Privacy policy
What data we handle, what for, who else touches it, and what you can do about it. No paragraphs that say nothing.
Version 2026-09-02b
1. Two different roles, worth keeping apart
From you, a gym owner, we process data on our own behalf: your name, your email, the gym you created, the country you signed up from, and what we need to bill you. There, we are the controller.
From your members we process data on your behalf: you decide what is stored and what for, and we carry it out. There, you are the controller and we are the processor. The conditions are in the Data processing agreement.
If you are a gym member who ended up here: to request, correct or delete your data, your gym is who you talk to. We assist them, and we do nothing with your data that your gym has not asked for.
2. What we store
From visitors to weappgym.com: the minimum for the site to work and to defend it from abuse. No advertising cookies, and we do not follow you across other sites.
From customers: name, email, gym name, language, country and currency, and the subscription history. We never see or store your card details — the payment processor holds them.
From a gym's members: name, contact, plan, attendance, payments, routines, and — if the gym uses it — the health record, which contains health data.
3. What for
To provide the service you subscribed to, bill you, support you, tell you about service matters, and keep everything secure. Nothing else.
We do not sell data, do not hand it to advertisers, and do not train models on it.
4. On what legal basis
With you: performance of the contract, and our legitimate interest in keeping the service secure.
With members' data: the gym's instruction — the gym is the one that must hold the legal basis towards them. For the health record that basis is the person's explicit consent, asked for in the same form where it is filled in.
5. Who else touches it
Four providers, each for one thing: Supabase holds the database and the accounts, in Brazil; Cloudflare serves the site and the network; Polar bills the subscription outside Argentina; Mercado Pago bills it in Argentina.
The list is published and we give notice before adding anyone. Nobody else has access.
6. Where it lives, and whether it leaves
The database lives in Brazil. If you are in the European Union or another country with international transfer rules, that is a transfer outside your territory, and we cover it with the clauses in the Data processing agreement.
The network that serves pages is global, so your site's public content is copied to servers worldwide. That does not include member data: the panel is never cached.
7. For how long
For as long as your account is active. If you cancel, your data and your members' data stay for 60 days — in case you come back or need a copy — and are then deleted.
Backups rotate: deleted data may remain in a backup for up to 30 further days, and then goes with it.
8. What you can do with your data
Over your own data — yours, your account's — you can ask for a copy, correct it, delete it, take it elsewhere and object to a use of it. Write to us and we do it.
Over your members' data, which is yours and not ours: on request we give you their contact list and the history of the payments you charged them. We do not hand over database dumps or copies of the system, to you or to anyone.
If you are a gym member, those requests go to your gym. What you can do on your own, from your panel, is delete your health record: it is yours and it goes when you say so.
9. Health data in particular
The health record — surgery, medication, diabetes, asthma, epilepsy, blood pressure, heart conditions, injuries — is sensitive data and we treat it as such.
It is readable by the person who filled it in, by the owner and reception of their gym, and by the teacher that person is assigned to. Nobody from another gym can see it, and it is the database that prevents that row by row, not the application.
Our technical team can reach the database to operate it, and does so only when needed to keep the service running or when the gym asks.
10. Minors
A gym may have members under age, and the record allows for a responsible adult. Obtaining that adult's authorisation is the gym's responsibility.
11. How we look after it
Each gym is isolated in the database by row-level rules: one gym's query cannot return another's data even if the code has a bug. Everything travels encrypted. Keys with broad access live only on the server.
We take backups and test them by restoring them, which is the only way to know whether they work.
If there were a breach affecting you, we tell you without undue delay and at the latest within 72 hours of detecting it, with what we know and what we are doing.
12. Cookies
The ones needed to keep your session open and to remember preferences such as language. None for advertising or cross-site tracking. If we ever add analytics, it will be cookieless or with your consent.
13. Contact
Write to hello@weappgym.com. We answer data requests within 30 days.