1Who we are and scope
Data Fiduciary / Controller: CodingRoof Software Technologies Private Limited. Product: FitForge. Website: https://codingroof.com/. Registered office: 2/107/1, Veerapandi Road, Oomatchikulam, Tirumalpuram, Madurai, Tamil Nadu, 625014, India.
This Policy applies to: (a) visitors to our marketing website and public pages; (b) gym owners, managers, and staff who create or use FitForge tenant accounts; (c) gym members who use the FitForge member mobile app at their gym’s invitation; and (d) individuals whose details are entered into FitForge by a customer gym (for example members, enquiries/leads, trainers, and emergency contacts).
Related documents: our Terms of Service (/terms) and this Privacy Policy should be read together. You can submit privacy rights requests at /privacy-request.
2Roles: controller vs processor
CodingRoof Software Technologies Private Limited acts as an independent controller (data fiduciary) for personal data we decide how to process for our own purposes, including: marketing-site interactions, sales inquiries, SaaS account administration, FitForge subscription billing, product security, fraud prevention, and improving FitForge.
For most operational data that a gym customer (tenant) stores in FitForge — including member profiles, memberships, enquiries, desk payment records, attendance/QR check-ins, class enrollments, trainer records, expenses, and WhatsApp message content the gym chooses to send — the tenant is typically the controller / data fiduciary, and CodingRoof Software Technologies Private Limited processes that data as a processor on the tenant’s documented instructions to provide the service.
If you are a gym member or staff user, your gym’s own notices and your relationship with the gym usually govern why your data is collected. This Policy still explains how FitForge technically processes that data.
3Personal data we collect
Depending on how you use FitForge, we may process the following categories:
- Account and identity data: name, mobile number (+91), optional recovery email, password (stored as a secure hash), role (Owner / Manager / Staff), gym and branch membership, and account status.
- Organization data: gym name, logo, branch details, plan/subscription identifiers, and settings.
- Member and enquiry data: names, phone numbers, addresses, emergency contacts, lead sources, membership plans, payment breakdowns, notes, and related history entered by the gym.
- Attendance and engagement data: QR check-in/check-out times, visit history, and visit leaderboard rankings derived from check-ins.
- Member app data: profile details, membership status, body metrics the member chooses to enter, and QR check-in activity.
- Operational data: class templates and sessions, coach/trainer profiles, expenses and categories, transactions ledger entries (Cash / UPI / Card payment recording).
- WhatsApp-related data: connection status, template/campaign configuration, and message delivery metadata when a gym connects WhatsApp inside FitForge.
- SaaS billing data: FitForge subscription status, plan, and Razorpay order/payment identifiers used only for upgrading the FitForge software plan (not for member dues online checkout).
- Device and session data: IP address, user agent, platform, and security/session metadata.
- Communications: emails, phone calls, or messages you send to us (for example sales or privacy requests).
- Cookies and similar technologies: consent preferences and strictly necessary storage used for authentication, security, and preferences (see Cookies section).
4How we use personal data
- Provide, operate, secure, and improve the Service.
- Create and administer accounts, authenticate users, and enforce role-based access.
- Process FitForge subscription trials, upgrades, and related billing.
- Respond to sales, support, and privacy requests.
- Send service-related notices (for example security or material product changes).
- Detect abuse, prevent fraud, and comply with law.
- With consent or where permitted, measure marketing-site performance using optional analytics cookies.
Where the DPDP Act, GDPR, or similar laws apply, we rely on appropriate legal bases such as contract performance, legitimate interests (security and product improvement), consent (where required for optional cookies or certain communications), and legal obligation.
6International transfers
We primarily serve customers in India. Service infrastructure may process data in other countries where our providers operate. Where required, we use appropriate safeguards (such as contractual protections) for cross-border transfers.
7Retention
We retain personal data only as long as needed for the purposes described in this Policy, including to provide the Service, meet legal, accounting, and security requirements, and resolve disputes. Tenant-controlled data is retained according to the tenant’s use of the Service and applicable deletion/export tools, subject to backup and legal holds.
8Security
We implement technical and organizational measures designed to protect personal data, including access controls, encrypted transport (HTTPS), password hashing, and role-based permissions inside FitForge. No method of transmission or storage is 100% secure; please use strong passwords and protect devices.
9Children’s data
FitForge is a business gym-management product. It is not directed at children. Gyms that enroll minors are responsible for obtaining any required parental/guardian consents under applicable law.
10Your rights
Depending on your location and role, you may have rights to access, correct, erase, withdraw consent, nominate a representative, or lodge a grievance under the DPDP Act, and additional rights under GDPR/UK GDPR or CCPA/CPRA (including know, delete, correct, and opt out of sale/share).
Submit requests at /privacy-request or email privacy@codingroof.com. We may need to verify your identity. If your request concerns data controlled by your gym employer or gym membership, we may redirect you to that gym.
12Do Not Sell or Share (CCPA)
We do not sell personal information for money. If you are a California resident and wish to opt out of “sale” or “sharing” as defined by the CCPA/CPRA (including certain advertising uses, if enabled), submit a request at /privacy-request?type=do-not-sell or email privacy@codingroof.com.
13Member mobile app permissions
The FitForge member mobile app may request permissions such as camera access (for QR check-in) and notifications (for optional alerts). Permissions are used only for the stated in-app features. Gym staff use the web app; attendance is recorded via branch QR check-in and related workflows — not biometric hardware integration.
14Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date. Material changes may be communicated through the Service or by email where appropriate.
15Contact and grievance
Privacy / grievance contact: privacy@codingroof.com. General contact: hello@codingroof.com, phone +91 9108623002. Registered office: 2/107/1, Veerapandi Road, Oomatchikulam, Tirumalpuram, Madurai, Tamil Nadu, 625014, India.
For rights requests, prefer /privacy-request so we receive structured details.