Privacy Policy

Jymbro is a platform for gyms and the people who train in them. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the control you have over it. It applies to the Jymbro mobile apps, the Jymbro website, and every related service.

Last updated: 22 July 2026

Who we are

  • The data controller is 6GO S.r.l., registered at Via Beatrice D Este 38, 20122, Milano, VAT/P.IVA 05395240962, operating the Jymbro platform.
  • For any question about this policy or about your personal data, write to [email protected]. We answer within 30 days, as required by the GDPR.
  • We have not appointed a Data Protection Officer, as we are not required to. [email protected] is the single point of contact for all privacy matters.

Data we collect

  • Account data: your name, email address, and password (stored only as a salted hash). If you sign in with Google or Apple, we receive your name, email address, and the provider account identifier — never your password with that provider.
  • Profile data: username, photo, date of birth, gender, height and weight if you record them, training experience, disciplines, and availability. All of it is optional and can be removed at any time.
  • Documents you upload: contracts, medical certificates, identity documents, and any other file you choose to store. These stay private to you unless you explicitly assign them to a gym you are a member of.
  • Membership and gym data: the gyms and locations you belong to, your plan, your membership status and its history.
  • Access and check-in data: every access pass scan is recorded in an immutable audit log with a timestamp, the location, the scanner device, and the outcome of the scan. This log is a security record and cannot be edited by anyone, including us.
  • Content you create: chat messages, training-session posts, workout logs, and any other content you publish through the platform.
  • Device data: device name, operating system, app version, and push notification token, so we can deliver notifications and let you review and revoke your devices.
  • Payment data: for sports facilities on a paid subscription, billing name, address, VAT number, and subscription history. Card numbers are handled entirely by Stripe and never reach our servers.
  • Technical data: IP address, approximate location derived from it, browser or app identifiers, diagnostic logs generated when something goes wrong, and product analytics events and masked session recordings describing how you used the app.

Why we use your data, and on what legal basis

  • To provide the service — creating your account, authenticating you, managing memberships, issuing access passes, and delivering the features you ask for. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • To take payments and manage subscriptions for sports facilities. Legal basis: performance of a contract, and compliance with tax and accounting obligations (Art. 6(1)(b) and (c) GDPR).
  • To keep gyms and members safe — recording access scans, detecting replayed or fraudulent passes, and alerting facility teams to suspicious activity. Legal basis: legitimate interest in the security of the platform and of physical premises (Art. 6(1)(f) GDPR).
  • To match you with training partners. Legal basis: your consent (Art. 6(1)(a) GDPR). Matchmaking is opt-in, uses a profile stripped of directly identifying details, and can be switched off at any time from your preferences.
  • To send you service messages about your account, your memberships, your billing, and security events. Legal basis: performance of a contract and legitimate interest.
  • To send marketing messages about Jymbro. Legal basis: your consent, which you can withdraw at any time using the unsubscribe link or your notification preferences.
  • To fix bugs, measure how the product is used, and improve it. Legal basis: legitimate interest in maintaining and improving a service you rely on.
  • To comply with legal obligations and to establish, exercise, or defend legal claims. Legal basis: legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR).

Special categories of data

  • Medical certificates you upload — and any health information they contain — are special category data under Art. 9 GDPR. We process them only because you explicitly choose to upload them and, where applicable, to share them with a gym (Art. 9(2)(a) GDPR: explicit consent).
  • You are never required to upload a medical certificate to use Jymbro itself; a gym may require one as a condition of its own membership. You can delete an uploaded document, or revoke a gym's access to it, at any time.

Who we share data with

  • Gyms you are a member of: your name, profile, membership status, check-in history at their locations, and any document you have explicitly assigned to them. Each gym is an independent data controller for what it does with that data.
  • Stripe Payments Europe, Ltd. — payment processing and subscription billing.
  • Apple Inc. and Google LLC — sign-in with Apple / Google, and delivery of push notifications through APNs and FCM.
  • Sentry — error monitoring and diagnostics, to detect crashes and faults.
  • PostHog — product analytics, to understand how the product is used and where it fails.
  • Our hosting, email delivery, and file storage providers, who run the infrastructure the platform depends on.
  • Public authorities, when we are legally required to disclose data, and professional advisers where necessary to defend a legal claim.
  • Every supplier above acts as a data processor under a written agreement, may use your data only on our instructions, and may not use it for their own purposes. We do not sell your personal data, and we never have.

Where your data is stored

  • Your data is stored on servers located in the European Union.
  • Some of our suppliers process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision of the European Commission or by the Standard Contractual Clauses, together with additional safeguards where required.
  • You can ask us for a copy of the safeguards applying to a specific transfer by writing to [email protected].

