PACE FIT
// Fit Privacy Policy
// Contents
  1. Scope
  2. Who is responsible
  3. Data we collect
  4. How we use data
  5. Legal bases
  6. Sharing
  7. Retention
  8. Security
  9. Your rights
  10. Children
  11. Wellness disclaimer
  12. International transfers
  13. Breach notification
  14. Changes
  15. Contact

Privacy Policy

Last updated: 17 May 2026 · Version 1.0

This Privacy Policy explains how Pace Platforms Private Limited ("Pace", "we", "us") processes personal data when you use Pace Fit — the member-facing mobile and web experience (the "Fit App") — including streaks, ranks, leaderboards, training journal, recovery insights, and fitness centre linking.

Not the fitness centre contract

Your fitness centre's relationship with you (membership, fees, access rules) is separate. This policy covers the Fit App and Pace's role as described below. Fitness centre operators are covered by our platform Privacy Policy.

App
Pace Fit
Law
India — DPDP Act 2023
Contact
privacy@aureus.app

01 Scope

This policy applies to individuals who use the Fit App as fitness centre members ("you", "Member"). It covers data collected through the Android application, progressive web app (PWA), and any member APIs that power the Fit App.

It does not govern Pace Admin (the management app used by fitness centre staff); see our platform Privacy Policy for that product.

02 Who is responsible for your data

For most information about your fitness centre membership, attendance, and how your fitness centre uses your data, your fitness centre is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Pace typically acts as a Data Processor on the fitness centre's instructions when we store and display check-ins, ranks, leaderboard entries, and related member records synced from Pace Admin.

For certain app-only data — such as device identifiers, crash logs, optional journal entries you create only in the Fit App, and product analytics configured by Pace — Pace may act as Data Fiduciary. Where that applies, this policy describes our practices and your rights.

If you want to exercise rights about fitness centre-controlled data (for example correcting your name on the gate list), contact your fitness centre first; we will assist them as processor where required.

03 Data we collect

CategoryExamplesSource
Account & linking Mobile number, one-time passwords (OTP), fitness centre invite or link code, selected fitness centre, member profile IDYou; your fitness centre; Pace Admin
Attendance & engagement Check-in timestamps, visit streaks, rank tier, leaderboard position, points or badges shown in the appFitness centre systems via Pace; app activity
Training journal Workout notes, exercises, sets/reps, photos you attach (if enabled) You (optional)
Recovery & wellness Self-reported sleep, soreness, mood, or similar inputs; derived scores shown as insightsYou (optional); in-app calculations
Biometric access data Biometric templates or identifiers used for fitness centre gate access are processed by your fitness centre's access control; the Fit App may display linked status but does not replace your fitness centre's biometric policy Fitness centre / access hardware via Pace (where integrated)
Device & technical Device model, OS version, app version, IP address, push notification tokens, crash and performance logsAutomatic
Communications Support messages you send to us or your fitness centre through in-app channels You

We do not require payment card data in the Fit App. Billing between you and your fitness centre happens outside this app unless your fitness centre explicitly enables a future payment feature, in which case we will update this policy.

04 How we use your data

  • Authenticate you and link your account to the correct fitness centre and member record.
  • Display streaks, ranks, leaderboards, and fitness centre-specific gamification rules set by your fitness centre.
  • Store and sync your optional journal and recovery entries across your devices.
  • Send service notifications (for example streak reminders) if you opt in.
  • Maintain security, prevent abuse of leaderboards, and debug app issues.
  • Comply with law and respond to lawful requests from authorities or your fitness centre as Data Fiduciary.
  • Improve the Fit App using aggregated or de-identified analytics where possible.

We do not sell your personal data. We do not use your journal or recovery inputs for third-party advertising.

05 Legal bases (DPDP Act)

Depending on context, we rely on:

  • Consent — for optional features (journal, recovery, marketing push notifications).
  • Performance of service — to provide the Fit App you request from a participating fitness centre.
  • Legitimate uses permitted under the DPDP Act — such as security, fraud prevention, and improving service quality, where consent is not required.
  • Legal obligation — where we must retain or disclose data under applicable law.

You may withdraw consent for optional processing in app settings or by contacting us; withdrawal does not affect processing already completed lawfully.

06 Sharing and subprocessors

We share personal data only as needed:

  • Your fitness centre — staff authorised by the fitness centre can view member engagement data in Pace Admin.
  • Infrastructure providers — cloud hosting, databases, and logging within India or in jurisdictions covered by appropriate safeguards.
  • Push notification services — for example Firebase Cloud Messaging on Android, to deliver notifications you enable.
  • Professional advisers — lawyers, auditors, insurers under confidentiality.
  • Authorities — when required by valid legal process.

A current list of material subprocessors is available on request at privacy@aureus.app.

07 Retention

We retain data while your member account is active at a fitness centre on Pace and for a reasonable period afterward to resolve disputes, enforce terms, and meet legal obligations.

When your fitness centre removes your membership or you request deletion (see below), we delete or anonymise Fit App data within timelines agreed with your fitness centre as Data Fiduciary, typically within 90 days, except where longer retention is required by law or for aggregated analytics that no longer identify you.

08 Security

We use encryption in transit (TLS), access controls, audit logging on production systems, and least-privilege access for staff. No method of transmission or storage is completely secure; report suspected issues to security@aureus.app.

09 Your rights

Under the DPDP Act, Data Principals may have rights to access, correction, erasure, grievance redressal, and nomination of a contact in certain circumstances. To exercise rights:

  1. Contact your fitness centre for membership and gate-access data they control.
  2. Email privacy@aureus.app for app-specific requests; we may verify your identity via OTP.

We will respond within timelines required by law, generally within 30 days.

10 Children

The Fit App is intended for fitness centre members enrolled by a participating fitness centre. If you are under 18, your parent or guardian should review this policy with you. Fitness centres must obtain any parental consent required under local law before enrolling minors.

11 Recovery & wellness disclaimer

Recovery scores, streaks, and journal features are for motivation and general wellness only. They are not medical advice, diagnosis, or treatment. Consult a qualified professional before changing exercise or health routines.

12 International transfers

We prefer processing and storing member data in India. If data is transferred outside India, we implement safeguards consistent with the DPDP Act and contractual commitments with your fitness centre.

13 Breach notification

If we become aware of a personal data breach likely to affect your rights, we will notify affected Data Fiduciaries (your fitness centre) and, where we are Fiduciary, you and the Data Protection Board of India as required, without undue delay.

14 Changes

We may update this policy. Material changes will be communicated in the app or by email where we have your address, at least 15 days before they take effect when practicable. Continued use after the effective date means you accept the updated policy.

15 Contact

Pace Platforms Private Limited
Email: privacy@aureus.app
Grievance: grievance@aureus.app (acknowledgement within 48 hours; resolution target 30 days)

Related: Fit Terms · Pace Fit · Pace Admin Privacy

← PACE FIT
FIT PRIVACY FIT TERMS ADMIN PRIVACY ADMIN TERMS
PACE_FIT_2026