Privacy Policy – GymOS

Effective date: 23 August 2026
Last updated: 23 August 2026

This Privacy Policy explains how Pisat Udyog Pvt Ltd (“Pisat Udyog”, “GymOS”, “we”, “us”, or “our”) collects, uses, stores, shares, retains, and deletes information when you use:

  • GymOS Members;

  • GymOS Admin;

  • GymOS websites;

  • GymOS web applications; and

  • Other services provided under the GymOS name.

GymOS provides software and services to gyms, fitness centres, sports academies, swimming pools, clubs, activity centres, and similar organisations (“Activity Centres”).

By using GymOS, you acknowledge the practices described in this Privacy Policy.

1. Our role in processing data

For information collected directly through the GymOS website, subscriptions, support requests, or business communications, Pisat Udyog Pvt Ltd acts as the data controller.

When an Activity Centre uses GymOS to manage its members, staff, attendance, memberships, fees, enquiries, or other operational data, the Activity Centre generally determines what information is collected and why it is used. In such cases, the Activity Centre is the data controller or data fiduciary, and Pisat Udyog Pvt Ltd processes the information on its behalf as a service provider or data processor.

Questions concerning records created by an Activity Centre may be referred to that Activity Centre.

2. Information we may collect

The information collected depends on whether you use GymOS as a member, employee, administrator, business customer, or website visitor.

Account and contact information

We may collect:

  • Name;

  • Email address;

  • Mobile number;

  • Postal address;

  • Date of birth;

  • Gender;

  • Profile photograph;

  • User ID, membership ID, employee ID, or other account identifiers;

  • Login credentials and authentication information; and

  • Details of your associated Activity Centre.

Passwords are stored using appropriate authentication and security controls. We do not have access to passwords stored in encrypted or hashed form.

Membership and activity information

We may process:

  • Membership plan and validity dates;

  • Attendance and check-in/check-out records;

  • Class, session, facility, or activity bookings;

  • Assigned trainer or staff information;

  • Enquiries, leads, follow-ups, and service history;

  • Membership status;

  • Access-control or attendance-machine identifiers;

  • Notices, posts, likes, follows, and other interactions; and

  • Records entered by an Activity Centre through GymOS.

Attendance data received from biometric or access-control equipment may include an attendance event, machine user number, device serial number, date, time, and centre. GymOS does not intentionally require fingerprint templates or facial biometric templates through its standard member application unless a specific feature is enabled and separately disclosed by the relevant Activity Centre.

Fitness and health-related information

Where voluntarily provided or entered by an authorised Activity Centre, GymOS may process information such as:

  • Height and weight;

  • Fitness goals;

  • Body measurements;

  • Workout information;

  • Health conditions, injuries, or fitness limitations; and

  • Other information required to provide fitness-related services.

Users should provide health information only when necessary. GymOS is not a medical service and should not be used as a replacement for professional medical advice.

Payment and transaction information

We may process:

  • Membership fees;

  • Invoices and receipts;

  • Payment amount, date, method, and status;

  • Outstanding balances;

  • Subscription and purchase history; and

  • Transaction or payment reference numbers.

Where online payments are enabled, payment credentials may be processed directly by the relevant payment provider. GymOS does not intentionally store complete debit card, credit card, banking-password, or UPI PIN information.

Images and files

If you or an authorised Activity Centre uses an upload feature, we may process profile photographs, documents, receipts, centre images, or other files selected for upload.

Location information

Some GymOS features may request location permission to verify attendance, support centre-based functionality, display relevant centres, or provide location-dependent services.

Location is accessed or collected only when the relevant feature is used and permission has been granted. Where required, the application will provide an in-app disclosure before requesting location permission.

Device and technical information

We may automatically receive:

  • Device type and operating system;

  • App version;

  • Browser type;

  • IP address;

  • Device or app identifiers;

  • Push-notification tokens;

  • Login time and session information;

  • Crash reports;

  • Diagnostic and performance information; and

  • Security and activity logs.

Camera, photographs, and storage

GymOS may request access to the camera, photographs, or files when you choose to:

  • Upload or change a profile photograph;

  • Scan or upload a document;

  • Upload a receipt or centre image; or

  • Use another feature requiring an image or file.

GymOS does not access photographs or files unrelated to the item selected by the user, except where separately disclosed and permitted.

Website and cookie information

When you visit a GymOS website, we may collect IP address, browser information, referring pages, pages visited, approximate location derived from IP address, cookies, and website-usage information.

3. How we use information

We may use information to:

  • Create, authenticate, and manage accounts;

  • Connect members and staff with their Activity Centre;

  • Manage memberships, attendance, bookings, fees, and services;

  • Provide reports and business-management tools;

  • Send service messages, reminders, alerts, notices, and notifications;

  • Process payments and maintain transaction records;

  • Provide customer support;

  • Respond to enquiries and complaints;

  • Maintain, secure, diagnose, and improve GymOS;

  • Prevent fraud, misuse, and unauthorised access;

  • Measure application performance and usage;

  • Display advertising where advertising is enabled;

  • Comply with applicable contractual, accounting, tax, security, and legal obligations; and

  • Protect the rights, safety, and property of users, Activity Centres, Pisat Udyog Pvt Ltd, and others.

We do not sell personal or sensitive user information.

4. How information may be shared

We may share information only as reasonably necessary with the following categories of recipients:

Your Activity Centre

Member information may be available to authorised owners, administrators, staff members, or service personnel of the Activity Centre with which the member is registered.

Activity Centres are responsible for controlling staff access and using member data only for legitimate purposes.

Service providers

We may use service providers for:

  • Cloud hosting and database services;

  • Authentication;

  • Application development and maintenance;

  • Notifications, email, SMS, or WhatsApp communication;

  • Payment processing;

  • Analytics, diagnostics, crash reporting, and security;

  • Advertising, where enabled; and

  • Customer support.

