1. Introduction and Overview
This Privacy Policy ("Policy") constitutes a formal legal disclosure by TheIronStack ("Company", "we", "our", or "us") regarding the collection, use, disclosure, retention, and protection of Personal Data (as defined herein) acquired through your access to and interaction with the platform.
TheIronStack provides a comprehensive software-as-a-service (SaaS) ecosystem enabling individual users ("Members") to discover fitness facilities, track athletic metrics, manage memberships, and engage with facility operators ("Gym Owners") and authorized instruction personnel ("Trainers"). Simultaneously, the platform provides business management tools for Gym Owners to administer facilities, personnel, attendance, and member subscriptions.
By registering an account, accessing, or utilizing any portion of the Services, you acknowledge that you have read, understood, and consented to the data practices described in this Policy. If you do not agree with the terms outlined herein, you must immediately discontinue use of the Services.
2. Scope and Applicability
This Policy governs all software products, web applications, mobile applications, application programming interfaces (APIs), and digital services operated by the Company that explicitly link to or reference this document (collectively, the "Services").
This Policy does not extend to third-party services, applications, or websites operating independently of the Company, notwithstanding any hyperlinks or integrations embedded within the Services.
3. Definitions
For the purposes of this Policy, the following terms shall be defined as set forth below:
- "Personal Data" means any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or online identifier.
- "Fitness & Health Data" means user-provided physical metrics, body measurements, workout schedules, nutritional records, and attendance histories collected through the platform.
- "Member" means any registered individual utilizing the platform for personal fitness management or gym membership access.
- "Gym Owner" means an authorized individual or corporate entity utilizing the Services to operate and manage a registered fitness facility.
- "Trainer" means an individual designated and authorized by a Gym Owner to administer fitness instruction or manage member routines within a specific facility.
- "Services" refers to the entirety of the software solutions, platforms, and digital interfaces maintained by the Company.
4. Categories of Data Collected
The Company collects data through direct user input, automated platform operations, and system-generated activity logs.
4.1 Account Credentials and Verification Data
Upon account initiation, the Company collects essential identification attributes, including:
- Full legal name and preferred username;
- Primary electronic mail address and telephone number;
- Cryptographic authentication tokens and encrypted password hashes;
- Account classification (Member, Trainer, or Gym Owner);
- User profile imagery.
Security Notice: Passwords are processed exclusively using modern salted one-way cryptographic hashing algorithms. Plaintext passwords are never stored or transmitted across our infrastructure.
4.2 Profile and Demographic Information
Users may voluntarily supplement their profiles with demographic parameters, including biography, gender, date of birth, and custom display preferences. Date of birth attributes are processed solely to compute chronological age. Where displayed across the Services, only calculated age values are rendered unless legal compliance mandates complete date-of-birth disclosure.
4.3 Physical Metrics and Fitness Data
To facilitate performance tracking, the platform records physical measurements voluntarily submitted by Members, including:
- Height, weight, and target weight objectives;
- Automated Body Mass Index (BMI) computations derived from submitted height and weight parameters;
- Structured workout routines, exercise parameters, and scheduling preferences;
- Custom dietary plans, meal logs, and nutritional notes;
- Historical attendance records and facility affiliation logs.
Data Integrity Commitment: Fitness Data is strictly utilized for core service functionality. The Company explicitly refrains from selling, monetizing, or utilizing user Fitness Data for artificial intelligence model training or third-party marketing.
4.4 Facility Management Data (Gym Owners & Trainers)
For Gym Owners registering a commercial facility, the Company collects business identification and operational parameters:
- Registered business name, trade name, and physical address;
- Commercial contact details, operating schedules, and geographic coordinates;
- Facility descriptions, amenity inventories, and promotional media galleries;
- Staff directory listings, instructor qualifications, and assigned administrative permissions.
4.5 Automated Check-In and Camera Operations
Participating facilities utilize QR code verification for attendance tracking. Upon scanning, camera input is processed locally on-device to decode authentication payloads. Camera image data is neither captured nor retained on Company servers; only the decoded verification token is transmitted for check-in logging.
4.6 Technical Metadata and Telemetry
Upon accessing the Services, system logging mechanisms automatically collect infrastructure metadata:
- Internet Protocol (IP) addresses and session identifiers;
- Operating system specifications, browser attributes, and device hardware models;
- Access timestamps, authentication events, and system performance metrics.
