FitFare Privacy Policy
This single Privacy Policy covers all FitFare products. Read the part that applies to you:
Part A FitFare user app (iOS & Android — book gyms, Fit Credits)
Part B FitFare Partner app (gym / studio owners)
Part C fitfare.in website
It explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and your rights. It supports Apple App Store App Privacy disclosures, Google Play Data safety disclosures, and applicable Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP).
By creating an account or using FitFare, you agree to this Policy. If you do not agree, please stop using the products.
1. Who we are & how to contact us
FitFare operates a fitness marketplace. Users discover gyms and studios, book day passes and sessions, and manage prepaid Fit Credits. Partner gyms list their centres, manage bookings and attendance, and receive payouts.
| Purpose | Contact |
|---|---|
| Privacy, data requests, deletion, grievance | collaborations@fitfare.in |
| General support | collaborations@fitfare.in |
| Phone | +91 7666400518 |
2. At a glance — what each product collects
| Data | User app | Partner app | Website |
|---|---|---|---|
| Name, phone, email | Yes | Yes | Only if you submit a form |
| Gender, date of birth | Yes (optional profile) | No | No |
| Profile / centre photos | No (user app has no profile photo) | Yes (centre & KYC images) | No |
| Location | Yes (with permission) | Centre address only | No |
| Government ID / PAN / business docs | No | Yes (KYC) | No |
| Bank account details | No | Yes (payouts) | No |
| Payment card / UPI credentials | No — handled by Razorpay | No | No |
| Push notification device ID | Yes | Yes | No |
| Crash / diagnostics | Basic app logs | Yes | Standard website logs |
We do not sell personal data and we do not use your data for third-party advertising.
3. Part A — FitFare user app
Applies to the FitFare user app on iOS and Android.
A1. Account & profile
- Name, phone number, email — to create your account, confirm bookings, and contact you about a booking. Email on your profile is for account and booking contact; it is not a separate login method unless you use Google or Apple Sign-In.
- Gender — collected during onboarding and editable later; used to personalise recommendations and filter centres with gender-specific access.
- Date of birth — optional; for age eligibility (18+) and personalisation.
- Profile photo — not collected in the user app.
- City and preferred activities — to personalise discovery.
A2. Sign-in
- You can sign in with a one-time code sent to your phone, with Google Sign-In, or with Sign in with Apple on iOS.
- Sign-in is provided by Google (Firebase) and Apple.
- If you use Google or Apple Sign-In, we may receive your name, email, and (for Google) profile photo when you share them. We never receive or store your Google or Apple password.
A3. Location
- With your permission, we use your foreground location to show nearby gyms and distance while you use the app.
- We do not request background location. Booking works without location access.
- You can turn location off anytime in device settings. We do not sell or share your location with advertisers.
A4. Bookings & check-in
- Centre, service, date and time, quantity, amount, payment method, and booking status.
- Check-in / attendance records when you visit.
- The Partner gym you booked receives only the details needed to honour your visit (see Sharing).
A5. Fit Credits
- Your Fit Credit balance, expiry dates, amounts held for a booking, and transaction history.
- Fit Credits are a prepaid balance used only to book physical visits at Partner gyms and studios (day-passes and similar on-site services). They are not used to unlock digital content, subscriptions, or in-app features unrelated to a Partner visit.
- If you transfer credits, we use the phone number or email you enter to find the recipient’s FitFare account and show their display name. Both sides get a transaction record and may get a notification.
A6. Favourites, reviews & activity
- Saved centres, ratings and reviews (shown publicly with your display name), and search/browse activity used to run and improve discovery.
A7. Payments
- Payments for Partner bookings and Fit Credit top-ups are processed by Razorpay.
- These payments are for physical fitness services delivered at Partner venues (or prepaid credit redeemable only for those services). They are not purchases of digital goods or unlockable content inside the app.
- FitFare keeps payment confirmation details such as amount, order/payment id, and status.
- Card numbers, CVV, UPI PIN, and net-banking passwords are never stored by FitFare.
A8. Notifications
- We store a push notification device ID linked to your account for transactional alerts (for example booking confirmed or Fit Credits received).
- It is removed when you log out or delete your account.
- You can turn notifications off in device settings; bookings still work.
A9. Camera & photos
- Camera — only to scan a check-in QR code. We do not record video.
- Photos / photo library — not used in the user app. We do not request photo-library access for a profile picture.
A10. Device & support
- Basic device and app information (for example device type, OS, app version) and error logs for reliability and security.
