Privacy policy.
How Kasratbook handles gym, staff, member, lead, billing, attendance, and device data.
Last updated · July 5, 2026
01Who this policy covers
This Privacy Policy explains how Kasratbook handles personal data when a gym owner, staff member, trainer, member, lead, or website visitor uses Kasratbook. Kasratbook is a gym management platform for memberships, billing, attendance, classes, personal training, WhatsApp communication, member portals, and related gym operations.
For member and lead records entered by a gym, the gym is normally the organization that decides why the data is collected and how it is used. Kasratbook processes that data to provide the software, support, security, and integrations the gym has enabled.
02Who provides Kasratbook
Kasratbook is a software product of ORDER CRAFT, the trade name of SAVALIYA PARTH HASMUKHBHAI, a Proprietorship. References to “Kasratbook”, “we”, “us”, or “our” mean this product and its operator.
Principal place of business: B-1111, 11th Floor, Pragati IT Park, Mota Varachha Main Road, Surat, Gujarat 394105, India. For privacy, legal, or entity-verification questions, email [email protected].
03Information we collect
We collect account information such as name, email address, phone number, gym name, business details, billing details, login activity, role and permission settings, and support conversations.
Gyms may store member and lead information in Kasratbook, including names, contact details, membership plans, invoices, payments, dues, attendance, class bookings, PT assignments, fitness notes, forms, emergency contacts, and communication history.
If a gym enables biometric attendance or device integrations, Kasratbook may store device identifiers, biometric user IDs, enrollment status, access logs, attendance events, device serial numbers, and sync metadata. We do not use this information for advertising or sell it to anyone.
We also collect technical information such as IP address, browser and device details, timestamps, authentication events, error logs, security events, and usage metadata needed to keep the service reliable and secure.
04Roles under privacy law
For gym member, lead, staff, attendance, billing, class, PT, biometric, and communication records that a gym adds to Kasratbook, the gym normally acts as the Data Fiduciary or Controller. Kasratbook acts as a service provider, Data Processor, or processor for that data and processes it on the gym’s documented instructions.
For account signup, billing, security, product analytics, support, and website visitor information that we collect directly, Kasratbook acts as the Data Fiduciary or Controller and decides how that information is used to operate and improve the platform.
05Google and OAuth sign-in
If you sign in with Google or another supported identity provider, we receive the basic profile information needed to create and authenticate your Kasratbook account, such as name, email address, profile image, and provider account ID.
We do not request access to your Gmail, Drive, Contacts, or other Google product data. Kasratbook’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including Limited Use requirements.
06Lawful basis and consent
We process data where it is necessary to provide the service, perform a contract, secure the platform, comply with law, pursue legitimate business interests, or where consent is required and has been obtained.
Gyms are responsible for giving required notices and collecting valid consent or another lawful basis before adding member or lead data to Kasratbook, especially for WhatsApp messaging, biometric attendance, health or fitness notes, minor members, and marketing communication.
07How we use information
We use information to run the platform: authenticate users, manage gym workspaces, process memberships and invoices, show attendance and class data, send reminders selected by the gym, support member portal access, prevent abuse, troubleshoot issues, and improve product reliability.
We may use aggregated or de-identified usage data to understand product performance and improve Kasratbook. Aggregated data does not identify a specific gym, staff user, member, or lead.
08Payments and financial data
Kasratbook records invoices, dues, refunds, payment status, payment method, and related accounting information. Online payments are processed by payment providers such as Razorpay. We do not store full card numbers, CVV, UPI credentials, or banking passwords on our servers.
09WhatsApp, email, and communication
When a gym enables messaging, Kasratbook may send transactional, operational, or gym-approved messages through WhatsApp, email, or other configured channels. Examples include OTPs, payment reminders, class updates, member follow-ups, renewal reminders, and support messages.
Message delivery may require sharing the recipient phone number, message content, template details, and delivery metadata with the selected communication provider, such as Meta WhatsApp Cloud API, a QR-based WhatsApp provider, or Brevo for email.
10Sub-processors
We use trusted providers to operate Kasratbook, including cloud hosting, database, storage, CDN/security, analytics for the marketing website, email, WhatsApp messaging, payment processing, and support tooling. These providers process data only for the services they provide to us.
Current categories include infrastructure and storage providers, Cloudflare for edge protection, Razorpay for payments, WhatsApp/Meta or QR-based WhatsApp infrastructure for messaging, Google for sign-in and marketing analytics, and Brevo for transactional email.
| Provider category | Purpose | Data involved |
|---|---|---|
| Cloud, database, storage, CDN/security | Hosting, storage, edge protection, backups | Platform data, files, logs, technical metadata |
| Payment providers | Online payments, mandates, refunds, receipts | Billing details, payment references, amounts |
| Messaging and email providers | WhatsApp, email, OTPs, reminders, support | Phone numbers, email addresses, message content, delivery logs |
| Authentication and analytics providers | Sign-in, fraud prevention, website analytics | Account identifiers, device/browser metadata, usage events |
We may update providers as the product changes. Where a change materially affects how customer data is processed, we will give reasonable notice through the product, email, or an updated policy page.
11Data ownership and controls
The gym owns the member, lead, invoice, attendance, class, PT, and business data it adds to Kasratbook. Gym owners and authorized staff can update, export, correct, or delete records according to their role permissions and applicable law.
If you are a gym member and want to access, correct, or delete your information, contact your gym first because they control the relationship with you. If you cannot resolve it with the gym, you can contact us and we will help route the request.
12Retention and deletion
We keep account and gym data while the account is active and for a reasonable period after cancellation so the gym can reactivate, export records, meet tax/accounting obligations, or resolve disputes.
Some records, such as invoices, payment records, audit logs, security logs, and tax documents, may need to be retained for legal, accounting, fraud-prevention, or compliance reasons even after an account is closed.
After cancellation, we aim to keep customer data available for export for a reasonable period, generally up to 30 days unless a different period is shown in-product or agreed in writing. Backups and security logs may remain for a limited additional period before normal rotation or deletion.
13Children and minors
Kasratbook is not directed to children. Gyms may record minor member details only where the gym has the required parental or guardian consent and a lawful basis for processing. We do not knowingly collect personal data directly from children for advertising or behavioral profiling.
14Your privacy rights
Depending on where you are located, you may have rights to access, correct, delete, restrict, export, or object to certain processing of your personal data. In India, this includes rights available under the Digital Personal Data Protection Act, 2023 as it comes into force.
To make a privacy request, write to [email protected]. We may need to verify your identity before acting on the request.
We aim to acknowledge privacy or grievance requests within 7 days and complete valid requests within 30 days where reasonably possible, unless a longer period is allowed or required by applicable law.
15International transfers
Kasratbook may use infrastructure and service providers located in India and other countries. Where cross-border transfer safeguards are required, we will use appropriate contractual, technical, and organizational measures, such as data processing terms, confidentiality obligations, access controls, encryption in transit, and provider security commitments.
16Security incidents
If we become aware of a personal data breach affecting customer data, we will investigate, take reasonable containment steps, and notify affected customers as required by applicable law. We may also provide information reasonably needed for a gym to meet its own notice obligations to members, staff, leads, regulators, or other affected people.
17Cookies and analytics
We use essential cookies to keep users signed in, protect sessions, remember preferences, and run the product. On the marketing website, we may use privacy-conscious analytics to understand traffic and page performance. We do not sell cookie data or use member records for third-party advertising.
18Changes to this policy
We may update this policy as the product, law, or our providers change. If we make a material change, we will notify affected customers by email or in-product notice. The latest version will always be available on this page.