Ascend Tech Ltd (“Ascend,” “we,” “us,” or “our”)
is a New Zealand company based in Auckland. We provide a white-label SaaS platform
for gyms and fitness studios to manage their operations, memberships, bookings, and
websites. This Privacy Policy explains how we collect, use, disclose, and safeguard
your information when you use our platform.
This policy is governed by the New Zealand Privacy Act 2020. If you are
located in the European Economic Area (EEA), the United Kingdom, or California, additional
rights under GDPR or CCPA may also apply to you (see Section 8).
By using the platform, you agree to the collection and use of information in accordance
with this policy. If you do not agree, please discontinue use immediately.
1. Information We Collect
1.1 Information You Provide Directly
We collect the following categories of personal information when you register, create a profile, or use our services:
- Identity Information: First name, last name, email address, phone number.
- Demographic Information: Date of birth, gender.
- Account Credentials: Email and password (stored as a hash — we never store plaintext passwords).
- Profile Information: Avatar image (uploaded and stored in Cloudflare R2).
- Emergency Contact: You may optionally provide an emergency contact’s name and phone number. This is another individual’s personal data, and by providing it you confirm you have the authority to do so. This information is stored solely for emergency purposes.
- Fitness & Booking Data: Class bookings, attendance records (including check-in/check-out times), cancellation history, membership plans purchased, and credits remaining on punch-card plans.
- Leaderboard & Streak Data: Attendance streaks, personal-record (PR) leaderboard scores, and rankings. You may opt out of leaderboard visibility via your account settings.
- Communication History: Records of transactional emails sent to you (e.g., OTP codes, welcome emails, payment receipts).
1.2 Payment Information
Payments are processed through Stripe Connect. When you make a payment, your payment card
details are sent directly to Stripe and never touch our servers. We do not store full card numbers,
CVV codes, or PINs.
We do store the following payment method information locally (mirrored from Stripe for display purposes):
- Card brand (e.g., Visa, Mastercard)
- Last four digits of the card
- Card expiration month and year
This stored information allows us to display saved payment methods in your account.
Test-mode payment methods (used during sandbox/testing) are stored separately with an
is_test_mode flag and are never mixed with live data.
1.3 Information Collected Automatically
Standard web server logs may include IP addresses, request timestamps, and user-agent strings. These are used exclusively for operational purposes (monitoring, debugging, and abuse prevention) and are not used for analytics or profiling.
No Cookies. We do not use cookies, tracking pixels, local storage, or any other client-side storage mechanism for tracking. There are no session cookies, persistent cookies, or third-party tracking scripts on our platform.
1.4 Information from Third-Party Sources
- Stripe: We receive webhook events from Stripe regarding payment status changes, subscription updates, and dispute filings.
- Instagram: Gym administrators may choose to display their gym’s public Instagram content on their website. We fetch publicly available Instagram posts using the official Instagram API. We do not collect personal information about Instagram users who interact with these posts.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To create and manage your account, process bookings, manage memberships and subscriptions, process payments via Stripe Connect, and deliver the core functionality of the platform.
- Communication: To send transactional emails (OTP codes for login, welcome emails, payment receipts, booking confirmations, and account notifications) via Mailjet.
- Internal Analytics: To understand aggregate usage patterns, improve our platform, and generate business intelligence. We export anonymized and pseudonymized data to Parquet files on disk for analysis via DuckDB. These exports include email, first name, last name, gender, date of birth, avatar reference, booking history, and subscription data. These exports are retained for 90 days and are used exclusively for internal reporting — never shared externally or used for marketing.
- Geocoding: When gym administrators enter an address, we may send it to the OpenCage Geocoding API to obtain latitude/longitude coordinates for map display.
- Security: To protect the platform against unauthorized access, abuse, and fraud.
- Legal Compliance: To comply with applicable legal obligations.
3. Legal Basis for Processing
3.1 New Zealand Privacy Act 2020
As a New Zealand company, we collect, use, and disclose personal information in accordance
with the 13 Information Privacy Principles (IPPs) under the New Zealand
Privacy Act 2020. Our processing is based on the following grounds:
- Purpose of Collection (IPP 1): We only collect personal information that is necessary for the operation of our platform.
- Direct Collection (IPP 2): We collect information directly from you, not from third parties (except where you provide emergency contact details for another individual).
- Use Limitations (IPP 10): We only use your information for the purposes for which it was collected (see Section 2).
- Disclosure Limitations (IPP 11): We do not disclose your information except as described in Section 5 or as required by law.
- Security (IPP 5): We take reasonable steps to protect your information against loss, unauthorized access, and misuse (see Section 7).
3.2 GDPR (For EEA/UK Residents)
If you are located in the EEA or the United Kingdom, we also process your personal data under the following GDPR legal bases:
- Contractual Necessity: Processing is necessary to perform our contract with you (e.g., managing your account, processing bookings and payments).
