Isolation at the database level. No trackers. No sharing.
What we do so your gym's and your members' data stays where it belongs.
Every database row carries the ID of the gym that owns it. Postgres rejects reads from anyone else. We don't rely on the application to do it.
Members, plans, payments, attendance: everything exports to CSV at any time, from the dashboard, without asking.
If you cancel, your data stays for 30 days so you have time to change your mind. After that, it's permanently removed.
We never touch your money. You upload the proof (PDF or image) and it gets validated. The flow leaves an auditable record.
Passwords are hashed with bcrypt. Sessions use HTTP-only cookies, secure in production, with strict SameSite.
No Google Analytics. No Facebook Pixel. No third-party cookies. Only minimal technical logs for debugging.
For compliance or contract questions, write to us. We don't hide technical details.