Privacy Policy
Last updated
Balvira holds two different kinds of personal data and treats them differently. Your own — the account holder's name, email and phone — is ours to answer for. Your members' data is your gym's to answer for and ours to hold on your instructions. This page says what happens to both.
The two roles, because they decide everything else
Under the Digital Personal Data Protection Act, 2023, your gym is the Data Fiduciary for its members and Balvira is the Data Processor acting on your instructions. For your own account and for visitors to balvira.in, Balvira is the Data Fiduciary. A member who wants their record corrected or erased should ask their gym; a gym owner who wants their own account data should ask us.
What we collect about you
When you open an account: the gym's name and kind, your name, your email address, your phone number, and a password we store only as a hash and can never read back. When you use the service: the times you sign in, the IP address a signup or a failed login came from, and the pages you opened. When you pay: the plan, the amount, the invoice, and the reference the payment gateway gives us. We never see or store your card details — the gateway does.
What your gym collects about its members
Whatever you enter or your members enter: name, phone, email, gender, date of birth, address, joining date, membership and payments, attendance, class bookings, and — where you use those features — measurements, progress photographs, workout and diet plans. Some of that is data about health, and it is held for you and shown to nobody outside your gym.
- Each gym's data is isolated from every other gym's, on every query
- Progress photographs are not visible to staff unless the member shares them
- A member can keep themselves off the public leaderboard and the community wall
- Staff and trainer logins see only the sections the owner has granted them
Who else sees it
As little as possible, and only what a job needs. Payment gateways — Razorpay and Cashfree — receive what a payment needs and are the ones holding card details, not us. WhatsApp reminders go out through your own account with an official WhatsApp Business provider such as Gupshup or Interakt, and carry the message and the number. Email leaves through the SMTP settings you configure, or ours for password resets. Hosting is with Hostinger, in India. We do not sell personal data to anybody, and we do not share it for anybody else's advertising.
Analytics, and where we deliberately do not measure
Google Analytics runs on the public marketing pages and on the sign-in, forgot-password and signup pages, which is the whole of the funnel worth measuring and carries nothing about anybody. It is not loaded anywhere inside the application, because those page addresses contain member, gym and invoice identifiers, and reporting them would hand a third party a map of which records are being looked at. It is also not loaded on a password-reset link, because that address is the credential.
Cookies
A session cookie that keeps you signed in and is required for the application to work at all. A preference cookie or two — the language a member chose, for instance. Google Analytics sets its own on the marketing pages. There is no advertising cookie and no third-party tracker beyond the analytics named above.
How it is protected
Passwords are hashed and never stored in a readable form. Credentials you give us for your own gateway and messaging accounts are encrypted before they are written down. Every database query is scoped to one gym, so one customer's data cannot be reached from another's session. Backups are taken. We do not claim a security certification we have not been audited for.
How long it is kept
For as long as your account is open. After it closes, ninety days in case the closure was a mistake, then deletion — apart from invoices and payment records, which tax law requires us to keep for eight years, and records we are otherwise legally obliged to retain.
Your rights
You may ask us what we hold about you, ask us to correct it, ask us to erase it where we are not required to keep it, withdraw a consent you gave, nominate somebody to exercise these rights if you cannot, and complain to us before you complain to the Data Protection Board of India. Write to the address on the contact page and we will answer within thirty days. If your relationship is with a gym rather than with us, ask the gym — and if they cannot help, tell us and we will.
Children
Balvira is sold to businesses, not to children, and an account may only be opened by an adult. A gym that enrols members under 18 is responsible for obtaining a parent or guardian's consent as the DPDP Act requires, and should not enable progress photographs or the public community wall for them.
Changes
The date at the top of this page is the version you are reading. A change that materially affects you is emailed to the account holder before it takes effect.
Who you are dealing with
- Name
- Balvira
- hello@balvira.in

