Version 2026-09-14-draft-1
PLUNGEOPS — PRIVACY POLICY (DRAFT — REQUIRES ATTORNEY REVIEW)
Effective date: to be set on release. Version: 2026-09-14-draft-1.
This Privacy Policy explains how PlungeOps CRM ("PlungeOps," "we," "us," or
"our") collects, uses, and shares information in connection with our
software-as-a-service platform (the "Service"). It applies to information we
handle about gym owners and staff (each a "Gym User") and gym members
("Members") whose gyms use the Service to manage their operations, as well
as visitors to plungeops.dsio.io.
1. WHO IS THE CONTROLLER.
1.1 PlungeOps is a processor of personal information about Members: the
Gym that uses the Service to manage its business is the controller.
Direct requests about your data to your Gym in the first instance.
1.2 PlungeOps is a controller of personal information about Gym Users
(owners, staff) in connection with account administration, billing,
and support.
2. INFORMATION WE COLLECT.
2.1 From Gym Users and Members:
- Contact information (name, email, phone, mailing address).
- Emergency contact and guardian information (for minors).
- Membership records (plan, status, join date, attendance history).
- Payment tokens and last-four card digits (from Authorize.net or
Stripe; we do not store full card numbers).
- Facial-recognition templates ("biometric templates") for optional
face check-in, computed on the device from a live camera scan.
- Signed documents (waivers, agreements) and their audit trails.
- Communications sent through the Service (chat messages, emails,
SMS content generated by or on behalf of the Gym).
2.2 Automatically:
- Device information (device type, operating system, app version,
install ID).
- Log information (IP address, timestamps, requested endpoints,
user-agent string).
- Cookies and similar technologies (session cookies, preference
cookies).
3. HOW WE USE INFORMATION.
We use the information listed in Section 2 to:
(a) provide, secure, and support the Service;
(b) authenticate users, prevent fraud, and enforce our Terms and AUP;
(c) process payments and calculate fees;
(d) send transactional messages (receipts, password resets, class
reminders, chat notifications) at the direction of the Gym;
(e) improve the Service, subject to the limits in Section 4; and
(f) comply with law and enforce our rights.
4. WE DO NOT USE YOUR DATA TO TRAIN OTHERS' MODELS.
We do not sell personal information. We do not share Customer Data with
third-party artificial-intelligence providers to train their models. Any
built-in AI helper we provide uses only the API key that the Gym itself
configures in Settings, and each Gym remains responsible for that
provider's terms.
5. HOW WE SHARE INFORMATION.
5.1 With the Gym that manages the account: staff and administrators of
the Gym you belong to can see Member records the Gym has authorized
them to see.
5.2 With service providers acting on our behalf: hosting (Vercel and
Neon), payment processing (Authorize.net; Stripe if the Gym opts
in), email (Resend), SMS (Twilio), file storage (Vercel Blob), and
equivalents. These providers process personal information only to
provide services to us and under written contracts.
5.3 With law enforcement or regulators, where we reasonably believe
disclosure is required by law or necessary to protect the safety,
rights, or property of any person.
5.4 In connection with a merger, acquisition, sale of assets, or other
corporate transaction, subject to the receiving party being bound
by protections at least as protective as this Privacy Policy.
6. YOUR CHOICES.
6.1 You can update your contact information, change your password,
manage notification preferences, and add or remove your face
template in the app.
6.2 You may opt out of non-transactional email or SMS by using the
unsubscribe link in the message or replying STOP to a text.
6.3 You have privacy rights under applicable law (for example,
GDPR, CCPA/CPRA, BIPA, PIPEDA). To exercise them, contact your Gym
(if you are a Member) or us at privacy@plungeops.dsio.io. We will
respond within the time limits the applicable law requires.
7. BIOMETRICS.
Facial-recognition templates are collected only after explicit
in-product consent that names biometrics as the subject of the
consent. The template is computed on the device; a scan is not
transmitted or stored as an image. Templates are stored only for the
Gym you are a member of, are used only to identify you at that Gym's
check-in screen, and are deleted when you remove your face from the
app, when your membership ends, or when the Gym enables retention
limits shorter than that. We rely on your consent as the lawful basis
under laws that require one for biometric processing.
8. DATA RETENTION.
We retain Customer Data for the life of your account and, after
termination, for up to 30 days to support export. Payment records and
audit logs are retained for as long as required by applicable law and
card-network rules. Biometric templates are retained as described in
Section 7.
9. INTERNATIONAL TRANSFERS.
We are based in the United States. If you access the Service from
outside the United States, your information will be transferred to and
processed in the United States. Where required, we rely on
Standard Contractual Clauses or equivalent transfer mechanisms.
10. SECURITY.
We implement commercially reasonable safeguards designed to protect
personal information. No system is impenetrable; you must protect
your credentials and notify us at security@plungeops.dsio.io of any known
or suspected compromise.
11. CHILDREN.
The Service is not directed to children under 13. A Gym may include
minors in its Member records with the consent of a parent or
guardian, who is then responsible for that Member's information.
12. CHANGES.
We may update this Privacy Policy from time to time. Material changes
take effect 30 days after posting or when you first accept them,
whichever is sooner.
13. CONTACT.
Privacy questions: privacy@plungeops.dsio.io
Security issues: security@plungeops.dsio.io
General support: support@plungeops.dsio.io
END OF PRIVACY POLICY.
Related: Terms of Service · Acceptable Use Policy