Privacy Policy
This Privacy Policy describes how CupidFaces Technologies ("we") collects, uses, and protects information when you or your members use GymProHub ("Service").
1. What we collect
Account data (name, email, gym name, country). Member data your gym uploads (member profile, payments, attendance, medical notes when you use that feature). Log data (IP, user agent, timestamps). Payment metadata from Paystack or Stripe (we do NOT store full card numbers).
2. How we use it
To provide the Service (log in, process payments, send reminders). To improve product quality (aggregated usage). To communicate service updates. To meet legal obligations.
3. Who we share with
Only the third parties strictly required to run the Service: Neon (database), Vercel (hosting), Paystack + Stripe (payments), Brevo (transactional email), Termii (SMS). Each processes only the minimum data they need. We do NOT sell data.
4. International transfers
Your data may be processed in the US, EU, or Nigeria depending on which of our providers holds it. All transfers are protected by contractual clauses and encryption in transit + at rest.
5. Retention
We keep your data for as long as your account is active. After cancellation we retain data for 30 days for recovery, then permanently delete it. Audit logs are retained 180 days for security.
6. Your rights
You can access, correct, export, or delete your data at any time from your settings. For members whose data your gym uploaded, the gym owner is the data controller and you should contact them first; we assist on request.
7. Medical notes (HIPAA-aligned)
Medical notes stored via the members feature are encrypted with a per-gym key. Only your gym owner + trainers with the "medical" permission can decrypt them. We treat them with US HIPAA-aligned safeguards.
8. Cookies
We use strictly necessary cookies (session, CSRF, locale). Optional analytics cookies (GA4) are only set after you accept the cookie banner.
9. Contact
Privacy questions: privacy@gymprohub.fun.