Who is responsible, you or your gym
There are two relationships on this platform and the difference decides who you ask when you want something changed.
- If you are a gym member: your gym decides what is recorded about you and why. Your gym is the controller of that data. Liftsol processes it on your gym’s instructions and does not decide what happens to it.
- If you are a gym owner or member of staff: Liftsol is the controller of your account details (the name, phone number and email you signed up with), and the processor for everything your gym records about its members.
Members: ask your gym first. They hold your membership, they decided what was recorded, and they can change or delete it from their own dashboard immediately. We act on their instruction, so going through them is faster in every case.
Liftsol is operated from Lahore, Punjab, Pakistan. Write to us at info.liftsol@gmail.com or message 0342 069 9570 on WhatsApp.
What a gym records about a member
The membership itself:
- Name and phone number, and optionally email, gender and date of birth
- CNIC, where a gym chooses to record one
- Emergency contact, for who to call if somebody is hurt on the floor
- Membership plan, start and expiry dates, and any freeze
- Invoices, payments, part payments and outstanding balance
- Which branch they belong to, where a gym has more than one
The training side, where a gym uses it:
- Check-in times
- Workout logs: exercises, sets, weights
- Nutrition logs
- Body measurements and weight
- Progress photographs
- Medical notes the gym enters: an injury, a condition a trainer should know
- Personal-training packages and sessions used
About gym owners and staff:
- Name, phone number, email and role
- Which gym and branches the account can reach
- A record of sensitive actions taken in the system, for audit
Collected automatically by the software:
- What is needed to serve a request (IP address, device and app version), and diagnostics when something fails
- Not advertising identifiers, and not tracking across other apps or websites
This marketing website itself sets no cookies and runs no analytics. see the cookies page.
Health data, photos and measurements
Medical notes, body measurements and progress photographs are the most sensitive things in a gym’s records, and they are treated differently from the rest.
- Medical notes never appear on a list screen. They are returned only when somebody deliberately opens that member’s record, and that access is written to the audit log.
- Progress photos are not public. They are held in a private bucket under keys nobody can guess and served through links that stop working after fifteen minutes. There is no URL to share by accident.
- Your gym decides whether any of it is recorded at all. A gym that never opens the training side of the product holds none of it.
Liftsol is software, not a clinician. A medical note is a message from a member to their trainer, stored so it is not forgotten. It is not a diagnosis, and nothing in the product interprets it.
Attendance, and why there is no fingerprint
Attendance is a record of where somebody was and when, which is why it gets its own clause rather than a line in a list.
Liftsol collects no biometric data. Check-in is a QR code scanned with a phone camera, or a member marked in by hand at the counter. No fingerprint, no face, no iris. Nothing that could not be changed if it leaked.
That is a deliberate choice rather than a missing feature. The usual alternative in this market is a fingerprint reader at the door; a fingerprint cannot be reissued after a breach, and storing one to solve a turnstile problem is a poor trade.
A member’s check-in history is visible to their gym’s staff and to the member themselves. It is not shared with anybody else, and it is not used to build a profile of anyone.
Why any of it is collected
- To run the membership: billing, renewals, receipts and attendance
- To send the messages a gym asks us to send: fee reminders, expiry notices and announcements, by WhatsApp, SMS or push
- To show a gym its own figures, and to show a member their own history
- To keep accounts secure and to investigate misuse
- To meet the record-keeping obligations that apply to payments
We do not sell data, and we do not use one gym’s data to market to another gym’s members.
Who else sees it
Data leaves our systems in only these cases:
- Your own gym’s staff, according to the permissions the gym owner has given them, so a receptionist and a trainer do not see the same screens
- Messaging providers, to deliver a WhatsApp message or SMS your gym asked for. They receive the member’s phone number and the text of that message, and nothing else.
- Payment providers, where a member pays online. Card and wallet credentials go to the provider and never reach Liftsol; we record that a payment happened and its reference. This covers JazzCash, Easypaisa and bank transfers.
- Our hosting and storage providers, who run the servers and the private file storage. They hold the data; they do not use it.
- Where the law requires it, in response to a valid legal demand
One gym can never see another gym’s members. That separation is enforced in the database layer rather than by each screen remembering to filter, and there is an automated test per collection. The security page explains how.
How long it is kept
While a gym’s account is active its data is kept, because that is the product: a member’s payment history is the record of what they have paid, and deleting it would break the thing the gym bought.
After an account closes, or after a member is deleted at their request, personal details are removed and only what financial record-keeping requires is kept.
- Personal details are removed within 30 days of an account closing, or of a member being deleted at their request.
- Payment records are kept for 6 years, because record-keeping rules that apply to any business taking payments require it. What survives is the amount, the date, the method and the invoice it settled, detached from the personal details, so what remains is a transaction rather than a person.
- Backups already written before a deletion are not rewritten. They expire on their own cycle within 35 days.
Exactly what is and is not removed is set out on the data deletion page.
How it is protected
- Each gym’s data is separated at the database layer, with a test per collection
- Payment records cannot be edited, because a correction is a reversal entry
- Medical notes and CNIC are kept off list screens and audited when opened
- Progress photos and receipts are served through links that expire in fifteen minutes
- One-time passcodes, session tokens, payment references and a gym’s check-in secret are kept out of logs
The security page goes through each of these, and is explicit about what we do not claim.
A member’s rights
You can ask for:
- A copy of the data held about you
- A correction, where something is wrong
- Deletion. See the data deletion page
- To stop receiving messages. Replying to stop works, and a member who opts out is never messaged again by the automated system
Ask your gym first; they can act immediately. If your gym has closed or will not respond, contact us directly and we will deal with it.
We acknowledge a request within 2 working days and complete it within 30 days, telling you when it is done. Support is answered Monday to Saturday, 10am to 8pm.
Members under 18
Plenty of gyms enrol teenagers. Where they do, the gym is responsible for obtaining a parent or guardian’s consent before recording that member’s details, including particularly, medical notes and progress photographs. Everything in this policy applies to their data in the same way.
A member under 16 needs a parent or guardian to agree before their details are recorded, and the gym records that agreement against the membership. Below that age a member is not given their own app login; the guardian deals with the gym directly.
Changes to this policy
When this policy changes materially we will tell gym owners through the dashboard before the change takes effect, and update the date at the foot of this page. Changes that only clarify existing wording will be made without notice.
Contacting us
Email info.liftsol@gmail.com or message 0342 069 9570 on WhatsApp. We are in Lahore, Pakistan.
If you are not satisfied with how we have handled something, tell us and we will look at it again. Pakistan does not yet have a general data protection authority to escalate a complaint to; if that changes, this page will name it.