These providers may process information only to provide their contracted services, subject to their respective privacy terms and applicable law.

Legal and safety requirements

We may disclose information where reasonably necessary to:

  • Comply with applicable law, regulation, court order, or lawful government request;

  • Detect or investigate fraud, security incidents, or illegal activity;

  • Protect users, Activity Centres, Pisat Udyog Pvt Ltd, or the public; or

  • Establish, exercise, or defend legal claims.

Business transfer

Information may be transferred as part of a merger, acquisition, restructuring, financing, or sale of all or part of the business, subject to appropriate confidentiality and legal safeguards.

5. Data retention policy

GymOS does not retain personal information indefinitely. We retain information only for the period reasonably necessary for the purposes described in this Policy, for the period required by the relevant Activity Centre, or as required by applicable law.

Our standard retention periods are:

  • Active account information: Retained while the GymOS account or associated Activity Centre relationship remains active.

  • Membership and attendance records: Normally retained during the membership or service relationship and for up to three years after the relationship ends, unless the relevant Activity Centre requests earlier deletion or a longer period is required by law, contract, dispute resolution, or legitimate business-record requirements.

  • Invoices, payment records, accounting records, and tax-related information: Retained for up to eight years, or for another period required under applicable accounting, taxation, audit, or regulatory laws.

  • Customer-support communications and complaint records: Retained for up to three years after the matter is closed.

  • Application security, access, and diagnostic logs: Normally retained for up to twelve months, unless a longer period is required to investigate fraud, abuse, or a security incident.

  • Marketing information: Retained until the user withdraws consent, unsubscribes, objects to marketing, or the information is no longer required.

  • Account-deletion request records: We may retain limited information about the request and its completion for up to three years to demonstrate compliance, prevent fraud, or resolve disputes.

  • Backups: Information removed from active systems may remain in encrypted or access-restricted backups for up to ninety days, after which it is deleted through the normal backup-rotation process. Backup information is not used for ordinary business purposes and will not be restored except for disaster recovery, security, or legal necessity.

If information is required for an active legal claim, fraud investigation, regulatory request, unpaid transaction, or other legal obligation, we may retain only the information necessary until that matter has been resolved.

When a retention period expires, information is securely deleted or irreversibly anonymised.

6. Account and data deletion

Users may request deletion of their GymOS account and associated personal information through:

The request should include the registered name, mobile number or email address, and associated Activity Centre so that we can verify the account.

After verification:

  • The account will be deleted or permanently de-identified from active GymOS systems within 30 calendar days;

  • Information stored in backups will be removed within the backup-retention period of up to 90 days;

  • Deactivation, suspension, or account blocking will not be treated as account deletion; and

  • We may retain limited records where required for accounting, taxation, fraud prevention, dispute resolution, security, or other legal obligations.

Where the Activity Centre controls the requested records, GymOS may notify or coordinate with the Activity Centre to complete the request. We will not use information retained for legal purposes for advertising or unrelated activities.

Deleting an account may permanently remove access to membership information, bookings, history, benefits, and other GymOS services.

7. User choices and rights

Subject to applicable law, users may have the right to:

  • Request access to their personal information;

  • Correct inaccurate or incomplete information;

  • Request deletion of information;

  • Withdraw consent where processing is based on consent;

  • Object to or restrict certain processing;

  • Unsubscribe from marketing communications;

  • Request information about how their data is handled; and

  • Submit a privacy complaint.

Users can disable camera, photograph, notification, or location permissions through their device settings. Disabling a permission may prevent the related feature from working.

To exercise a privacy right, contact support@gymos.in.

8. Data security

We use reasonable administrative, technical, and organisational safeguards designed to protect information against unauthorised access, loss, misuse, alteration, or disclosure.

These safeguards may include:

  • Encryption during transmission using HTTPS;

  • Authentication and access controls;

  • Role-based permissions;

  • Database and server-security controls;

  • Logging and monitoring;

  • Restricted administrative access; and

  • Backup and recovery procedures.

No electronic system or Internet transmission can be guaranteed to be completely secure. Users and Activity Centres are responsible for protecting their passwords, devices, and account access.

9. International data processing

GymOS and its service providers may process or store information in India or other countries where cloud or technology providers operate.

Where required, we use reasonable contractual, organisational, and technical safeguards for international processing or transfers.

10. Children and minors

GymOS is intended for use in connection with legitimate fitness, sports, club, academy, or Activity Centre services.

Where an account relates to a minor, the account and personal information should be created or provided by a parent, legal guardian, or authorised Activity Centre in accordance with applicable law.

If we learn that a minor’s personal information was collected without required authorisation, we will take reasonable steps to delete it.

11. Third-party websites and services

GymOS may contain links to third-party websites, payment services, messaging platforms, or other applications. Their privacy practices are governed by their own policies, and GymOS is not responsible for services it does not control.

12. Changes to this Privacy Policy

We may update this Privacy Policy when our services, technology, legal obligations, or data-handling practices change.

The revised Policy will be published on this page with an updated effective date. Where changes materially affect users’ rights or the processing of sensitive information, we may provide additional notice through the application, website, email, or another appropriate method.

13. Contact information

For questions, complaints, privacy requests, or account-deletion assistance, contact:

Pisat Udyog Pvt Ltd
GymOS Privacy Team
5/Building 15, Flat 3, Ground Floor, Wing B
Dindoshi Sayali Nagari Nivara CHS
Goregaon, Mumbai, Maharashtra – 400065
India

Email: support@gymos.in
Alternative email: gymosone@gmail.com
Phone: +91 96991 01202
Website: https://gymos.in