Policy · v1.0 · Effective July 1, 2026

Privacy Policy

This Privacy Policy explains how Creovate Technologies (operated by Abhinav K and Ajay KM, founders; private limited registration pending) ("MyGymPanel", "we", "us", or "our") collects, uses, stores, shares, and protects information when you use the MyGymPanel application, website, and related services (collectively, the "Service"). We're committed to handling your data lawfully, fairly, and transparently — wherever you live.

1. Who we are

MyGymPanel is operated by Creovate Technologies (operated by Abhinav K and Ajay KM, founders; private limited registration pending), based in India. You can reach our privacy team at support@mygympanel.com for any question, request, or complaint covered by this policy. For users in the European Economic Area (EEA), the United Kingdom, California, or India, you have additional statutory rights described in §10.

2. Scope

This policy applies to:

  • The MyGymPanel web application accessible at mygympanel.com and any subdomains.
  • Account creation, onboarding, member management, billing, attendance, community, store, workouts, diet, and notification features.
  • Communications we send you (email, in-app, and any future SMS / WhatsApp messages you opt into).

This policy does not cover third-party websites we link to, or independent services you connect to your account (e.g. Google for sign-in, Razorpay for payments). Each of those is governed by its own privacy policy.

3. Information we collect

We collect only what's needed to run a gym-management product. Categories of personal data we process:

Account data
Name, email, password hash (we never store your raw password), profile photo, phone number, role (owner or member).
Identity & sign-in
If you sign in with Google, we receive your basic Google profile (name, email, avatar). We do not receive your Google password.
Owner / gym data
Gym name, branding (logo, banner), address, working hours, membership plans, pricing, and trainer information you choose to add.
Member profile data
Date of birth, gender, blood group, address, height, weight, fitness goals, fitness level, dietary preferences, medical notes you voluntarily provide, and preferred workout times.
Operational data
Attendance check-ins, workout/diet plan assignments, invoices, billing status, community messages, feedback tickets, notifications, store orders, and wishlist items.
Payment data
We currently do not process card payments. When Razorpay is enabled, card and UPI details are collected and stored by Razorpay directly — we only receive a payment status and transaction reference.
Technical & device data
IP address, browser type, device type, operating system, language, time zone, referring URL, pages visited, and timestamps. Used for security and product analytics.
Cookies & local storage
Session tokens (so you stay signed in), theme preference, and minimal product analytics. We do not use third-party advertising cookies.
Sensitive personal data
Health-related fields (weight, height, medical notes, blood group) are sensitive. You provide them voluntarily and can leave them blank or delete them at any time from your settings. We never sell or share these to advertisers.

4. How we use your information

We use personal data only for the purposes below, each tied to a lawful basis:

  • Provide the Service — create your account, run your gym, show your members, accept attendance, generate invoices. Lawful basis: contract.
  • Secure the Service — detect abuse, prevent fraud, rate-limit, investigate incidents. Lawful basis: legitimate interest.
  • Improve the Service — anonymous product analytics, debugging, performance monitoring. Lawful basis: legitimate interest.
  • Communicate with you — transactional emails (sign-in, billing, security), in-app notifications, customer support replies. Lawful basis: contract / legitimate interest.
  • Legal & compliance — tax records, responding to lawful requests, enforcing our Terms. Lawful basis: legal obligation.
  • Consent-based features — marketing emails, optional integrations. Lawful basis: your consent, withdrawable any time.

We do not use your data to train machine-learning models, sell it to data brokers, or share it with advertising networks.

5. How we share information

We share data only with the limited categories of recipients below:

  • Within your gym — owners can see the members they manage; members can see basic owner contact info and other members' display names in the community feed.
  • Service providers (processors) — infrastructure, database, authentication, email delivery, and (when enabled) Razorpay for payments. They process data only on our instructions.
  • Legal requests — when required by valid Indian law or a competent court order. We push back on overbroad requests.
  • Business transfers — if Creovate Technologies is acquired, merged, or reorganised, your data may transfer to the new entity under the same protections.
No sale of personal information
We do not sell your personal information and have not sold any in the past 12 months, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).

