← Back to Home

Privacy Policy

Last updated: May 14, 2026

Ascend Tech Ltd (“Ascend,” “we,” “us,” or “our”) is a New Zealand company based in Auckland. We provide a white-label SaaS platform for gyms and fitness studios to manage their operations, memberships, bookings, and websites. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

This policy is governed by the New Zealand Privacy Act 2020. If you are located in the European Economic Area (EEA), the United Kingdom, or California, additional rights under GDPR or CCPA may also apply to you (see Section 8).

By using the platform, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use immediately.

1. Information We Collect

1.1 Information You Provide Directly

We collect the following categories of personal information when you register, create a profile, or use our services:

1.2 Payment Information

Payments are processed through Stripe Connect. When you make a payment, your payment card details are sent directly to Stripe and never touch our servers. We do not store full card numbers, CVV codes, or PINs.

We do store the following payment method information locally (mirrored from Stripe for display purposes):

This stored information allows us to display saved payment methods in your account. Test-mode payment methods (used during sandbox/testing) are stored separately with an is_test_mode flag and are never mixed with live data.

1.3 Information Collected Automatically

Standard web server logs may include IP addresses, request timestamps, and user-agent strings. These are used exclusively for operational purposes (monitoring, debugging, and abuse prevention) and are not used for analytics or profiling.

No Cookies. We do not use cookies, tracking pixels, local storage, or any other client-side storage mechanism for tracking. There are no session cookies, persistent cookies, or third-party tracking scripts on our platform.

1.4 Information from Third-Party Sources

2. How We Use Your Information

We use the information we collect for the following purposes:

3. Legal Basis for Processing

3.1 New Zealand Privacy Act 2020

As a New Zealand company, we collect, use, and disclose personal information in accordance with the 13 Information Privacy Principles (IPPs) under the New Zealand Privacy Act 2020. Our processing is based on the following grounds:

3.2 GDPR (For EEA/UK Residents)

If you are located in the EEA or the United Kingdom, we also process your personal data under the following GDPR legal bases:

4. Data Retention

We retain your personal data as follows:

5. Data Sharing and Third-Party Services

We share your information only as necessary to provide our services and as described below:

5.1 Service Providers

We engage trusted third-party service providers to help us operate our platform. These providers are contractually bound to protect your information and may only use it for the purposes we specify. Categories of service providers include:

5.2 Gym Operators (Data Controllers)

When you join a gym that uses our platform, that gym is the data controller for the personal data you provide in the context of your membership (your name, contact details, fitness data, booking history, and payment records). Ascend Tech Ltd acts as a data processor for this data. The gym’s privacy policy governs how they use your data. We are a data controller only for the platform account data we collect directly (your email address and name used to create your user account).

5.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process (e.g., a court order or subpoena).

6. What We Don’t Do

We want to be clear about the following:

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

7.1 Breach Notification

In compliance with the New Zealand Privacy Act 2020, we have a Privacy Officer responsible for managing data privacy and security. In the event of a data breach that poses a risk of harm to affected individuals, we will notify the New Zealand Privacy Commissioner and affected individuals as required by law.

8. Your Rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the following rights regarding your personal data:

8.1 For EEA/UK Residents (GDPR)

8.2 For California Residents (CCPA)

Note on Automated Deletion and Export: You can request deletion of your account via our Request Account Data Deletion page. To exercise any of these rights, please contact us at ascendgym@proton.me and we will respond within the timeframe required by applicable law (typically 30 days).

9. Children’s Privacy

Our services are intended for gyms and fitness studios that primarily serve individuals aged 13 and older. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at ascendgym@proton.me so we can delete the information.

10. International Data Transfers

Our servers are hosted in Sydney, Australia via Google Cloud (subject to change). If you are located outside Australia, your personal data may be transferred to and processed in Australia. When transferring data from the EEA or UK to Australia, we rely on Standard Contractual Clauses (SCCs) with our service providers to ensure an equivalent level of data protection.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the “Last updated” date at the top. We encourage you to review this policy periodically.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

If you have an unresolved privacy or data-use concern that we have not addressed satisfactorily, you have the right to lodge a complaint with your local data protection authority.