Legal

Privacy Policy

Last updated: 13 May 2026

1. Who we are

Membry ("we", "us") provides member management software for gyms, martial arts academies, and clubs. This policy explains what data we collect, how we use it, and the rights you and your members have.

2. What we collect

From gym owners and staff

  • Account info: name, email, password (hashed)
  • Gym details: name, address, contact info, logo, timezone
  • Usage data: pages visited, actions taken (for product improvement)

From members (uploaded by gym staff)

  • Name, email, phone, date of birth, emergency contact, membership status
  • Class bookings, attendance records, payment history

3. How we use it

  • Provide the service (logins, bookings, attendance, billing)
  • Send transactional emails (invites, password resets, receipts)
  • Improve the product based on aggregated usage

We do not sell your data, your members' data, or use it for advertising.

4. Where it lives

Data is hosted on Supabase (Frankfurt, EU) and Vercel (global edge). We comply with GDPR. Each gym's data is isolated using row-level security.

5. Sharing

We share data only with:

  • Stripe (when billing is enabled, for payment processing)
  • Resend / Supabase (for transactional emails)
  • Authorities, where legally required and we have notified you when permitted

6. Your rights

Under GDPR you can request access to, correction of, or deletion of your personal data. Members should request these via their gym in the first instance, and we'll support that request. For platform-level concerns, email hello@membry.org.

7. Cookies

We use only essential cookies (session, auth, CSRF). No tracking or advertising cookies.

8. Changes

We'll post any updates to this page and notify gym owners by email of material changes.

Questions? Email hello@membry.org.