Skip to content

Security

You are handing us your members’ details. Here is what happens to them.

Names, phone numbers, sometimes a CNIC, sometimes a medical note. Six things we do about that, each one a rule the system enforces rather than a habit somebody has to remember.

One gym cannot see another gym’s data

Separation is enforced at the database layer, on every collection, by a rule the query has to pass through, not by a filter each screen remembers to add. Each collection has an automated test that fails the build if it could ever return another gym’s rows.

A payment cannot be quietly edited

Payment records are append-only. Correcting one creates a reversal entry beside it rather than changing what was there, so the history of what was taken and when survives intact, including for the person who took it.

A recorded payment is never half-recorded

The invoice, the payment and the audit entry are written in a single database transaction. Either all three land or none do. There is no state where a member has paid but the invoice disagrees.

Medical notes and CNIC stay off list screens

Neither is returned by any list endpoint. They are fetched only when somebody deliberately opens that member’s record, and that access is recorded.

Progress photos and receipts are not public

They are held in a private bucket with non-guessable keys and served through links that expire in fifteen minutes. There is no public URL to guess at or share by accident.

Some things are never written down at all

Your gym’s check-in secret never leaves the server and appears in no API response. One-time passcodes, session tokens and payment references are kept out of logs and error reports, so they cannot leak through a screenshot of a crash.

What we do not claim

Things this page will not tell you

Every security page on the internet says the same four words. These are the ones we have not earned, and saying so is more useful than a badge.

  • We hold no SOC 2, ISO 27001 or PCI certification. If a competitor’s page shows a badge, ask which audit it came from and when.
  • We publish no uptime figure, because we have no measured SLA to stand behind yet.
  • Card details never reach us. Payments through JazzCash, Easypaisa or a bank go through the provider, and Liftsol records that it happened, not the instrument.

Your members’ rights

Members can ask for their data, and can ask for it gone

Your gym is the one that decides what is collected; we hold it on your behalf. A member wanting a copy, a correction, or deletion goes through you, and we do the work behind it.

Found something that looks wrong?

If you think you have found a security problem, tell us before you tell anyone else and we will fix it. Message the same number that answers everything else.