Privacy Policy

Version 2026-08-draft · Last updated 2 August 2026 · Effective [TO CONFIRM: effective date — set at launch]

What personal data Open Gym collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We do not sell personal data.

1. What this covers

This policy applies to everyone who visits opengym.in, uses our mobile apps, buys a ticket, or lists activities as an Expert. It is written to meet the information requirements of Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Hungarian Act CXII of 2011 on informational self-determination and freedom of information ("Infotv.").

It does not cover the practices of Experts. An Expert who collects your data separately — for example on their own sign-up sheet or their own website — is an independent controller for that data, and you should ask them about it.

2. Who is responsible

The controller of your personal data is Nomo Consulting Kft., registered seat 1082 Budapest, Baross utca 74., Hungary, company number 01-09-294594.

You can reach our privacy contact at privacy@opengym.in. (We are not required to appoint a Data Protection Officer under GDPR Art. 37 and have not appointed one; privacy requests go to the address above.)

3. What we collect

Data you give us

  • Account: email address, name, and — if you choose to add them — phone number, profile photo, biography, and language preference.
  • Billing: billing address and the name on the order.
  • Content: photos you upload, activity descriptions, and reviews you write.
  • Experts only: the identity, address, and tax details you provide to Stripe for onboarding, and your attestation that you hold liability insurance. Stripe collects verification documents directly — we receive only the verification status, not the documents.

We do not ask you for health data. Please do not put health information into free-text fields such as reviews or profile biographies — tell the Expert directly instead.

Data generated by your use

  • Orders, tickets, vouchers, payments, refunds, and applied discount codes.
  • Attendance records for sessions you booked.
  • Technical data: IP address, browser and device information, sign-in events and sessions.
  • Approximate location derived from your IP address, at city level, used to show you activities near you. We do not collect precise GPS location.
  • Cart contents, including carts you abandon, and a visitor identifier stored in a cookie.
  • Usage analytics — see section 10.

Data from others

  • If you sign in with Google, Facebook, or X: your email address and name from that provider. We do not receive your password or post on your behalf.
  • From Stripe: payment status, the last four digits and brand of the card, and payout status for Experts. We never receive your full card number.
  • If someone gives you a voucher, we learn that you claimed or cancelled it.

4. Why we use it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Create and run your account; sign you inAccount data, sign-in eventsContract — 6(1)(b)
Process orders, issue tickets and vouchers, send confirmations and reminders, handle cancellations and refundsAccount, order, payment, ticket dataContract — 6(1)(b)
Give the Expert the attendee list so they can run the sessionFirst name, last initial, ticket statusContract — 6(1)(b)
Pay Experts and account for platform feesExpert identity, payout and order dataContract — 6(1)(b)
Issue invoices; keep accounting and tax recordsOrder, payment, billing dataLegal obligation — 6(1)(c)
Prevent fraud and abuse; enforce our Terms; keep the Platform secureTechnical data, order patterns, reportsLegitimate interests — 6(1)(f)
Show you activities near youCity-level location from IPLegitimate interests — 6(1)(f)
Publish reviews and ratingsReview text, rating, reviewer display nameContract — 6(1)(b)
Invite you to review a session you attended; milestone remindersAttendance and review status, email addressLegitimate interests — 6(1)(f)
Analytics to understand and improve the PlatformUsage events, device data, identifiersConsent — 6(1)(a)
Marketing emails and newslettersEmail address, city of interestConsent — 6(1)(a)
Respond to legal claims and authority requestsWhatever is strictly relevantLegal obligation / legitimate interests — 6(1)(c), (f)

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. You can object at any time — see section 8 — and you can withdraw consent at any time without affecting processing already carried out.

5. Who we share it with

We do not sell personal data, and we do not share it for third-party advertising.

Experts. An Expert whose session you booked sees your

  • first name and last initial, and
  • ticket and attendance status for their own sessions.

Experts do not receive your email address, phone number, or billing address from us. In respect of their own attendee records, the Expert is an independent controller.

