Privacy Policy
Last updated: June 21, 2026
This Privacy Policy explains how Priyanshu, a sole proprietor based in Gurugram, Haryana, India, operating "OSM Apps" ("OSM Apps", "we", "us", or "our"), collects, uses, discloses, and protects information when you use our websites, applications, and services, including the OSM Gym product available at gym.osmapps.com (the "Services"). By using the Services, you agree to this Policy.
Two kinds of users. Our paying customers are businesses such as gyms ("Business Customers"). When a Business Customer enters information about its own members or customers into the Services, that business decides what to collect and why, and is responsible for it — we process it on their behalf and under their instructions. For that member data, the Business Customer is the data fiduciary and we act as a data processor. For the account information we collect directly from Business Customers, we act as the data fiduciary.
1. Information we collect
- Account information: when a Business Customer signs up — name, email, phone number, business name, login credentials.
- Business and operational data: information you enter to run your business — members/customers, membership plans, attendance records, and payment records you log.
- Payment information: we do not currently process online payments or collect card or bank details. The Services only record payment information that you enter (for example, fees you have collected). If we introduce online payments in future, a third-party payment processor will handle that data and we will update this Policy.
- Usage and device data: technical information such as IP address, browser type, device identifiers, pages viewed, and timestamps, collected through cookies and similar technologies.
2. Photos and images
- What's captured: where an OSM application offers photo-capture functionality (for example, profile photos), a photo is taken only when a user of the application explicitly initiates the capture.
- Where they are stored: in each customer's own private cloud storage, scoped per customer using row-level security so one customer can never see another customer's photos. OSM Apps staff do not view these photos.
- Who has access: only the customer's authorised users. OSM Apps does not share, sell, or use these photos for any purpose.
- Retention: a photo is kept for as long as its associated record exists. It is deleted when the record is erased (at the user's erasure request) or when the customer account is closed.
- Consent: the customer is responsible for obtaining consent from any individual whose photo is captured before initiating the capture.
3. Camera access
- When the camera is used: an OSM application accesses the device camera only when a user explicitly initiates a capture action (for example, tapping a "take photo" button).
- What is not captured: there is no continuous recording, no background camera access, and no audio is captured. No image is uploaded without the user's explicit action.
- Platform permissions: the operating system (Android, and iOS where applicable) requests camera permission the first time a capture is attempted. This permission can be revoked at any time from your device settings.
4. Cookies and similar technologies
- We use only essential cookies and local storage needed to keep you signed in and to make the Services work.
- We do not use third-party analytics, advertising, or tracking cookies.
- Our website loads fonts from Google Fonts, which may receive your IP address as part of serving those fonts.
5. How we use information
We use information to: create and manage accounts; operate, maintain, and improve the Services; provide customer support; send service-related communications; maintain security and prevent abuse; and comply with applicable law.
6. Legal bases and consent
We process personal data based on your consent, to perform our contract with you, to comply with legal obligations, and for our legitimate interests in operating and improving the Services. Where we rely on consent, you may withdraw it at any time, without affecting processing already carried out.
7. Sharing of information
We do not sell your personal information. We share it only with: service providers who help us run the Services (such as hosting and infrastructure providers); payment processors, if and when we introduce online payments; authorities or others where required by law, including under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023; and a successor entity in connection with a merger, acquisition, or sale of assets, subject to confidentiality.
8. Where your data is stored (cross-border transfer)
Our Services are hosted on infrastructure located in the United States. Our website and DNS are served via Cloudflare. By using the Services, you understand that your information may be transferred to and processed in the United States and other countries. We take reasonable steps to protect it wherever it is processed.
9. Data retention
We retain personal data for as long as your account is active or as needed to provide the Services, and as required to meet legal obligations, resolve disputes, and enforce our agreements. Business Customers may request deletion of their data.
10. Security
We use reasonable administrative, technical, and physical safeguards to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Data accuracy
While we make commercially reasonable efforts to ensure that data displayed in the Services is accurate, no software is entirely free from errors. You should verify critical data — especially financial and tax-related figures — before acting on it. Please refer to our Terms & Conditions for full details.
12. Your rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you may have rights to access, correct, update, or erase your personal information, to withdraw consent, to nominate another person to exercise your rights, and to grievance redressal. To exercise these rights, contact us or our Grievance Officer below. If your data was provided by a Business Customer (for example, your gym), please contact that business first, as they control that data; we will support them in responding.
13. Children
The Services are intended for use by businesses. A Business Customer may record information about members who are under 18. Where it does, the Business Customer is responsible for obtaining verifiable consent from a parent or legal guardian before adding a minor's data, as required under the Digital Personal Data Protection Act, 2023. We do not knowingly collect personal data directly from children.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Services or by email.
15. Contact and Grievance Officer
Operated by: Priyanshu (sole proprietor), Gurugram, Haryana, India.
Email: support.osmapps@gmail.com
Grievance Officer (as required under Indian law): Priyanshu, reachable at support.osmapps@gmail.com.