MinGym Privacy Policy
MinGym is a pay-per-visit gym access app operated by NARVO. This policy explains what personal data the app collects, why, who it is shared with, and how to delete it. It covers the MinGym iOS and Android apps.
1. Who we are
NARVO is the data controller for MinGym. For any privacy question or request, contact us at narvoai@outlook.com.
2. Minimum age
MinGym is for adults. You must be at least 18 years old to create an account, because using the app means entering into paid transactions. We ask for your date of birth during signup to enforce this. MinGym is not directed to children, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, email us and we will delete it.
3. What we collect
Account and identity
- Phone number — required. It is your login credential and is verified by SMS one-time code.
- First and last name — required, so gyms can identify you at check-in.
- Date of birth — required, used to confirm you meet the minimum age.
- Email address — optional, used to send receipts. Verified by a confirmation link.
- Gender — optional, self-reported, and may be left unanswered.
- Profile photo — optional. See section 6 for how these images are stored.
Gym visits
Every check-in and check-out creates a session record: which gym, the start and end time, the duration in minutes, and the amount charged. We also keep a log of QR scan attempts, including failed ones, to detect fraud and to investigate access problems. Your cumulative paid minutes are stored on your profile.
Payments and wallet
We store your wallet balance and a full transaction ledger: amounts, currency, type, description, running balance, and the payment provider’s reference for each entry.
We never see or store your card number. All card entry happens on Stripe’s own hosted checkout page, opened in your browser. Stripe returns only non-sensitive details to us — the card brand, its last four digits, and the expiry month and year — which we store so you can recognise your saved card.
Location
If you grant location permission, the app reads your precise location to show your position on the gym map, sort gyms by distance, and re-centre the map. Your coordinates are never sent to or stored on our servers. They stay on your device for as long as the map screen is open. You can deny or revoke this permission in your device settings; the app remains fully usable, and you can still browse and check in to gyms.
On Android, the map is drawn using tile images fetched from CARTO’s content delivery network. Because the map is centred near you, those requests reveal the approximate area you are viewing, together with your IP address, to CARTO. On iOS the map uses Apple MapKit instead, and no third-party tile provider is contacted.
Referrals
Each account has a referral code. If you sign up through someone’s code, we record the link between your account and theirs so that reward points can be credited correctly.
Notifications and live session display
On iOS, if you use the live session display on your lock screen, we store an Apple-issued push token together with the session identifier so the elapsed time and running cost can be updated while the app is closed. The gym name and your running cost are shown on your own lock screen.
Diagnostics and usage
We use Sentry to collect crash reports, error traces, and a breadcrumb trail of in-app actions such as opening the app, starting or ending a session, scanning a QR code, beginning a top-up, and redeeming points. These reports are tagged with your account’s internal identifier so we can correlate a crash with an affected account. Sentry is configured not to attach your IP address, name, email, or phone number.
4. What we do not do
- We do not track you across other companies’ apps or websites.
- We do not sell or share your personal data with data brokers or advertisers.
- There is no advertising SDK, attribution SDK, or advertising identifier in the app.
- We do not collect your contacts, browsing history, or search history.
- We do not collect identity documents, national ID numbers, or any other KYC records.
5. Who we share data with
We share data only with service providers that operate parts of MinGym on our behalf:
| Provider | Purpose | What they receive |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All account, session, and transaction data |
| Stripe | Payment processing | Card details you enter on their page, payment amounts, and your internal account identifier |
| SMS provider | Delivering login one-time codes | Your phone number |
| Resend | Sending email verification links | Your email address |
| Apple | Push notifications and iOS maps | Push token, session cost and duration |
| CARTO | Map tiles on Android | Approximate map area and IP address |
| Sentry | Crash and error reporting | Crash traces, in-app action breadcrumbs, and your internal account identifier |
Gyms you visit receive your name and check-in details so they can admit you and reconcile their payouts.
We may also disclose data where required by law, or to establish, exercise, or defend legal claims.
6. Profile photos are publicly addressable
Profile photos are stored in a public storage bucket. The address of each image is long and effectively unguessable, and the app does not let anyone list or browse the bucket. However, anyone who obtains the direct link to an image can open it without signing in. Please keep this in mind when choosing a profile photo.
7. Deleting your account
You can delete your account at any time from Profile → Edit profile → Delete account inside the app. No email or support request is required.
Deleting your account permanently removes:
- Your profile, name, phone number, email, date of birth, and gender
- Your profile photos
- Your wallet balance and full transaction history
- Your gym session history
- Your saved card references, points, and referral records
- Any stored push notification tokens
Some records are kept, and you should be aware of them:
- QR scan logs and administrative audit logs are retained for fraud prevention and accounting, but the link to your account is severed, leaving them anonymous.
- Stripe retains its own payment records. Deleting your MinGym account does not delete data held by Stripe, which keeps transaction records to meet its own legal and financial obligations.
- Sentry retains previously submitted crash reports tagged with your internal identifier until its retention period expires.
8. How long we keep data
We keep your account data for as long as your account exists. Financial transaction records may be retained after deletion, in anonymised or provider-held form, for as long as tax and accounting law requires. Crash reports expire according to Sentry’s retention schedule.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or object to our processing of your personal data, and to withdraw consent. You can view and correct most of your data directly in the app, and you can delete everything using the in-app deletion described above. For anything else, email narvoai@outlook.com and we will respond within 30 days.
10. Security
Data is transmitted over encrypted connections and stored with per-user access rules enforced at the database level, so one account cannot read another’s data. No system is perfectly secure, but we work to protect your information and to respond quickly if a problem is found.
11. Changes to this policy
If we make a material change, we will update the effective date above and notify you in the app. Continuing to use MinGym after a change means you accept the updated policy.
12. Contact
Questions, requests, or complaints: narvoai@outlook.com