Privacy Policy
Last updated: August 1, 2026
Fitmark is a connected fitness business platform made up of the Fitmark web management platform, the Fitmark Team staff/trainer mobile app, and client/member app experiences. This Privacy Policy explains how Fitmark accesses, collects, uses, shares, retains, and deletes user data across these surfaces, including the Fitmark Team app listed on Google Play.
Who We Are
Fitmark is developed and operated by Intagrit Developers, the developer entity named for Fitmark Team in app store listings. Accounts are provisioned to gyms, fitness studios, and personal training businesses ("gym organizations"), which administer their own staff, trainers, and members inside the platform.
For privacy questions, data correction requests, export requests, or account/data deletion requests, contact us at jagadishjagadish2022@gmail.com.
Information We Collect
Depending on the user's role and gym configuration, Fitmark may process:
- Account and login information, including username, phone or email identifiers when used for login, role, company, branch, subscription status, authentication tokens, and secure session data.
- Staff and trainer profile information, including name, phone number, email, gender, address, role, staff type, PT status, salary, specialization, certificates, achievements, branch, status, and selected profile photo.
- Member and PT client information needed for gym operations, including name, contact details, profile details, membership plans, assigned trainers, PT slots, attendance, fitness or lifestyle fields entered by the gym, measurements, plan history, and renewal history.
- Operational records, including attendance, QR check-in scans, sessions, renewals, payments, invoices, expenses, reports, follow-ups, and dashboard data.
- Staff attendance punch records, including the punch timestamp, session, shift and late/half-day outcome, the selfie captured at each punch, and the device location reading (latitude, longitude, and accuracy where available) taken at the moment of that punch, together with the distance from the gym calculated by the server.
- Payment and billing records, including payment amounts, payment modes, balances, dues, receipt details, invoice details, and subscription or renewal records. Fitmark is not a payment card processing app and does not intentionally collect card numbers or government identification numbers.
- Selected images and uploaded content, such as profile photos chosen by an authorized user.
- Push notification tokens when notification permission is granted or when operational push messaging is enabled for the account.
- Device, app, and diagnostic data needed for security, debugging, reliability, support, analytics, crash reporting, and app update delivery, such as device type, operating system, app version, environment, logs, crash data, network metadata, and similar technical information.
- Support communications, including messages, phone calls, emails, or request details sent to Fitmark for help, privacy, deletion, billing, or service support.
Fitmark does not intentionally collect contacts, SMS, call logs, microphone audio, health data from Health Connect, the list of installed apps, payment card numbers, or government identification numbers. Precise location is collected only for staff attendance punches, in the narrow way described in Staff Attendance: Selfie and Location below.
Staff Attendance: Selfie and Location
Gym organizations can switch on mobile attendance so that staff and trainers mark their own attendance from the Fitmark Team app. Where it is enabled, this is the only part of Fitmark that uses the camera for photos of people or reads device location.
When a user taps Punch In or Punch Out, the app captures a selfie with the front camera and takes a single device location reading at that moment. The photo, the latitude and longitude, and the accuracy of the reading where the device provides it, are sent to that gym's Fitmark backend. The server uses the coordinates to confirm the user is within the gym's allowed radius, then stores the punch time, the calculated distance, and the selfie as part of the attendance record.
- Only at the moment of a punch. Location is read while the app is open and in use, when the user submits a punch. Fitmark Team does not request background location, does not track location while the app is closed, and does not follow users between punches.
- Never for advertising or profiling. Attendance selfies and location readings are used to verify workplace attendance and are not used for advertising, ad targeting, profiling, or sale to third parties.
- Visible to the employer. Attendance records, including punch selfies and times, are visible to administrators and managers of the user's own gym organization and branch, who use them for attendance, payroll, and audit purposes.
- Anti-fraud check. On Android the app checks whether a location reading came from a mock-location ("fake GPS") provider and refuses the punch if it did, so attendance records remain trustworthy.
- Optional. Camera and location permission are requested at the point of use and can be declined or later revoked in device settings. Declining does not block the rest of the app; it only prevents punching attendance from that phone.
Gym organizations that enable mobile attendance are responsible for informing their staff, and for having a lawful basis for workplace attendance monitoring under the employment and data protection laws that apply to them.
Permissions and Device Access
- Camera: used when a user opens the QR scanner to scan a member or client QR code, and when a user captures an attendance punch selfie.
- Location (while using the app): used only to verify presence at the gym at the moment a staff attendance punch is submitted, as described above. Background location is not requested or used.
- Photos or image picker: used only when an authorized user chooses a specific image for a profile photo. Fitmark does not need access to the user's entire photo library for this purpose.
- Notifications: used to send operational alerts, renewal reminders, session messages, and service messages when enabled. A push token may be registered for delivery.
- Secure storage: used to store authentication tokens and session data on the device.
- Diagnostics and updates: app infrastructure, update, crash-reporting, and monitoring tools may process technical data needed to keep the service secure and reliable.
How We Use Information
- Authenticate users and keep accounts secure.
- Enforce role, company, and branch permissions.
- Manage staff, members, PT clients, renewals, payments, expenses, follow-ups, reports, attendance, and QR sessions.
- Record and verify staff attendance punches, including confirming that a punch was made at the gym and rejecting falsified location readings.
- Upload and display selected profile photos.
- Send operational push notifications.
- Provide support, troubleshooting, fraud prevention, security, audit, and service reliability.
Sharing
We do not sell personal or sensitive user data. Data may be shared with:
- The gym organization that provides and administers the account.
- Backend hosting, database, storage, authentication, app update, and infrastructure providers.
- Push notification delivery providers, including app platform providers used to deliver operational notifications.
- Diagnostics, analytics, crash-reporting, or monitoring providers, such as Sentry or similar services, when configured.
- Legal, compliance, safety, or security parties when required by law or to protect users and the service.
Security
Fitmark stores authentication tokens using secure device storage where available. App traffic is transmitted using modern cryptography, such as HTTPS. Access to screens, records, and API actions is controlled by user role, company, branch, and subscription permissions. We use administrative, technical, and organizational safeguards intended to protect personal and sensitive user data from unauthorized access, disclosure, alteration, or loss.
Retention and Deletion
Gym business records are retained while the gym account is active and as needed for operational, legal, tax, audit, security, fraud-prevention, backup, dispute-resolution, and legitimate business purposes.
Users can request correction, export, account deletion, or deletion of associated personal data through their gym administrator or by emailing jagadishjagadish2022@gmail.com. This page is the public web resource for starting privacy and deletion requests outside the app. Please include the gym organization name, branch if known, user name, account phone/email if used, and the request type so we can verify and process the request.
Most Fitmark Team accounts are created and managed by authorized gym administrators, so we may need to verify the request with the gym organization before deleting business records or role access. When a deletion request is accepted, Fitmark deletes or anonymizes the relevant account data and associated personal data where reasonably possible. Temporary deactivation, disabling, or freezing of an account is not treated as account deletion. Some records may be retained when required for legal, tax, audit, security, fraud-prevention, backup, dispute-resolution, or legitimate business reasons.
If Fitmark later offers public self-service account creation in an app, Fitmark will provide a readily discoverable way to request account deletion both inside the app and outside the app.
Children
Fitmark is intended for gym staff, trainers, and business operations. It is not directed to children.
Changes
We may update this policy when the platform, backend, legal requirements, store requirements, SDKs, or data practices change. The latest version is always available at https://fitmark.in/privacy.html.
Questions about this policy? Email jagadishjagadish2022@gmail.com.