1. Introduction and Scope
Welcome to Levit.fit ("Levit", "we", "us", or "our"). Levit operates a comprehensive fitness operations and retention platform consisting of:
- Levit Web Platform & Dashboard: Accessible at
https://levit.fitand our API services athttps://api.levit.fit. - Levit Member Mobile App: Available on Android (Application ID:
fit.levit.member) and iOS (Bundle ID:fit.levit.member). - Levit Partner Mobile App: Available on Android (Application ID:
fit.levit.partner) and iOS (Bundle ID:fit.levit.partner).
This Privacy Policy governs our processing of personal data across all three surfaces. We are committed to transparency, data minimization, and providing individuals with complete control over their personal and fitness records.
2. Data Controller vs. Data Processor Roles
To understand our privacy responsibilities under global data protection laws (including GDPR, UK GDPR, CCPA/CPRA, and the India Digital Personal Data Protection Act, 2023), it is essential to distinguish between our two operational capacities:
Levit as a Data Controller
When you create an account directly with Levit (via email/password, Google OAuth, or phone OTP), manage your profile credentials, or track personal workouts in the Member App, Levit is the Data Controller responsible for the security and handling of your authentication credentials and personal user account.
Levit as a Data Processor
When you join or link your account to an independent gym or fitness center ("Partner Gym"), that specific gym is the Data Controller for your gym-specific membership records (e.g. membership contracts, check-ins, sales invoices, dues, and trainer assignments). Levit acts solely as a Data Processor providing cloud software to that gym.
3. Information We Collect
We only collect information strictly required to deliver, secure, and improve our services.
3.1 Information You Provide Directly
- Identity & Authentication: Full name, verified mobile phone number, email address, and cryptographically hashed passwords. For users authenticating through Google Sign-In, we receive the Google subject ID, verified email, and profile name. Plaintext passwords are never stored or accessible by Levit staff.
- Member Fitness & Activity Logs: Voluntary exercise logs, workout templates, sets, repetitions, weights, workout durations, consistency streak counters, challenge completions, and milestone achievements. Notice: Fitness logs are user-recorded exercise logs; Levit does not collect or process clinical healthcare records, diagnoses, or biometric identifiers.
- Staff & Business Operations: Staff roles, permissions, front-desk notes, lead follow-up task entries, and gym operational configuration.
- Billing & Invoicing Context: Plan subscriptions, invoice line items, tax numbers, and payment status. All credit/debit card transactions are handled directly through certified PCI-DSS Level 1 compliant payment processors. Levit servers never store, process, or view your full credit card numbers or payment PINs.
3.2 Information Collected Automatically & Mobile Diagnostics
When you access our mobile apps or web platforms, our systems automatically collect technical telemetry strictly necessary for security and reliable performance:
- Device & Network Data: Operating system version, device model, IP address, general regional locale, and application build number.
- Privacy-Safe Diagnostics: Our apps utilize strict privacy-safe diagnostic logging (
PrivacySafeDiagnostics). Diagnostic events record latency and error status codes, while automatically redacting email addresses, phone numbers, and database record identifiers before any log entry is recorded. - Encrypted On-Device Storage: Mobile caches on your device use
sqlite3mcencrypted storage with installation-scoped keys (PRAGMA key). Android backup rules explicitly prevent local databases from being transferred via unencrypted device backups.
4. How We Use Your Information
We process your data only for legitimate, lawful purposes:
| Purpose of Processing | Legal Basis | Data Categories Used |
|---|---|---|
| Authenticating users, maintaining stateful sessions, and managing accounts | Performance of Contract | Name, email, phone number, hashed password, OAuth subject |
| Logging workouts, tracking personal progress, calculating streaks, and challenges | Performance of Contract / Consent | Exercise logs, sets, reps, load, streak metrics |
| Delivering gym operations, billing, membership plans, and POS invoices | Performance of Contract / Legitimate Interest | Membership tier, check-in history, invoice records |
| Sending OTP verification codes and critical security notifications | Legitimate Interest / Security | Phone number, email address |
| Detecting fraud, mitigating attacks, and enforcing multi-tenant isolation | Legitimate Interest / Legal Obligation | IP address, request IDs, rate-limit counters |
| Retaining statutory tax invoices and business receipts | Legal & Statutory Compliance | Invoice numbers, transaction values, tax rates |
5. Zero Sale or Commercialization of Personal Data
Levit does not sell, rent, monetize, or trade your personal or workout data to third-party data brokers, marketers, or advertisers. We do not serve third-party targeted advertisements inside our mobile applications or web platforms, nor do we track users across third-party websites or services.
