Skip to content
Security & Privacy Trust Center

Your gym's data is yours. We never sell it. Period.

Over 500+ gyms across India rely on KasratBook for daily operations. Here is our ironclad commitment to protecting your members, revenue, and business privacy.

Zero Data Selling GuaranteeBank-Grade AES-256 & TLS 1.3India DPDP Act 2023 Compliant1-Click Full Data ExportStaff Anti-Theft & Number MaskingRBI-Authorized Razorpay Gateway
Our Written & Legally Binding Guarantee

We make money from software subscriptions — never by monetizing your members.

Many low-cost or free software tools secretly harvest member phone numbers to sell to supplement companies, dietitians, or competitor fitness chains. KasratBook has never sold, rented, shared, or monetized a single gym or member record, and we never will.

Your members trusted you when they gave you their phone number and payment details. We honor that trust by treating your database like a locked vault. This guarantee is explicitly codified in our Privacy Policy and Terms of Service.

Zero advertising networks
No supplement brand partnerships
No competitor data sharing
Security Pillars

Six layers of protection around your gym.

From the moment a lead walks through your front door to automated monthly renewals, your operational data is safeguarded at every layer.

Zero Vendor Lock-In

100% Data Ownership & Portability

You own every single piece of information entered into KasratBook — member profiles, payment receipts, attendance streaks, and custom workout plans. You are never trapped.

  • 1-Click instant export of your entire member list and billing history to CSV / Excel
  • No hidden fees or barriers to download your own business records
  • Immediate data deletion upon account closure with zero lingering copies
Rest & Transit

Bank-Grade 256-Bit Encryption

Your gym records are shielded by the same military-grade encryption standards used by tier-1 commercial banks and financial institutions worldwide.

  • All traffic encrypted with 256-bit TLS 1.3 / HTTPS across desktop, mobile, and APIs
  • Databases and automated daily cloud snapshots encrypted with AES-256 at rest
  • Staff and owner passwords salted and securely hashed using bcrypt
Architectural Isolation

Strict Multi-Tenant Database Isolation

Every gym on KasratBook operates in an isolated digital partition. It is architecturally impossible for another gym or competitor to see your members or numbers.

  • Tenant scoping enforced at the database query layer by unique gym workspace IDs
  • Competitor gyms cannot query or view your member pricing, churn, or revenue
  • Separate cache namespaces and strict API authorization tokens per branch
Internal Protection

Staff Anti-Theft & Role-Based Controls

Gym owners' #1 fear is staff members taking member contact lists. KasratBook provides specialized controls to prevent database copying or leaks.

  • Restrict CSV / Excel export privileges exclusively to the Owner / Super Admin
  • Turn on phone number masking (+91 98765 *****) for front-desk receptionists
  • Granular role permissions: Front Desk, Trainer, Accountant, and Gym Owner
PCI-DSS & RBI Compliant

Payment & Financial Credential Security

Collect membership fees, POS sales, and UPI Autopay recurring mandates safely. We never touch or store sensitive banking credentials.

  • All digital transactions processed via RBI-licensed gateways (Razorpay)
  • Zero credit card numbers, CVVs, net-banking passwords, or UPI PINs stored
  • Instant GST-ready invoice generation with cryptographic webhook verification
Secure Hardware Sync

Biometric & IoT Device Protection

Integrate fingerprint scanners, RFID readers, and turnstiles without exposing member biometrics to privacy vulnerabilities.

  • Token-authenticated cloud communication with eSSL, ZKTeco, and IoT turnstiles
  • Raw biometric images are never uploaded — only anonymous device template IDs
  • Device APIs are gym-scoped and protected against unauthorized local access
Legal Framework

Built for India's Digital Personal Data Protection (DPDP) Act, 2023.

India's privacy law establishes clear responsibilities for businesses handling personal data. Here is how KasratBook ensures your gym stays fully compliant.

Your Gym's Role

Data Fiduciary (Data Owner)

Under the DPDP Act, your gym is the legal Data Fiduciary. You decide what member information to collect, determine membership rules, and control the customer relationship.

  • You own 100% of member records & consent history
  • Full authority to add, modify, or delete member records
  • Export or migrate your entire database anytime
KasratBook's Role

Data Processor (Software Operator)

KasratBook acts strictly as your Data Processor. We process data solely on your documented system instructions to provide billing, attendance, reminders, and support.

  • Zero independent processing or advertising usage
  • Bank-grade security measures and multi-tenant isolation
  • Dedicated grievance officer: [email protected]
Security & Privacy FAQ

Direct answers to gym owner concerns.

Have questions about how your member records, revenue numbers, and biometric data are handled? Here is the complete breakdown.

Need a formal Data Processing Agreement (DPA) or security review for your gym?

Email our privacy team at [email protected] or [email protected]. We respond within 24 hours.

Responsible Disclosure & Security Grievances

If you are a security researcher or customer who believes they have discovered a potential vulnerability or security concern, please contact our security team immediately at [email protected]. We investigate all valid reports within 24 hours.

Start growing your business today.

3 days free. Full onboarding done for you. No credit card. No lock-in.