6. Sub-processors

Our current sub-processors:

  • Supabase (managed Postgres, authentication, storage) — primary data store.
  • Cloudflare (edge compute, CDN) — application hosting and DDoS protection.
  • Google (OAuth sign-in only, if you choose it).
  • Razorpay (when payments go live) — card / UPI / netbanking processing.

We notify you in advance of material sub-processor changes through the in-app changelog. The current list is also available in §6 of this page, updated as it changes.

7. International data transfers

MyGymPanel is built and operated from India. Some of our sub-processors (e.g. Cloudflare, Supabase) operate globally. When we transfer personal data outside India, the European Economic Area, the United Kingdom, or California, we rely on appropriate safeguards such as the Standard Contractual Clauses (SCCs) and equivalent transfer mechanisms, and we only use providers with strong privacy commitments.

8. Data retention

We keep personal data only as long as necessary for the purpose it was collected, or as required by law. Specific retention windows for each data category are documented in our Data & Storage Policy.

  • Attendance check-ins: 12 months, then auto-deleted.
  • Read or dismissed notifications: 30 days after being read.
  • Unread notifications: 90 days.
  • Community messages: 12 months (pinned messages indefinitely).
  • Invoices and billing records: indefinitely, to meet tax record-keeping obligations.
  • Account & profile: until you delete your account; then permanently removed within 30 days, except where law requires longer retention.
Pre-deletion notice (coming soon)
Before any auto-deletion, we will send you an email and an in-app notification 14 days in advance, with a one-click button to export the affected data. You will never lose data without prior warning.

9. Security

We use commercially reasonable safeguards to protect your data:

  • TLS 1.2+ encryption for all data in transit.
  • Encryption at rest for our primary database.
  • Row-level security policies so users only access data they're allowed to see.
  • Hashed and salted passwords (we never store raw passwords).
  • Principle of least privilege for internal admin access.
  • Regular security scans and dependency updates.

No system is 100% secure. If we ever discover a breach affecting your personal data, we'll notify you and the relevant regulators (Indian CERT-In, EU supervisory authorities, California Attorney General) within the timelines required by law.

10. Your rights

You have the following rights, subject to local law. Email us at support@mygympanel.com to exercise any of them — we respond within 30 days (or sooner where required).

Access
Get a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete data.
Erasure
Ask us to delete your data ('right to be forgotten').
Restriction
Limit how we use your data in certain cases.
Portability
Receive your data in a portable format (CSV / TXT — see Data & Storage Policy).
Object
Object to processing based on legitimate interests.
Withdraw consent
Where processing is based on consent, withdraw any time.
Complain
Lodge a complaint with your local data protection authority.

EEA / UK (GDPR): the rights above are statutory. You can also complain to your local supervisory authority.
California (CCPA/CPRA): you have the right to know, delete, correct, and opt-out of "sale" or "share" of personal information. We do not sell or share for cross-context behavioural advertising.
India (DPDP Act, 2023): as a Data Principal, you have the right to access, correct, erase, nominate, and grieve. Our designated grievance contact is the email above.

11. Children

MyGymPanel is not directed at children under 16. If you are a gym owner enrolling a minor, you must obtain verifiable parental consent before adding their personal data. If we learn we have collected data from a child without proper consent, we will delete it.

12. Cookies & tracking

We use a minimal set of first-party cookies and browser storage for sign-in sessions, theme preference, and aggregated product analytics. We do not use third-party advertising cookies, cross-site tracking, or fingerprinting. You can clear cookies from your browser at any time; doing so will sign you out.

13. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in-app at least 30 days before they take effect, and the "Effective" date at the top will be updated. Continued use after the effective date constitutes acceptance of the revised policy.

14. Contact

Questions, requests, or complaints about this policy or your personal data:
support@mygympanel.com
Creovate Technologies (operated by Abhinav K and Ajay KM, founders; private limited registration pending)
India