Skip to content
POCKETLYTECH LLP
Company Product Approach Start a conversation ↗

PRIVACY POLICY

Your data, explained.

Effective: 28 July 2026

TermsPrivacy policy

1. Scope and roles

This Privacy Policy explains how Pocketly Tech LLP collects, uses, stores, shares, and deletes personal data through this website and our web and mobile products.

For account, billing, website, support, and product-usage data collected for our own purposes, Pocketly determines why and how the data is processed. For member and staff data entered by a gym customer, the gym generally determines the purpose and means of processing and Pocketly processes the data on the gym’s instructions. Members should normally direct requests about gym records to their gym first.

2. Information we may collect

Account and contactName, business or gym name, role, email address, phone number, login identifier, and account preferences.
Gym-member recordsMember name, contact details, date of birth or age where needed, membership plan, joining and renewal dates, attendance/check-in history, assigned trainer, notes, emergency contact, and status.
Business and transactionPlan charges, invoices, payment status, tax information, and transaction references. Full card details are intended to be handled by authorised payment providers, not stored by Pocketly.
Technical and usageIP address, device and browser type, operating system, timestamps, pages or features used, approximate location derived from IP, diagnostic logs, crash data, and security events.
CommunicationsEmails, support requests, feedback, survey responses, and records of business communication.
Permissions-based dataNotifications, camera, contacts, or location information only if a product feature needs it and the user grants device permission. The relevant screen will explain the purpose.

We do not intend to collect health diagnoses, biometric identifiers, government identity documents, precise continuous location, or card security codes through the gym product unless we first provide a specific notice and implement the necessary safeguards. Customers should not enter such information into free-text fields.

3. How information is collected

Information comes directly from users and gym administrators; automatically from devices when a Service is used; from integrated services selected by a customer; and from payment, authentication, hosting, analytics, or communication providers involved in delivering the Services.

4. Why we process information

We process personal data to create and administer accounts; provide member management, attendance, renewal, communication, and reporting features; authenticate users; process and reconcile payments; respond to support; maintain backups; monitor reliability; prevent fraud and security incidents; comply with legal obligations; and improve product usability and performance.

Processing is based, as applicable, on consent, steps requested before or under a contract, compliance with law, and other lawful uses recognised by applicable data-protection law. Where consent is the basis, it may be withdrawn as easily as it was given, although previous lawful processing remains unaffected.

5. How and where data is stored

Product data will be stored electronically on access-controlled systems operated by Pocketly and contracted cloud, database, backup, authentication, email, monitoring, and payment service providers. Data may be held in primary databases, encrypted backups, system logs, support systems, and user devices where the product permits local caching.

Before commercial launch, Pocketly will identify its production hosting locations and material processors in product documentation or an in-product notice. If information is transferred outside India, we will use providers and locations permitted under applicable law and apply appropriate contractual and technical safeguards. We will not claim that data remains only in India unless the selected production architecture guarantees it.

6. Security

We use safeguards appropriate to the nature and risk of the data, designed to include encryption in transit, encryption or equivalent protection at rest where supported, access controls, least-privilege administration, authentication controls, logging and monitoring, backups, vulnerability management, vendor review, and incident-response procedures.

No method of storage or transmission is completely secure. Users must protect credentials, use secure devices, grant staff only necessary access, and notify us promptly of suspected compromise. If a personal-data breach occurs, we will investigate, mitigate harm, preserve relevant records, and provide notices to affected persons and authorities where required by applicable law.

7. When information is shared

We may share limited information with service providers acting for us, such as hosting, database, backup, authentication, customer support, communications, analytics, monitoring, and payment providers; with integrations a customer chooses to enable; with professional advisers under confidentiality obligations; with authorities where legally required; or as part of a merger, financing, reorganisation, or sale subject to appropriate protection.

We do not sell personal data. We do not permit service providers to use Customer Data for their own advertising. We disclose only what is reasonably necessary for the relevant purpose.

8. Retention and deletion

Active accountsKept while the account is active and as needed to provide the Services.
After closureCustomer Data will ordinarily be deleted or de-identified from active systems within 90 days after account closure or a valid deletion instruction, unless a longer period is agreed or legally required.
BackupsResidual copies may remain in protected, access-restricted backups until overwritten under normal backup cycles, ordinarily within a further 90 days.
Billing and legal recordsInvoices, tax, fraud-prevention, dispute, consent, and compliance records may be retained for the period required by applicable law or necessary to establish or defend legal claims.
Support and security logsKept only as long as reasonably needed for support, reliability, investigation, and security, then deleted or de-identified.

A gym administrator may delete or correct member records through available product controls or request assistance. Deletion may be delayed where information must be preserved for security, fraud prevention, legal compliance, or an active dispute. Aggregated or irreversibly de-identified information may be retained because it no longer identifies an individual.

9. Individual rights and choices

Subject to applicable law, an individual may ask for a summary of personal data being processed and processing activities; correction, completion, or updating of inaccurate data; erasure where retention is no longer necessary or lawful; withdrawal of consent; and grievance redressal. Individuals may also nominate another person to exercise applicable rights in the event of death or incapacity where the law provides.

We may need to verify identity and authority before acting. Gym members should contact their gym for member-record requests; Pocketly will assist the gym where required. Account users may contact us directly. We will not retaliate against anyone for exercising a privacy right.

10. Children

The business Services are intended for gym owners and authorised staff, not for children to open their own administrative accounts. Where a gym records information about a member who is a child, the gym is responsible for obtaining verifiable consent from a parent or lawful guardian and for complying with restrictions on tracking, behavioural monitoring, and targeted advertising applicable to children. Pocketly does not use gym-member data for targeted advertising.

11. Cookies, analytics, and communications

This informational website currently does not intentionally set advertising cookies. Future product sessions may use strictly necessary storage for authentication, security, preferences, and continuity. Any non-essential analytics or marketing technology will be disclosed and, where required, offered with a consent choice.

Operational messages needed to provide an account may still be sent. Optional promotional messages will include a way to opt out; opting out does not affect service, security, billing, or legal notices.

12. Grievances and contact

For privacy questions, rights requests, complaints, or security concerns, email pocketlytech@gmail.com with the subject “Privacy Request”. Please describe the account or gym involved and the request without sending unnecessary sensitive information. We will acknowledge and address grievances within the period required by applicable law.

If a complaint is not resolved, an individual may use remedies available under applicable Indian data-protection law, including approaching the competent authority when the relevant provisions apply.

13. Changes to this policy

We may update this Policy as the product, storage architecture, providers, or law changes. The effective date will be revised and material changes will be communicated through the Service or by email where appropriate. Previous versions may be requested by email.

POCKETLYTECH LLP
LEGAL

Terms · Privacy

© 2026

All rights reserved.