- Some non-sensitive data may be stored on your device to make the app open faster. Clearing app data removes it.
- Support messages and screenshots you send us.
A11. Permissions — user app
| Permission | Why | Required? |
|---|---|---|
| Internet | Connect to FitFare | Required |
| Location (foreground) | Show nearby gyms and distance | Optional |
| Camera | QR check-in | Optional |
| Photos / media | Not requested in the user app | No |
| Notifications | Booking and Fit Credit alerts | Optional |
We do not request SMS inbox, call logs, contacts, or microphone access in the user app.
4. Part B — FitFare Partner app
Applies to the FitFare Partner app used by gym and studio owners/operators. Partners must be 18+ and represent a legitimate business.
B1. Account
- Owner/business email, phone, and sign-in details.
B2. Identity & KYC documents
- Owner name; government identity documents — Aadhaar, Passport, or Driving Licence.
- PAN.
- Business registration documents as applicable — GST certificate, Shops & Establishment licence, Udyam registration, certificate of incorporation, LLP or partnership deed.
- Optional cancelled cheque or bank passbook image.
Used for identity verification, fraud prevention, payout eligibility, and legal/tax compliance. Access is limited to authorised FitFare reviewers and systems.
B3. Bank & payout data
- Account holder name, bank account number, and IFSC. Account numbers are stored securely.
- Bank verification status. We may verify the account through our payment partner (RazorpayX), including a small test deposit.
- Payout statements, settlement amounts, commission, and adjustments.
B4. Business & operations data
- Centre profile: name, address, photos, amenities, hours, services, slots, trainers, and pricing.
- Bookings received, check-in / attendance records, no-shows, and support messages.
B5. Notifications, media & diagnostics
- Push notification device ID for alerts such as a new booking or KYC status update.
- Camera and photos — to capture or upload KYC and centre images, and to save your centre QR if you choose.
- Crash and stability reports, and app version information.
B6. What Partners see about users
Partners receive only what is needed to honour a visit: booking reference, display name, booking date/time, service, quantity, and check-in status. Partners do not receive payment credentials, Fit Credit balance, or full account profile. Partners must not reuse or sell user data.
B7. Permissions — Partner app
| Permission | Why | Required? |
|---|---|---|
| Internet | Connect to FitFare | Required |
| Camera / Photos | KYC and centre documents, save QR | Optional |
| Notifications | Booking and KYC/payout alerts | Optional |
The Partner app does not request location, SMS, contacts, or microphone access.
5. Part C — fitfare.in website
- Contact and enquiry forms — name, email, phone, and message.
- Careers applications — details you send us by email.
- Standard website logs — for security and abuse prevention.
- We do not run advertising trackers or sell website visitor data.
6. How we use data
| Purpose | Typical data |
|---|---|
| Create and secure your account | Name, phone, email, sign-in |
| Show nearby centres | Location, search activity |
| Process bookings, check-in, and Fit Credits | Booking and credit records |
| Take payments and issue refunds | Payment confirmation details via Razorpay |
| Send transactional notifications | Push device ID, booking events |
| Verify Partner identity and pay out | KYC, PAN, bank details |
| Prevent fraud and misuse | Device, sign-in, and transaction signals |
| Provide support | Messages, booking history |
| Improve reliability | Diagnostics |
| Comply with law | As required |
7. Sharing & service providers
We share personal data only as needed to run FitFare:
| Recipient | What for | Applies to |
|---|---|---|
| Google / Firebase | Sign-in, push notifications, remote settings, crash reports (Partner) | User, Partner |
| Supabase | Database and file storage under our instructions | User, Partner |
| Cloud hosting (Render) | Running the FitFare API | User, Partner |
| Razorpay / RazorpayX | Payments, refunds, bank verification, partner payouts | User, Partner |
| Maps / navigation | Only when you open directions to a centre | User |
| Partner gyms | Limited booking details to honour your visit | User |
| Email provider | Website contact form and support email | Website |
| FitFare staff | KYC review, support, fraud checks | User, Partner |
| Authorities | When legally required | All |
Service providers process data on our behalf and are not allowed to use it for their own purposes.
8. Retention
- Account and booking records — while your account is active and for a reasonable period afterwards for disputes, accounting, and fraud prevention.
- Payment and payout records — as long as tax, audit, and chargeback rules require.
- Partner KYC and bank documents — while the partnership is active; after offboarding, deleted or anonymised subject to legal retention.
