Privacy policy
Last updated: 18 September 2026. This policy applies to joinclanfit.com, the ClanFit Android and iOS apps, and related APIs. It is written to meet Google Play Data safety and Apple App Privacy disclosure needs, and India’s Digital Personal Data Protection Act, 2023.
1. Who we are
ClanFit (“we”, “us”) provides a connected fitness platform for gym owners, trainers, and members. We are the data fiduciary for platform accounts. Your gym is often a data fiduciary for membership, attendance, and billing records it creates about you.
Privacy and account requests:
- Email: team@joinclanfit.com
- Phone: +91 76248 65656
- Website: https://joinclanfit.com
2. Scope
This policy covers personal data processed when you create an account, join a gym, use owner/trainer/member features, pay for gym SaaS on Android through Razorpay or in-app purchases, or visit this website. It does not cover independent gym websites or biometric hardware vendors except as described below.
3. Data we collect and why
We collect only what the product needs. Fields marked as gym-entered are stored because a gym admin or trainer recorded them for that facility.
Account and identity
- Mobile number (primary login via OTP), optional email, optional username and password for staff login, full name, profile photo, account role, gym association, and verification status.
- Use: authenticate you, keep sessions, route you to the right gym, recover access, and prevent duplicate accounts.
Profile, body metrics, and fitness goals
- Height, weight, age or date of birth, gender, address, activity level, fitness goal.
- Derived wellness values such as BMI, BMI category, and estimated maintenance calories.
- Use: personalise member onboarding, diet and workout context, and in-app wellness summaries. This is fitness and wellness data generated in ClanFit. We do not connect to Apple Health, HealthKit, or Google Fit.
Government identity (where a gym records it)
- Aadhaar number, if a gym collects it during member onboarding.
- Use: gym identity and membership administration only. We do not use Aadhaar for advertising. Gyms that collect Aadhaar must have a lawful purpose under applicable Indian law.
Emergency contacts
- Emergency contact name and phone, if a gym records them.
- Use: gym safety and member administration.
Gym and staff operations
- Gym name, address, map coordinates, operating radius, GSTIN, logo, plans, staff notes, trainer salary and shift details, enquiries and leads (name, phone, email, photo, gender, address, message, source, follow-ups).
- Use: run the facility, track leads, manage staff, and show the gym on a map.
Workouts and training
- Assigned and personal workout plans, exercises, sets, reps, weights, volume, duration, completion status, and personal records.
- Use: trainers assign and review plans; members log sessions; the gym can show progress and leaderboards based on completed workouts or attendance.
Nutrition
- Diet plans, scheduled meals, logged foods, calories, protein, carbs, fat, meal photos, meal type, and timestamps.
- Use: diet adherence, trainer review, and daily nutrition targets. Meal photos are content you or staff upload, not camera access for advertising.
Attendance and access
- Check-in and check-out times, date, and source (QR token, biometric device, or manual entry).
- QR codes used for timed member check-in.
- If the gym connects fingerprint hardware: employee or member biometric mapping codes, blocked status, and device credentials stored as hashes. Fingerprint templates stay on the gym’s biometric vendor system, not in ClanFit’s member database.
- Use: access control, attendance, payroll inputs for trainers, and engagement leaderboards.
Payments and subscriptions
- Member gym payments: amount, currency, method label (cash, UPI, card), reference, invoice and membership links, freeze and extend history. We do not store card PAN, CVV, or UPI PINs.
- Gym SaaS billing (Android): Razorpay subscription id, payment id, and signature so we can activate or renew the gym’s ClanFit plan.
- App Store and Play in-app purchases: product identifiers and purchase status processed by Apple or Google. We do not receive your full card number from those stores.
- Trainer salary payments and gym expenses: amounts, categories, GST fields, and linked staff where recorded.
- Use: collect dues, keep books, pay staff, and bill the gym for ClanFit.
Shop
- Product catalogue: names, prices, stock, images, and member favorites.
- Use: let a gym show supplements and merchandise to its members. Checkout order records are not a current core dataset in the product.
Messages and community
- In-app broadcasts and notifications: title, body, image, audience, read state.
- Leaderboard scores and challenge or community participation tied to your gym.
- WhatsApp messages the gym or platform sends to a member phone (welcome, payment, expiry, and similar operational templates).
- Use: keep members informed and engaged. We do not sell message content.
Device, location, and technical data
- Push token (FCM) to deliver notifications.
- Approximate location or precise location when you grant permission, used to pick a gym address on the map or search Places. We store gym latitude and longitude you save. We do not run a continuous GPS trail of members.
- Photos from camera or gallery when you upload a profile image, food photo, gym logo, enquiry photo, or broadcast image.
- Security audit metadata: IP address, user agent, and request identifiers for abuse prevention.
- Session refresh tokens (hashed).
We do not collect advertising IDs, contacts, microphone audio, or Bluetooth identifiers. We do not use third-party advertising or analytics SDKs such as Firebase Analytics, Mixpanel, or Sentry in the current app.
4. App permissions (Android and iOS)
- Internet: load the product.
- Camera: scan QR attendance and capture photos you choose to upload.
- Photos or media: pick images from the gallery.
- Location (when in use): centre the map and fill gym or address coordinates. Live workout tracking notifications are a foreground timer, not a GPS broadcast of your route.
