Gym Software Data Security: 12 Questions to Ask a Vendor
Gym software data security, explained for Indian owners: your DPDP Act duties, 12 questions to ask any vendor, what good answers sound like, and simple daily habits.
Member data in gym software is safe when three things are true: the vendor keeps your gym's data walled off from every other gym, protects it with encryption and individual logins, and can tell you in writing how it handles breaches, backups and deletion. Under India's DPDP Act your gym stays legally responsible for that data even when a software company holds it, so you need to ask. Below are 12 questions to put to any vendor, what a good answer sounds like, and the everyday habits that matter just as much.
MyGymGate is gym management software for Indian gyms, and at the end you'll find our own answers to the same 12 questions, including the ones where the honest answer is "ask us".
Why does a gym hold such sensitive data?
A gym knows more about its members than most shops do. Look at a typical front desk and you'll find:
- phone numbers, emails and home addresses
- dates of birth and emergency contacts
- health notes: injuries, blood pressure, diabetes, pregnancy, surgeries
- body weight, measurements and progress photos
- payment history and plan details
- attendance logs that show when someone is (and isn't) at home
- possibly face templates or fingerprints for check-in
Some of this is plainly sensitive. The 2011 SPDI Rules, still in force until the DPDP Act fully takes over, treat health information and biometrics as "sensitive personal data". If you use face check-in, read our guide on face recognition attendance and consent before you switch it on.
Moving this into software is usually an improvement, but it puts everything in one place, so who can reach it matters more, not less.
What is the gym's legal role under the DPDP Act?
Under the Digital Personal Data Protection Act, 2023, your gym is the data fiduciary: you decide why member data is collected and how it's used. The software company is a data processor, defined in Section 2(k) as someone who processes personal data on a fiduciary's behalf.
Section 8 is where your duties live. In plain words:
- 8(1): you are responsible for compliance, including for processing a processor does for you.
- 8(2): you may hand data to a processor only under a valid contract.
- 8(5): you must take reasonable security safeguards to prevent a personal data breach, including at your processor.
- 8(6): if a breach happens, you must inform the Data Protection Board and each affected member.
- 8(7): you must erase data once the purpose is over or consent is withdrawn, unless another law needs you to keep it, and make your processor erase it too.
The DPDP Rules, 2025 fill in the detail. Rule 6 lists minimum safeguards (encryption or masking, access control, logs, backups, and security terms in processor contracts). Rule 7 says to tell affected members without delay and send the Board a detailed report within 72 hours of becoming aware of the breach. Most of these duties apply from May 2027. Our member data privacy guide covers consent, member rights and the timeline in more depth.
This is general information as of October 2026, not legal advice. Confirm your setup with a lawyer.
What about CERT-In's 6-hour rule?
Separately from the DPDP Act, CERT-In's directions of 28 April 2022, issued under Section 70B(6) of the IT Act, require "service providers, intermediaries, data centres, body corporate and Government organisations" to report listed cyber incidents to CERT-In within 6 hours of noticing them. The list includes unauthorised access to IT systems or data, and data breaches. The same directions ask these entities to keep system logs for a rolling 180 days.
Software companies and data centres sit clearly inside that list. Whether a small owner-run gym counts as a "body corporate" here is a question for your lawyer. Either way, a serious vendor will already have an incident process, so ask about it.
12 questions to ask any gym software vendor
Ask every vendor the same questions in the same order, and write the answers down. A vague answer is itself an answer.
| # | Question | What a good answer sounds like |
|---|---|---|
| 1 | Where is our data hosted? | A named provider and region, for example "a major cloud provider, servers in India" |
| 2 | Is data encrypted in transit and at rest? | HTTPS everywhere, plus a clear yes or no on encryption of stored data |
| 3 | How do you stop other gyms seeing our data? | Separation enforced in the database itself, not just hidden in the app screens |
| 4 | Can each staff member have their own login and role? | Yes, with limited roles such as a check-in-only scanner login |
| 5 | How often are backups taken, and have you restored one? | A schedule, a retention period and a tested restore |
| 6 | Will you tell us about a breach, and how fast? | A written commitment fast enough for you to meet the 72-hour Board report |
| 7 | Can we export all our data and get it deleted? | Full export in Excel or CSV without a fee, and a deletion timeline in writing |
| 8 | How is face data handled? | Opt-in, member consent recorded, templates not photos, deleted when the member leaves |
| 9 | How long do you keep data? | A written retention policy, including what happens after you cancel |
| 10 | Which sub-processors touch our data? | A named list: hosting, email and so on, with what each one does |
| 11 | Is there a log of who changed what? | An activity log, or an honest "not yet" |
| 12 | What does the contract say about data? | Security, breach notice, deletion and confidentiality terms you can read before paying |
A few notes on the trickier ones
On question 3. Many gyms sharing one system is normal, provided separation is enforced at the data level. Ask: "If your app had a bug, could gym A's screen show gym B's members?" A good vendor will explain why not.
On question 4. One shared admin password means you can never tell who did what, and you can't cut off one person when they leave. Our post on gym staff management covers how to split roles at the desk.
On question 6. You have the legal duty to report, but you can only report what you know. If the vendor's contract says nothing about breach notice, you're relying on goodwill.
