Privacy Policy
Last updated: 7 August 2026
Who this policy covers
GymReply is a managed gym lead-follow-up service powered by software. This policy covers gym account holders, people who submit a GymReply lead-capture form or exchange SMS messages through the service, and visitors to gymreply.com.
A gym normally decides why and how its lead data is used. In that setting, the gym is normally the controller and GymReply processes the data to provide the service. GymReply is responsible for data used to operate its own accounts, security, billing and support.
Information we process
Accounts, workspaces and billing
- Account identity, authentication and security records.
- Gym identity, location, offers, verified prices, booking links, messaging hours and follow-up settings.
- Plan, allowance and usage records for Starter, Growth and Managed workspaces.
- Stripe customer, Checkout, subscription, invoice, payment, cancellation and prepaid SMS-pack records.
Leads, consent and conversations
- Names, phone numbers and information submitted through a capture form or supplied in an authorised import.
- The source and wording of SMS consent, timestamps, consent status and opt-out evidence.
- Inbound and outbound messages, delivery status, conversation notes and scheduled follow-up.
- Lead stage, staff handoff, booking-link activity and outcomes recorded by the gym.
Technical and service data
- IP address, browser and device information, request metadata, rate-limit records and security events.
- Operational logs, error records, webhook identifiers and provider delivery identifiers.
- AI-generated drafts or replies and bounded generation metadata used to operate and review the service.
How we use information
- Provide lead capture, SMS follow-up, staff handoff, conversation management and booking-link handoff.
- Preserve consent evidence and prevent messages after consent is withdrawn or a suppression applies.
- Use configured gym facts and relevant conversation context to generate and assess follow-up with OpenAI.
- Operate Stripe billing, plan entitlements, prepaid SMS credits, payment-failure controls and cancellation.
- Secure, monitor, support and improve the service and meet applicable legal obligations.
AI-assisted follow-up and human control
OpenAI-assisted generation and analysis can be inaccurate. GymReply constrains messages to configured gym facts, applies server-side policy checks and can require a staff handoff. Gym staff can pause automation and take control of a conversation. A booking link is a handoff to the gym's booking service; a link click is not proof of a booking, attendance, membership or revenue.
GymReply does not guarantee bookings, memberships or revenue. Results also depend on lead quality, the gym's offer, availability and sales process.
SMS consent, imports and suppression
Gyms must have an appropriate lawful basis for the leads and instructions they provide. Importing a lead does not itself create SMS consent. GymReply records canonical consent evidence through supported capture, import-attestation and inbound-keyword paths.
Recognised opt-out messages, including STOP, withdraw consent, stop automated follow-up and create a suppression that blocks later outbound processing. A gym must not use GymReply to contact purchased, scraped or otherwise unsolicited lists.
Service providers
We share only the data needed to operate the relevant part of GymReply with:
- Supabase for hosted PostgreSQL and related storage services.
- OpenAI for AI-assisted message generation and analysis.
- Twilio for SMS delivery and inbound webhooks when SMS is enabled.
- Stripe for Checkout, subscriptions, payment processing and billing records.
- Render for application hosting.
- Inngest, Sentry and Upstash for background processing, error monitoring and rate limiting.
- Google when a user chooses Google sign-in.
These providers may process data in other countries and apply their own contractual retention periods and security controls. GymReply does not publish a zero-retention claim for a provider unless that setting has been separately verified.
Retention and erasure
GymReply keeps active account, lead, message, consent, security and operational records while they are needed to provide and protect the service. A verified lead-erasure workflow stops follow-up, removes or anonymises active lead and conversation data, and preserves a minimal workspace-scoped suppression so the erased person is not silently re-enrolled.
Workspace erasure disables automation and access before removing or anonymising application data. Minimal consent, suppression, security and financial-lineage records may be retained where needed for compliance, fraud prevention, payment reconciliation or legal claims. Copies held in provider logs, event histories and backups follow the relevant provider's deletion capability and retention period.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to or receive a copy of personal data, and to withdraw consent. A gym lead should normally contact the gym that collected the information. Requests may also be sent to GymReply for coordination with that gym.
Security and cookies
GymReply uses measures including TLS in transit, access controls, authentication safeguards, signed webhook verification, rate limiting, consent gates and workspace-scoped data access. No system is completely secure. Essential cookies are used for authentication, security and core functionality.
Children
GymReply accounts are intended for business users aged 18 or over. Gyms are responsible for applying appropriate consent and safeguarding processes if they receive enquiries from younger people.
Contact
For privacy questions or rights requests:
- GYM REPLY LTD, company number 17146363
- 7 Ledson Park, Liverpool, England, L33 1RL
- support@gymreply.com