ZYMHOP Logo

Trending Searches

Gyms with steam rooms
CrossFit equipment
Yoga classes near me
HIIT workouts

Pro tip: Use voice search for hands-free gym discovery

PRIVACY POLICY

ZymHop Privacy Policy

Your privacy is important to us. This policy explains how ZYMHOP collects, uses, and protects your personal information.

Last updated: January 21, 2025

This Privacy Policy ("Policy") describes how Zymhop ("Zymhop", "we", "our", or "us"), a platform connecting customers with fitness centers and related services, collects, uses, processes, discloses, and retains personal data of individuals ("you", "your") in connection with your use of our website and mobile application (collectively, the "Service"). This Policy applies to all users of Zymhop's digital platforms – including customers (B2C users) and our gym/fitness center partners (B2B users). Zymhop is committed to protecting your personal data and privacy in accordance with applicable Indian laws, including the Information Technology Act, 2000 (the "IT Act"), its Rules, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").

This Policy explains the legal bases for data processing, the types of personal data we collect, how we use and protect that data, and your rights under Indian data protection law. Please read this Policy carefully. By using the Service, registering an account, or providing information to Zymhop, you consent to the practices described herein (as may be updated from time to time).

1

Definitions

For purposes of this Policy, the following terms have the meanings given below (as derived from applicable Indian data protection laws):

  • "AltGym Private Limited" operating under the brand name ZymHop, shall hereinafter be referred to as "ZymHop". The term ZymHop shall be deemed to include AltGym Private Limited.
  • "Personal Data" refers to any data about an individual who can be identified from that data, either directly or indirectly. This includes data such as name, contact information, profile details, location data, and any other information that relates to an identifiable individual.
  • "Sensitive Personal Data" (also called Sensitive Personal Information under the IT Act 2000 and its Rules) includes a subset of personal data that carries greater privacy sensitivity. Under the IT Act's Rules, examples of Sensitive Personal Data include financial information (such as credit/debit card or bank account details), health and medical records, biometric data, passwords, sexual orientation, and similar categories.
  • "Data Principal" means the individual to whom the personal data relates. This includes customers, users, or any individual whose personal information we process.
  • "Data Fiduciary" means any person or entity (including Zymhop) that, alone or in conjunction with others, determines the purpose and means of processing personal data.
  • "Data Processor" means any person or entity who processes personal data on behalf of a Data Fiduciary and under its instructions (e.g., third-party service providers, payment gateways, analytics providers, etc.).
  • "Processing" of personal data encompasses any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organizing, storage, retrieval, use, dissemination, disclosure, or destruction.
  • "Consent" means any freely given, specific, informed and unambiguous indication of the Data Principal's wishes by which they, by a statement or clear affirmative action, signify agreement to the processing of personal data for a specific purpose.
2

Scope and Purpose

This Privacy Policy applies to the processing of personal data collected through Zymhop's digital platforms (website and mobile app) and related services. It explains:

  • The categories of data we collect from customers (B2C) and gym partners (B2B).
  • The purposes for which we use that data and the legal bases for processing.
  • How we share data with third parties and partners.
  • Our use of cookies and analytics tools.
  • Data retention, security measures, and how data is deleted.
  • Cross-border data transfer policies, if any.
  • The rights of data principals (users) including access, correction, deletion, and consent withdrawal.
  • Special provisions for sensitive data and data of minors/children.
  • Our grievance redress mechanism and dispute resolution process.
  • How we update this Policy and notify users of changes.
  • Contact details for the Grievance Officer.

We handle all personal data in compliance with Indian data protection laws. Specifically, Zymhop conforms to the requirements of the IT Act 2000 (including the SPDI Rules, 2011) and the DPDP Act, 2023.

3

Data Collected from Customers (B2C)

Personal and Profile Information

When you register or use Zymhop as a customer, we collect the following personal data:

  • Identity Data: Full name, date of birth, gender, and photograph.
  • Contact Data: Email address, mobile phone number, billing address, shipping address.
  • Account Data: Username, password, and preferences chosen by you in your profile (e.g., fitness goals, preferred workout categories).
  • Usage Data: Fitness preferences, workout schedules, booking history, past gym classes attended or booked, and any feedback you provide.

This information is collected directly from you when you create an account, complete your profile, make bookings, purchase services, or interact with the platform.

