Last updated 27 September 2026
Privacy Policy
What we collect, why we collect it, and what you can ask us to do with it.
Who this policy is for
GymCaptain is gym management software. Two kinds of people appear in it: the gym owner or staff member who holds an account and signs in, and the gym's members, whose details staff enter to run the gym.
Gym owners decide what member information to record and are responsible for telling their members about it. We process that information on their behalf and do not use it for anything else.
What we collect
Account holders (gym owners and staff) give us:
- Name, email address and phone number
- A password, stored only as a one-way hash — we cannot read it
- Gym name, address and contact number
What gym staff record about members
Staff enter member details to run the gym. Only name and phone number are required; everything else is optional and left blank unless the gym chooses to record it.
- Name, phone number and joining date
- Optionally: email, date of birth, gender, address, father's name, occupation, height, blood group and fitness goal
- Optionally: an emergency contact name and number
- Optionally: a profile photo
- Membership plans, payments, attendance check-ins and body measurements recorded over time
How we use it
We use this information only to provide the service: showing the roster, tracking membership expiry, recording check-ins and payments, and producing the reports a gym owner asks for.
We do not sell personal information. We do not share it with advertisers. We do not use it to train machine learning models.
Where it is stored
Data is stored on Amazon Web Services and Neon, in data centres in Asia. Connections use TLS, and member photos are kept in private storage that is only reachable through short-lived signed links.
Passwords are hashed. Sessions use signed tokens that expire.
Who else can see it
A gym's data is visible only to that gym's own account holders. Gyms cannot see each other's members.
We use a small number of infrastructure providers to run the service — Amazon Web Services for hosting and storage, and Neon for the database. They process data on our instructions and for no purpose of their own.
We disclose information to anyone else only where the law requires it.
How long we keep it
We keep data for as long as the account is open. When an account is deleted, its gyms, members, photos, payments and check-ins are deleted with it — see the account deletion page for details and timing.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to md.alishanali88@gmail.com and we will respond within 30 days.
Gym members who want their details changed or removed should ask their gym, since the gym controls that record. If the gym does not respond, write to us and we will help.
Children's data
GymCaptain is for gym staff and is not directed at children. Where a gym records a member under 18, the gym is responsible for having the consent it needs.
Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes will be notified to account holders by email.
Contact
Questions about this policy: md.alishanali88@gmail.com