with you, and on our legitimate interests in running a secure service, as permitted under the Digital Personal Data Protection Act, 2023.
Where it is stored
Primary storage is in Mumbai with an encrypted replica in Hyderabad. Some support and error-reporting tools process limited data outside India; where that happens we use contractual safeguards and keep the data minimal. A gym on the Multi-site or Enterprise plan can require that all processing stays within India.
How long we keep it
| Data | Retention |
|---|---|
| Active account and member records | While the account is live |
| Biometric templates | Deleted 30 days after membership ends |
| Attendance and payment history | 8 years, for tax and dispute purposes |
| Closed account data | 60 days, then permanent deletion |
| Support tickets | 3 years |
| Server and audit logs | 13 months |
| Backups | 35 days, rolling |
How we protect it
TLS 1.2+ in transit, AES-256 at rest, per-gym encryption keys for biometric templates, two-factor authentication on every staff account, least-privilege access with quarterly review, hourly encrypted backups with tested restores, and an audit log on every write.
If a breach is likely to affect you, we will notify you and the Data Protection Board of India without undue delay, with what happened, what data was involved and what we are doing about it.
Your rights
Under the DPDP Act you may ask us for a copy of your data, correct it, have it erased, withdraw a consent you gave, nominate someone to act for you if you cannot, and complain about how we handled it.
Write to privacy@fyngym.com. We verify who you are, then answer within seven working days and always within 30 days. There is no fee. If you are unhappy with our answer, you may escalate to the Data Protection Board of India.
Children
FynGym accounts are for adults running a business. A gym may enrol a member under 18 only with verifiable consent from a parent or guardian, and must not enable biometric check-in for anyone under 14. We do not profile or target children in any way.
Changes to this policy
If we make a material change we will email account holders and show a notice inside the console at least 14 days before it takes effect. Older versions are available on request. Continuing to use FynGym after a change means you accept the updated policy.
Questions about this document?
Write to privacy@fyngym.com or post to the Grievance Officer, Webspace IN Private Limited, 4th floor, Pride Icon, Kharadi, Pune, Maharashtra 411014. We answer legal and data requests within seven working days.