Security
Last updated June 2025
Security is built into GyMap from the ground up. Here's how we protect your gym's and your members' data.
Tenant isolation
GyMap is multi-tenant with strict row-level security. Every record is scoped to a gym, and members can only ever access data belonging to their own gym. Admins only see their own gym's members and content.
Encryption
Data is encrypted in transit (TLS) and at rest. Sensitive media such as progress photos is stored in private buckets and served only via short-lived, signed links.
Authentication
Accounts use secure email-based authentication with one-time codes. Access to the dashboard is restricted to verified gym admins; the platform console is restricted to platform administrators.
Payments
Card data is handled entirely by Stripe, a PCI-DSS Level 1 certified provider. GyMap never stores card numbers.
Infrastructure
GyMap runs on managed, reputable cloud infrastructure with automated backups, monitoring and least-privilege access controls.
Reporting an issue
If you believe you've found a security vulnerability, please contact us right away at nrgym1@hotmail.com so we can investigate and respond quickly.
This page is provided for general information and should be reviewed against your own legal advice before launch.