wodloop. Need help?
Legal · Last updated 2026-05-09

Privacy policy

Wodloop is a gym back-office. We hold the data your gym needs to run classes, manage members, and bill plans — nothing else. This page tells you exactly what we keep and why.

What we collect

From gym owners (you):

  • Email address and a hashed password (we never see your password in plaintext).
  • Gym name, URL slug, time zone, default capacity — the data you enter at onboarding.
  • Records you create: classes, plans, packs, coaches, member accounts.

From your members, on your behalf:

  • Email address and hashed password.
  • Booking history, late-cancel and no-show events, plan / pack consumption.
  • Strike records when our late-cancel or penalty rules trigger.

What we don't collect:

  • Payment card numbers — cards are entered on Stripe's hosted pages and handled by Stripe (PCI DSS Level 1). What lands in our database per online payment: Stripe transaction references, the amount, payment state, and the card's brand and last four digits, so your gym can recognise the payment.
  • Health data, biometric data, or anything outside the booking workflow.
  • Third-party tracking — no Facebook Pixel, no Google Analytics, no marketing cookies.

We do run our own first-party usage analytics, stored on our own servers and shared with nobody: which pages are visited and which actions are taken, with IP address and browser identifier, tied to a session and, when signed in, to your account. It exists to operate and improve the service; form contents are filtered and passwords are never recorded.

Legal basis

  • Contract — accounts, bookings, plans and payments: processing needed to provide the service you or your gym signed up for.
  • Legal obligation — invoices and accounting records (French commercial code).
  • Legitimate interest — security, error diagnosis, first-party usage analytics.

Who processes it for us

Three processors, each doing one job:

  • Stripe (payments) — Stripe, Inc., USA. Transfers rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • OVH (hosting) — OVH SAS, France. Data stays in the EU.
  • Postmark (transactional email) — ActiveCampaign LLC, USA. Transfers rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.

That's the full list. Error tracking is self-hosted on our own infrastructure — no third-party service sees crash data.

How we use it

Strictly to operate the service:

  • Authenticate you and your members.
  • Render schedules, manage bookings, run the late-cancel and no-show rules you configure.
  • Send transactional email — confirmations, password resets, booking notifications.
  • Bill your gym for the wodloop subscription (when this is wired).
  • Diagnose bugs from server-side error logs.

We do not sell, rent, or share your data with advertisers. We do not train AI models on your data.

Where it's stored

PostgreSQL hosted with OVH in France — your data stays in the EU except where a processor above says otherwise. Encrypted in transit and at rest; operational backups are encrypted and kept at most 14 days. Error tracking is self-hosted, and its payloads never include exception messages or form contents.

Cookies

Two cookies, both essential — neither is for tracking:

  • _wodloop_session — your sign-in session. Cleared on log out.
  • cldr_locale — remembers whether you picked English or French.

Minors

Wodloop is not directed at children. Gyms may not enroll members under 16 without lawful guardian consent — that responsibility sits with the gym as data controller, and we delete a minor's account at a guardian's request.

Your rights (GDPR)

If you're in the EU/EEA you have the right to:

  • Access — get a copy of your data.
  • Rectify — fix anything inaccurate.
  • Erase — close your account; we delete identifiable records within 30 days, except where law requires retention (invoices: 10 years).
  • Port — get your data in a machine-readable format.
  • Object / restrict — limit specific uses.

To exercise any of these, email privacy@wodloop.com. We respond within 30 days.

Member data: who's the controller?

For the data your gym's members give us, your gym is the data controller and wodloop is the data processor — the same way Salesforce processes data on behalf of its customers. You decide what to collect, why, and for how long. We process it on your instructions and per this policy.

If you'd like a Data Processing Agreement (DPA), email legal@wodloop.com.

Retention

  • Active accounts: held while the account is active.
  • Closed accounts: hard-deleted within 30 days, except invoices and legal records (retained 10 years per FR commercial code).
  • Server logs: 30 days.
  • Backups: 14 days.

Changes

If we change this policy materially, signed-in owners get an email and a notice on the dashboard at next sign-in. The "last updated" date at the top of this page always reflects the current version.

Contact

Privacy questions: privacy@wodloop.com. General support: support@wodloop.com.