Sensitive Personal Data and Health Information

We also collect certain sensitive personal data from customers with their explicit consent. For example, Zymhop may gather your declared medical conditions (e.g., asthma, diabetes) and body metrics (such as weight, height) if you choose to provide these. Such data helps us customize fitness recommendations and ensure safe gym experiences. Under Indian law, health data is classified as sensitive. Therefore, we only process it with clear, informed consent from you.

Technical and Device Data

We automatically collect certain technical information when you use our Service, including:

  • Device Data: Device type and identifiers (device ID), operating system and version, device language settings.
  • Log and Usage Data: IP address, browser type and version (for web), app version, crash logs, browsing behavior on our site or app (pages visited, features used).
  • Location Data: General location information (e.g., city or region) inferred from IP address or device settings.
  • Activity Data: Time spent on the platform, links clicked, and other interactions.

Payment and Financial Data

For purchases or bookings, Zymhop collects payment information (such as billing details). Important: Zymhop does not store your full credit/debit card numbers or sensitive payment credentials on our servers. We use PCI-compliant third-party payment processors (e.g., Stripe, PayU, Razorpay, etc.) to handle transactions securely. These processors securely capture card data and return only a token or reference to us.

4

Use of Customer Data

We use the collected data for multiple purposes, all in accordance with Indian law:

  • Service Provision and Operations: To create and manage your Zymhop account; to process and fulfill your bookings for gym classes, equipment, or sessions; to enable gym access generating OTP to validate the session for entry and to manage membership or subscription payments.
  • Personalization: To provide personalized fitness recommendations, tailor class suggestions, and match you with suitable gym partners based on your preferences and goals.
  • Analytics and Improvement: To perform data analytics (on a personal or aggregate level) in order to improve our Service. This includes analyzing user behavior and feedback to optimize the app/website, fix bugs, and develop new features.
  • Marketing and Communications: With your explicit consent, Zymhop may send you promotional messages, newsletters, discounts, and marketing content about Zymhop services.
  • Legal and Security Compliance: To comply with legal obligations, enforce our Terms of Service, and protect against fraud and security risks.

All data uses are bound by the principles of purpose limitation and data minimization set out in the DPDP Act. We will only use your personal data for purposes explicitly described in this Policy or that you consented to.

5

Legal Basis for Processing

Under Indian law DPDP Act 2023 and the IT Act Rules:

  • Consent: The primary legal basis for processing customer personal data is your consent. At registration and certain points of interaction, you are asked to consent to this Privacy Policy and the processing of your data.
  • Contractual Necessity: Certain processing is necessary to perform the contract between you and Zymhop/its partners (e.g., booking and delivering gym services).
  • Legitimate Interests: In limited cases (such as improving the Service, preventing fraud, or maintaining security), we process data based on our legitimate interests.
  • Legal Obligations: We may process data to comply with legal obligations (e.g., accounting and taxation records retention, responding to lawful subpoenas).
6

Data Retention and Security

Data Retention

Zymhop retains personal data only as long as necessary to fulfill the purposes outlined above, to provide our Service, and to comply with legal obligations. We apply retention periods as follows:

  • Customer Account Data: Retained for as long as your account is active, plus a reasonable period of 2 years after account deletion for backup and legal compliance.
  • Communications and Support Logs: Retained for 1 year after resolution unless needed longer to resolve ongoing issues.
  • Analytics and Logs: Aggregated analytics may be kept indefinitely in anonymized form. Individual logs (e.g., login records) are typically retained for 3-6 months and then deleted or anonymized.
  • Gym Partner Records: Retained as long as the partnership is active, plus a short buffer (e.g., 1 year) to handle any closing obligations.

Security Measures

We implement reasonable technical, administrative, and physical safeguards to protect personal data against unauthorized access, disclosure, alteration, and destruction, in line with India's RSPP requirement. These measures include:

  • Encryption: Data is encrypted in transit (using SSL/TLS for our website and encrypted APIs) and at rest (using industry-standard encryption on our servers).
  • Access Controls: We enforce strict role-based access controls; employees and third parties have access to personal data only on a need-to-know basis.
  • Secure Infrastructure: We store data on secure servers and cloud environments (in India, to comply with DPDP) with regular security audits.
  • Security Audits and Testing: Periodic security assessments, vulnerability scans, and penetration tests are conducted.
  • Employee Training and Policies: All Zymhop personnel undergo data protection training and must follow our internal privacy and security policies.
7

Rights of Data Principals (Users)

Under the DPDP Act, you have specific rights as a Data Principal. Zymhop respects these rights and provides mechanisms to exercise them:

  • Right to Access / Confirmation: You have the right to know what personal data Zymhop holds about you and how it is being processed.
  • Right to Correction / Update: You can correct or update your personal data (e.g., change address, update preferences) at any time by editing your profile in the app/website or by contacting support.
  • Right to Withdraw Consent: You may withdraw your consent at any time (for all or specific processing operations) by adjusting your account settings or contacting us.
  • Right to Data Portability: As allowed under DPDP, you have the right to receive your personal data in a structured, commonly used format.
  • Right to Object/Restrict Processing: You may object to our processing of your personal data where processing is based on legitimate interests or for direct marketing.
  • Right to Grievance Redressal: If you have any complaints about our handling of your data, you can first contact Zymhop's Grievance Officer.