On question 7. Your member list is the business. If you can't get it out, you can't leave, and you can't answer a member who asks for a copy of their data.
On question 10. Every vendor uses other companies for hosting or email. A vendor that can't name them hasn't thought about it.
If you're comparing vendors on more than security, our gym software checklist has 25 questions covering check-in, renewals, pricing and lock-in too.
Which is safer: register, Excel or gym software?
None is safe by default. Each fails differently.
| Paper register | Excel on a desk PC or phone | Gym software | |
|---|---|---|---|
| Who can see it | Anyone at the counter | Anyone with the device or file | Only people with a login |
| Separate staff access | No | Rarely | Usually, if roles exist |
| Backup | None | Only if someone remembers | Vendor's job; ask how |
| Leaves with an ex-employee | Photos on their phone | Copied file | Remove their login |
| Deletion | Tearing pages | Manual, often forgotten | Depends on the vendor's process |
| Main risk | Loss, prying eyes | Copies everywhere | Weak passwords, shared logins |
Honestly, most gym data leaks are not hackers. They're a member list forwarded on WhatsApp, a trainer who left with the Excel file, or a front-desk phone with no screen lock.
What can owners do this week?
Software security is half the job. The other half is how your team uses it.
- Use a strong, unique password for the owner account, and never reuse your email or banking password.
- Give everyone their own login. Never share the owner login, even with a trusted manager.
- Remove ex-staff access the same day they leave. Make it part of the exit routine, along with collecting keys.
- Don't send admin logins on WhatsApp. Chats get backed up, forwarded and seen on shared phones. Tell people in person, and change it if it ever went out by message.
- Lock the front-desk phone. Screen lock on, and if possible a check-in-only mode so it can't open the full member list.
- Delete old exports. That "members_final_2.xlsx" in your downloads folder is a copy you'll forget about.
- Write a one-page breach plan: who to call at the vendor, who tells members, and the 72-hour deadline.
How MyGymGate answers these 12 questions
Here are our answers, taken only from what the product and our published privacy policy say today. Where we haven't published an answer, it says "ask us", and we'll put the details in writing for you.
| # | Question | MyGymGate's answer |
|---|---|---|
| 1 | Hosting | Supabase, Mumbai region (India) |
| 2 | Encryption | All traffic encrypted in transit (HTTPS). At rest: ask us |
| 3 | Separation between gyms | Each gym sees only its own data, enforced by row-level security in the database |
| 4 | Staff roles | Owner, staff and scanner logins with roles; the scanner phone is locked down to check-in |
| 5 | Backups | Ask us |
| 6 | Breach notification | Ask us |
| 7 | Export and deletion | Gym data deleted within 30 days of closing your account, except records the law requires us to keep. Full export: ask us |
| 8 | Face data | Optional and off by default; enrolled only with the member's consent (time of consent recorded); matching happens on the scanner phone; a face template is stored, not the photo; withdrawing consent deletes it |
| 9 | Retention | Kept while you use the service; 30-day deletion after closure; face templates deleted 30 days after a membership ends |
| 10 | Sub-processors | Named in the privacy policy: Supabase, Amazon Web Services (CloudFront), Hostinger (email), Netlify (backup website hosting) |
| 11 | Audit log | Ask us |
| 12 | Contract terms | The privacy policy sets out our role as processor for member data; for anything specific to your gym, ask us |
Two more points. The privacy policy states that for member data the gym is the data fiduciary and MyGymGate processes it on the gym's behalf, matching the DPDP model above. And members don't need an account: they get a QR pass by email and a private tracker link, so there are no member passwords to leak.
We'd rather you see four "ask us" rows now than discover a gap after you've moved 300 members in.
Quick checklist
- Ask every vendor the 12 questions above and keep the answers.
- Get breach notice, export and deletion terms in writing.
- Give every staff member their own login; delete ex-staff the same day.
- Never share admin passwords on WhatsApp.
- Collect only the data you need, and lock the desk phone.
- Keep a one-page breach plan with the 72-hour deadline.
- Have a lawyer check your consent forms before May 2027.
If you'd like to go through these questions with us, book a free 15-minute demo through our contact form. We'll show you the roles, the scanner lock and the face consent flow live, and setup and member import are included. You can also get the Android app and look around first.
Useful links
Frequently asked questions
Is gym member data safe in cloud software?
It can be safer than a register or a shared Excel file, but only if the vendor keeps each gym's data separate, encrypts traffic, gives every staff member their own login and has a clear breach and deletion process. Ask for those answers in writing before you sign.
Who is responsible if my gym software vendor has a data breach?
Under the DPDP Act the gym is the data fiduciary and stays responsible for data processed on its behalf, even by a vendor. That is why your contract should require the vendor to tell you quickly about any breach so you can inform members and the Data Protection Board.
Should a gym store Aadhaar copies in its software?
Usually there is no need. The DPDP Act allows only the data necessary for the stated purpose, and most gyms can run memberships with a name, phone number and emergency contact. If you do keep ID copies, restrict who can see them and delete them on a schedule.
What is MyGymGate and how much does it cost?
MyGymGate is gym management software for Indian gyms: QR or optional face check-in on any Android phone, renewal and inactivity emails, one-tap WhatsApp templates, a TV leaderboard and an owner app. It costs ₹399 a month with unlimited members, everything included and no setup fee.