1. Introduction & Scope
Qawi ("we," "us," "our," or "the Platform"), accessible via https://theqawi.com, operates a multi-tenant Gym Management SaaS ecosystem designed for gym owners, club managers, branch administrators, staff, trainers, and gym members.
This Privacy Policy governs the collection, use, transmission, processing, storage, and deletion of user data when you access or use the Qawi Admin mobile application, web dashboard, and related services (collectively, the "Services").
2. Roles: Data Controller vs. Data Processor
We act as a Data Controller for direct customer account records, billing interactions, platform operational logs, and technical telemetry collected from administrative users.
When gym organizations (Club Owners, Gym Owners, or Branch Managers) use Qawi to process data about their staff, trainers, and gym members, the gym organization acts as the Data Controller, and Qawi acts as the Data Processor handling data strictly under organizational direction.
3. Information We Collect
We collect data strictly required to deliver, secure, and operate enterprise gym management workflows:
Full name, business email address, phone number, hashed password, role/permission tiers, and assigned branch identifiers.
Club/branch business names, physical location addresses, staff rosters, trainer assignments, subscription tier settings, and facility capacity configurations.
Check-in timestamps, member identifier tokens, branch IDs, and check-in status recorded via QR code scans.
Membership plan assignments, subscription start/expiration dates, payment status, transaction reference IDs, and aggregated revenue figures. (Note: Full payment card numbers are processed directly by certified PCI-DSS third-party payment gateways; Qawi does not store unencrypted payment card details).
Device model, operating system version, unique device identifiers, IP address, crash analytics, session timestamps, and network status to ensure platform stability and prevent unauthorized access.
4. Device Permissions & On-Device Hardware Use
Qawi Admin accesses device capabilities strictly when initiated by the user for operational workflows:
CAMERA)Utilized exclusively for real-time QR code scanning to process member check-ins and verify attendance. Qawi does not record, capture, or transmit still photos or raw video feeds from your device camera.
Accessed strictly in the foreground (ACCESS_FINE_LOCATION) when configuring or verifying physical gym branch coordinates. Location is never tracked in the background.
Required for secure, real-time synchronization between the client application and our cloud infrastructure.
Profile image selection and exports are handled via native Android system pickers and secure sandboxes, requiring no persistent access to your media library.
5. How We Use Collected Information
- Operating and maintaining role-based admin workflows, staff assignments, and member logs.
- Authenticating authorized personnel and securing tenant gym data.
- Aggregating business analytics, capacity reporting, and revenue metrics for gym and club owners.
- Delivering service notifications, platform updates, and security alerts.
- Preventing fraudulent transactions, unauthorized account sharing, and security breaches.
6. Data Sharing & Third Parties
We do not sell, rent, or monetize your personal or operational data to data brokers or advertising networks under any circumstances.
We disclose data only to trusted service providers operating under strict confidentiality and security agreements:
Secure database, compute, and encrypted authentication providers.
PCI-DSS compliant payment gateways for subscription and facility billing.
When strictly mandated by applicable laws or enforceable court orders.
7. Security Safeguards
All traffic is encrypted using modern TLS 1.3 / HTTPS protocols.
Passwords are salted & hashed. Backups use AES-256 standard encryption.
Multi-tenant database rules isolate branch data strictly to authorized staff.
8. Data Retention & Account Deletion Policy
Retention: We retain administrative and operational data only for as long as your gym organization maintains an active subscription with Qawi, or as necessary to comply with legal, tax, and accounting requirements.
How to Request Account & Data Deletion:
- In-App Deletion: Navigate to Settings > Account > Delete Account / Request Erasure.
- Web-Based Deletion Portal: Submit an instant data erasure request without reinstalling the app at:
Upon receiving a verified deletion request, all personal identifiers, login credentials, and session tokens are permanently expunged or anonymized from active databases within 30 days.
9. Children’s Privacy
Qawi Admin is an enterprise B2B management system intended strictly for adult professionals aged 18 and older. We do not knowingly collect personal information from children under the age of 13.
10. Privacy Contact & Data Protection Officer
If you have questions, data inquiries, or wish to exercise your data privacy rights, reach out to our Data Protection Officer: