DRAFT — OWNER AND LEGAL REVIEW REQUIRED
This repository-owned draft is public for transparent review. It is not approved, not effective legal text, and not an acceptance mechanism. Viewing it or signing in records no legal acceptance.
Privacy notice (Draft)
A plain-language description of the current GymRunner product boundary. Owner-controlled legal facts remain explicit review items rather than invented promises.
Status and accountable party
This page describes repository-supported product behavior; it is not a completed privacy notice. [OWNER REVIEW REQUIRED: identify the legal service provider and the controller/processor roles for each pilot relationship.] [OWNER REVIEW REQUIRED: publish a monitored privacy and support contact channel.]
Information the product can handle
- Authentication account data and the separate product person mapping.
- Gym operations records such as staff roles, leads, members, households, guardians, schedules, attendance, agreements, and test-mode invoices.
- Contact points and consent or suppression history. An email address or phone number is contact metadata, never the product identity key.
- Import/export metadata, security and audit records, customer-controlled support grants, and change or readiness evidence.
- Assistant conversations and approval proposals when Ask GymRunner is configured. Every write still requires explicit in-product approval.
Gyms, authorized staff, members or guardians, and the independent authentication service can supply these records. The public site has no public account or organization signup.
How the current product uses information
The checked-in product uses records to provide tenant-scoped gym operations, member/guardian self-service, authentication, security, customer-authorized support, data portability, and operational audit. Routine telemetry is field-allowlisted and excludes free-form record content. The repository contains no advertising profile or behavioral analytics implementation.
[LEGAL REVIEW REQUIRED: confirm purposes, lawful bases, notices for minors and guardians, and any jurisdiction-specific consent requirements.]
Access and service-provider boundaries
Row-Level Security is the primary tenant boundary. Product support has no standing customer access: an organization owner must grant read-only, module-scoped, case-linked access for no more than seven days and can revoke it. The application does not use a service-role shortcut for these customer workflows.
Deployment, authentication, hosting, backup, monitoring, and any optional assistant provider are owner-selected external services. This draft does not identify processors, promise subprocessor terms, or assert transfer or compliance status. [OWNER AND LEGAL REVIEW REQUIRED: approve and publish the actual provider list, sharing purposes, locations, contracts, and transfer terms before this notice becomes effective.]
Security and account controls
Repository controls include forced tenant RLS, least-privilege roles, append-only audit/security records, single-use capability invitations, redacted operational telemetry, and real TOTP assurance checks for the supported sensitive workflow. These controls reduce risk but are not a guarantee that incidents cannot occur. Provider configuration, MFA, monitoring, backup, and recovery remain owner-reviewed launch gates.
Retention, export, and deletion
The product model supports a 90-day read-only export window for canceled locations. It preserves financial, security, identity, consent, support, and audit history where the repository marks records append-only. The repository does not yet automate final deletion or anonymization and does not establish a complete legal retention schedule.
[LEGAL REVIEW REQUIRED: approve record-by-record retention, legal holds, backup-copy handling, deletion/anonymization procedure, and request response timelines.]
Choices and requests
The product records communication consent, withdrawal, and suppression; those controls do not by themselves define every legal right. The applicable access, correction, portability, objection, restriction, or deletion process depends on the accountable party and jurisdiction. [OWNER REVIEW REQUIRED: publish the verified request channel and identity verification procedure.] Do not place credentials, one-time links, or sensitive records in an unverified request.
Browser storage
Configured authentication uses GymRunner's independent session cookies. Invitation and portal-claim capabilities are read from the URL fragment and removed from browser history. The checked-in public surface has no advertising cookie or analytics tracker. [LEGAL REVIEW REQUIRED: verify the deployed cookie inventory and publish any required controls.]
Facts required before approval
Legal identity, contact channel, effective date, controller/processor allocation, provider disclosures, international-transfer terms, jurisdictional rights, minors treatment, retention schedule, and incident notice obligations are intentionally unresolved on this draft. A human owner and qualified reviewer must resolve them in the private review record bound to the exact release before replacing the draft status.