Official Legal Documentation

Privacy Policy

Covering Qawi Admin and the Qawi Gym Management Platform Ecosystem.

Effective Date: August 22, 2026
Last Updated: August 22, 2026
Governing Domain: theqawi.com

1. Introduction & Scope

Qawi ("we," "us," "our," or "the Platform"), accessible via https://theqawi.com, operates a multi-tenant Gym Management SaaS ecosystem designed for gym owners, club managers, branch administrators, staff, trainers, and gym members.

This Privacy Policy governs the collection, use, transmission, processing, storage, and deletion of user data when you access or use the Qawi Admin mobile application, web dashboard, and related services (collectively, the "Services").

2. Roles: Data Controller vs. Data Processor

Qawi as Data Controller

We act as a Data Controller for direct customer account records, billing interactions, platform operational logs, and technical telemetry collected from administrative users.

Qawi as Data Processor

When gym organizations (Club Owners, Gym Owners, or Branch Managers) use Qawi to process data about their staff, trainers, and gym members, the gym organization acts as the Data Controller, and Qawi acts as the Data Processor handling data strictly under organizational direction.

3. Information We Collect

We collect data strictly required to deliver, secure, and operate enterprise gym management workflows:

Account & Authentication Credentials:

Full name, business email address, phone number, hashed password, role/permission tiers, and assigned branch identifiers.

Gym Business & Operational Data:

Club/branch business names, physical location addresses, staff rosters, trainer assignments, subscription tier settings, and facility capacity configurations.

Attendance & Check-In Telemetry:

Check-in timestamps, member identifier tokens, branch IDs, and check-in status recorded via QR code scans.

Financial & Subscription Records:

Membership plan assignments, subscription start/expiration dates, payment status, transaction reference IDs, and aggregated revenue figures. (Note: Full payment card numbers are processed directly by certified PCI-DSS third-party payment gateways; Qawi does not store unencrypted payment card details).

Device, Diagnostic & Usage Data:

Device model, operating system version, unique device identifiers, IP address, crash analytics, session timestamps, and network status to ensure platform stability and prevent unauthorized access.

4. Device Permissions & On-Device Hardware Use

Qawi Admin accesses device capabilities strictly when initiated by the user for operational workflows:

Camera (CAMERA)

Utilized exclusively for real-time QR code scanning to process member check-ins and verify attendance. Qawi does not record, capture, or transmit still photos or raw video feeds from your device camera.

Location Services

Accessed strictly in the foreground (ACCESS_FINE_LOCATION) when configuring or verifying physical gym branch coordinates. Location is never tracked in the background.

Network & Connectivity

Required for secure, real-time synchronization between the client application and our cloud infrastructure.

Photo & Document Selection

Profile image selection and exports are handled via native Android system pickers and secure sandboxes, requiring no persistent access to your media library.

5. How We Use Collected Information

  • Operating and maintaining role-based admin workflows, staff assignments, and member logs.
  • Authenticating authorized personnel and securing tenant gym data.
  • Aggregating business analytics, capacity reporting, and revenue metrics for gym and club owners.
  • Delivering service notifications, platform updates, and security alerts.
  • Preventing fraudulent transactions, unauthorized account sharing, and security breaches.

6. Data Sharing & Third Parties

We do not sell, rent, or monetize your personal or operational data to data brokers or advertising networks under any circumstances.

We disclose data only to trusted service providers operating under strict confidentiality and security agreements:

Cloud Infrastructure

Secure database, compute, and encrypted authentication providers.

Payment Gateways

PCI-DSS compliant payment gateways for subscription and facility billing.

Legal Compliance

When strictly mandated by applicable laws or enforceable court orders.

7. Security Safeguards

Encryption in Transit

All traffic is encrypted using modern TLS 1.3 / HTTPS protocols.

Encryption at Rest

Passwords are salted & hashed. Backups use AES-256 standard encryption.

Role-Based Isolation (RBAC)

Multi-tenant database rules isolate branch data strictly to authorized staff.

8. Data Retention & Account Deletion Policy

Retention: We retain administrative and operational data only for as long as your gym organization maintains an active subscription with Qawi, or as necessary to comply with legal, tax, and accounting requirements.

How to Request Account & Data Deletion:

  • In-App Deletion: Navigate to Settings > Account > Delete Account / Request Erasure.
  • Web-Based Deletion Portal: Submit an instant data erasure request without reinstalling the app at:

Upon receiving a verified deletion request, all personal identifiers, login credentials, and session tokens are permanently expunged or anonymized from active databases within 30 days.

9. Children’s Privacy

Qawi Admin is an enterprise B2B management system intended strictly for adult professionals aged 18 and older. We do not knowingly collect personal information from children under the age of 13.

10. Privacy Contact & Data Protection Officer

If you have questions, data inquiries, or wish to exercise your data privacy rights, reach out to our Data Protection Officer:

Entity: Qawi Platform Operations