Jymtra

Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains what information Jymtra collects, why, and how it's handled. Jymtra is gym-management software: a Super Admin (the person or team running Jymtra) creates gym owner accounts, and each gym owner then uses their own dashboard to track their gym's members, renewals, and payments. There is no public sign-up — every account is created directly by the Super Admin.

Not yet finalized: the legal entity or individual operating Jymtra hasn't been specified yet. Until it is, this document refers to “the operator of Jymtra.”

1. Who this policy covers

This policy covers two kinds of people: gym owners, who have a login to Jymtra, and gym members, whose information a gym owner enters into Jymtra to run their own gym. Gym owners are the ones deciding what member information to collect and why — Jymtra provides the software they use to store and manage it. If you're a gym member with a question about your own information, the fastest path is to ask your gym directly, since they hold the relationship with you; see Contact if you'd rather reach the operator of Jymtra.

2. Information we collect

Gym owner account information — provided by the Super Admin when an account is created, or by the gym owner afterward:

  • Name and email address
  • Password (stored as a one-way bcrypt hash — never in plain text)
  • Gym name, gym code, and optionally the gym's address and phone number

Member information — entered by the gym owner, about the people who use their gym:

  • Name, age, gender, date of birth (all optional except name)
  • Phone number, an optional alternate mobile number, and an emergency contact
  • Address and email (optional)
  • Height, weight, and free-text notes (optional)
  • A photo, if the gym owner chooses to upload one
  • Membership plan, join date, and renewal/expiry history

Payment records — Jymtra does not process payments and never collects card numbers, UPI PINs, or bank credentials. When a gym owner records that a member paid, Jymtra stores the amount, a payment-method label they choose (e.g. Cash, UPI, Card, Bank Transfer), a date, an internally generated receipt number, and any notes the owner adds — a record of what happened, not a payment transaction itself.

Authentication and security information — a session cookie that keeps a logged-in user logged in; a temporary, single-use password-reset token (expires after one hour); and, to slow down repeated login/reset/activation-code guessing, a small internal counter keyed to the email address or gym involved. That counter does not include your IP address or device information — Jymtra does not currently collect either.

Internal activity log — Jymtra keeps a short operational record of actions like “member renewed” or “payment recorded” (which gym, which logged-in user, a short description, and a timestamp). This powers the “Recent Activity” feed gym owners and the Super Admin see in their own dashboards, and helps with support and troubleshooting.

3. Cookies and similar technology

Jymtra uses one cookie: a session cookie that keeps you signed in, set by the authentication system (NextAuth). It is strictly necessary for the app to function and is not used for advertising or cross-site tracking. A light/dark theme preference is saved in your browser's local storage, not a cookie. Jymtra does not use analytics, advertising, or third-party tracking scripts of any kind.

4. How information is used

Information is used only to operate Jymtra itself:

  • Running the login, password-reset, and account-activation flows
  • Tracking each member's membership status, renewal dates, and dues
  • Generating receipts and the payments ledger/export a gym owner sees
  • Slowing down automated login/password-reset/activation-code guessing
  • Providing support and troubleshooting when something goes wrong

Information is never sold, and never used for advertising, profiling, or any purpose unrelated to running the gym-management features described above.

5. Who can access this information

A gym owner can only see their own gym's members, payments, and activity — this is enforced on every request, not just hidden in the interface. The Super Admin who operates Jymtra can access every gym's data, including member records, because Jymtra currently has a single trusted operator rather than a team of administrators — this access exists for account setup, support, and troubleshooting across all gyms, the same way it's described in Jymtra's own product documentation. There is no self-service way for a gym owner to grant staff their own separate login today.

6. Where information is stored

Jymtra's database and member photos are hosted using Supabase (PostgreSQL for records, Supabase Storage for photos), and the application itself is hosted on Vercel. Member photos are stored at an unguessable file path but, as configured today, that path is not access-restricted the way the rest of the dashboard is — treat it the same as any other file you'd be comfortable existing at a hard-to-guess web address. Password-reset emails and gym-activation-code emails, when sent, go through a standard outbound email service the operator configures; if none is configured, those messages are never emailed at all.

7. Data security

Passwords are never stored in plain text. Activation codes are stored as one-way hashes, the same way passwords are. A password change immediately invalidates any other active login session. Every gym owner action is independently re-checked on the server against that gym owner's own gym, so one gym owner cannot read or modify another gym's data by guessing or editing a URL. The application sends standard security headers (including a Content-Security-Policy) on every response. That said, no system is perfectly secure, and Jymtra has not undergone a formal third-party security audit or certification — treat any specific security or compliance claim beyond what's described here as not established.

8. Data retention and deletion

Jymtra keeps records for as long as a gym owner's account is active, so historical renewal and payment data stays accurate and available. There is currently no automatic deletion of member records after any fixed period. A gym owner can archive a member (a reversible action) and, once a member is archived, can permanently delete that member — which also permanently removes their membership history, payment history, and photo, and cannot be undone. Deleting a gym owner's own account is not currently a self-service feature; it would need to be requested through the Super Admin (see Contact).

Separately, the operator keeps periodic, self-managed backups of the database and stored photos for disaster-recovery purposes (in case of accidental data loss, not as a member-facing feature). A specific backup retention period has not been fixed as of this writing.

9. Gym owner responsibilities

Because gym owners choose what member information to enter, they're responsible for having an appropriate basis for collecting it — for example, letting members know their details are being kept in a gym-management system — and for keeping their own login credentials confidential. If a gym owner believes their account has been compromised, they should contact the Super Admin immediately using the phone number, WhatsApp, or email your gym administrator used when they set up your account.

10. Children's information

Jymtra itself has no age restriction or age-verification step, and gym members of any age — including minors — can be entered into the system by a gym owner as part of managing that person's gym membership. Jymtra does not independently verify the age of any gym member. A gym owner entering a minor's information should do so consistent with whatever consent or parental-notice practice applies to their own gym.

11. Sharing and disclosure

Information is shared only with the infrastructure providers listed in Section 6, to the extent needed to run Jymtra, and only if required by law (for example, a valid legal request from an authority with jurisdiction over the operator of Jymtra). Information is never sold or shared for advertising purposes.

12. Governing law

Not yet finalized: a specific governing-law and jurisdiction statement hasn't been chosen yet — this is a legal decision for the operator of Jymtra to make, ideally with a lawyer's input, rather than one this document should guess at.

13. Changes to this policy

This policy may be updated as Jymtra changes. The “Last updated” date at the top of this page will change whenever it does. There is currently no automated notification when this page changes — check back periodically if that matters to you.

14. Contact

Questions about this policy, or about information Jymtra holds, can be sent via the phone number, WhatsApp, or email your gym administrator used when they set up your account. See the Contact page for details.

This page is a practical product document written to accurately describe how Jymtra works today. It is not a substitute for review by a qualified lawyer before relying on it as a finished legal agreement.