Hero Cover

Privacy Policy

Effective date: 28 July 2026 · Version 2.0

Privacy Policy

Prior versions are available on request.

1. Who we are

Gymlive Limited ("GymLive", "we", "us"), a company registered in Ireland with its registered
office at Dame Street, Dublin 2, Ireland, is the data controller for the GymLive platform: the
GymLive mobile and watch apps, club portal, club onboarding, dashboards and the gymlive.app
websites.

Privacy contact: privacy@gymlive.app

Where a sports club uses GymLive to manage its members, the club is a separate controller for its member relationship; GymLive processes that data on the club's behalf, and as a controller for operating the platform.

2. Who this policy covers

Players and athletes (including children — see section 6), parents and guardians, coaches, club administrators, event attendees and website visitors.

3. What we collect

  • Account and profile: name, email address, username, password (stored hashed), phone number, date of birth, profile photo, bio, club and team membership.

  • Children's data: a child's name, date of birth, profile, performance and wellness data, collected with parental consent (section 6).

  • Health and fitness data (only with your explicit consent — section 5): heart rate, including live heart-rate from a connected watch, sleep, steps, calories, distance, activity sessions, wellness check-ins (sleep quality, muscle soreness, mood, energy), injury or discomfort notes, and — for performance programmes — height, weight and growth estimates.

  • Payments: subscription and payment records. Card details are entered directly with our payment processor, Stripe; we never store card numbers.

  • Media: photos and videos you upload, live-session video and recordings, player-card images.

  • Surveys: onboarding and scouting survey answers, such as playing position, height, club history and parent/guardian contact details.

  • Messages: chat messages.

  • Technical data: device information, app version, IP address, crash and error reports (pseudonymised — section 7), and push-notification tokens.

We do not collect medical diagnoses or genetic data.

4. Why we process your data

  • Providing accounts, club membership, schedules, training programmes and live sessions —
    performance of our contract with you.

  • Payments, invoicing and fraud prevention — contract and legal obligation.

  • Health, wellness and performance tracking — your explicit consent.

  • Children's participation — parental consent (section 6).

  • Transactional email, SMS verification and push notifications — contract and legitimate interest.

  • In-app search, service analytics and crash reporting — our legitimate interest in running and improving GymLive.

  • Install attribution for the mobile app — our legitimate interest in measuring app installs, and consent where the law or your device requires it (for example Apple's App Tracking Transparency).

5. Health data

Health and fitness data is special-category data. We process it only with your — or, for a child, a parent or guardian's — explicit consent, given when you connect a wearable, enable wellness check-ins or join a performance programme. You can withdraw consent at any time in
the app (disconnect the wearable, stop check-ins), which stops collection, and you can ask us to delete historical health data (section 10).

6. Children and youth players

GymLive is used by youth sports clubs. In Ireland the digital age of consent is 16; where you live elsewhere, the age set by your local law applies. For players under that age:

  • registration requires the consent of a parent or guardian, and we record when and by whom consent was given;

  • health-data features and photo/video features require the additional consents described in this policy;

  • coaches and club staff see a child's data only within their club role;

  • a parent or guardian can review, export or delete the child's data at any time (section 10).

We do not show advertising to children and we never use children's data for marketing.

7. Service providers

We do not sell or rent personal data, and we do not share it with data brokers. We share personal data only with the service providers we need to run GymLive, under data-processing agreements, each only for the purpose listed:

  • Stripe — payments and payouts to clubs

  • Amazon Web Services — hosting, storage and email delivery (EU region)

  • Terra — wearable and health-data connections (only with your health-data consent)

  • Stream (GetStream) — chat

  • Zego — live audio/video sessions

  • Twilio — SMS verification

  • Firebase (Google) — push notifications and app analytics

  • AppsFlyer — install attribution for the mobile app

  • Sentry — error monitoring (pseudonymised: names, emails and identifiers are removed before sending; EU servers)

  • Axiom — operations logs (EU)

  • Google and Apple — sign-in, address autocomplete and app-store purchases

We use Firebase Analytics and AppsFlyer to measure installs and app usage. We do not use your data to show you third-party advertising.

Beyond these providers, your data is visible only to you, to your club's coaches and staff within their role, and to our internal support and engineering teams for technical purposes.

8. International transfers

Where a provider processes data outside the European Economic Area, we rely on European Commission adequacy decisions (including the EU-US Data Privacy Framework where the provider is certified) or Standard Contractual Clauses, with supplementary measures where needed.

9. Retention

  • Account and profile data: while your account is active; deleted within 30 days of account deletion.

  • Health and wellness data: until you withdraw consent or delete your account; deleted within 30 days.

  • Media content: deleted on request or when your account is deleted.

  • Payment and transaction records: up to 7 years, as required by Irish tax law.

  • Error and crash reports: 90 days.

  • Other diagnostic and performance logs: up to 12 months, then deleted or anonymised.

  • Anything else is kept no longer than needed for the purposes in section 4.

10. Your rights

You — and parents/guardians on behalf of their children — can access, correct, export, delete, restrict or object to the processing of personal data, and withdraw any consent at any time, by emailing support@gymlive.app or using the in-app controls. We respond within one month. You can also complain to the Irish Data Protection Commission (www.dataprotection.ie) or your local supervisory authority.

11. Security

Data is encrypted in transit (TLS) and at rest. Access is role-restricted and logged, payment card data never touches our servers, and error reports are scrubbed of identifying data before leaving our infrastructure. Because GymLive is a team platform, content you share is by design
visible to the coaches, club staff and teammates you share it with — it is not end-to-end encrypted.

12. Cookies

Our websites use essential cookies needed for sign-in and security. If we introduce analytics or other non-essential cookies, we will ask for your consent first.

13. Where this policy is published, and changes

The current policy is published at gymlive.app/policies/privacy-policy and in-app. We will notify account holders of material changes by email or in-app notice before they take effect, and keep prior versions available on request.

Contact

Gymlive Limited · Dame Street, Dublin 2, Ireland
📧 privacy@gymlive.app (privacy) · support@gymlive.app (general)
🌍 www.gymlive.app