Legal information

Privacy Policy

This Policy explains how Inf CRM processes personal data through infcrm.app, the Inf CRM service and the Inf CRM Mobile application for iOS and Android.

1. Scope and contact

This Privacy Policy applies to the infcrm.app website, its contact and product request forms, the web-based Inf CRM service, support communications, the website AI assistant and the Inf CRM Mobile application for iOS and Android (together, the Services).

For personal data relating to the global Inf CRM Mobile account, website visitors and people who contact us directly, Inf CRM determines the purposes and means of processing. Questions, privacy requests and complaints can be sent to info@infcrm.app.

This Policy is a notice about data processing. Acceptance of the Terms of Service or acknowledgement that this Policy was presented does not by itself constitute consent for every processing activity. Where consent is required, it is requested separately for the relevant purpose.

2. Inf CRM and fitness club responsibilities

Inf CRM Mobile is a universal application that can connect one user to client records held by one or more fitness clubs. A fitness club normally determines why and how it processes its client, membership, payment, visit and booking records. For that information the club is generally the controller and Inf CRM acts as its service provider or processor, subject to the agreement with that club.

A club may provide its own privacy policy and terms in the application. Requests to correct or delete a specific club client record, including financial and attendance history, should normally be addressed to that club. Deleting the global Inf CRM Mobile account is a separate operation described below.

3. Website and direct communication data

  • Contact details such as name, email address, phone number, messenger username or social media profile.
  • Business information such as club name, city, role, locations, modules of interest and comments submitted in forms.
  • Messages sent to sales or support, product questions, feedback and website AI assistant prompts.
  • Technical and usage data such as IP address, browser, device type, visited pages, referral source, language preference, cookie identifiers and analytics events.

4. Inf CRM Mobile account and authentication data

  • Internal user ID, display name, preferred language, account status and creation or update timestamps.
  • Verified email and identity information received from Google Sign-In or Sign in with Apple, including provider, issuer, provider subject, email verification status and login timestamps. We do not receive your Google or Apple password.
  • Phone number entered in international format and the time and version of the phone binding. The phone is not verified by SMS OTP.
  • Installation or device identifier, active sessions, hashed refresh tokens, session expiry, reauthentication and revocation information.
  • Security history such as keyed hashes of previous and new phone numbers, link or replacement events, rate-limit events, correlation IDs and audit records without secret credentials.

5. Club and client information shown or created in the application

  • Selected club and branch, club contact details, branding and configuration.
  • Links between the mobile account and club client records, the method and time of linking, validation status and assigned branches.
  • Client profile information made available by the club, including name, phone, client number and other profile fields.
  • Memberships, validity periods, balances, debts, available visits, mobile card, barcode or QR value and status. Card values are treated as confidential identifiers.
  • Booking and attendance information, including classes, trainers, services, dates, waiting-list position, cancellation deadline, attendance and no-show status.
  • Payment-related information supplied by the club, such as payment history, balances, debts and the amount of the latest eligible payment when used as a linking proof. Inf CRM Mobile is not intended to collect full payment card credentials in these flows.
  • When a user creates a guest client profile: first name, surname, optional middle name, date of birth, the phone from the mobile account and the selected branch. These details are sent to the selected club and the date of birth is not stored in the global Inf CRM Mobile account.

6. Notifications, analytics, diagnostics, device data and permissions

If push notifications are enabled, we may collect a push token, installation or device identifier, platform, language, notification preferences, last-seen time and delivery or invalid-token status. The token may be sent to notification delivery providers such as Expo Push Service, Apple Push Notification service or Firebase Cloud Messaging. It is used to deliver service messages such as booking updates, reminders and membership notices. A push token is removed or disabled when it becomes invalid, notifications are disabled, the session or device is revoked, or the account is deleted, subject to limited security records.

