Privacy Policy
How Kinfit collects, uses and protects your information.
This Privacy Policy explains how Kinfit ("Kinfit", "we", "us" or "our") collects, uses, discloses, retains and safeguards personal information when you use the Kinfit website, the Kinfit web application, and our mobile applications published on Google Play:
- Kinfit Admin (package
in.kinfit.healthclubadmin) – used by fitness club owners and staff to manage their business. - Kinfit Member (package
co.abijith.mhc.member) – used by members of a fitness club to view their own membership.
These are referred to together as the "Services". By creating an account or using the Services, you agree to this Policy. If you do not agree, please do not use the Services.
1. Our role and your fitness club's role
Kinfit is a business-to-business platform. Fitness clubs, gyms and studios ("Clubs") subscribe to Kinfit and use it to manage their own members.
- For data about a Club's members, the Club is the data controller – it decides what member data to record and why. Kinfit acts as a data processor and handles that data on the Club's instructions.
- For a Club's own account data, billing data, and for our website and marketing, Kinfit is the controller.
If you are a gym member and want your data corrected or erased, contact your Club first. You may also contact us and we will assist your Club in responding.
2. Information we collect
2.1 Information you or your Club provides
- Account and identity data: name, username, password (stored only as a salted hash), role (owner, staff, trainer, member) and the Club you belong to.
- Contact data: mobile number, email address and postal address.
- Membership data: admission number, date of joining, membership plan, plan validity, batch or workout type, and membership status.
- Profile photograph: optional, uploaded by the member or by Club staff for identification at the front desk.
- Health and fitness data: optional entries such as date of birth, gender, height, weight and fitness goals, where the Club chooses to record them. We treat this as sensitive personal data.
- Emergency contact details, where recorded by the Club.
2.2 Attendance and biometric integration
Clubs may connect Kinfit to a biometric attendance device installed at their premises. In that case Kinfit receives, from the Club's device, a numeric device user ID and the punch date and time only. Kinfit does not collect, receive, process or store fingerprint images, facial images or any biometric template. Biometric templates remain on the Club's own device and are governed by the Club's policy.
2.3 Payment and financial data
Kinfit records fee demands, payments received, payment mode (cash, card, UPI, bank transfer), receipt numbers and outstanding balances so that a Club can maintain its accounts. Kinfit does not collect or store full card numbers, CVV, UPI PINs or bank credentials. Where online payment is offered, it is handled by a PCI-DSS-compliant payment gateway that processes those details directly.
2.4 Information collected automatically
- Device and app data: device model, operating system version, app version and a generated installation identifier.
- Log and diagnostic data: IP address, request timestamps, API endpoints accessed, and crash and error reports, used to keep the Services secure and reliable.
- Push notification token: a Firebase Cloud Messaging (FCM) registration token, used solely to deliver notifications to your device.
- Session data: a JSON Web Token (JWT) stored on your device to keep you signed in.
2.5 Permissions the apps request
- Internet and network state – required to communicate with the Kinfit servers.
- Notifications – to send renewal reminders, payment receipts and Club announcements. You may decline or revoke this permission at any time.
- Photos and media (Member app) – only to let you pick a profile picture. We access the single image you choose; we do not scan or upload your gallery.
Kinfit does not request or collect precise location, contacts, SMS, call logs, microphone or background camera access.
3. How we use your information
- To create and administer your account and authenticate sign-in.
- To provide the core features of the Services: membership records, attendance, plans, fee demands, payment collection, receipts and reports.
- To send transactional messages by push notification, email or WhatsApp – for example welcome messages, payment receipts, due-date and expiry reminders – triggered by your Club.
- To generate aggregated business insights and reports for your Club.
- To provide customer support and respond to your requests.
- To maintain security, prevent fraud and misuse, and diagnose faults.
- To comply with legal, tax and accounting obligations.
We do not sell your personal information. We do not use your data for behavioural advertising, and we do not share it with data brokers or advertising networks.
4. Legal basis for processing
Where data protection law requires a legal basis, we rely on: performance of a contract with you or your Club; your consent (for optional health data, profile photographs and marketing messages, which you may withdraw at any time); our legitimate interests in operating and securing the Services; and compliance with legal obligations.
5. How we share information
We share personal information only as described below.
- With your Club. Authorised staff of the Club you belong to can see your membership record, attendance and payment history.
- With service providers who process data on our behalf under contract and only for the purposes we specify: cloud hosting and database providers, Google Firebase Cloud Messaging (push notifications), email delivery providers, WhatsApp Business message providers, and payment gateways.
