Last updated: July 27, 2026
Privacy Policy
Contents
- Scope
- Information we collect
- How we use information
- Legal bases for processing
- How we share information
- Cookies and similar technologies
- Data retention
- Your privacy rights
- US state privacy rights
- European and UK rights
- Security
- International transfers
- Children
- Third-party links and services
- Changes to this policy
- Contact
The short version. We collect what we need to sell you a pass, get you through the door, and pay the gym or trainer. We do not sell your personal information and we do not share it for cross-context behavioural advertising. You can export or delete your data at any time from your account settings.
1. Scope
This Privacy Policy explains how Fit Flex Pass (“we,” “our,” or “us”) collects, uses, discloses, and safeguards information when you use our website, mobile applications, and related services (the “Service”). It applies to members who buy passes, and to gym owners and personal trainers who list on the Service.
It does not cover the independent gyms and trainers you buy from. When you visit a gym or train with a coach, that business collects information under its own privacy practices — including any waiver, intake form, or membership record it asks you to complete. We are not responsible for those practices.
2. Information we collect
Information you give us
- Name, email address, and phone number
- Profile details, preferences, and profile photo
- Billing address and emergency contact, if you choose to provide them
- For gyms and trainers: business name, address, description, photographs, pricing, specialties, social links, and the identity and bank details required by Stripe to pay you
- Reviews, ratings, and support correspondence
Payment information
Card payments are processed by Stripe, Inc. Card numbers go directly to Stripe and are never stored on our servers. We retain a payment record — amount, currency, status, last four digits, and Stripe’s identifiers — so we can show receipts, handle refunds, and meet accounting obligations.
Location
With your permission, we use your device location to sort gyms and trainers by distance and centre the map near you. Location is used at the time of the request and is not used to build a movement history. You can revoke the permission in your device settings at any time; the Service still works, you just search by city instead.
Camera and photos
With your permission, we access the camera to scan pass QR codes at check-in and to take a profile photo, and your photo library so you can choose a profile or listing image. QR scans are used only to validate a pass. We do not retain camera imagery beyond what you explicitly save.
Push notifications
With your permission, we store a device push token so we can send purchase confirmations, check-in confirmations, and pass expiry reminders. You can turn notifications off in your device settings.
Information collected automatically
- Pass purchases, activations, and check-in events (which gym or trainer, and when)
- Device and technical data: device type, operating system, app version, browser type, language, and IP address
- Log data about requests to our API, retained for security and debugging
We do not use third-party advertising trackers, and we do not run advertising pixels on the Service.
Information we do not collect
We do not collect health, biometric, workout, or body-measurement data. We do not collect precise background location. We do not ask for government ID from members. If a gym or trainer collects any of that from you directly, it is theirs, not ours.
3. How we use information
- Create and maintain your account and authenticate you
- Process purchases, issue passes and QR codes, and deliver receipts
- Validate passes at check-in and record that a check-in happened
- Settle payouts to gyms and trainers and report their earnings to them
- Provide customer support and handle refunds and disputes
- Send transactional messages, and marketing messages where you have consented
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Analyse aggregate usage to fix problems and improve the Service
- Comply with legal, tax, and accounting obligations
We do not use your information to make decisions producing legal or similarly significant effects about you without human involvement, and we do not use your personal information to train machine-learning models.
4. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on: contract — to provide the Service you bought; legitimate interests — to secure the Service, prevent fraud, and improve it, balanced against your rights; consent — for location, camera, push notifications, non-essential cookies, and marketing email, each withdrawable at any time; and legal obligation — for tax and accounting records.
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
We share only in these situations:
- With the gym or trainer you bought from — your name and the fact that you hold a valid pass, so they can honour it at check-in. They do not receive your card details, home address, or purchase history at other businesses.
- With service providers who process data on our behalf under contract: Stripe (payments and payouts), our email delivery provider, push notification delivery, our hosting and database provider, and OpenStreetMap/Nominatim for map tiles and address lookup. They may use the data only to provide the service to us.
- For legal reasons — to comply with law, a subpoena, or a lawful request; to enforce our Terms; or to protect the rights, safety, or property of Fit Flex Pass, our users, or the public.
- In a business transfer — if we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will notify you before your information becomes subject to a materially different policy.
- With your direction — anything you choose to publish, such as a review, is visible to others.
6. Cookies and similar technologies
We use a deliberately small number of cookies, in two categories:
- Strictly necessary. A session cookie that keeps you signed in, and a cookie recording your cookie preference. These cannot be switched off — without them the Service cannot function — and they do not require consent.
- Analytics (optional). Aggregate measurement of which pages are used, so we can fix what is broken. These are only set if you accept them in the cookie banner, and you can change your mind at any time.
We do not use advertising or cross-site tracking cookies. If you decline optional cookies, the Service works exactly the same. You can also clear or block cookies in your browser settings, though blocking the session cookie will sign you out. We honour Global Privacy Control signals as an opt-out of optional cookies.
7. Data retention
- Account data — for as long as your account is active, then deleted or anonymised within 30 days of a deletion request.
- Payment and payout records — retained up to 7 years to meet tax, accounting, and audit obligations, even after account deletion.
- Pass and check-in records — retained while needed to resolve disputes with the gym or trainer, then anonymised into aggregate counts.
- Support correspondence — up to 3 years.
- Server logs — up to 90 days, then deleted.
8. Your privacy rights
Wherever you live, you can:
- Access and correct your information in your account settings
- Export a machine-readable copy of your data
- Delete your account, subject to the retention rules above
- Withdraw consent for location, camera, push, and marketing email
- Opt out of marketing using the unsubscribe link in any such email
On the web these live under your account settings; in the app, under Profile › Privacy & Security. Or email [email protected] and we will action it within 30 days. We will not discriminate against you for exercising any of these rights.
9. US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have the right to know what personal information we collect and why, to access and obtain a portable copy, to correct inaccuracies, to delete it, and to opt out of sale or targeted advertising.
We do not sell personal information and do not process it for targeted advertising, so there is nothing to opt out of — but the mechanism above is available regardless. California residents may also request the categories of information collected, the sources, the business purpose, and the categories of third parties it was disclosed to; that information is set out in sections 2 through 5 above. You may use an authorised agent, and we may need to verify your identity before acting.
To appeal a decision on a request, reply to our response or email [email protected] with “Appeal” in the subject line.
10. European and UK rights
If you are in the EEA, UK, or Switzerland, you additionally have the right to object to processing based on legitimate interests, to request restriction of processing, and to lodge a complaint with your local supervisory authority. Contact [email protected] to exercise any of these.
11. Security
We protect information with measures including TLS in transit, hashed passwords, encryption at rest for stored secrets, scoped access controls, rate limiting, and signed webhook verification for payment events. Card data never touches our servers.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any required regulator as the law requires. To report a vulnerability, see our security contact.
12. International transfers
We operate in the United States, and our service providers may process information there and elsewhere. If you access the Service from outside the US, you understand your information will be transferred to and processed in the US, where data protection law may differ. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism.
13. Children
The Service is intended for adults. It is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has provided us information, email [email protected] and we will delete it.
14. Third-party links and services
The Service links to third-party sites — a gym’s own website, its Google Business listing, social profiles, and the app stores. We do not control them, and this policy does not apply to them. Review their privacy policies before providing information.
15. Changes to this policy
We may update this policy. We will post the revised version here with a new “Last updated” date, and for material changes we will give notice by email or in-product before they take effect.
16. Contact
Privacy questions and requests: [email protected]
General support: [email protected]
Security reports: [email protected]