Your privacy is important to us. This policy explains what data we collect and how we use it.
Last updated: September 3, 2026
01
Data We Collect
When using the GymFlow mobile application, we collect the following information:
Account data: name, email, and phone number (optional). Provided by your gym upon
registration.
Membership data: plan, expiration date, credits, and classes attended.
Training data: weight records and one-rep max (1RM) entries that you voluntarily
input after each class.
Booking data: classes booked, cancelled, and attendance history.
Health Data: medical conditions, medications, active injuries, emergency contact,
and medical clearance information. See section 1b for details.
Device token: for push notifications via Firebase Cloud Messaging.
We do not collect banking or payment information. Payments are managed
directly by the gym.
01b
Health Data
GymFlow allows the gym to record and manage member health information through the
Medical History module. This functionality is operated by gym staff and may include the
following data:
Health data we collect:
Pre-existing medical conditions: chronic diseases, allergies, or other conditions
relevant to sports practice (e.g., asthma, hypertension, diabetes).
Medications: current medication that may affect physical activity.
Active injuries: injuries being monitored with start date, affected area, and
recovery status.
Emergency contact: name and phone number of an emergency contact person.
Medical clearance: physical fitness certificate with issuance and expiration dates.
The certificate may be uploaded as an attachment.
Physical performance data (fitness data): one-rep max (1RM) records per exercise,
weight history, and progression over time, voluntarily entered by the member.
How we use this health data:
To allow gym staff to adapt training to each member's conditions.
To alert instructors about active injuries or medical restrictions before a class.
To manage medical clearance expiration and notify for renewal.
To allow members to keep a personal record of their physical progression (RM).
To contact the emergency person if needed during a class.
Important: Health data is treated as sensitive information. It is only accessible by
authorized gym staff (administrators and instructors) and by the GymFlow technical team for support
purposes only. It is not shared with third parties under any circumstances β not even with systems your
gym connects through an integration, which cannot access it even with the gym's permission β except
when required by law.
Legal basis for processing:
Health data is collected with the explicit consent of the member or their legal
guardian (in the case of authorized minors), at the time of gym registration.
Members may request the deletion of their medical history at any time by contacting
privacidad@gymflow.com.ar
or their gym administrator.
Storage and protection:
Health data is stored on the same secure infrastructure as all other data (firewall-restricted
servers, HTTPS/TLS 1.2+ communication).
Access to this data is limited by roles: only users with administrator or instructor permissions at
the gym can view a member's medical history.
Physical performance data (RM) is only visible to the member themselves and authorized gym staff.
02
How We Use Your Data
We use the information to:
Authenticate your access and maintain your active session.
Display your membership, bookings, and training progress.
Send you push notifications from the gym (expirations, news, schedule changes).
Calculate and store your one-rep max (RM) history and athletic progression.
Allow you to book and cancel classes on the schedule.
Manage your medical history and health data (see section 1b).
Facilitate real-time communication between you and gym staff via chat.
We never use your data for advertising purposes nor do we sell it to third parties.
03
Camera Usage
The app requests camera access exclusively to scan WOD QR codes at the end of each
class.
The camera does not take photos or videos stored anywhere.
The camera does not activate automatically; only when you press the scan button.
The permission is optional: you can use the app and enter data manually from the RM Calculator.
You can revoke camera permission in Settings β Apps β GymFlow β Permissions.
Apart from Firebase, GymFlow does not engage or enable any third-party service with access to your
personal data on its own initiative.
Integrations enabled by your gym
Your gym may connect GymFlow to another system β its own website, or a vendor's tool β so that both
work with the same data. That decision belongs to the gym, which is the controller of
your data: we do not make it on their behalf, and we never enable integrations on our own.
Whenever your gym enables an integration, the following always applies:
On the gym's side, only the administrator can enable it, from their own panel: front
desk, staff and instructors cannot. They can revoke it at any time, and revoking cuts off
access immediately.
Access is granted permission by permission, and starts with none: the connected system
receives only what the gym explicitly allowed β for example your name and the status of your
membership fee β and nothing else.
The scope is your gym and nothing more. An integration can never see the members
of a different gym.
It never includes your health data, your medical history, or your password.
None of that is shared with any integration, not even if the gym wanted to allow it.
It is audited: every request is logged, and the gym can see what was queried and when.
If you want to know which integrations your gym has enabled, or ask that they stop receiving your data,
you can ask the gym directly or write to
privacidad@gymflow.com.ar
and we will take it up with them.
Under no circumstances do we sell your data or use it for advertising, and neither may any system your
gym connects.
05
Data Retention
Your data is retained while your account is active. Upon account cancellation:
Your account data is deleted or anonymized within 30 days.
Health data and medical history are deleted along with the account.
RM history can be exported before deletion by contacting support.
Push tokens are deleted immediately upon logout.
06
Your Rights (ARCO)
You have the right to:
Access: know what data we hold about you.
Rectification: correct inaccurate data.
Cancellation/Deletion: request that we delete your data.
Opposition: object to processing in certain cases.
If your gym has an integration enabled,
deletion also has to be passed on to that system, since it holds its own copy of whatever it received.
Ask us along with your deletion request and we will tell you who it has to be handled with; the gym,
as the controller of your data, is the party that must instruct them.
07
Security
All communications use HTTPS (TLS 1.2+).
Authentication tokens have automatic expiration.
Passwords are stored hashed (never in plain text).
Database access is restricted by firewall.
If you discover a vulnerability, please report it responsibly to
hola@gymflow.com.ar.
08
Minors
GymFlow is intended for users aged 16 and older. We do not intentionally collect data from minors without
verifiable parental consent.
If you believe your child has provided us with data without your consent, contact us at
hola@gymflow.com.ar and we will proceed with deletion.
09
Changes to This Policy
We will notify you of significant changes through an in-app notice and an email to your registered
address, with at least 15 days' advance notice.
Continued use of the app after changes implies acceptance of the updated policy.