Your members trust you with their data. We take that seriously.
A gym holds sensitive things, who trains, when, what they pay, and increasingly their health goals. Here is how BOMKGPL handles that, described honestly rather than dressed up.
Member data privacy
We collect what running the gym requires, contact details, membership and plan status, check-ins, attendance, and logged training progress. Nothing is sold, and data is retained only for as long as a gym keeps an account active, plus a limited window for records that law or accounting requires.
Payment data handling
Card and bank details are processed through established payment providers, not stored on our own servers in raw form. BOMKGPL keeps the record of what was charged and whether it succeeded, the sensitive payment credentials stay with the processor built for them.
Role-based access
Access follows the role. Front-desk staff see check-ins and today's floor, trainers see the members and plans they coach, and owners or head office see the full picture. A trainer never sees the chain's finances; the front desk never sees a member's full payment history.
Compliance posture
We describe only where we actually stand. Data is encrypted in transit, access is scoped by role, and our data-handling practices are documented for the gyms we work with. We don't claim certifications we don't hold, and we'll tell you exactly what applies to your region during onboarding.
Collect less, keep it scoped, be honest.
We work from a simple rule: hold the minimum that running a gym genuinely needs, keep each person's view of it scoped to their role, and never describe our posture as more than it is. Security theatre helps no one, clarity does.
- Data is encrypted in transit between members, staff, and BOMKGPL.
- Access is scoped by role, so staff only see what their job requires.
- Members' payment credentials are handled by dedicated payment providers.
- Retention is tied to your account, close it, and member data is removed on a defined schedule.
- We state our current compliance status only, and never overclaim certifications.
Have a specific requirement for your region or your members? Raise it in a demo and we'll tell you plainly whether we meet it today.
Ask us the hard security questions
We'd rather answer them directly than hide behind badges. Bring your checklist to a demo.
