← Back to GyMap

Security

Last updated June 2025

Security is built into GyMap from the ground up. Here's how we protect your gym's and your members' data.

Tenant isolation

GyMap is multi-tenant with strict row-level security. Every record is scoped to a gym, and members can only ever access data belonging to their own gym. Admins only see their own gym's members and content.

Encryption

Data is encrypted in transit (TLS) and at rest. Sensitive media such as progress photos is stored in private buckets and served only via short-lived, signed links.

Authentication

Accounts use secure email-based authentication with one-time codes. Access to the dashboard is restricted to verified gym admins; the platform console is restricted to platform administrators.

Payments

Card data is handled entirely by Stripe, a PCI-DSS Level 1 certified provider. GyMap never stores card numbers.

Infrastructure

GyMap runs on managed, reputable cloud infrastructure with automated backups, monitoring and least-privilege access controls.

Reporting an issue

If you believe you've found a security vulnerability, please contact us right away at nrgym1@hotmail.com so we can investigate and respond quickly.

Questions about this policy? Contact us at nrgym1@hotmail.com or call 01535 667338.

This page is provided for general information and should be reviewed against your own legal advice before launch.