Effective 2026-04-27
Privacy Policy
MatFlow ("we") describes here how we handle personal data on behalf of gyms (our customers) and on behalf of those gyms' members.
1. Roles
- For your gym subscription: MatFlow is the data controller of your owner/staff account details (name, email, role).
- For member data: MatFlow is a data processor; the gym is the controller. We process member data on the gym's instructions.
2. What we store
- Member name, email, phone, optional date of birth, optional medical/emergency contact info
- Membership type, account type (adult/junior/kids), and waiver acceptance snapshot
- Stripe customer ID, subscription ID, and payment status (no card numbers — Stripe holds those)
- Attendance and class records
- Audit logs of sensitive operations (timestamp, IP, user agent)
We never store card numbers, CVVs, or full PANs. Stripe collects payment data directly via Stripe-hosted UI; MatFlow only receives a Stripe customer/subscription ID.
3. Lawful basis (UK GDPR)
- Contract — to provide the service the gym subscribed to
- Legitimate interest — security, fraud prevention, audit logging
- Explicit consent — for medical conditions, emergency contacts, and waiver storage
4. Children's data
Gyms may create junior/kids accounts for members under 18. These accounts are set up and managed by a parent or legal guardian (or by the gym with the parent's consent), are passwordless by design, and are linked to the parent's account. Waivers for children are signed by the parent or guardian, and we store the signed waiver snapshot on the gym's behalf. We collect no more data about children than about adult members (name, optional date of birth, attendance, rank), and never contact children directly. Parents can review, correct, or request deletion of their child's data through their gym, or via privacy@matflow.studio.
5. Sub-processors
We use third-party services as sub-processors. The current list is at /legal/subprocessors. Material changes are announced at least 30 days in advance.
6. Retention
- Active member data — for as long as the gym remains a customer
- Signed waivers — six years after the member leaves (UK limitation period)
- Audit logs — twelve months, then deleted by a scheduled job that runs daily
- Email delivery logs — twelve months, deleted by the same daily job
- Expired sign-in links and password-reset links — purged daily, within 24 hours of expiry
- Closed gyms — a gym marked for deletion is recoverable for 30 days, after which its records are permanently erased
- Backups — our database provider keeps continuous point-in-time backups. The window depends on our current plan and is typically between 7 and 30 days. Because a restore rolls the database back in time, we re-apply any deletion requests fulfilled after the restore point before the restored data is used again.
7. Your rights
Members of a gym should contact their gym for access, correction, deletion, or portability requests in the first instance. The gym (as data controller) responds, with MatFlow's assistance where needed. You may also email privacy@matflow.studio.
UK members have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
8. International transfers
MatFlow uses Vercel, Neon, and Resend. Where data leaves the UK/EEA, transfers are protected by the UK IDTA or the EU Standard Contractual Clauses with applicable supplementary measures.
9. Security
We use TLS for all transport, encrypt OAuth tokens at rest with AES-256-GCM, hash passwords with bcrypt, and maintain audit logs of sensitive operations. Card data never reaches MatFlow servers — Stripe handles it.
10. Contact
Privacy questions: privacy@matflow.studio.