- Legitimate Interests: Processing for internal analytics, security monitoring, and platform improvement serves our legitimate business interests and does not override your fundamental rights.
- Consent: Where required by law, we obtain your consent before processing certain data (e.g., optional profile fields).
- Legal Obligation: Processing necessary to comply with legal requirements (e.g., tax and accounting records).
4. Data Retention
We retain your personal data as follows:
- Account Data: Retained for the duration of your account or membership with a gym. If your membership ends, your data remains associated with your user account unless you request deletion.
- Analytics Exports: Parquet files containing denormalized user data are retained for 90 days before automatic deletion.
- Transaction Records: Retained for the period required by applicable tax and accounting laws (typically 7 years).
- Server Logs: Retained for a rolling period of 30 days for operational purposes.
5. Data Sharing and Third-Party Services
We share your information only as necessary to provide our services and as described below:
5.1 Service Providers
We engage trusted third-party service providers to help us operate our platform. These providers are contractually bound to protect your information and may only use it for the purposes we specify. Categories of service providers include:
- Payment Processing: Payment card details are sent directly to our payment processor and never stored on our servers. We receive back only a payment method token, the card brand, last four digits, and expiry date for display purposes.
- Email Delivery: Transactional emails (OTP codes, receipts, account notifications) are sent through our email service provider.
- Cloud Infrastructure & File Storage: User-uploaded content such as avatar images and gym logos are stored via our cloud storage provider.
- Geocoding: Address strings may be sent to a geocoding provider to obtain geographic coordinates for map display.
- Social Media Content: Public content from social media platforms may be displayed on gym websites at the gym administrator’s direction.
5.2 Gym Operators (Data Controllers)
When you join a gym that uses our platform, that gym is the data controller for the personal
data you provide in the context of your membership (your name, contact details, fitness data,
booking history, and payment records). Ascend Tech Ltd acts as a data processor for
this data. The gym’s privacy policy governs how they use your data. We are a data controller
only for the platform account data we collect directly (your email address and name used to
create your user account).
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal process
(e.g., a court order or subpoena).
6. What We Don’t Do
We want to be clear about the following:
- No Cookies: We do not use cookies or similar tracking technologies on our platform.
- No Analytics or Tracking Scripts: We do not embed Google Analytics, Facebook Pixel, or any third-party analytics or tracking scripts.
- No Data Selling: We do not sell your personal information.
- No Advertising: We do not serve advertisements on our platform.
- No Social Login: We do not offer or use social media login (Google, Facebook, Apple, etc.).
- No Profiling: We do not engage in automated decision-making or profiling that produces legal effects concerning you.
7. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in Transit: All traffic is encrypted using industry-standard protocols.
- Encryption at Rest: Passwords are stored as hashes. Payment data is handled by Stripe, which is PCI-DSS compliant.
- Access Controls: Role-based access controls ensure that only authorized personnel and gym staff can access specific data. Users can only access data for gyms they are members of.
- Infrastructure: Our infrastructure is hosted in secure data centres with regular security updates, monitoring, and access restrictions.
7.1 Breach Notification
In compliance with the New Zealand Privacy Act 2020, we have a Privacy Officer
responsible for managing data privacy and security. In the event of a data breach that poses
a risk of harm to affected individuals, we will notify the New Zealand Privacy
Commissioner and affected individuals as required by law.
8. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the following rights regarding your personal data:
8.1 For EEA/UK Residents (GDPR)
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): You can request deletion of your personal data, subject to legal retention obligations.
- Right to Restrict Processing: You can request that we limit how we use your data.
- Right to Data Portability: You can request a machine-readable copy of your data to transfer to another service.
- Right to Object: You can object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
8.2 For California Residents (CCPA)
- Right to Know: You can request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You can request deletion of personal information we have collected from you.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
- No Sale of Data: We do not sell your personal information. You have the right to opt out of sales (there are none to opt out of).
Note on Automated Deletion and Export: You can request deletion of your account
via our
Request Account Data Deletion page. To exercise any of
these rights, please contact us at
ascendgym@proton.me and we will respond within
the timeframe required by applicable law (typically 30 days).
9. Children’s Privacy
Our services are intended for gyms and fitness studios that primarily serve individuals aged
13 and older. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal data without
your consent, please contact us immediately at ascendgym@proton.me so we can delete
the information.
10. International Data Transfers
Our servers are hosted in Sydney, Australia via Google Cloud
(subject to change). If you are located outside Australia, your personal data may be transferred
to and processed in Australia. When transferring data from the EEA or UK to Australia, we rely
on Standard Contractual Clauses (SCCs) with our service providers to ensure an equivalent level
of data protection.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by
posting the new policy on this page and updating the “Last updated” date at the top.
We encourage you to review this policy periodically.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data
practices, please contact us:
If you have an unresolved privacy or data-use concern that we have not addressed satisfactorily,
you have the right to lodge a complaint with your local data protection authority.