Privacy Policy

Last updated: July 26, 2026

This Privacy Policy describes how Vulcan Forge ("we", "us", or "our") collects, uses, and protects your personal information across all Atlas applications, including the Member App, Admin App, and Terminal App.

1. Information We Collect

We collect information to provide and improve the Atlas platform. The types of data we collect depend on which Atlas apps you use and your role within a fitness facility.

1.1 Account & Profile Information

When you create an account as a gym owner, member, or staff member, we collect:

  • Full name (first and last)
  • Email address
  • Phone number
  • Password (stored as a secure hash, never in plaintext)
  • Gender and date of birth
  • Profile photograph
  • Gym facility name and code (for gym owners)

1.2 Check-In & Access Data

When you check in to a fitness facility using the Terminal App or Member App, we collect:

  • Check-in and check-out timestamps
  • Branch/facility location visited
  • Access method used (fingerprint, RFID card, PIN, or QR code)
  • Access result (granted or denied)
  • Associated booking information (session type, time slot)

1.3 Subscription & Transaction Data

When you purchase a subscription or make a payment, we collect:

  • Transaction amount and currency
  • Payment method type (card, bank transfer, mobile money, USSD)
  • Card last four digits and card brand (received from our payment processor)
  • Transaction reference number
  • Subscription plan details (tier, billing cycle, expiry date)

We never store full card numbers. All payment card data is handled directly by our PCI-compliant payment processors (Paystack and Flutterwave).

1.4 Device Information

When you use our mobile or terminal applications, we may collect:

  • Push notification tokens (for delivering notifications)
  • Device type and operating system version
  • Application version
  • ZKTeco terminal device metadata (serial number, firmware version, MAC address, IP address) for facilities using physical check-in devices

1.5 Usage & Analytics Data

We collect anonymised usage data to improve the platform:

  • Screens and features accessed within the application
  • Session duration and frequency
  • Error logs and crash reports
  • Feature flag evaluations (to enable or disable features for your account)

2. Biometric Data

If your facility uses fingerprint-based check-in, we process biometric data in the form of fingerprint templates.

2.1 What We Collect

When you enrol your fingerprint at a check-in terminal, the device generates a mathematical representation (template) of your fingerprint. This template is a numerical encoding of fingerprint characteristics, not an actual image of your fingerprint. We store:

  • Fingerprint template data (mathematical representation)
  • Which finger was enrolled (e.g., right thumb)
  • Scan quality score at time of enrolment
  • The staff member who assisted with enrolment

2.2 How Biometric Data Is Used

Fingerprint templates are used solely for identity verification during check-in. Templates are stored on our servers and synced to ZKTeco check-in devices. When you scan your finger at a device, the device compares your live scan against the template stored locally on the device. We do not perform biometric matching on our servers.

2.3 Biometric Data Consent

Fingerprint enrolment is entirely voluntary. You may choose to check in using an RFID card, PIN code, or QR code instead. If you have enrolled your fingerprint, you may request deletion of your biometric data at any time by contacting your facility administrator or emailing contact.atlas@vulcanforge.org.

2.4 Biometric Data Retention

Fingerprint templates are retained for as long as you maintain an active membership at a facility that uses biometric check-in, or until you request deletion. Templates are deleted when your account is deleted or when you leave the facility.

3. Health & Medical Data

Certain Atlas features allow fitness facilities to collect optional health information from members. This includes:

3.1 Health Report Data

  • Age range
  • Weight and height
  • Fitness goals
  • Medical conditions (heart conditions, asthma, diabetes, high cholesterol, joint problems)
  • Exercise-related symptoms (pain, dizziness during exercise)
  • Medical fitness clearance status
  • Occupation

3.2 HMO / Health Insurance Data

If your facility supports HMO-based payments, we may collect:

  • HMO provider name
  • HMO member/enrolment ID
  • Sessions per month entitlement
  • Verification status

3.3 Health Data Consent

Health report and HMO information is entirely optional. This data is only collected when you choose to complete a health profile within the Member App. The data is accessible only to you and to authorised staff at your facility. It is not shared with third parties.

4. Payment Processing

Atlas uses third-party payment processors to handle transactions. We do not directly collect, store, or process full payment card numbers on our servers.

