Privacy policy.
What we collect, why we collect it, and how you stay in control. In plain English.
Last updated · April 1, 2026
01What we collect
When you sign up for Kasratbook, we collect information you give us directly — your name, email, phone number, gym name, and the details of the members you add. We also collect information automatically, like your IP address, browser type, and usage patterns, so we can keep the product working and improve it over time.
We never collect more than we need. If a piece of data isn't useful to run your gym or improve Kasratbook, we don't ask for it.
02Signing in with Google
When you choose Sign in with Google to create or access your Kasratbook account, Google shares the following information from your Google account with us: your name, email address, profile picture, and your Google account ID. We use this information for one purpose only — to create and authenticate your Kasratbook account. We do not request or access any other Google product data such as Gmail, Drive, Calendar, or Contacts.
Kasratbook’s use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements. We do not use Google account data for advertising, do not sell it, and do not transfer it to third parties except where necessary to provide the Kasratbook service to you (sub-processors listed below) or to comply with a lawful legal request.
You can revoke Kasratbook’s access to your Google account at any time from your Google Account permissions page. Doing so disconnects future sign-ins; to also delete the Kasratbook account itself, email [email protected].
03How we use your data
We use your data to operate the service: authenticating users, processing payments, sending WhatsApp reminders to your members on your behalf, generating analytics, and providing support when you need it.
We also use aggregated, anonymized data to understand how gyms use Kasratbook so we can make better product decisions. This data never contains personally identifiable information.
04Who owns the data
Your gym owns every piece of member data you put into Kasratbook. We are the custodians — we store it, secure it, and process it on your behalf. You can export all of it at any time from the dashboard, in CSV or JSON format, with no restrictions.
05Who we share data with
We share data with a small number of trusted sub-processors who help us run the product: our hosting provider (Oracle Cloud Infrastructure), our CDN and edge security (Cloudflare), our payments processor (Razorpay), our transactional messaging provider (WhatsApp Business API via Meta), our authentication identity providers (Google for “Sign in with Google”), our analytics provider (Google Analytics for marketing-site visitor measurement only), and our transactional email provider (Brevo). Each one processes data only to perform its function and is bound by a data-processing agreement.
We do not sell your data. We never will. If a government agency makes a lawful request for your data, we will notify you first unless legally prohibited from doing so.
06How long we keep it
We keep your data for as long as your account is active. If you cancel, we keep it for 30 days so you can reactivate, then we delete it permanently. You can request immediate deletion at any time by writing to [email protected].
07Your rights
Under India's Digital Personal Data Protection Act, the EU's GDPR, and similar laws elsewhere, you have the right to access, correct, export, and delete your personal data. Every one of these is a single click in the Kasratbook dashboard — no forms, no email chains.
If you're a member of a gym that uses Kasratbook, the gym is the data controller for your information. Please contact them first; if you can't reach a resolution, write to us and we'll help.
08Cookies and tracking
We use first-party cookies to keep you signed in and to remember your preferences. We use Google Analytics 4 to understand how visitors find and use our marketing site — this is configured to anonymize IP addresses, does not feed advertising, and stores only aggregated metrics. We do not use advertising cookies or cross-site trackers.
You can opt out of Google Analytics by installing Google’s opt-out browser add-on or by enabling Do Not Track in your browser.
09Changes to this policy
If we make meaningful changes to how we handle your data, we'll notify you by email at least 14 days before they take effect. Cosmetic updates (fixing typos, clarifying language) happen without notification — the last-updated date at the top will always tell you when anything changed.