PrivacyAccount deletionTermsSign in
Privacy at Gymatic

Privacy Policy

This policy explains how Gymatic handles information across our website, organization accounts, gym workspaces, local reception devices and connected services.

Effective date5 August 2026Version1.0

1. Who we are and what this policy covers

Gymatic, an IsotopeOS product (“Gymatic”, “we”, “us” or “our”), provides business software for gyms and fitness organizations. This policy applies to our public website, organization accounts, gym-management applications, mobile applications, Gymatic Bridge software, support services and related commercial communications (together, the “Services”).

It does not replace the privacy notices that a gym provides to its own members, employees or trainers. Each gym organization remains responsible for explaining its own data practices and obtaining any consent it requires.

2. Our role and your gym’s role

For member, staff, attendance, access, payment and other operational records entered by a gym, the subscribing organization decides why and how that information is used. Gymatic processes that information on the organization’s instructions to provide the Services.

Gymatic acts for its own purposes when handling website analytics, organization registration, account administration, subscription billing, security logs, service communications and support requests.

3. Information we handle

  • Account information: names, work email addresses, phone numbers, authentication identifiers, roles and organization invitations.
  • Organization information: legal and trading names, branch locations, packages, regional settings, staff assignments and subscription details.
  • Gym operational data: member profiles, contact information, photographs, membership plans, dues, payment records, attendance, access decisions, credential identifiers, trainer assignments and notes entered by authorized users.
  • Device and technical data: IP address, browser and operating-system information, application events, synchronization status, Bridge connectivity, hardware event identifiers and security logs.
  • Commercial information: invoices, plan usage, tax information and payment confirmation. Card or bank-payment details may be collected directly by a payment provider rather than Gymatic.
  • Communications: support conversations, implementation notes, feedback and records of notices we send.

Raw biometric templates should remain within the gym’s biometric hardware unless a separate written configuration explicitly provides otherwise. Gymatic may receive a device-generated credential or event identifier used to match an access event to a member record.

4. How we use information

  • Provide, secure and maintain the Services.
  • Authenticate users and enforce owner, manager, receptionist, trainer and member permissions.
  • Process member access, attendance, memberships, payments and branch operations on the organization’s instructions.
  • Synchronize authorized records between local devices and the organization’s cloud environment.
  • Administer subscriptions, invoices, regional plans and customer support.
  • Detect abuse, investigate security incidents and maintain audit records.
  • Improve reliability and usability using aggregated or de-identified information where practical.
  • Comply with applicable law and valid legal process.

We do not sell personal information or use gym member records for third-party advertising.

5. Local-first operation and Gymatic Bridge

To keep reception operating during short connectivity interruptions, an authorized device may temporarily retain member lookups, access rules, queued events and related operational information. The device synchronizes eligible records when connectivity returns.

The organization is responsible for securing reception devices, operating-system accounts, local networks and connected hardware. Removing browser data, uninstalling the application or replacing a device may remove locally queued information that has not synchronized.

Gymatic Bridge translates supported RFID, biometric and gate hardware events into a standard interface. Bridge logs may contain device identifiers, timestamps, access results and diagnostic information needed to operate or troubleshoot the integration.

6. When we share information

We may share only the information reasonably necessary with:

  • Cloud hosting, authentication, database, monitoring, communications and customer-support providers.
  • Payment processors, banks and tax or accounting providers involved in subscriptions or transactions.
  • Implementation partners or hardware vendors authorized by the subscribing organization.
  • Professional advisers, auditors, insurers and prospective transaction parties subject to confidentiality obligations.
  • Courts, regulators, law-enforcement bodies or other parties when disclosure is legally required or necessary to protect rights, safety and service integrity.

Service providers may process information only for contracted purposes and are expected to apply appropriate confidentiality and security controls.

7. International processing

The Services may use infrastructure or providers located outside the country where a user or gym member is located. When information is transferred internationally, we apply contractual, organizational and technical safeguards appropriate to the information and applicable requirements.

Some regulated organizations may have additional localization or sector-specific obligations. Customers are responsible for telling us about mandatory requirements before enabling a service or integration that may be affected.

8. Retention and deletion

We retain information for as long as needed to provide the Services, satisfy the organization’s documented settings, maintain security and audit records, resolve disputes and meet legal, tax or accounting obligations.

After an organization account ends, we may provide a limited export period before deleting or anonymizing customer data, subject to backups, legal holds and the applicable service order. Backup copies may remain for a limited period until they are overwritten through normal processes.

Gym members and trainers can review the account and data deletion instructions to request removal of mobile access and associated personal data.

9. Security

We use measures designed to protect confidentiality, integrity and availability, including role-based access, authentication controls, encryption in transit where supported, organization isolation, audit logging, monitoring and restricted administrative access. No system can guarantee absolute security.

Organizations must use strong credentials, assign the minimum necessary permissions, remove departed staff promptly and report suspected compromise without delay.

10. Your choices and rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, portability or withdrawal of consent. Gym members and staff should normally submit requests to the gym organization that controls their record. We will assist subscribing organizations with appropriate requests as required by contract or law.

Account holders may update certain information within their workspace. We may need to verify identity and authority before completing a request, and lawful exceptions may apply.

11. Children and younger members

Organization accounts are intended for authorized adults acting for a business. Gyms may maintain memberships for minors, but the gym is responsible for parental or guardian notices, consent and age-appropriate handling required by applicable law. Gymatic does not knowingly invite children to create organization administrator accounts.

12. Website technologies

We use essential browser storage for sign-in, security, preferences and service operation. On our public marketing website, Google Analytics 4 loads only after you accept optional analytics. Rejecting analytics does not prevent you from using the website.

With your permission, Google receives public page views and selected actions, such as opening the demo or clicking pricing, signup or app-download links, together with browser and device information. We send clean public page URLs and referring-site origins, excluding URL queries and fragments. We do not intentionally send names, email addresses, phone numbers, authentication tokens or gym member records. Analytics is not installed in the account application or gym workspaces.

Advertising storage, advertising personalization and Google Signals are disabled in this integration. Analytics cookies and your consent choice expire after 180 days. You can change your choice using “Cookie preferences” in the footer; withdrawing consent stops collection and removes this website’s analytics cookies. Previously collected information is not automatically deleted by withdrawal. Learn more about how Google uses information from websites that use its services.

13. Changes and contact

We may update this policy as the Services, our providers or applicable requirements change. Material updates will be identified by a new effective date and may also be communicated through the website, workspace or registered account email.

Privacy questions and requests may be submitted through the official support contact shown in the organization workspace or the customer’s service order. If that contact is unavailable, email privacy@gymatic.co. Legal notices should identify the organization, the requester’s relationship to it and the nature of the request.

© 2026 Gymatic · An IsotopeOS productReturn to GymaticCookie preferences