- Push device IDs — removed on logout or deletion.
- Support messages — for a reasonable period.
9. Account deletion
User app
Go to Profile → Edit Profile → Delete my account.
- Deletion is scheduled with a 30-day hold and you are signed out.
- If you sign in again within 30 days, deletion is cancelled.
- After 30 days, we permanently delete or anonymise your account identifiers (name, email, phone, photo, gender, date of birth, preferences), remove your push device ID, and remove your sign-in account.
- Records we must keep for law or tax may remain in limited or de-identified form.
Partner app
Request deletion from the Partner app profile screen, or email collaborations@fitfare.in from your registered address. Pending settlements are reconciled first; KYC/financial records are retained where law requires.
Either app
You can always email collaborations@fitfare.in for a verified deletion request.
10. Security
- Encrypted connections (HTTPS) for data in transit.
- Secure sign-in and access controls on account data.
- Partner bank details and KYC documents are stored with restricted access.
- Payment card and UPI credentials are handled by Razorpay and never stored by FitFare.
No system is completely secure. Keep your device and sign-in access protected.
11. Your rights (including DPDP) & grievance
Subject to applicable law, you may:
- Access the personal data we hold about you;
- Correct or update your profile in-app where available;
- Request deletion (see Account deletion);
- Withdraw consent by turning off location, camera, or notifications in device settings;
- Nominate another person to exercise your rights in case of death or incapacity, as provided under DPDP;
- Raise a grievance about how your data is handled.
Email collaborations@fitfare.in. We may verify your identity before acting and will respond within the period required by law.
12. Children
FitFare is for people aged 18 or older. We do not knowingly collect personal data from children. Contact us if you believe a child has used FitFare and we will delete the data.
13. International transfers
Your data may be processed in India or in other countries where our service providers operate. We take steps reasonably designed to protect it under applicable law.
14. Google Play “Data safety” mapping — user app
| Play category | Collected | Shared | Purpose |
|---|---|---|---|
| Personal info (name, email, phone, gender, DOB) | Yes | Limited to Partner for your booking | Account, app functionality |
| Photos | No | — | — |
| Location | Yes (optional) | No | Nearby gyms |
| Financial info (purchase history) | Yes (payment confirmation) | With payment processor | Payments for physical Partner services |
| Payment card / UPI credentials | No — handled by Razorpay | — | — |
| App activity | Yes | No | App functionality |
| Messages (support) | Yes, if you send them | No | Support |
| Device or other IDs | Yes (push device ID) | With Google/Firebase for push | Notifications |
| Crash logs / diagnostics | Yes (basic) | No | Reliability |
Data is encrypted in transit. You can request deletion in-app or by email. We do not sell data and do not use it for third-party advertising.
15. Apple App Privacy mapping — user app (iOS)
Use this section when completing App Store Connect → App Privacy. FitFare does not track users across apps or websites owned by other companies for advertising.
| Apple data type | Collected? | Linked to identity? | Used for tracking? | Purpose |
|---|---|---|---|---|
| Name | Yes | Yes | No | App functionality |
| Email address | Yes | Yes | No | App functionality |
| Phone number | Yes | Yes | No | App functionality |
| Physical address | No | — | — | — |
| Photos or Videos | No | — | — | — |
| Precise Location | Yes (optional, while using the app) | Yes | No | App functionality (nearby gyms) |
| Coarse Location | No (we use precise when permitted) | — | — | — |
| Purchase History | Yes | Yes | No | App functionality (bookings / credits) |
| Product Interaction | Yes | Yes | No | App functionality |
| Advertising Data | No | — | — | — |
| Device ID | Yes (push notification token) | Yes | No | App functionality |
| Crash Data | Yes | No | No | App functionality / reliability |
| Performance Data | Yes (basic) | No | No | App functionality / reliability |
| Other User Content (e.g. reviews, support) | Yes, if you submit it | Yes | No | App functionality / customer support |
Sign in with Apple: available on iOS alongside phone OTP and Google Sign-In. Account deletion: Profile → Edit Profile → Delete my account (30-day hold), or email us.
16. Changes to this Policy
We may update this Policy. Material changes are shown by updating the “Last updated” date and, where appropriate, by in-app notice. Continued use after an update means you accept the revised Policy.
17. Contact
Privacy, deletion and grievance: collaborations@fitfare.in
Support: collaborations@fitfare.in
Phone: +91 7666400518
See also: Terms of Service · Cancellation & Refunds · Contact