Processors acting on our instructions, each under a data processing agreement meeting GDPR Art. 28:

RecipientPurposeLocation
StripeCard payments, Expert onboarding and payoutsEU / US
PostHogProduct analytics (consent-based)EU (eu.posthog.com)
iubendaCookie consent managementEU
DigitalOceanApplication hosting, database, and image storage (Spaces)European Union (EEA)
Websupport s.r.o. (websupport.sk)Transactional and notification email deliverySlovakia (EU)

[TO CONFIRM: Google Analytics is named as a planned marketing-analytics tool in the project docs but is not integrated in the codebase today, so it is deliberately not listed above. Add it to this table and to the Cookie Policy before it goes live — a privacy notice must describe actual processing, not planned processing.]

Others. Professional advisers under confidentiality; public authorities and courts where we are legally obliged to disclose, limited to what is requested; and, if we are ever involved in a merger or acquisition, the acquiring party — we would notify you first.

6. International transfers

Your data is stored in the European Economic Area. Our application and database run in an EEA datacentre region, and our analytics run on PostHog's EU infrastructure, so the storage of your data is not a transfer outside the EEA.

Two of our processors are nonetheless US companies — Stripe and DigitalOcean. Their staff may be able to access data from the United States for support and administration even though it is stored in Europe, and that access counts as a transfer. For it we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where the recipient is certified, the EU–US Data Privacy Framework, together with the supplementary technical measures described in each processor's documentation. You may request a copy of the relevant safeguards at privacy@opengym.in.

7. How long we keep it

DataRetention
Account and profile dataUntil you close your account, then anonymised
Orders, payments, invoices, accounting records8 years from the end of the financial year, as required by the Hungarian Accounting Act (Act C of 2000, §169)
Tax recordsAs required by Hungarian tax law
ReviewsUntil deleted; retained in anonymised form after account closure
Security and audit logs12 months
Analytics data14 months
Marketing consent recordsUntil you withdraw consent, plus 3 years to evidence the consent

8. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted, except where we must keep it by law (see section 7).
  • Restriction — have processing paused while a dispute is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests, including profiling. We stop unless we can show compelling legitimate grounds that override your rights.
  • Withdraw consent — at any time, for analytics and marketing, without affecting processing already carried out.

Email privacy@opengym.in from the address on your account. We respond within one month, extendable by two further months for complex requests — we will tell you if that happens. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.

9. Closing your account

You can close your account from Account → Security. When you do, we overwrite the following fields with anonymised values: email address, name, phone number, profile photo, biography, billing address, date of birth, and the link to your Stripe account. Any activities you own are archived, and every active sign-in session is ended, so you are signed out on all devices.

We keep your orders, payments, tickets, and audit records, because we are legally required to — but they then reference an anonymised user rather than an identifiable person. This is why account closure is described as anonymisation rather than complete erasure.

10. Cookies & analytics

We use a small number of strictly necessary cookies to keep you signed in, remember your cart, record your language, and attribute referrals. Analytics cookies and analytics tracking — PostHog and Google Analytics — require your consent, which we collect through a consent banner and which you can withdraw at any time.

Our Cookie Policy lists every cookie by name, purpose, and lifetime.

11. Security

We use TLS for all traffic, encrypt data at rest with our hosting and storage providers, restrict internal access on a least-privilege basis, require multi-factor authentication for administrator accounts, and keep audit logs of administrative actions. We never store full card numbers — Stripe handles card data under PCI DSS.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights, we will notify the Hungarian supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high, as GDPR Arts. 33 and 34 require.

12. Children

Open Gym is not intended for children under 16, and we do not knowingly collect their personal data. Sixteen is also the age at which a child can consent to information society services in Hungary under Infotv. If you are a parent or guardian who believes a child under 16 has created an account, contact privacy@opengym.in and we will close it and delete the data.

13. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means alone. Automated rules do flag suspicious orders and payments for fraud review, but a person decides before any account is suspended or any order is refused, and you can contest that decision by writing to privacy@opengym.in. Stripe applies its own automated fraud screening to card payments.

14. Changes

We will update this policy as the Platform changes. For material changes we notify registered users by email at least 15 days before they take effect. The version and date at the top of this page always tell you which version is current.

15. Contact & complaints

Privacy questions and requests: privacy@opengym.in, or by post to Nomo Consulting Kft., 1082 Budapest, Baross utca 74., Hungary.

If you are unhappy with our response, you can complain to the Hungarian Data Protection Authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
1055 Budapest, Falk Miksa utca 9–11.
Postal: 1363 Budapest, Pf. 9.
naih.hu

If you live in another EEA country, you may instead complain to your local supervisory authority. You also have the right to an effective judicial remedy.