To exercise any of the above rights, please contact us through the methods listed below. We will verify your identity before responding to any request, to protect your privacy.

8

Special Provisions for Sensitive and Children's Data

Sensitive Personal Data

As noted, certain categories of data (health, biometric, financial) are sensitive and receive extra protection under Indian law. Zymhop collects minimal sensitive data (e.g., medical conditions or biometric fitness stats like weight). We process such sensitive data only with your explicit consent and only for the purposes you agreed to (e.g., tailoring fitness plans).

Children's Data

Zymhop does not target children for marketing, and our Service is generally intended for users aged 13 and above. If you are under 18, by using the Service you must have the consent of a parent or legal guardian. Under the DPDP Act, individuals under 18 are considered "children," and special rules apply. We will obtain verifiable parental consent before processing the personal data of any user under 18.

If Zymhop becomes aware that we have inadvertently collected personal data from a child without parental consent, we will immediately delete that data.

9

International Data Transfers

All personal data collected by Zymhop is stored on servers located in India. As of now, Zymhop does not routinely transfer customer data outside India. If, in the future, data processing involves transfer to a third country (e.g., to use an overseas analytics service or backup location), we will ensure it complies with DPDP requirements. Under the DPDP Act, cross-border transfers are allowed only with appropriate safeguards (such as standard contractual clauses) and only to countries not blacklisted by the government.

10

Dispute Resolution and Grievance Mechanism

Zymhop has established a multi-tiered mechanism to address any data privacy grievances:

Zymhop Grievance Officer

We have designated a Grievance Officer responsible for privacy concerns. If you have any complaints or queries about our privacy practices or this Policy, you may contact:

Grievance Officer: V Kranthi Kumar

Email: admin@zymhop.com

Phone: +919032350555

Office Address:
126-49/8, Bhavani Nagar, Gorantla, Revenue Ward 5
Gorantla, Guntur – 522034, Andhra Pradesh

You can submit a complaint in writing or via email. We will acknowledge receipt and work to resolve it, typically within 30 days (or as prescribed by law).

11

Changes to This Privacy Policy

Zymhop may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or user feedback. When significant changes occur, we will take the following steps to inform you:

  • Notice of Update: We will post the updated Policy on our website/app with a new effective date.
  • Consent for Material Changes: For substantial changes (e.g., new processing purposes, sharing with new categories of third parties), we will require users to acknowledge the updated Policy.
  • Granular Updates: Non-material or clarifying edits such as stylistic updates or departmental changes may be made at any time without prior consent, though we will still update the effective date.
12

Contact Information

If you have any questions about this Privacy Policy, data practices, or your privacy rights, please contact Zymhop at:

Grievance Officer: V Kranthi Kumar

Email: admin@zymhop.com

Phone: +919032350555

Office Address:
126-49/8, Bhavani Nagar, Gorantla, Revenue Ward 5
Gorantla, Guntur – 522034, Andhra Pradesh

You may also reach out via mail to the address provided or call our support line. We will respond to verifiable requests in accordance with law.

Acknowledgment

By using Zymhop's services, you acknowledge that you have read and understood this Privacy Policy and consent to our processing of your personal data as described herein. You understand that Zymhop processes your data only as authorized and protected under applicable laws.

Key Points at a Glance:

  • We collect personal data (name, email, contact, preferences, health info with consent) to provide gym access and fitness services.
  • We use data for service delivery, personalization, support, improvement, and (with consent) marketing.
  • Cookies and tracking are used only with your consent and are transparent.
  • We retain data only as long as needed and secure it with industry-standard measures.
  • You have rights to access, correct, erase, and withdraw consent for your data, subject to legal limits.
  • We have a dedicated Grievance Officer and processes to address complaints, per Indian law.
  • This Policy complies with the IT Act (43A, 72A) and the Digital Personal Data Protection Act, 2023.