How GymCore Apps handles personal information.
Effective June 6, 2026. This policy explains what we collect, why we collect it, how we protect it, and how gyms and users can exercise privacy rights.
1. Who we are and our role
GymCore Apps provides a Canadian branded gym software platform, including platform web tools, Front Desk web tools, a unified mobile app template with member and trainer experiences, support, build workflows, and optional payment integrations.
Our role is hybrid. We are accountable for information we collect directly for owner accounts, staff accounts, billing, support, security, and platform operations. For gym-controlled member, guardian, staff, attendance, shop, badge, news, trainer, and personal-training records, we act as a service provider or software processor for the gym that controls those records.
Jason Wall, Owner and Privacy Lead of GymCore Apps, is the named person responsible for GCA privacy accountability and privacy operations.
2. Information we collect
Depending on how the service is used, we may process these categories of personal information:
- Owner and staff account details such as name, email, telephone number where supplied, roles, permissions, authentication state, and invite status.
- Gym configuration, branding, media, forms, app settings, locations, operating hours, class rooms, memberships, add-ons, and launch intake information.
- Support messages, account notices, operational requests, trainer communications, and platform audit events.
- Billing and subscription identifiers, Stripe customer, checkout, subscription, order, and connected-account references, and payment status metadata.
- Member, student, guardian, barcode, membership, attendance, check-in, notification, access-code, shop order, badge, and news records entered or generated by gyms.
- Trainer profiles, profile images, biographies, qualifications, class notes, 1-on-1 client cards, session bookings, check-ins, session timing, trainer notes to members, and optional member feedback.
- Optional personal-training profile notes, health notes, goals, age, sex, and physical stats if a gym or trainer chooses to enter them.
- Device, session, security, and diagnostic information needed to run the web and mobile experience.
3. Information we do not store
We design the platform to avoid storing information we do not need. We do not intentionally store:
- Raw card numbers, card security codes, bank payout credentials, or complete payment account data. Stripe handles payment processing.
- Stripe identity verification documents or raw verification details, except limited status or account references needed for platform operation.
- Plaintext passwords or Supabase Auth password hashes.
- Supabase service-role keys, production secrets, or other secret credentials in tenant exports.
- Unrelated tenant records in customer exports.
4. Why we use information
We use personal information to provide and secure the service, including to:
- Create and manage accounts, invites, roles, permissions, and staff access.
- Generate and operate branded gym apps, Front Desk tools, trainer tools, member tools, schedules, attendance, badges, news, shop workflows, and support workflows.
- Process subscriptions, platform billing, optional gym payments, access-code redemptions, refunds, disputes, and order fulfillment through payment providers.
- Send transactional emails, app notifications, account notices, trainer communications, support replies, and operational alerts.
- Detect, investigate, and prevent abuse, unauthorized access, security events, billing issues, and service misuse.
- Maintain backups, logs, audit records, legal compliance records, and service reliability.
Mobile location may be used for check-in radius verification. Normal attendance records store the verification result and relevant device or context metadata, not exact submitted user coordinates.
5. Consent and gym responsibilities
We rely on meaningful consent, contractual necessity, legal obligations, and legitimate service operations as applicable. Gym owners and administrators are responsible for collecting member, guardian, staff, and trainer information lawfully, providing appropriate privacy and waiver notices, and obtaining required consent before entering records into the platform.
Gyms are especially responsible for appropriate consent for children and youth member records. Where optional trainer notes or health-related fields are used, gyms and trainers should only enter information that is necessary for the service and appropriate for their business context. Ontario health privacy laws, including PHIPA, may be relevant if a gym or professional acts as a health information custodian or handles health information in that capacity.
6. Service providers and cross-border processing
We may use service providers to host, secure, build, deliver, support, and process the service. These may include Supabase, Vercel or other hosting providers, Stripe, Resend, Expo, GitHub Actions or build automation, Apple and Google app-store services, Google Maps geocoding, Cloudflare, backup storage providers, and professional advisors.
Personal information may be processed outside Canada by us or our service providers. We use contractual, organizational, and technical safeguards appropriate to the sensitivity of the information and the provider role, while recognizing that information processed in another jurisdiction may be accessible to courts, law enforcement, or regulators in that jurisdiction.
7. Safeguards and breach response
We use safeguards such as tenant-scoped access controls, authenticated APIs, role permissions, row-level security, environment-secret separation, encrypted transport, provider security controls, backups, audit logs, and operational runbooks. No system is perfect, but we work to reduce risk and limit access to what is needed.
We maintain records of safeguards breaches as required by PIPEDA. If a breach creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required, and we will support affected gyms with information reasonably needed for their own notification duties.
8. Retention and deletion
Active tenant data is retained while the service is active. After final cancellation, tenant operational data is retained for six months for export, recovery, and wind-down support, then destroyed or de-identified unless a longer period is required for legal, billing, security, dispute, audit, or backup reasons. Backups rotate separately under operational backup schedules. Breach records are retained for at least two years, and billing or audit records may be retained as legally or operationally required.
9. Access, correction, deletion, and challenges
Individuals may request access to, correction of, or deletion of personal information, or challenge our compliance with this policy. Gym members should usually contact their gym first because the gym controls most member records. We will support tenant requests where we operate the platform and will respond to direct GCA account, billing, support, and platform privacy requests.
Privacy requests can be sent to Jason Wall, Owner and Privacy Lead of GymCore Apps, at privacy@gymcoreapps.ca. Support requests can be sent to support@gymcoreapps.ca.
10. Changes to this policy
We may update this policy as the service, law, or provider list changes. When changes are material, we will update the version and effective date and may require platform owners, administrators, and trainers to accept the updated documents before continuing.