How long we keep it

  • Account and profile data: for as long as your account exists. When you delete your account we erase your personal data within 30 days.
  • Documents you upload: until you delete them, or until your account is deleted.
  • Chat messages and content you publish: until you delete them, or until your account is deleted. Messages you sent to another user may remain visible in their copy of the conversation.
  • Access scan audit logs: retained for 24 months for security and dispute resolution, then anonymised. Because these logs are immutable, individual entries cannot be edited or selectively removed.
  • Invoices and accounting records: 10 years, as Italian tax law requires.
  • Diagnostic and error logs: up to 90 days.
  • Backups: encrypted backups are rotated and fully overwritten within 35 days, so data deleted from the live system disappears from backups within that window.

Your rights

  • Access — obtain confirmation that we process your data and receive a copy of it.
  • Rectification — correct data that is wrong or incomplete; most of it you can edit yourself from your profile.
  • Erasure — delete your account and your personal data, subject to the retention periods above.
  • Portability — export your data in a structured, machine-readable format.
  • Restriction — ask us to pause processing while a dispute about your data is resolved.
  • Objection — object to processing based on our legitimate interest, and opt out of matchmaking and marketing at any time.
  • Withdraw consent — where processing relies on your consent, withdraw it at any time, without affecting the lawfulness of what was processed beforehand.
  • To exercise any of these rights, use your account settings or write to [email protected]. We reply within 30 days and never charge for a first request.
  • You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of the country where you live.

Deleting your account

  • Open the app, go to Settings, then Account, and choose "Delete account". The same option is available on the website under Settings.
  • Deletion is permanent. Your profile, documents, messages, preferences, and devices are erased within 30 days.
  • Records we are legally obliged to keep — invoices, and access-scan audit entries within their retention period — are retained and dissociated from your identity where possible.
  • If you cannot access your account, write to [email protected] from the email address on the account and we will handle the deletion for you.

Security

  • All traffic is encrypted in transit with TLS. Passwords are stored as salted hashes and are never recoverable, by us or by anyone else.
  • Access passes are single-use and rotate, so a captured pass cannot be replayed. Replay attempts are detected, logged, and reported to the gym.
  • Two-factor authentication is available on every account, and we recommend enabling it.
  • Access to production data inside our team is restricted to the people who need it, and is logged.
  • If a breach ever puts your rights at risk, we notify the Garante within 72 hours and inform you without undue delay.

Children

  • Jymbro is not intended for children under 16. If you are between 16 and 18, you may use Jymbro only with the consent of a parent or guardian.
  • If we learn that we hold data about a child under 16 without a valid legal basis, we delete it. If you believe this has happened, write to [email protected].

Cookies and local storage

  • The website uses strictly necessary cookies to keep you signed in, protect forms against cross-site request forgery, remember your language and appearance preferences, and record your answer to the cookie banner. These do not require consent.
  • When you search the directory, we store up to six recent search terms on your device. They stay there until you clear your browser data or remove them from the search box.
  • We count views of facility, brand, listing and profile pages so sports facilities and members can see how their pages perform. These counts are aggregates: a facility sees how many people opened a page, never who they were.
  • If you allow it, we store one first-party cookie holding a random identifier, so we can tell a returning visitor from a new one across days. If you decline, we store nothing on your device: the visit is still counted, using an identifier derived from your address and browser with a key that changes every day and therefore cannot follow you into tomorrow.
  • We also use product analytics to understand how Jymbro is used and where it fails. For signed-in members the legal basis is our legitimate interest in maintaining and improving a service you rely on (Art. 6(1)(f) GDPR). For visitors who are not signed in, it runs only with your consent.
  • You can turn product analytics off at any time from your preferences. Doing so also stops session recordings. It does not remove your visits from the aggregate page counts a facility sees, because those carry no identity. Crash and error diagnostics continue, because we need them to keep the service working.
  • Some sessions are recorded so we can see how a page was actually used. All text and all form inputs are masked before the recording leaves your device, so what you type and read is never captured. Recordings are stored in the European Union and deleted on the same schedule as our diagnostic logs.
  • The mobile apps use local device storage for the same purposes; they do not use advertising identifiers, and we do not run third-party advertising.

Automated decisions

  • We do not make decisions with a legal or similarly significant effect on you by automated means alone.
  • Matchmaking suggests training partners using the preferences you set. It is a suggestion, never a decision, and you can turn it off at any time.

Changes to this policy

  • When we change this policy we update the date at the top of the page. For material changes we notify you in the app or by email before they take effect.
  • Continuing to use Jymbro after a change takes effect means you accept the updated policy.

Contact us