privacy policy

your data, your control.

We collect the minimum we need, store it securely, and never sell it. Period.

1. who we are

springfit is operated by springfit Pty Ltd ("springfit", "we", "us"), an Australian company providing studio operating software to boutique pilates, yoga, barre and fitness studios worldwide.

Our registered address and contact email are listed at the bottom of this page.

2. information we collect

Account information: name, email, business name, billing details when you create a springfit account.

Usage information: how you and your members interact with the product (pages viewed, features used, device & browser data).

Member data on your behalf: information your studio members provide to you through the springfit app (bookings, payment methods via Stripe, profile data).

We do not sell personal information. Ever.

3. how we use information

To deliver and improve the springfit product.

To process payments (via Stripe — see their privacy policy).

To send transactional emails (booking confirmations, receipts, account notices).

To respond to support requests and provide customer service.

To comply with legal obligations.

4. data we share

Sub-processors: Stripe (payments), Resend (transactional email), AWS (hosting), Supabase (database).

We share only what each sub-processor needs to perform its function.

We do not share member data with marketing platforms unless your studio explicitly connects them (e.g., Mailchimp, Klaviyo).

5. your rights (GDPR, APP & CCPA)

Access — request a copy of personal data we hold about you.

Correction — request corrections to inaccurate data.

Deletion — request deletion (subject to legal retention requirements).

Portability — export your data in machine-readable format anytime via the dashboard.

Email privacy@springfit.ai to action any of the above.

6. data security

Encryption in transit (TLS 1.3) and at rest (AES-256).

Stripe handles all card data — we never touch it.

Role-based access controls and audit logs internally.

Annual third-party penetration testing.

7. data retention

Account data: retained while your account is active. Deleted 30 days after cancellation (unless legally required to retain longer).

Financial records: retained for 7 years per Australian tax law.

Support correspondence: retained for 2 years.

8. cookies & analytics

We use minimal cookies — essential session cookies, plus Google Analytics 4 with Consent Mode v2 enabled by default.

You can opt out of analytics in our cookie banner without losing product functionality.

9. children

springfit is a B2B product for studio operators and is not directed at children under 16. We do not knowingly collect data from children.

10. changes to this policy

We'll notify account owners by email at least 30 days before any material changes take effect.

11. contact

privacy@springfit.ai for all privacy queries, data subject requests and complaints.

Last updated: 1 January 2026.