- Notifications: membership, workout, attendance, and operational alerts. Android 13+ asks for notification permission.
- Billing: Google Play Billing / Apple In-App Purchase for gym plans where enabled.
You can refuse optional permissions. Core login still works with phone OTP. Map pick, QR scan, photo upload, and push will not work without the matching permission.
5. How we use data (purpose summary)
- Provide the ClanFit service you requested (contract).
- Authenticate users and protect accounts (contract and security).
- Let owners run memberships, staff, revenue, attendance, shop catalogues, and leads.
- Let trainers assign workouts and diets and review completion.
- Let members log training, nutrition, and progress.
- Send transactional SMS OTP, push notifications, and optional WhatsApp templates.
- Process gym SaaS payments and record in-gym collections.
- Comply with law, tax, and dispute requests.
We do not sell personal data. We do not use workout, diet, height, weight, or Aadhaar data to build advertising profiles or to remarket third-party products.
6. Who can see your data
ClanFit is organised per gym, not as a public social network.
- Owners and authorised staff see operational data for their gym.
- Trainers see members assigned to them.
- Members see their own profile, plans, logs, and gym community surfaces they join.
- Other gyms cannot browse your member list.
7. Sharing with service providers
We share data with processors only to run ClanFit:
- MSG91: send and verify SMS or voice OTP to your phone.
- Firebase Cloud Messaging: deliver push notifications using your device token.
- WhatsApp (Meta Cloud API and/or Twilio, depending on gym configuration): send operational messages to the member phone.
- Razorpay: gym SaaS subscriptions on Android. Card and UPI details are handled by Razorpay, not stored as PAN in ClanFit.
- Apple and Google: in-app purchases.
- Google Maps and Places: address search and map display when you use location features.
- Gym biometric hardware vendor (SOAP/device API): enroll or block a member on the gym’s fingerprint device using employee code and name. Fingerprint images remain with that vendor.
- Cloud hosting, database, and job-queue providers that store ClanFit production data under our instructions.
We may disclose data if required by law, to protect users, or in a merger or asset transfer, with notice where the law requires it.
8. Payments
Front-desk collections are recorded as amounts and method labels. We are not your card issuer. For ClanFit gym subscriptions on Android, Razorpay is the payment processor. For App Store or Play purchases, Apple or Google is the merchant of record for that transaction. Direct refund questions for store purchases go through those stores; gym membership refunds are decided by your gym.
9. Health and fitness data
Height, weight, age, gender, activity, goals, BMI estimates, workouts, and meal logs are used only to operate fitness features. They are not clinical records. We do not provide medical advice. Do not use ClanFit as a substitute for a clinician.
10. Children
ClanFit is not directed at children under 13. Member onboarding requires a stated age of 13 or older. We do not knowingly create accounts for children under 13. If a gym enrols a person aged 13 to 17, the gym must obtain parent or guardian permission where the law requires it. Email us to delete data created in error.
11. Retention
We keep account and gym records while the gym or user stays active, and afterwards as needed for invoices, attendance disputes, tax, and legal holds. OTP challenges are short-lived. Push tokens are updated or cleared when you sign out or delete the account.
12. Account deletion (Play Store and App Store)
You can delete your ClanFit account in the app: open Profile and choose delete account, or email team@joinclanfit.com from the registered address or phone.
What deletion does:
- Revokes login sessions and clears your push token.
- Releases your phone, email, and username so they can be used to register again.
- Deactivates gym memberships and related profiles according to your role.
- Gym payment history, invoices, and attendance needed for the facility’s books may remain in archived form so the gym can meet accounting and access-control duties. Those records are no longer usable as an active login.
We do not currently offer a full machine-readable export. You can request a copy of personal data we hold by emailing the team. We will respond within the time the law requires, usually 30 days unless a gym confirmation is needed.
13. Your rights (India and similar regimes)
Subject to law and the gym’s records, you may request access, correction, erasure, nomination, grievance redressal, and withdrawal of consent where processing was consent-based. OTP login and core gym operations are contractual. Contact team@joinclanfit.com or +91 76248 65656. If you are a member, we may ask the gym admin to confirm the request before changing operational records.
14. Security
We use HTTPS, hashed passwords and refresh tokens, role-based access, and hashed biometric device secrets. Uploaded images are stored so the product can show them. No system is perfectly secure. Report suspected account takeover immediately to the contacts above.
15. International processing
Primary operations are designed for India. Processors such as Google, Apple, Firebase, Meta, Twilio, or Razorpay may process data in other countries. We use them only to provide the features described here.
16. This website
joinclanfit.com is a static marketing site. It does not set advertising cookies and does not run an advertising pixel. Hosting logs may include IP address and user agent for security and uptime. The support form does not store messages on this website. Send uses your email app to reach team@joinclanfit.com. WhatsApp send uses the published support number. We receive only what you choose to send.
17. Data we do not collect
- Advertising ID / IDFA for tracking across other companies’ apps.
- Contacts, microphone, or Bluetooth lists.
- Precise continuous location history of members.
- Card PAN, CVV, or bank passwords.
- HealthKit or Google Fit clinical feeds.
18. Changes
If we change this policy in a material way, we will update the date above and, where required, notify users in the app or by email. Continued use after the effective date means you accept the updated policy, unless the law requires a fresh consent. Related: Terms of Use.