Written for the person in your gym who asks the hard question before you sign — a partner, an accountant, or the franchisee whose members are about to be in someone else’s system. No badges, no jargon. Just what the software does.
A gym’s database is a list of local people, their phone numbers, their photographs, what they paid and when they turn up. It deserves to be treated as seriously as that sounds, and a buyer is right to ask what happens to it.
What follows is how Fitplex works, not a list of intentions. Where we do not do something — and there are things on this page we do not do — it says so.
Each gym runs on its own address with its own session cookie, so a login at one gym is not a login at any other. Every record carries the gym it belongs to and every query filters on it. A gym id sent up in a request is checked against your session rather than believed.
Every page and every API call runs over HTTPS, with certificates renewed automatically. Session cookies are HttpOnly and Secure, and are reissued when you log in so an old cookie cannot be reused.
Managers, trainers, receptionists, accountants and view-only logins each get their own permission set, configurable per gym. A view-only role physically cannot write - the buttons are hidden and the handler refuses the request, not one or the other.
Passwords are stored as one-way hashes. Nobody at Fitplex can read yours, including us. There is no master password and no backdoor.
Your members' fingerprint and face templates live on the biometric machine in your gym. Fitplex records that a check-in happened and who it belonged to. We do not collect or store the template itself.
Every form carries a token, and a request arriving from another website is refused before it reaches any handler. Login attempts are rate-limited per address, and phone OTPs separately.
Daily backups of every database and the application itself: on the server, in cloud object storage with versioning, and synced to hardware in a different building. Monthly copies kept twelve months. The backup key cannot delete what it has written.
Export members, payments, attendance and reports on any plan including free, yourself, at any time, at no cost. If you leave, you take everything. Ask us to delete the account and we delete it.
We are not ISO 27001 certified and we are not SOC 2 audited. Plenty of software companies your size imply otherwise with a badge on a page; we would rather you found out from us than from asking.
What we will do instead is answer any specific question in writing, let your own IT person poke at a trial account, and put the answers in your contract if that is what it takes. If a certification is a hard requirement for your organisation, tell us early and we will say honestly whether we are the right fit.
If you believe you have found a security problem in Fitplex, write to us at support@fitplex.in with enough detail to reproduce it. We will confirm we have received it, keep you posted while we fix it, and we will not come after anyone acting in good faith.
No. Every gym gets its own address and its own session, and every record in the database carries the gym it belongs to. Queries are filtered by that, and a gym id arriving in a web request is re-checked against the logged-in session rather than trusted. It is the single rule the whole system is built around.
You do. Your members, payments, attendance and documents are yours. You can export them on any plan including the free one, without asking us and without a fee, and you can ask us to delete the account and everything in it.
Only what you allow. Permissions are set per gym and per role, so a receptionist can take a payment without seeing the revenue report, and an accountant or an investor can be given a genuinely read-only login that cannot write anything at all. The roles ship with sensible defaults and you can change any of them.
Backups run every day and are kept in three separate places: on the server, in cloud object storage, and on hardware in a different building. Monthly copies are kept for a year. Restores are tested rather than assumed - the last test restored all 236 tables successfully.
No, and we would rather say so than imply it. We are a small Indian software company and those audits are not something we have done. What is on this page is a description of how the system actually works, which you are welcome to test during a trial or have your own IT person question.
On servers in India, with backups in Indian cloud regions. Biometric templates stay on your device where the law and common sense both prefer them - Fitplex stores the check-in event, not your members' fingerprints.
No. There is deliberately no backdoor password in the system. Our support team can open a session into your account only when you have a support request open, and everything done in that mode is recorded.
We would rather answer a hard question before you sign than after.