Fitness ERP · Legal
Privacy Policy
Last updated: 4 July 2026
This Privacy Policy explains how Clicknify ("Clicknify", "we", "us") handles data on Fitness ERP (the "Service"). It applies to gym owners and staff who use the Service directly, and to the member data those gyms store within it.
1. Who controls what
Fitness ERP is used by gyms to manage their own members. In data-protection terms, the Gym Owner is the data controller for the information they enter about their members, staff, invoices, and inventory — they decide what to collect and why. Clicknify acts as a data processor, storing and processing that data only to provide the Service, on the Gym Owner's instructions.
2. What we collect
- Account data — name, email, phone number, and a securely hashed password for anyone who signs up (gym owners, staff, trainers).
- Member data entered by gym staff — name, phone, address, an optional profile photo, membership tier and plan, attendance check-ins, and billing/payment history.
- Payment data — subscription payments to Clicknify, and membership/POS payments a gym's own members make to that gym, are processed by Razorpay. We store transaction references, amounts, and status — never raw card numbers or UPI credentials, which Razorpay handles directly.
- Usage & security data — login timestamps, an audit trail of key actions (e.g. who created or edited a record), and basic technical logs used to keep the Service reliable and secure.
3. How we use it
Data is used to: operate the Service (member records, invoicing, attendance, reporting); process payments; send account, billing, and attendance-alert emails; keep the platform secure and investigate misuse; and respond to support requests. We do not use member data for advertising, and we do not sell personal data to third parties.
4. Where data lives & how it's protected
- Data is hosted on Supabase (PostgreSQL), in the Mumbai (India) region.
- Passwords are hashed (never stored in plain text); sensitive payment-gateway credentials are encrypted at rest (AES-256-GCM) and never exposed in plain form after being saved.
- Each gym's data is logically isolated — every record is scoped to that gym's account, and the application enforces this on every request so one gym cannot see another's data.
- Access to administrative and platform-level tooling is restricted by role.
5. Who we share data with
We share data only with the infrastructure providers needed to run the Service: Razorpay (payment processing), Supabase (database and file storage), and Resend (sending transactional email such as receipts and absent-member alerts). Each is bound by its own security and privacy commitments. We do not share data with advertisers or data brokers.
6. How long we keep data
Invoices, payments, refunds, and credit notes are retained for at least 3 years in line with Indian tax record-keeping requirements. Other member and account data is retained for as long as the gym's account remains active, and is deleted or anonymised on request after account closure, subject to the retention obligations above.
7. Your rights
If you are a gym member, requests to access, correct, or delete your personal data should first go to your gym — they control that data and can action most requests directly within the Service. If you're a gym owner/staff account holder, or if your gym is no longer able to help, you can reach us directly (see Contact below) and we will assist within a reasonable time.
8. Cookies & sessions
We use a single secure session cookie to keep you signed in. We do not use third-party advertising or tracking cookies.
9. Children's data
Fitness ERP is intended for use by gym staff managing their business. Some gyms may have members under 18 — where a Gym Owner enters a minor's details, the Gym Owner is responsible for ensuring it has appropriate parental/guardian consent to do so.
10. Changes to this policy
We may update this Privacy Policy from time to time; the "Last updated" date above will reflect the most recent revision. See also our Terms & Conditions.
11. Contact
Privacy questions or requests can be sent to support@clicknify.com.