Privacy Policy

Last updated: September 1, 2026

1. Information We Collect

We collect information you provide directly, including: name, email address, phone number, gym/studio name, billing information, and member records, which can include a member's date of birth, home address, notes, attendance, rank, bookings and purchases. We also record the network address (IP address) of a request when an account is created, when Shindo's terms or a gym's waiver are accepted, and when certain records are changed (by an administrator, or when you claim or dismiss a household record), and we count sign-in attempts per address to block abuse. We do not use analytics or tracking tools.

2. How We Use Your Information

We use your information to: provide and maintain the Service, process payments, send notifications, improve our product, comply with legal obligations, and communicate with you about your account.

3. Payment Information

We do not store full credit card numbers. Payment processing is handled by Stripe, Inc. Please refer to Stripe's Privacy Policy for information on how they handle payment data. We store Stripe customer IDs and subscription references.

4. Data Sharing

We do not sell your personal information. We share data only with the providers that run the Service: Stripe (payments and payouts), SendGrid (delivering the emails we and your gym send you), and Google, only if you choose to sign in with Google, which tells us your email address, that Google has verified it, and an account identifier we keep so we can recognise you next time. Fonts on our pages are served by Google Fonts, which receives your browser's request. We also disclose data as required by law or with your explicit consent. Gym owners and their administrators can see the member records within their own account.

5. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS), hashed passwords, and role-based access controls. However, no method of transmission over the internet is 100% secure.

6. Cookies and Tracking

We use only the cookies the Service needs to work, and no advertising or analytics cookies: a sign-in session cookie (up to 7 days), a security cookie after two-factor sign-in (24 hours), a kiosk-mode cookie on a gym's check-in tablet (kept until kiosk mode is exited), cookies that protect the sign-in form for the length of your browser session, cookies that complete a Google sign-in (15 minutes), and three short-lived cookies that return you to the right gym page after signing in (5 minutes). Your light-or-dark theme choice is kept in your browser's local storage. None of these track you, so there is no cookie banner; blocking them in your browser will prevent signing in.

7. Your Rights

Depending on your jurisdiction, you may have the right to: access, correct, or delete your personal data; object to processing; or request data portability. To exercise these rights, contact us at info@shindoapp.com.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Upon account deletion, we will remove or anonymize your data within 30 days, except where retention is required by law.

9. Children's Privacy

The Service is built for gym owners and adult members, and it does not ask for anyone's age. Children's records reach Shindo in two ways: a parent or guardian adds a child to their own household account, or a gym enters or uploads its roster, which can include a child's name, date of birth and home address. We hold those records on the gym's behalf so it can run its classes and billing, and we use them for nothing else. A child should not create a portal account of their own. If you are a parent or guardian and want a child's record corrected or removed, contact the gym or email us at info@shindoapp.com.

10. Contact Us

For privacy-related questions, email info@shindoapp.com.