← Palestra Ime

Privacy Policy

Last updated: 31 August 2026

1. Who we are

Palestra Ime is gym access and membership software, built and operated by Halosoft Labs, based in Tirana, Albania (“we”, “us”).

Your gym decides that you should have an account and what your membership allows. For data protection purposes your gym is the controller of your personal data and we act as its processor, handling that data on its instructions. Questions about your membership go to your gym; questions about the software itself can be sent to [email protected].

2. Data we collect

Account details, entered by your gym when it creates your account: first name, surname, email address, and phone number if you or the gym provide one.

Sign-in credentials. Passwords you choose yourself are stored only as a cryptographic hash and cannot be read back by anyone, including us. Where your gym issues you a password instead of you setting your own, that password is also retained in a readable form so reception staff can re-send it to you on request. If you would rather gym staff could not see your password, set your own from the app or website.

Membership records: your plan, its start and end dates, the price recorded against it, and any entry allowances an administrator grants you.

Access and attendance records, generated when you use the gym: the date and time you enter and leave, which door or reader was used, whether entry was allowed or refused and why, and the resulting per-day totals of visits and time spent inside.

Technical data:the IP address associated with administrative actions on your account, and — when you sign in on a phone — your device model and operating system (for example “android · Pixel 7”), so that active sessions can be told apart.

Stored on your device only:your theme and language choice, which notices you have dismissed, and a cached copy of the screens you last viewed so the app works briefly without a connection. Your sign-in token is held in the operating system’s keychain (iOS) or keystore (Android). None of this is readable by us.

3. What we do not collect

The app contains no advertising, analytics, or third-party tracking software. It does not:

  • request or record your location
  • access your camera, microphone, photos, or contacts
  • build advertising profiles or track you across other apps and websites
  • sell or rent your personal data to anyone, for any purpose

Your entry code is a QR image drawn on your device from your account identifier. It is not a photograph and nothing is scanned by the app.

4. How your data is used

  • to decide whether to open the door when you present your entry code
  • to show you your plan, remaining entries, and attendance history
  • to let your gym administer memberships, and see who is currently inside for safety and capacity reasons
  • to send you account emails such as invitations and password resets
  • to keep the service secure and diagnose faults

Whether other members’ attendance or the live head-count is visible to you is a setting each gym chooses. Where a gym turns it off, the figure is not sent to your device at all.

No decision producing legal effects is made about you by automated means alone.

5. Legal basis

Where the GDPR applies, we and your gym rely on performance of a contract for the data needed to give you access and manage your membership, on legitimate interests for security, capacity management and fault diagnosis, and on legal obligation where records must be kept for accounting or tax purposes.

6. Who your data is shared with

  • Your gym’s staff and administrators, who can see your account, membership and attendance records.
  • Mailgun (Sinch), which delivers our account emails. Message delivery data is processed in the United States under the appropriate transfer safeguards.
  • Our hosting provider, Hetzner (Germany), which stores the database and runs the service.
  • Authorities, where we are legally required to disclose information.

Members cannot see one another’s personal details, attendance, or contact information.

7. How long it is kept

  • Account, membership, and summarized attendance (visit counts, days attended, time inside): for as long as you are a member, and afterwards for as long as your gym chooses to keep them. Your gym’s administrator controls your account and decides when it is deleted — we do not delete it automatically on a fixed schedule.
  • Raw entry/exit scan records (the individual door events behind those attendance summaries): automatically deleted after 3 months, regardless of membership status.
  • Door scanner operational logs: automatically deleted after 30 days.
  • Administrative audit records: kept alongside the account for as long as it exists, so changes to your account remain traceable.
  • Data stored on your device: until you sign out or uninstall the app.

8. Your rights

Subject to local law, you may request access to your data, correction of anything inaccurate, deletion, restriction of or objection to processing, and a portable copy. Because your gym decides what happens to your membership data, ask your gym first — it can action most requests directly, and we will assist it. You may also complain to your national data protection authority.

Accounts are created and closed by your gym, so there is no self-service deletion in the app. To close your account, contact your gym or write to [email protected].

9. Security

Traffic between the app and our servers is encrypted with TLS. Passwords you set yourself are stored hashed. Sign-in tokens are held in your device’s secure keychain or keystore and can be revoked by your gym. Access to member data is limited to your own gym’s administrators. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.

10. Children

The app itself sets no minimum age. Where a gym admits members who are minors under local law, their account must be set up, and use of the service consented to, by a parent or guardian, in line with that gym’s own policy.

11. Changes

If this policy changes materially we will update the date at the top and, where the change affects you, notify you in the app. Continuing to use the service after a change means you accept the updated policy.

12. Contact

Questions or requests: [email protected]. We’re Halosoft Labs, based in Tirana, Albania.