If the user separately enables optional analytics and diagnostics, Inf CRM Mobile uses Firebase Analytics and Firebase Crashlytics. These services may receive semantic screen and action names, operation outcomes, application version and build, operating-system version, platform, language or locale, device manufacturer and model, app-instance or installation identifiers, network and general location information derived from the connection, crash state, stack traces and technical breadcrumbs needed to reproduce an error.

Inf CRM does not intentionally add names, phone numbers, email addresses, client, card or membership numbers, barcodes, QR values, access or push tokens, proof or payment amounts, or CRM, club-link and booking identifiers to mobile analytics events or diagnostic reports. Advertising ID collection, personalized advertising and advertising use are disabled for this integration.

Mobile analytics and diagnostic upload are disabled by default and begin only after the user makes a separate optional choice in the application. The choice can be changed at any time under Analytics and diagnostics in the profile. Turning collection off stops new optional collection, resets the local Analytics app-instance data and removes unsent crash reports where supported; it does not retroactively erase reports already transmitted and processed under the previous consent.

Camera access is requested only when the user opens the club QR scanner. The application uses the camera view to read the code and does not intentionally record video or audio. Manual invitation-code entry remains available if camera access is denied.

After a booking the user may choose to open the system calendar flow. Calendar access, if required by the platform implementation, is requested only after that action. The application does not read the calendar at startup or perform background calendar synchronization. Microphone access is not required for these features.

7. How we use personal data

  • Create and secure the global mobile account, authenticate the user and maintain sessions.
  • Connect a user to an authorized club client record and display club, profile, membership, card and schedule information.
  • Create guest profiles, bookings, waiting-list entries, cancellations and other actions requested by the user and allowed by the club.
  • Deliver enabled push notifications and user-requested calendar actions.
  • With the user's optional permission, measure use of application screens and actions, diagnose crashes and non-fatal errors, evaluate reliability and improve the user experience.
  • Respond to product requests, provide support and communicate about the Services.
  • Operate, troubleshoot, protect and improve the website, application, BFF and club integrations.
  • Prevent fraud, credential abuse, unauthorized linking and other security incidents.
  • Meet accounting, legal, regulatory and dispute-resolution obligations.

8. Legal bases

Where applicable law, including the GDPR, requires a legal basis, processing may be necessary to perform a contract or take requested pre-contract steps, comply with a legal obligation, pursue legitimate interests such as service security and improvement, or act on consent for a specific optional purpose.

A user can withdraw consent where processing depends on consent. Optional mobile analytics and diagnostics can be disabled under Analytics and diagnostics in the application profile. Withdrawal does not affect processing already carried out lawfully and does not prevent processing based on another valid legal basis. Device permissions can be changed in the operating-system settings.

9. Service providers and recipients

We do not sell personal data. Providers receive only the information reasonably required for their function and must handle it under applicable contractual and legal safeguards.

  • The fitness clubs selected or linked by the user and their authorized personnel.
  • Hosting, database, storage, security, email, support and infrastructure providers needed to operate the Services.
  • Google and Apple for authentication when the corresponding sign-in method is used.
  • Expo Push Service, Apple Push Notification service and Firebase Cloud Messaging when push delivery is enabled for the relevant platform.
  • Google Firebase Analytics and Firebase Crashlytics when the user enables optional mobile analytics and diagnostics.
  • Trello when website forms, product requests or external account-deletion requests are converted into internal work items.
  • Google Analytics for website measurement, subject to applicable consent requirements and settings.
  • Google AI services when the website AI assistant processes a submitted question to generate an answer.
  • Professional advisers, auditors, authorities or other parties where disclosure is required by law or necessary to establish, exercise or defend legal claims.

10. Cookies, analytics, diagnostics and the website AI assistant

The website may use cookies or local storage for language preferences, necessary functionality and, where permitted, analytics. Non-essential analytics cookies are used subject to the consent requirements applicable to the visitor.

Optional mobile analytics is used to understand which application areas are used and whether an action succeeds or fails. Optional diagnostics is used to receive crash and sanitized non-fatal error reports. These data are not used by Inf CRM for advertising, ad personalization or cross-service marketing profiles.

