Your gym's data — members, payments, attendance, plans, conversations — is the lifeblood of your business. Here's exactly how we protect it, what's in your hands, and how to report something that doesn't look right.
owner, member) live in a dedicated user_roles table and are checked server-side via a security-definer function. Roles can't be escalated from the browser.MyGymPanel is multi-tenant. Each gym's data is logically isolated using row-level security policies tied to the owner's user ID. A query made from one gym physically cannot return another gym's rows, even if the application code had a bug.
Subscription payments are processed by Razorpay (PCI-DSS Level 1 certified). We do not store full card numbers, CVVs or UPI credentials on our servers. We only retain the tokenized references and metadata needed to reconcile invoices.
Data is primarily processed in regions operated by our infrastructure providers. The current sub-processors are documented in our Privacy Policy (Supabase, Cloudflare, Google, Razorpay). We update that list when it changes.
We welcome responsible disclosure from security researchers. If you believe you've found a vulnerability, please email support@mygympanel.com with the subject line [SECURITY].
If we detect or are notified of a security incident that affects your data, we will investigate, contain and remediate as our first priority. Where the law requires (GDPR, India DPDP, applicable US state laws), we will notify affected owners without undue delay and within statutory timelines, along with the facts we have, the impact, and the steps you should take.
For privacy-specific requests (access, deletion, portability), see the contact section of our Privacy Policy.