Skip to main content
Legal

Privacy Policy

Your gym's data and your members' data are yours. This page explains exactly what we collect, why we collect it, who we share it with, and how you stay in control.

Last updated: 2 August 2026

1. Overview

This Privacy Policy explains how Smarto Gym ("Smarto Gym", "we", "us") handles personal information across our website at https://smartogym.in, our dashboard at app.smartogym.in, and our support channels.

It applies to two different groups of people, and it matters which one you are:

  • Gym owners and staff who register and use Smarto Gym. We decide how your account information is handled, so we are the data fiduciary (controller) for it.
  • Gym members whose details a gym enters into the platform. The gym decides what to collect and why; we only process that data on the gym's instructions as a data processor. If you are a member with a question about your records, please contact your gym first — they control that data.

2. Information we collect

Account information you give us. Your gym's name and location, your name, email address, mobile number, sign-in credentials (stored only as a secure hash), your chosen subscription plan and your billing details.

Member records you enter. Whatever your gym chooses to store about its members — name, photo, contact number, address, membership plan, joining and expiry dates, registration ID, payments and outstanding balances, attendance history, and any notes you add.

Biometric data (only if you enable it). Where your gym uses fingerprint attendance or door access, the connected device generates a mathematical template from a fingerprint and links it to a member record. See section 6 for how this is treated.

Payment information. Subscription payments are processed by third-party payment gateways. We receive confirmation of the transaction — amount, status, timestamp, a reference ID and the last few digits of the instrument. We never receive or store your full card number, CVV, UPI PIN or net-banking credentials.

Technical and usage information. IP address, browser and device type, pages viewed, dates and times of access, and diagnostic logs. We use this to keep the Service secure, debug problems and understand which features are used.

Communications. Emails, WhatsApp messages and support conversations you have with us, including any attachments you send.

3. How we use information

We use the information above to:

  • Create and run your gym's workspace and provide the features you subscribed to;
  • Process subscription payments, issue receipts and manage renewals;
  • Send service messages — renewal reminders, expiry warnings, security alerts and important changes;
  • Provide support when you contact us and investigate issues you report;
  • Keep the platform secure — detect fraud, abuse, unauthorised access and technical faults;
  • Improve the product, using aggregated and de-identified statistics wherever possible;
  • Meet our legal, tax and accounting obligations.

We do not sell your data or your members' data. We do not share it with other gyms, and we do not use member records for our own marketing.

5. Member data — what your gym is responsible for

Your members' records belong to your gym. We act on your instructions, and we will not access, disclose or use them for anything other than running the Service, supporting you, or complying with the law.

As the gym, you are responsible for:

  • Telling your members what you collect and why, through your own privacy notice;
  • Having a lawful basis or consent for the records you enter;
  • Keeping the records accurate and up to date;
  • Responding to members who ask to access, correct or delete their information.

We will help you action any of those requests inside the dashboard, and we will pass on to you any request a member sends us directly.

6. Biometric data

Fingerprint data is sensitive, and we treat it differently from ordinary member details:

  • Enrolment happens on the biometric device at your gym. The device stores a mathematical template, not a photograph of the fingerprint, and the original fingerprint image cannot be reconstructed from it.
  • Smarto Gym uses the template only to match a check-in to a member record and, where enabled, to allow door access. It is never used for any other purpose.
  • Biometric templates are never sold, shared with other gyms, or used to train any product of ours.
  • Your gym must obtain each member's clear, specific consent before enrolment, and must offer an alternative check-in method to anyone who declines.
  • When a member is deleted, or when your gym stops using the biometric add-on, the associated templates are deleted from the platform, and you should also clear them from the device.

7. Who we share information with

We share information only where it is needed to run the Service:

  • Hosting and infrastructure providers that store and serve the application and its backups.
  • Payment gateways that collect subscription fees and handle refunds. They process your payment details under their own privacy policies.
  • Messaging providers, including WhatsApp and email/SMS services, which deliver the notifications you and your gym send.
  • Professional advisers such as accountants and auditors, bound by confidentiality.
  • Authorities, where we are legally required to disclose information — for example a valid court order or a lawful request from a government agency.
  • A successor entity, if Smarto Gym is ever involved in a merger, acquisition or transfer of business. We will notify you before your data becomes subject to a different privacy policy.

Service providers act on our instructions and are not permitted to use your data for their own purposes.

8. Cookies and similar technologies

This marketing website is a static site and does not use advertising or cross-site tracking cookies. Fonts and assets are served with the page.

The dashboard at app.smartogym.in uses strictly necessary cookies to keep you signed in, to remember your preferences, and to protect forms against cross-site request forgery. These cannot be switched off without breaking sign-in. If we introduce optional analytics in future, we will ask for your consent first and update this section.

9. How we protect information

We apply security measures appropriate to the sensitivity of the data we hold, including:

  • Encryption in transit over HTTPS/TLS for all traffic to the website and dashboard;
  • Passwords stored only as salted, one-way hashes — never in plain text;
  • A separate, private workspace per gym, so one gym can never read another's records;
  • Role-based access controls, so staff only see what their role requires;
  • Regular backups, and restricted internal access on a need-to-know basis;
  • Monitoring and logging to detect unusual activity.

No system can be guaranteed completely secure. If a breach affects your data, we will notify you and the relevant authority without undue delay, and tell you what happened and what to do.

10. How long we keep information

While your subscription is active, we keep your data so the Service works. After a subscription expires or is cancelled, we retain your workspace in an inactive state for 90 days so you can renew without losing anything. After that window we may permanently delete it.

You can ask us to delete your workspace sooner by writing to support@smartogym.in from your registered email address. We will action verified deletion requests within 30 days.

We keep invoices, payment records and tax documents for as long as tax and accounting law requires, even after deletion of the workspace. Backups are rotated on a fixed schedule, so deleted data may persist in encrypted backups for a short period before being overwritten.

Export your data before you cancel. Reports and member data can be exported from the dashboard at any time while your account is active.

11. Your rights

Subject to applicable law, you can ask us to:

  • Confirm what personal information we hold about you and give you a copy;
  • Correct information that is inaccurate, incomplete or out of date;
  • Delete information we no longer need to keep;
  • Stop sending you marketing messages;
  • Withdraw a consent you previously gave;
  • Nominate someone to exercise these rights on your behalf if you are unable to.

Write to support@smartogym.in from your registered email address. We may ask you to verify your identity before acting, and we will respond within 30 days.

If you are a gym member rather than a gym owner, send your request to your gym — they control your records. If you contact us instead, we will forward your request to them.

12. Children

Smarto Gym is a business tool and is not directed at children. Accounts may only be created by adults. If your gym enrols members under 18, you must obtain verifiable consent from a parent or guardian before entering their details, and you must not enrol a child's biometric data without that consent.

13. Where data is stored

We aim to store and process data on infrastructure located in India. Some service providers — for example messaging or email delivery — may process limited data outside India. Where that happens, we take steps to ensure the data continues to receive an appropriate level of protection and is transferred only to jurisdictions permitted under Indian law.

14. Changes to this policy

We may update this Privacy Policy as the product and the law evolve. The "Last updated" date at the top always reflects the current version. If a change materially affects how we handle your information, we will notify you by email or in the dashboard before it takes effect.

15. Contact and grievances

For any privacy question, request or complaint, contact our grievance officer:

We acknowledge privacy complaints within 1 business day and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate the matter to the appropriate data protection authority in India.

Questions about this page?

Write to us and we'll get back to you within 1 business day. Please include your gym name so we can find your account faster.