Legal
Privacy Policy
Contents
1. Scope & Who This Applies To
This Privacy Policy ("Policy") describes how Body Shape Fitness Studio LLC, doing business as StudioCheck ("StudioCheck," "we," "us," or "our"), collects, uses, discloses, and safeguards information in connection with the StudioCheck web application and related services (collectively, the "Service").
This Policy applies to two categories of individuals, and their rights under it differ:
- Studio Owners / Account Holders — the boutique fitness, yoga, or pilates studio that registers for and operates a StudioCheck account ("Customer," "you").
- End Clients — the individual members, students, or clients of a Customer's studio, whose data may appear within a Customer's StudioCheck account because it originates from the Customer's connected booking software ("End Client Data").
Where StudioCheck processes End Client Data, it does so as a data processor / service provider acting on the Customer's instructions, not as the party responsible for the underlying collection of that data from the end client. The Customer remains the data controller for End Client Data and is responsible for ensuring it has a lawful basis to share such data with StudioCheck. A separate Data Processing Addendum ("DPA") governs the processor relationship and is available on request to Customers who require one for their own compliance obligations.
2. Data We Collect
2.1 Information You Provide Directly
- Account information: name, email address, studio name, phone number, billing address.
- Payment information: processed by our third-party payment processor; StudioCheck does not store full payment card numbers.
- Communications: support requests, survey responses, feedback you submit to us.
2.2 Information From Connected Booking Software (Read-Only)
When you connect a third-party booking platform (e.g., Mindbody, Glofox, Momence) to StudioCheck, we access, on a read-only basis, the following categories of data solely to generate the analytics and recommendations described in the Service:
| Category | Examples |
|---|---|
| Class & scheduling data | Class times, capacity, instructor assignment, room/format, check-ins |
| Membership & package data | Package type, sessions remaining, expiration dates, pricing |
| Client engagement signals | Visit frequency, last visit date, booking/cancellation patterns |
| Revenue data | Aggregated and per-package revenue figures needed for financial analytics |
StudioCheck's integration is architected to be read-only: our Service does not have the technical ability to modify bookings, charge clients, alter membership records, or write data back into your connected booking platform.
2.3 Information Collected Automatically
- Usage data: pages viewed, features used, timestamps, session duration.
- Device/log data: IP address, browser type, operating system, referring URLs.
- Cookies and similar technologies (see Section 11).
3. How We Use Data
We use the data described above to:
- Provide, operate, and maintain the Service, including generating occupancy analytics, churn-risk alerts, and revenue-leak detection;
- Authenticate accounts and secure the Service against unauthorized access;
- Process payments and manage subscriptions;
- Communicate with you about your account, updates, and — where you have not opted out — product announcements;
- Analyze aggregated, de-identified usage trends to improve the Service (such aggregated data does not identify any individual Customer or End Client);
- Comply with legal obligations, enforce our Terms of Service, and protect the rights, property, and safety of StudioCheck, our Customers, and others.
We do not sell personal data or End Client Data. We do not use End Client Data to build cross-customer advertising profiles, and we do not share End Client Data with data brokers.
4. Legal Basis for Processing (EEA/UK Users)
Where the EU General Data Protection Regulation ("GDPR") or UK GDPR applies, we rely on the following legal bases:
- Contractual necessity — processing needed to provide the Service under our Terms of Service;
- Legitimate interests — securing the Service, preventing fraud, and improving product functionality, balanced against your rights;
- Consent — for optional marketing communications and non-essential cookies, which you may withdraw at any time;
- Legal obligation — where processing is required to comply with applicable law.
6. Data Retention
We retain account data and End Client Data for as long as your account is active and for a reasonable period thereafter to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. Upon account termination, we will delete or anonymize data within 30 days of the effective termination date, except where retention is required by law or reasonably necessary for legitimate business purposes such as fraud prevention or dispute resolution. Customers may request earlier deletion in accordance with Section 8.
7. Security Measures
We maintain administrative, technical, and physical safeguards designed to protect data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit and at rest, access controls, and regular security review. See our Security page for further detail. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Request deletion of your data, subject to legal retention requirements;
- Object to or restrict certain processing;
- Request a portable copy of your data in a structured, machine-readable format;
- Withdraw consent, where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us using the details in Section 13. We will respond within the timeframe required by applicable law. Where a request relates to End Client Data, we will direct the request to the relevant Customer (as data controller) unless we are legally required to respond directly.
9. International Data Transfers
StudioCheck may process and store data in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms, including the European Commission's Standard Contractual Clauses, to ensure an adequate level of protection.
10. Children's Privacy
The Service is intended for business use by studio owners and operators who are at least 18 years old. We do not knowingly collect personal data directly from children. End Client Data may incidentally include minors who participate in a Customer's studio programs; Customers are responsible for ensuring they have appropriate parental/guardian consent for any such data shared with StudioCheck.
12. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via the Service or by email to the address associated with your account at least 14 days before taking effect, except where a shorter period is required by law. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
13. Contact & Data Protection Inquiries
Questions, requests, or complaints regarding this Policy or our data practices may be directed to:
Body Shape Fitness Studio LLC
Attn: Data Protection
Miracle Hills 2, No. 9, Arjan, Dubai, UAE
Email: hello@studiocheckapp.com