Technology

Gym Software Data Security: 12 Questions to Ask a Vendor

Gym software data security, explained for Indian owners: your DPDP Act duties, 12 questions to ask any vendor, what good answers sound like, and simple daily habits.

Gym Software Data Security: 12 Questions to Ask a Vendor

Member data in gym software is safe when three things are true: the vendor keeps your gym's data walled off from every other gym, protects it with encryption and individual logins, and can tell you in writing how it handles breaches, backups and deletion. Under India's DPDP Act your gym stays legally responsible for that data even when a software company holds it, so you need to ask. Below are 12 questions to put to any vendor, what a good answer sounds like, and the everyday habits that matter just as much.

MyGymGate is gym management software for Indian gyms, and at the end you'll find our own answers to the same 12 questions, including the ones where the honest answer is "ask us".

Why does a gym hold such sensitive data?

A gym knows more about its members than most shops do. Look at a typical front desk and you'll find:

  • phone numbers, emails and home addresses
  • dates of birth and emergency contacts
  • health notes: injuries, blood pressure, diabetes, pregnancy, surgeries
  • body weight, measurements and progress photos
  • payment history and plan details
  • attendance logs that show when someone is (and isn't) at home
  • possibly face templates or fingerprints for check-in

Some of this is plainly sensitive. The 2011 SPDI Rules, still in force until the DPDP Act fully takes over, treat health information and biometrics as "sensitive personal data". If you use face check-in, read our guide on face recognition attendance and consent before you switch it on.

Moving this into software is usually an improvement, but it puts everything in one place, so who can reach it matters more, not less.

Under the Digital Personal Data Protection Act, 2023, your gym is the data fiduciary: you decide why member data is collected and how it's used. The software company is a data processor, defined in Section 2(k) as someone who processes personal data on a fiduciary's behalf.

Section 8 is where your duties live. In plain words:

  • 8(1): you are responsible for compliance, including for processing a processor does for you.
  • 8(2): you may hand data to a processor only under a valid contract.
  • 8(5): you must take reasonable security safeguards to prevent a personal data breach, including at your processor.
  • 8(6): if a breach happens, you must inform the Data Protection Board and each affected member.
  • 8(7): you must erase data once the purpose is over or consent is withdrawn, unless another law needs you to keep it, and make your processor erase it too.

The DPDP Rules, 2025 fill in the detail. Rule 6 lists minimum safeguards (encryption or masking, access control, logs, backups, and security terms in processor contracts). Rule 7 says to tell affected members without delay and send the Board a detailed report within 72 hours of becoming aware of the breach. Most of these duties apply from May 2027. Our member data privacy guide covers consent, member rights and the timeline in more depth.

This is general information as of October 2026, not legal advice. Confirm your setup with a lawyer.

What about CERT-In's 6-hour rule?

Separately from the DPDP Act, CERT-In's directions of 28 April 2022, issued under Section 70B(6) of the IT Act, require "service providers, intermediaries, data centres, body corporate and Government organisations" to report listed cyber incidents to CERT-In within 6 hours of noticing them. The list includes unauthorised access to IT systems or data, and data breaches. The same directions ask these entities to keep system logs for a rolling 180 days.

Software companies and data centres sit clearly inside that list. Whether a small owner-run gym counts as a "body corporate" here is a question for your lawyer. Either way, a serious vendor will already have an incident process, so ask about it.

12 questions to ask any gym software vendor

Ask every vendor the same questions in the same order, and write the answers down. A vague answer is itself an answer.

#QuestionWhat a good answer sounds like
1Where is our data hosted?A named provider and region, for example "a major cloud provider, servers in India"
2Is data encrypted in transit and at rest?HTTPS everywhere, plus a clear yes or no on encryption of stored data
3How do you stop other gyms seeing our data?Separation enforced in the database itself, not just hidden in the app screens
4Can each staff member have their own login and role?Yes, with limited roles such as a check-in-only scanner login
5How often are backups taken, and have you restored one?A schedule, a retention period and a tested restore
6Will you tell us about a breach, and how fast?A written commitment fast enough for you to meet the 72-hour Board report
7Can we export all our data and get it deleted?Full export in Excel or CSV without a fee, and a deletion timeline in writing
8How is face data handled?Opt-in, member consent recorded, templates not photos, deleted when the member leaves
9How long do you keep data?A written retention policy, including what happens after you cancel
10Which sub-processors touch our data?A named list: hosting, email and so on, with what each one does
11Is there a log of who changed what?An activity log, or an honest "not yet"
12What does the contract say about data?Security, breach notice, deletion and confidentiality terms you can read before paying

A few notes on the trickier ones

On question 3. Many gyms sharing one system is normal, provided separation is enforced at the data level. Ask: "If your app had a bug, could gym A's screen show gym B's members?" A good vendor will explain why not.

On question 4. One shared admin password means you can never tell who did what, and you can't cut off one person when they leave. Our post on gym staff management covers how to split roles at the desk.

On question 6. You have the legal duty to report, but you can only report what you know. If the vendor's contract says nothing about breach notice, you're relying on goodwill.

On question 7. Your member list is the business. If you can't get it out, you can't leave, and you can't answer a member who asks for a copy of their data.

On question 10. Every vendor uses other companies for hosting or email. A vendor that can't name them hasn't thought about it.

If you're comparing vendors on more than security, our gym software checklist has 25 questions covering check-in, renewals, pricing and lock-in too.

