GymPro by SRTDigi β your privacy is our priority.
SRTDigi (βweβ, βourβ, βusβ) operates the GymPro gym management platform available at srtdigi.inand associated mobile applications (collectively, the βServiceβ).
This Privacy Policy explains what personal information we collect, why we collect it, how it is stored, who we share it with, and your rights in relation to it. By using the Service, you agree to the collection and use of information in accordance with this policy.
This policy complies with the Information Technology Act, 2000 and its amendments (India), the GDPR (for EU/EEA users), and the DPDP Act, 2023 (Digital Personal Data Protection Act, India).
A. Account & Profile Data
B. Member & Gym Data (uploaded by gym owners)
C. Usage & Technical Data
D. Communications
π³ Important β We do NOT store your card details
GymPro does not store, process, or transmit credit/debit card numbers, CVV codes, or bank account details on our servers. All payment data is handled exclusively by our certified PCI-DSS Level 1 payment partners.
Payment Processors We Use:
What we do receive from payment processors:
Gym member payments: When gym owners collect membership fees through GymPro's integrated billing, the same PCI-DSS protections apply. Gym owners are responsible for obtaining member consent to process payments via GymPro.
Authentication for GymPro is powered by Clerk (clerk.com), a SOC 2 Type II certified authentication provider. Clerk handles:
Clerk's privacy policy: clerk.com/privacy
We store your Clerk User ID linked to your gym profile in our own database. We do not store passwords. Session tokens expire after 24 hours of inactivity.
We do not sell your personal data to advertisers or data brokers.
We only share data with third parties in the following circumstances:
Clerk (Authentication)
User identity and session management.
Razorpay / Stripe (Payments)
Billing data for subscription and member payments.
Vercel / AWS (Hosting)
Platform infrastructure and CDN delivery. Data processed in India/US/EU data centres.
Resend / SendGrid (Email)
Sending transactional emails. Email address only.
Analytics (Privacy-first)
Anonymised usage metrics. No individual tracking.
Legal Authorities
If required by Indian law, court order, or regulatory authority.
Where data is stored: Primary data is stored on servers within India (Mumbai region) and replicated to Singapore for disaster recovery. EU user data may be stored in the EU region.
Security measures we implement:
You may request early deletion by contacting us at privacy@srtdigi.in, subject to legal retention requirements.
Depending on your jurisdiction, you have the following rights regarding your personal data:
ποΈ
Right to Access
Request a copy of all data we hold about you
βοΈ
Right to Rectification
Correct inaccurate or incomplete data
ποΈ
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
π¦
Right to Portability
Receive your data in a portable, machine-readable format
π«
Right to Object
Object to processing for marketing purposes
βΈοΈ
Right to Restriction
Request restriction of processing in certain circumstances
π€
Right to Consent Withdrawal
Withdraw consent at any time without affecting prior processing
π’
Right to Complain
Lodge a complaint with your national data protection authority
To exercise any right, email privacy@srtdigi.in. We will respond within 30 days.
GymPro is intended for business operators aged 18 and above. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal information, please contact us at privacy@srtdigi.in and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
Continued use of the Service after changes constitutes acceptance of the updated policy.
Data Controller
SRTDigi
Website: https://srtdigi.in
Privacy enquiries: privacy@srtdigi.in
For GDPR-related requests, include βGDPR Requestβ in your email subject line. For DPDP Act requests, include βDPDP Requestβ.