Legal

Privacy Notice

Last updated: 1 September 2026

1. Who we are

Membry ("we", "us") provides member management software for gyms, martial arts academies, and clubs. This notice explains what data we collect, how we use it, and the rights you and your members have.

2. What we collect

From gym owners and staff

  • Account info: name, email, password (hashed)
  • Gym details: name, address, contact info, logo, timezone
  • Usage data: pages visited, actions taken (for product improvement)

From members (uploaded by gym staff or the member)

  • Name, email, phone, date of birth, emergency contact, membership status
  • Class bookings, attendance records, payment history
  • Belt rank and promotion history, and staff notes about the membership
  • Health notes your gym records for training safety (injuries, allergies, conditions) — special-category data under Article 9, stored with extra care and never sent to AI features
  • A face photo, where your gym uses photos for check-in identification (stored privately)
  • Waiver signature records, including the exact waiver text you signed against
  • Messages you exchange with your club in the app, and a log of the emails and notifications sent to you
  • Device push tokens, when you enable notifications in the app

3. How we use it

  • Provide the service (logins, bookings, attendance, billing)
  • Send transactional emails (invites, password resets, receipts)
  • Power optional AI features for your gym (drafting messages, announcements and waiver templates, summarising your gym's own statistics, and a member's in-app monthly training recap). These send only limited data — such as a member's first name, activity figures (e.g. attendance), belt rank and most-attended class — to our AI provider, Anthropic (United States), under a data-processing agreement. We never send health notes, date of birth, contact details, photos or payment data. Staff-facing drafts are reviewed and edited by your gym before use; some member-facing text (such as the in-app monthly recap) is generated and shown to the member automatically. This data is not used to train AI models.
  • Improve the product based on aggregated usage

We do not sell your data, your members' data, or use it for advertising.

4. Where it lives

Your data is stored in the European Union — on Supabase (Amazon Web Services, Ireland / eu-west-1). Our application is served via Vercel. We comply with GDPR, and each gym's data is isolated using row-level security.

5. Sharing & sub-processors

We share data only with the service providers (sub-processors) we need to run Membry:

  • Supabase (EU — Ireland / eu-west-1) — database, authentication, and file storage
  • Vercel — application hosting and delivery
  • Stripe — payment processing (card details go directly to Stripe and never touch our servers)
  • Resend — transactional and gym-sent email
  • Anthropic (United States) — provider of the optional AI features described in section 3 (limited data only; not used for model training; processed under a data-processing agreement with Standard Contractual Clauses)
  • Expo — mobile push-notification delivery (device push tokens)
  • Google (Firebase Cloud Messaging) — push delivery to Android devices (device push tokens; the transport beneath Expo push on Android)
  • Sentry (EU data residency) — application error monitoring (technical error details only; no session recordings, no message or health-data content)
  • Cloudflare Turnstile — bot protection on sign-up forms

International transfers: our core systems keep data in the EU (database, storage and hosting in Ireland; error monitoring in Frankfurt). Where a provider processes data outside the EU/EEA — for example Anthropic (AI) or Expo (push delivery) — the transfer is safeguarded by the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework.

Beyond these, we disclose data only to authorities where legally required, and we notify you when permitted. We'll update this list before adding a new sub-processor.

6. Your rights

Under GDPR you can request access to, correction of, or deletion of your personal data. Members should request these via their gym in the first instance, and we'll support that request. For platform-level concerns, email hello@membry.org.

7. Children & members under 18

Many gyms train members under 18 (kids' and juniors' classes). Where a gym adds data about a minor, the gym is the data controller and is responsible for obtaining the appropriate consent from a parent or guardian. We process that data only on the gym's instructions, to provide the Service.

We do not knowingly collect personal data directly from children. Members under 18 interact with Membry through their gym and, where relevant, a parent or guardian account.

8. Data retention

We keep your data for as long as your account is active. After you cancel, we retain it so you can reactivate or export it. You can request deletion at any time — from your member portal or by contacting us — and we act on such requests within one month, as GDPR requires. Some records must be kept longer where the law demands it (for example, invoices for tax purposes).

9. Cookies

We use only essential cookies (session, auth, CSRF). No tracking or advertising cookies. Any analytics we use is privacy-friendly and cookieless.

10. Changes

We'll post any updates to this page and notify gym owners by email of material changes.

Questions? Email hello@membry.org.