Privacy Policy
Effective Date: August 2, 20261. Information We Collect
Activsaga provides a cloud-based multi-tenant Software-as-a-Service (SaaS) platform for gym management. In order to render our platform services across single and multi-outlet gym businesses, we collect the following categories of information:
- Account & Registration Data: Name, business email, business address, telephone number, and subscription billing details provided by gym administrators during tenant creation.
- Gym Operations & Member Data: Data entered by your authorized staff including member rosters, membership plan assignments, attendance logs, trainer records, equipment catalog inventory, and customer lead/enquiry details.
- Financial & Accounting Records: Invoices, billing statements, expense entries, chart of accounts records, and payroll data created within your isolated tenant workspace.
- System Audit & Usage Logs: Automated security and access records including user role permissions, IP addresses, authentication tokens, timestamped modification logs (Audit Trail), and browser metadata.
2. How We Use Your Information
We process collected data solely for legitimate business operations and platform execution, including:
- Provisioning isolated tenant databases and verifying outlet-scoped permissions (RBAC).
- Processing subscription billing, payment receipts, and subscription tier features.
- Generating immutable security audit logs to protect your account against unauthorized access or privilege escalation.
- Delivering automated system communications (e.g., password resets, security notifications).
- Maintaining system performance, server stability, and continuous platform uptime.
3. Multi-Tenant Data Isolation & Security
Activsaga enforces strict row-level tenant and outlet data scoping (via explicit tenant_id and outlet_id contextual validation on every API invocation). Technical security measures include:
- Zero Cross-Tenant Leakage: Database queries are scoped per request to prevent cross-tenant or cross-outlet data exposure.
- Encryption: Data in transit is protected using TLS 1.3/HTTPS encryption. User credentials and passwords are encrypted using secure cryptographic hashing algorithms.
- Role-Based Access Control (RBAC): Per-user granular permission flags (View, Create, Edit, Delete, Accounting Access) ensure your staff members only access authorized platform modules.
4. Third-Party Disclosures & Data Processing
Activsaga does not sell, rent, or trade your business or member information to third-party advertisers or data brokers. Data disclosures occur strictly under the following conditions:
- Infrastructure & Service Providers: Trusted cloud hosting, database, and payment processing vendors under strict data processing agreements.
- Legal Compliance: When required by binding legal process, court orders, or enforceable governmental requests.
5. Data Retention & Export Rights
Your business data remains active for the duration of your subscription. Upon account termination or expiration, Activsaga provides a grace period during which administrators can export complete data records (including members, financial ledgers, and equipment logs) via built-in CSV export tools. Permanent data deletion follows the expiration of mandatory legal holding periods.
6. Updates to This Policy
We may update this Privacy Policy periodically to reflect architectural upgrades or legal requirements. Material revisions will be posted on this page with an updated effective date.
7. Contact & Privacy Inquiries
For questions or formal inquiries regarding data privacy and protection, please contact our security team at:
Email: hello@activsaga.com