Which is safer: register, Excel or gym software?

None is safe by default. Each fails differently.

Paper registerExcel on a desk PC or phoneGym software
Who can see itAnyone at the counterAnyone with the device or fileOnly people with a login
Separate staff accessNoRarelyUsually, if roles exist
BackupNoneOnly if someone remembersVendor's job; ask how
Leaves with an ex-employeePhotos on their phoneCopied fileRemove their login
DeletionTearing pagesManual, often forgottenDepends on the vendor's process
Main riskLoss, prying eyesCopies everywhereWeak passwords, shared logins

Honestly, most gym data leaks are not hackers. They're a member list forwarded on WhatsApp, a trainer who left with the Excel file, or a front-desk phone with no screen lock.

What can owners do this week?

Software security is half the job. The other half is how your team uses it.

  1. Use a strong, unique password for the owner account, and never reuse your email or banking password.
  2. Give everyone their own login. Never share the owner login, even with a trusted manager.
  3. Remove ex-staff access the same day they leave. Make it part of the exit routine, along with collecting keys.
  4. Don't send admin logins on WhatsApp. Chats get backed up, forwarded and seen on shared phones. Tell people in person, and change it if it ever went out by message.
  5. Lock the front-desk phone. Screen lock on, and if possible a check-in-only mode so it can't open the full member list.
  6. Delete old exports. That "members_final_2.xlsx" in your downloads folder is a copy you'll forget about.
  7. Write a one-page breach plan: who to call at the vendor, who tells members, and the 72-hour deadline.

How MyGymGate answers these 12 questions

Here are our answers, taken only from what the product and our published privacy policy say today. Where we haven't published an answer, it says "ask us", and we'll put the details in writing for you.

#QuestionMyGymGate's answer
1HostingSupabase, Mumbai region (India)
2EncryptionAll traffic encrypted in transit (HTTPS). At rest: ask us
3Separation between gymsEach gym sees only its own data, enforced by row-level security in the database
4Staff rolesOwner, staff and scanner logins with roles; the scanner phone is locked down to check-in
5BackupsAsk us
6Breach notificationAsk us
7Export and deletionGym data deleted within 30 days of closing your account, except records the law requires us to keep. Full export: ask us
8Face dataOptional and off by default; enrolled only with the member's consent (time of consent recorded); matching happens on the scanner phone; a face template is stored, not the photo; withdrawing consent deletes it
9RetentionKept while you use the service; 30-day deletion after closure; face templates deleted 30 days after a membership ends
10Sub-processorsNamed in the privacy policy: Supabase, Amazon Web Services (CloudFront), Hostinger (email), Netlify (backup website hosting)
11Audit logAsk us
12Contract termsThe privacy policy sets out our role as processor for member data; for anything specific to your gym, ask us

Two more points. The privacy policy states that for member data the gym is the data fiduciary and MyGymGate processes it on the gym's behalf, matching the DPDP model above. And members don't need an account: they get a QR pass by email and a private tracker link, so there are no member passwords to leak.

We'd rather you see four "ask us" rows now than discover a gap after you've moved 300 members in.

Quick checklist

  • Ask every vendor the 12 questions above and keep the answers.
  • Get breach notice, export and deletion terms in writing.
  • Give every staff member their own login; delete ex-staff the same day.
  • Never share admin passwords on WhatsApp.
  • Collect only the data you need, and lock the desk phone.
  • Keep a one-page breach plan with the 72-hour deadline.
  • Have a lawyer check your consent forms before May 2027.

If you'd like to go through these questions with us, book a free 15-minute demo through our contact form. We'll show you the roles, the scanner lock and the face consent flow live, and setup and member import are included. You can also get the Android app and look around first.

Frequently asked questions

Is gym member data safe in cloud software?

It can be safer than a register or a shared Excel file, but only if the vendor keeps each gym's data separate, encrypts traffic, gives every staff member their own login and has a clear breach and deletion process. Ask for those answers in writing before you sign.

Who is responsible if my gym software vendor has a data breach?

Under the DPDP Act the gym is the data fiduciary and stays responsible for data processed on its behalf, even by a vendor. That is why your contract should require the vendor to tell you quickly about any breach so you can inform members and the Data Protection Board.

Should a gym store Aadhaar copies in its software?

Usually there is no need. The DPDP Act allows only the data necessary for the stated purpose, and most gyms can run memberships with a name, phone number and emergency contact. If you do keep ID copies, restrict who can see them and delete them on a schedule.

What is MyGymGate and how much does it cost?

MyGymGate is gym management software for Indian gyms: QR or optional face check-in on any Android phone, renewal and inactivity emails, one-tap WhatsApp templates, a TV leaderboard and an owner app. It costs ₹399 a month with unlimited members, everything included and no setup fee.

Keep reading

Technology

Fitness Studio Software in India: Functional, Pilates, Boxing

Fitness studio software for Indian functional, Pilates and boxing studios: packs, check-ins, retention lists and leaderboards, plus what you'll still bolt on.

Technology

Academy Management Software for Martial Arts, Dance and Sports

Academy management software for martial arts, dance and sports academies in India: attendance, monthly fee reminders, parent messages and child data rules.

Technology

Gym Member App Without the Download: What Members Actually Use

Do you need a gym member app? Most members won't install one. Compare a branded app, a web link and WhatsApp, and give members their pass without a download.