- For legal reasons – where required by law, court order or a lawful request from a public authority, or to establish or defend legal claims.
- In a business transfer – if Kinfit is involved in a merger, acquisition or sale of assets, subject to this Policy continuing to apply.
Members of one Club can never see the data of another Club. Data is separated by tenant at every layer of the application.
6. International transfers
Kinfit data is hosted on servers located in India. If data is transferred outside your country, we use appropriate safeguards such as standard contractual clauses with our providers.
7. Data retention
- Active member and Club records are retained for as long as the Club's subscription is active.
- If you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where longer retention is required by law.
- Financial and transaction records may be retained for up to 8 years to meet Indian tax and accounting requirements.
- Server and security logs are retained for up to 90 days.
- Backups are purged on a rolling cycle of up to 90 days.
8. Account and data deletion
You can request deletion of your Kinfit account and the personal data associated with it at any time. Deletion is handled by email request, so that we can confirm the request genuinely comes from you before any record is removed.
How to request deletion
Send an email to kinfitindia@gmail.com with the subject line "Delete my account", and include the following so we can verify your identity:
- Your full name as registered with your fitness club.
- Your registered mobile number and, if you have one, your admission or membership number.
- The name of the fitness club you are a member of, or that you operate.
- A photograph or scan of a government-issued photo identity document, so that we can confirm the request comes from the account holder. You may mask any number or detail on the document that is not needed to match your name and photograph.
Sending the request from the email address already registered on your Kinfit account helps us verify it faster. Gym members may also ask their fitness club's front desk to raise the deletion request on their behalf.
What happens next
- We acknowledge your request within 7 days of receiving it.
- If the information you sent is not enough to verify you, we will write back and ask for what is missing. We may decline a request we cannot verify, and we will tell you why.
- Once verified, we complete the deletion within 30 days and confirm by email when it is done.
- The identity document you send is used only to verify the request and is deleted from our systems once the request is closed. It is never added to your membership record.
What is deleted, and what is kept
Deleted: your login credentials, profile and contact details, profile photograph, health and fitness entries, emergency contact, attendance history and push notification tokens.
Kept: financial and transaction records that your fitness club is required to retain under Indian tax and accounting law, as described in section 7. These are anonymised so that they no longer identify you, and are not used for any other purpose.
Deleting your account is permanent and cannot be undone. If you are a gym member, deletion ends your access to the Kinfit Member app; it does not by itself cancel or refund any membership you hold with your fitness club, which remains a matter between you and the club.
9. Your rights
Subject to applicable law, you may:
- Access the personal data we hold about you and request a copy.
- Correct data that is inaccurate or incomplete.
- Request erasure of your data.
- Withdraw consent you previously gave, without affecting processing already carried out.
- Object to or restrict certain processing.
- Request portability of the data you provided, in a machine-readable format.
- Opt out of promotional messages at any time, while continuing to receive essential service messages.
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity, as provided under India's Digital Personal Data Protection Act, 2023.
To exercise a right, email kinfitindia@gmail.com. We respond within 30 days. If you are dissatisfied with our response, you may complain to your local data protection authority, or in India to the Data Protection Board.
10. Security
- All traffic between the apps and our servers is encrypted using HTTPS/TLS.
- Passwords are stored only as salted BCrypt hashes and are never readable by us.
- Access is controlled by role-based permissions and expiring JWT session tokens.
- Each Club's data is isolated from every other Club's data.
- Access to production systems is limited to authorised personnel and is logged.
No method of transmission or storage is completely secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
11. Children's privacy
The Services are not directed to children under 13. Where a Club enrols a minor, the Club must obtain verifiable consent from a parent or guardian before entering the minor's data, and the guardian's contact details are recorded. We do not knowingly create accounts for children under 13. If you believe a child's data has been provided to us without proper consent, contact us and we will delete it.
12. Third-party links and services
The Services may link to third-party websites or payment pages. This Policy does not cover those sites, and we encourage you to read their privacy policies. Our use of Firebase Cloud Messaging is additionally governed by Google's Privacy Policy.
13. Cookies
Our website uses strictly necessary cookies to maintain your session and remember your preferences. The mobile apps do not use advertising cookies or third-party trackers.
14. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above will change, and material changes will be notified in the app or by email at least 7 days before they take effect. Continued use after that date means you accept the revised Policy.
15. Contact us
For any question, request or complaint about this Policy or your personal data:
Kinfit
Grievance Officer / Privacy Contact
Email: kinfitindia@gmail.com
For account deletion, use the subject line "Delete my account" – see
section 8.