5. Processing Purposes and Legal Bases
The Company processes Personal Data strictly in accordance with applicable data protection laws. Processing is executed pursuant to the following operational purposes:
| Category | Primary Processing Purpose | Legal Basis |
|---|---|---|
| Account Administration | User authentication, identity verification, and role-based access control. | Performance of Contract |
| Fitness Services | Calculation of fitness metrics, routine tracking, and diet administration. | Performance of Contract / Consent |
| Facility Operations | Facilitating member check-ins, subscription tracking, and trainer assignments. | Legitimate Interest / Contract |
| System Security | Fraud detection, threat mitigation, audit logging, and service stability. | Legal Obligation / Legitimate Interest |
| Communications | Delivery of transactional notices, security alerts, and administrative updates. | Performance of Contract |
6. Access Control and Role-Based Permissions
Information disclosure within the platform is strictly governed by principles of least-privilege access:
- Member Self-Access: Members maintain full visibility over their personal account data, routines, and historical logs.
- Authorized Facility Personnel: Upon a Member joining a specific gym, authorized Gym Owners and designated Trainers associated with that facility receive restricted access to relevant workout routines, diet plans, and attendance records necessary for instructional coaching.
- Public Attributes: Gym listings, facility descriptions, public ratings, and published reviews are publicly accessible for facility discovery purposes. Individual Member records remain private and are excluded from public indexing.
7. Data Sharing and Third-Party Disclosures
The Company does not trade, rent, or sell Personal Data to third parties. Information disclosures are limited strictly to the following parameters:
- Subprocessors and Infrastructure Vendors: We engage verified third-party vendors for cloud hosting, database administration, encrypted media storage, and transactional messaging. These entities operate under rigorous contractual confidentiality obligations.
- Legal and Regulatory Mandates: Disclosure may be executed if required by valid judicial order, legal process, legal regulation, or governmental inquiry.
- Corporate Restructuring: In the event of a merger, acquisition, asset transfer, or corporate reorganization, user records may be transferred subject to equivalent privacy protections.
8. Data Security Architecture
The Company maintains technical, physical, and administrative safeguards designed to protect Personal Data against unauthorized access, loss, alteration, or disclosure:
- Encryption Standards: Transmissions are protected via Transport Layer Security (TLS 1.3). Data at rest is encrypted utilizing AES-256 standards.
- Access Safeguards: Administrative infrastructure access is restricted via multi-factor authentication (MFA) and strict role-based authorization protocols.
- Audit Logging: System interactions are logged and monitored continuously for security anomalies.
While comprehensive safeguards are enforced, no electronic storage architecture can guarantee absolute immunity from breach. Users remain responsible for maintaining the confidentiality of their credentials.
9. Data Retention and Account Termination
Personal Data is retained only for the duration required to fulfill the operational purposes set forth in this Policy, or as required by applicable legal, tax, and accounting standards.
Upon receipt of a verified account deletion request:
- Active account credentials and profile attributes are permanently purged from primary application databases;
- Associated routines, diet logs, and facility affiliations are queued for permanent deletion;
- Residual data contained within encrypted disaster recovery backups is overwritten in accordance with standard backup rotation cycles.
10. Data Subject Rights
Subject to statutory provisions in your jurisdiction, you may exercise the following rights regarding your Personal Data:
- Right to Access: Request formal confirmation and copy of Personal Data under processing;
- Right to Rectification: Request correction of inaccurate or incomplete records;
- Right to Erasure: Request permanent deletion of Personal Data ("Right to be Forgotten");
- Right to Data Portability: Obtain personal records in a structured, machine-readable format;
- Right to Object/Restrict: Limit processing under specific legal grounds.
Requests may be submitted to our Privacy Compliance Officer at support@theironstack.in. Identity verification may be required prior to request execution.
11. Regulatory Compliance and Governing Law
This Policy and all matters arising hereunder shall be governed by and construed in accordance with the laws of the Republic of India, including the Digital Personal Data Protection Act (DPDP), without giving effect to conflict-of-law principles.
12. Contact Information
For inquiries, formal privacy grievances, or rights requests, please direct communications to:
TheIronStack Data Protection Office
Email: support@theironstack.in
Website: https://theironstack.in