Skip to main content

Security

Built in, not bolted on.

How we look after your gym and the people in it, said plainly, with the honest bits left in.

Passkey sign-inMFA for staff and ownersFull audit trailYour gym's data is isolated

Signing in

Passwords are the weakest link in most software, so we lead with passkeys: sign in with your face, fingerprint or device, nothing to phish or reuse.

  • Passkey sign-in by default for owners and staff
  • Multi-factor authentication available on every account
  • Sessions expire and can be revoked, so a lost device isn't a lost gym

Your members' data

The details people trust you with, medical notes, guardians, payment details, are treated as exactly that: sensitive. Access is limited to the people in your gym who need it.

  • Sensitive fields encrypted, in transit and at rest
  • Role-based access, so reception doesn't see what only an owner should
  • Payment details handled by Stripe, never stored by us directly
  • Money actions are limited to the roles you choose, and every one is written to the audit log.

Your gym, your data

Your gym's records are yours alone. One gym can never see another's members, classes or numbers, the separation is built into the platform, not a setting someone could fat-finger.

  • Each gym's data is isolated from every other gym
  • Export your full member list any time, no lock-in
  • Our team only accesses your data with a time-limited, logged grant

Members and minors

A gym is full of kids, parents and people partway through their journey. Accounts follow the membership, not the other way round.

  • A login is only created when someone actually gets access through an active or trial membership, or a live class pass. Importing someone's details never creates a login.
  • Set a minimum age for member logins, and anyone under it simply never gets one. Anything concerning a junior member is addressed to their guardian.
  • When someone leaves, their access winds down on its own. It stays read-only for a window you choose (90 days by default), then disabled.

Where it runs

We'd rather tell you the honest version than a comforting one.

The honest bit

Some services run overseas today: payments go through Stripe in the USA, and the site is served from a global content-delivery edge. Australian data hosting is our target architecture and is not yet in place. We'll update this page as that changes, rather than imply it's already done.

If something is broken, we say so in public. The service status page shows what we monitor and how to reach a human, and what's new lists every change as it ships.

What you can see

Trust comes from being able to check. Every meaningful action in your gym leaves a trail you can read.

  • A full audit log of who did what, and when
  • Visibility into staff access and sign-ins
  • Clear records when sensitive details are viewed or changed

Questions a checklist won't answer?

Ask us anything about how your members' data is handled. We'll give you the real answer.

Talk to us