Last updated: 26 August 2026
This Privacy Policy explains how Aerobit Technologies, operating the Okfit platform ("Okfit", "we", "us", or "our"), collects, uses, stores, discloses, and protects personal data in connection with the Okfit website, web application, mobile applications, integrations, support services, and related services (together, the "Services").
This policy should be read together with our Terms of Service and any agreement or order form signed with a customer.
Okfit is a fitness studio and gym management SaaS platform. Our customers are gyms, fitness studios, trainers, and similar businesses ("Customers"). Customers use Okfit to manage their business operations, including memberships, attendance, invoices, payments, communications, bookings, and related records.
This Privacy Policy applies to:
For account, billing, support, sales, and website data relating to our Customers and website visitors, Okfit acts as a data fiduciary/controller because we decide why and how that data is processed.
For personal data of gym members, leads, guests, and staff that a Customer enters into the Okfit platform, the Customer is generally the primary data fiduciary/controller. Okfit processes that data on behalf of the Customer to provide the Services.
Customers are responsible for providing appropriate notices, collecting required consents, and ensuring they have a lawful basis to enter and process personal data in Okfit.
Depending on how the Services are used, we may process the following categories of personal data:
Okfit does not collect or store biometric identifiers, biometric templates, fingerprint templates, facial templates, or similar biometric information of gym members.
Where a gym uses a biometric attendance device, the biometric data is stored on the local biometric device installed at the gym premises and remains under the control of the gym and/or the device vendor. Okfit may receive attendance events or related metadata from such integrations, such as member ID, attendance timestamp, check-in/check-out status, and device reference, only for providing attendance management features.
Okfit does not require Customers to enter clinical health records. If a Customer chooses to enter fitness progress information, body measurements, assessment notes, or similar non-clinical information into the platform, Okfit processes that information only to provide the Services on the Customer's behalf.
We use personal data for the following purposes:
We do not sell personal data.
Where personal data belongs to gym members, leads, guests, or staff entered by a Customer, the Customer is responsible for ensuring that the data has been collected lawfully and that required notices and consents have been provided.
Customers must not enter personal data into Okfit unless they have the right to do so. This includes personal data collected through forms, attendance devices, invoices, payment links, WhatsApp/SMS/email communications, or any third-party integration used by the Customer.
We may share personal data with:
We require service providers to process personal data only for authorised purposes and to apply reasonable security safeguards.
Okfit may use cloud hosting providers, infrastructure vendors, communication vendors, analytics tools, and other service providers located in India or outside India. Where personal data is processed outside India, we take reasonable steps to ensure that such processing is consistent with applicable law and contractual obligations.
We use reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These safeguards may include:
No internet-based service can guarantee absolute security. Customers are responsible for using strong passwords, limiting user access, securing their devices, managing staff permissions, and protecting any local hardware or biometric devices installed at their premises.
We retain personal data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain backups, and support legitimate business needs.
On termination of a Customer account, Customer data may be retained for up to 12 months, after which it may be deleted or anonymised unless retention is required by law or a separate agreement.
Customers may request export or deletion support by contacting us. Some deleted data may continue to exist in encrypted backups for a limited backup retention period before being overwritten or removed in the normal backup cycle.
Our website and Services may use cookies, local storage, analytics tools, and similar technologies to operate the platform, remember preferences, understand usage, improve performance, and secure the Services.
The web application may also use session replay and error-monitoring tools. These tools may record how authorised users interact with the portal, including pages viewed, clicks, and information visible on screen while using the Services. We use this information to troubleshoot issues, provide support, and improve reliability and security. Password fields are not recorded. Session replay data may be processed by a third-party provider located outside India.
Users may disable cookies through browser settings, but some parts of the Services may not function properly without required cookies.
Subject to applicable law and verification, individuals may request access, correction, updating, deletion, withdrawal of consent, or grievance redressal regarding their personal data.
Where the data is controlled by a Customer, such as gym member records entered into Okfit, requests should generally be directed to the relevant gym. We may assist the Customer in responding to such requests where required by law or contract.
Requests can be sent to [email protected].
Okfit is not intended for direct use by children without involvement of a gym, parent, guardian, or authorised representative. If a Customer enters data of minors into the platform, the Customer is responsible for ensuring appropriate parental/guardian consent and compliance with applicable law.
If we become aware of a security incident affecting personal data, we will assess the incident and take reasonable steps to contain, investigate, and remediate it. Where required by applicable law or contract, we will notify affected Customers, individuals, and/or authorities.
Customers must promptly notify Okfit if they become aware of any unauthorised access, misuse, compromise, or breach involving their account, users, devices, or data.
We may update this Privacy Policy from time to time. The latest version will be posted on our website. Continued use of the Services after an update means the updated policy applies from the effective date stated above, unless otherwise required by law.
For questions, requests, or grievances related to this Privacy Policy or personal data, please contact:
Aerobit Technologies
Email: [email protected]
Website: https://okfit.in