6. Information Sharing & Disclosure
We share information only in strictly delimited scenarios:
- With Your Associated Partner Gym: When you connect your Member App to a gym, authorized trainers, managers, and owners at that specific facility can view your attendance, current membership status, dues, and workouts assigned or performed in connection with that gym. They cannot access your private data from other unrelated facilities.
- With Infrastructure Subprocessors: We utilize vetted enterprise service providers for cloud hosting, managed databases, transactional SMS/OTP dispatch (e.g. MSG91), Google Identity verification, and PCI-DSS compliant payment processing. All subprocessors are bound by strict contractual data processing agreements.
- For Legal Protection & Compliance: We may disclose information if required by a valid court order, subpoena, or statutory regulation, or to defend our rights against unlawful activity.
- Business Transfers: If Levit undergoes a corporate merger, acquisition, or restructuring, user data will be transferred only under binding commitments that the successor upholds this Privacy Policy.
7. Data Security & Technical Safeguards
We apply defense-in-depth engineering practices to protect your data:
Encrypted in Transit
Strict TLS 1.3 / HTTPS encryption for all mobile and web API traffic. Unencrypted HTTP is rejected.
Encrypted at Rest
Server database encryption, cryptographic token hashing, and on-device sqlite3mc encryption.
Multi-Tenant Isolation
Gym data boundaries and scoped role-based access control (RBAC) enforced in backend handlers.
8. Account and Data Deletion (Google Play & App Store Compliance)
In accordance with Google Play Store User Data policies and global privacy regulations, you have an absolute right to request the permanent deletion of your account and personal information.
What Data is Deleted vs. Retained
- Permanently Deleted: Your profile, email, phone number, authentication credentials, personal workout logs, routine templates, consistency streaks, leaderboard rankings, and device tokens are wiped within thirty (30) days.
- Statutory Retention for Tax Invoices: Official sales invoices and tax records generated by gym operations must be retained for 5 to 7 years in accordance with applicable tax and corporate accounting laws. In retained records, personal contact data is scrubbed/anonymized to the fullest extent permitted by law.
9. Your Privacy Rights
Depending on your location, you hold statutory rights regarding your personal information:
- Right to Access & Portability: Obtain a copy of your stored personal information in a structured format.
- Right to Rectification: Request correction of incomplete or inaccurate data.
- Right to Erasure: Request permanent removal of your account and personal history.
- Right to Restrict or Object: Restrict processing or object to legitimate-interest processing.
- Non-Discrimination: You will never be penalized, charged different rates, or denied equal service for exercising privacy rights.
To exercise any of these rights, contact us at privacy@levit.fit.
10. Children’s Privacy Protection
Levit services are strictly intended for individuals aged 18 and older. We do not knowingly solicit or collect data from children under the age of 13 (or under 16 in the European Union). If we become aware that personal information has been collected from a child without verified parental consent, we take immediate corrective steps to delete such data permanently. Please alert us at support@levit.fit if you suspect inadvertent minor registration.
11. International Data Transfers
Levit operates cloud infrastructure globally. Personal data may be transferred to and processed in countries outside your jurisdiction of residence. When such transfers occur, we implement robust contractual safeguards, including approved Standard Contractual Clauses (SCCs), ensuring equivalent protection under applicable data privacy frameworks.
12. Contact and Data Protection Inquiries
For questions, data subject requests, or regulatory inquiries, reach out to our dedicated team:
Dedicated support for privacy, account deletion, and data safety compliance.