Privacy Policy
Last updated 26 September 2026
This explains what personal data Liftmora handles, why, who sees it and what you can do about it. We follow applicable data protection law, including Indonesia's Personal Data Protection Law (UU 27/2022).
Who is responsible
Your gym decides why and how your membership data is used, so for members the gym is the data controller. Liftmora provides the software and processes that data on the gym's behalf. For gym owner and staff accounts, and for the subscription itself, Liftmora is the controller.
What we collect
- Members: full name, email, WhatsApp number, password (stored only as a hash), an optional profile photo, membership plan and dates, check-in times and results, and payment records (amount, date, status).
- Gym owners and staff: name, email, phone number for account help and billing notices, password (hashed), and the gym's subscription and invoices.
- Technical: a secure session cookie to keep you logged in. To limit abuse we keep a keyed hash of your IP address on sign-up and password-reset requests, not the address itself.
We never see or store card numbers or bank logins. Online payments are taken on our payment provider's page.
Why we use it
- To run memberships: sign you in, show your QR code, record check-ins, extend your membership when you pay.
- To send service messages on WhatsApp: activation and password links, receipts, expiry reminders and billing notices.
- To keep the service secure and to prevent abuse and fraud.
- To keep financial records that our customers and we need for accounting and tax.
We do not sell personal data and we do not use it for advertising.
Who else handles it
- The gym you belong to, and its staff, can see your member details and history. Lists show your phone and email partly masked.
- Suppliers that run the service for us: hosting (Vercel), database (Neon), payments (Xendit or Midtrans), WhatsApp delivery (Fonnte or a similar gateway) and image storage (Vercel Blob). They handle data only to provide their service, and some are located outside Indonesia.
- Authorities, when the law requires it.
How we protect it
Phone numbers are encrypted in the database and passwords are hashed. Every gym's data is kept apart, enforced in the application and again inside the database, so one gym cannot read another's. Connections are encrypted. No system is perfectly secure; if a breach affects you we will notify you and the authorities as the law requires.
How long we keep it
We keep your data while your account exists. If you delete your account, or your gym erases you, your name, email, phone, photo and login are removed. Payment and visit records stay, with no personal details attached, because the gym needs them for its accounts.
Your rights
You may ask to see your data, correct it, restrict or object to how it is used, withdraw consent, or have it deleted, and you may complain to the data protection authority.
- Members: you can delete your account and data yourself from your dashboard (“Delete my account and data”). For anything else, ask your gym, or contact us and we will pass it on.
- Gym owners and staff: contact us.
Cookies
We use one cookie, needed to keep you signed in, plus a theme preference. There are no advertising or tracking cookies.
Children
The service is not aimed at children. A person under 18 should only join a gym with a parent or guardian's agreement.
Changes and contact
If we change this policy the date above changes, and for significant changes we will tell gym owners. Questions or requests: repstackadmin@gmail.com.