The AI assistant processes the submitted question and limited conversation context to answer product questions. A limited chat history may be stored in the browser. Do not enter passwords, access tokens, payment card details, health records or other unnecessary confidential information into the assistant.

11. On-device storage and security

The application may store refresh credentials in protected operating-system storage and an allowlisted offline copy of selected personal data in an encrypted local database. Public branding and non-sensitive preferences may use ordinary application storage.

Personal offline data is scoped to the account and club connection and is cleared on logout, user switch, security revocation, unlink or replacement, phone change and account deletion. Cached information can be stale; fresh server data remains authoritative for booking and access decisions.

We use reasonable technical and organizational safeguards, including encrypted transport for public connections, hashed session credentials, access controls, rate limiting, audit trails and rules intended to keep phone numbers, card values, proof amounts and provider tokens out of application logs. No online service can guarantee absolute security.

12. Retention

We retain personal data only for as long as needed for the purposes described in this Policy, the relationship with the user or club, security, legal compliance and dispute resolution. Active mobile refresh sessions normally expire after up to 30 days unless rotated, revoked or terminated earlier.

Push tokens are kept while the relevant device and notification registration remain active and are removed or disabled when invalidated, revoked or deleted. Offline mobile data is subject to feature-specific expiry and wipe rules.

Optional analytics and diagnostic information already sent to Firebase is retained according to the applicable Firebase product settings and only for as long as reasonably required for measurement, troubleshooting, security and service improvement. Aggregated or de-identified statistics may no longer identify an individual app instance.

After account deletion, direct identifiers, sessions, provider identities, phone and client links are deleted or anonymized unless a specific record must be retained. Minimal legal-acceptance, deletion and security audit information, including keyed hashes that do not retain previous phone numbers in plain text, may be retained for the period reasonably required for legal obligations, fraud prevention, security investigations or legal claims.

Club CRM records follow the retention policy and legal obligations of the relevant club. Website enquiries and support correspondence are retained while they are needed to handle the request, maintain the business relationship or meet applicable legal requirements.

13. Account and data deletion

A user can request deletion of the global Inf CRM Mobile account in the application or at https://infcrm.app/account-deletion. We may verify the request before irreversible processing. Deletion revokes sessions and removes or anonymizes the mobile account, authentication identities, phone, club links, device and push-token information according to the retention rules above.

Deleting the mobile account does not automatically delete a client record held by a fitness club. Financial, contractual, attendance, booking or guest-profile records in a club CRM must be addressed with that club. The club may need to retain some records under its own legal obligations.

14. International transfers

Some service providers or infrastructure may operate outside the user's country, including outside the European Economic Area. Where required, we use recognized transfer mechanisms and contractual or organizational safeguards appropriate to the destination and the information involved.

15. Your rights

Depending on location and applicable law, a person may have rights to access, correct, delete or receive a copy of personal data; restrict or object to processing; withdraw consent; and complain to a competent supervisory authority.

Send a request to info@infcrm.app. We may need to verify identity. If the relevant information is controlled by a fitness club, we may direct the request to that club or assist it as required by our service agreement.

16. Age limitation

Only people aged 18 or older may create an account or use Inf CRM Mobile. People under 18 must not create an account or use the application. The website and CRM are primarily intended for business use. If you believe a person under 18 has provided data directly to Inf CRM contrary to these rules, contact info@infcrm.app.

17. Changes to this Policy

We may update this Policy when the Services, mobile permissions, SDKs, providers or legal requirements change. The current version and update date are published on this page. A material new required version may also be presented in the application for acknowledgement before protected features continue.

18. Contact

For privacy questions, rights requests or complaints, contact Inf CRM at info@infcrm.app. For a club's client, payment, attendance or membership record, use the club contact shown in Inf CRM Mobile.

See whether Inf CRM fits your club

During the demonstration, we will walk through your core workflows, show the product in action and discuss data migration. There is no obligation to switch right away.