Security

How Fitnexa protects your data

A fitness center's system holds names, phone numbers, payment history, attendance and — where it is used — biometric enrolment. This page describes how that is protected, in terms specific enough to check.

One centre cannot see another centre's data

Fitnexa is multi-tenant: many fitness centers share one system. The obvious risk in that arrangement is one centre seeing another's members, and the usual defence — remembering to add a filter to every query — fails the first time someone forgets.

Isolation is enforced at the database level rather than in application code, so a query that omits the tenant filter returns nothing instead of returning someone else's data. The application connects with a role that this enforcement applies to, which is the detail that makes it real rather than decorative.

People see the screens their role needs

Access is scoped by role and by branch throughout. A trainer sees their assigned members; front-desk staff see the desk workflow for the branch they work in; a branch manager sees their location; organisation-wide revenue is visible only to the people who should see it.

Permissions are granular rather than a handful of fixed roles, so a centre that wants a staff member to take payments but not edit plans can have exactly that.

Biometric data, consent and the record of it

Face ID is optional, and a centre can run entirely on QR check-in instead. Where it is used, enrolment includes an explicit consent step recorded against the member, and matching runs server-side against a stored descriptor rather than leaving images on the device at your front desk.

Every check-in attempt — success, mismatch, timeout or staff override — is logged with a timestamp, the device, and who authorised any override.

An audit trail that answers questions after the fact

Changes to members, memberships, invoices, payments, staff and permissions are recorded with who made them and when. That is the control that matters in the moments where it is least convenient: a disputed charge, a membership someone insists was frozen, a refund nobody remembers approving.

Backups, monitoring and knowing when something breaks

Backups run on a schedule and their status is monitored rather than assumed — an unmonitored backup is a backup you find out about on the day you need it. Application and infrastructure metrics, logs and uptime checks feed alerting, so failures surface as alerts rather than as a customer report.

Reporting something

If you believe you have found a security issue in Fitnexa, contact us and we will look at it. A report gets a response; we would rather hear about a problem from you than from someone else.