4.1 Member Subscriptions (Paystack)

When a gym member pays for a subscription, the payment is processed through Paystack. We send Paystack only the amount, currency, and email address to initiate the payment. Paystack handles all card data on their secure, PCI-compliant hosted checkout page. Paystack's webhook confirms the transaction, and we store only the last four digits of the card and the card brand for your reference.

4.2 Facility Subscriptions (Flutterwave)

Gym owners pay for their Atlas subscription through Flutterwave. The process is similar: we send the owner's email and name to create a hosted checkout link. Card data is handled entirely by Flutterwave. We store only the last four digits and card brand after payment.

5. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the service: Authenticating your identity, processing check-ins, managing subscriptions, and delivering the core functionality of each Atlas application.
  • Communication: Sending transactional notifications (booking confirmations, subscription updates, payment receipts) and, where permitted, promotional communications.
  • Security: Detecting and preventing fraudulent access, protecting against unauthorised transactions, and maintaining the integrity of the platform.
  • Improvement: Analysing aggregated and anonymised usage patterns to improve features, fix bugs, and optimise performance.
  • Compliance: Fulfilling legal obligations under applicable data protection laws, including responding to lawful requests from authorities.

6. Data Sharing & Third Parties

We do not sell your personal data. We share information only in the following circumstances:

6.1 Service Providers

We work with trusted third-party services that process data on our behalf:

  • Paystack — payment processing for gym member subscriptions
  • Flutterwave — payment processing for facility (gym owner) subscriptions
  • Firebase Cloud Messaging (FCM) — delivering push notifications to mobile devices
  • PostHog — product analytics and feature flag management
  • Sentry — error tracking and crash reporting
  • Fly.io — application hosting infrastructure
  • MongoDB Atlas — database hosting

6.2 Facility Administrators

If you are a member of a gym, authorised staff at your facility (gym owners, branch managers, and front desk staff) can access your profile information, subscription status, check-in history, and any health report data you have provided. This access is necessary for the facility to manage your membership.

6.3 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, the safety of our users, or the public.

7. Data Retention

We retain your personal data for as long as necessary to provide the services and fulfil the purposes described in this policy:

  • Account data: Retained for the lifetime of your account. When you delete your account, your personal data is permanently removed from our active systems within 30 days.
  • Fingerprint templates: Retained while you have an active membership at a facility using biometric check-in. Deleted upon account deletion or when you leave the facility.
  • Health report data: Retained while you maintain an active membership. Deleted upon account deletion or request.
  • Transaction records: Retained for as long as necessary for financial record-keeping and audit purposes. After this period, records are anonymised.
  • Access logs: Retained for security and audit purposes, then periodically purged.
  • Analytics data: Anonymised and retained for product improvement. No personal identifiers are retained in analytics data.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Request a copy of your data in a structured, machine-readable format.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to object: Object to the processing of your data for certain purposes, including direct marketing.

8.1 Applicable Frameworks

Depending on your location, you may have additional rights under the Nigeria Data Protection Act 2023 (NDPA) or the EU General Data Protection Regulation (GDPR). If you are located in Nigeria or the European Economic Area, you may exercise your rights under the applicable framework.

8.2 How to Exercise Your Rights

To exercise any of these rights, contact your facility administrator (for facility-managed data) or email us directly at contact.atlas@vulcanforge.org. We will respond to your request within 30 days.

9. Data Security

We implement industry-standard security measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Passwords stored as salted cryptographic hashes, never in plaintext
  • Role-based access controls limiting which staff can view member data
  • Regular security monitoring and vulnerability assessments
  • Isolated database instances per facility to prevent cross-tenant data access

While we take reasonable precautions, no method of transmission or storage is completely secure. If you become aware of a security vulnerability, please report it to contact.atlas@vulcanforge.org.

10. Children's Privacy

Atlas is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If a parent or guardian believes their child has provided us with personal data without proper consent, they should contact us at contact.atlas@vulcanforge.org and we will promptly delete the information.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the Atlas application or via email. Your continued use of the Atlas platform after such changes constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Vulcan Forge

Atlas Platform

Email: contact.atlas@vulcanforge.org

Website: vulcanforge.org

Disclaimer: This privacy policy is a template draft prepared for Atlas applications. It should be reviewed by a qualified legal professional before publication to ensure compliance with all applicable laws and regulations in your jurisdiction.