Privacy

Last updated: June 2026

This policy describes how Retenr collects, uses, and protects data.

What data we collect
  • Member data you upload (name, email, phone, attendance) to calculate churn risk and generate recommendations.
  • Lead data received via WhatsApp, Instagram, or web forms (name, phone, messages) to manage follow-up and conversion.
  • Account data (owner email, gym name) and session cookies.
How we use data
  • Compute churn risk and generate prioritized save lists.
  • Reply to leads on WhatsApp (AI Employee mode) or draft messages for your approval (manual mode).
  • Generate AI-suggested messages using language models (LLMs). Your gym's data is not used to train these models.
  • Display reports, metrics, and outcome tracking.
  • Technical support and troubleshooting.
Third-party integrations
  • Meta (WhatsApp Business API, Instagram): to send and receive messages. We only process data necessary for communication.
  • OpenAI / LLM providers: to generate personalized replies. No identifiable data is sent beyond the message context.
  • Stripe: for payment processing. We do not store card data.
  • Cal.com: to book demos and calls from our contact page. It only processes the name, email, and meeting time you provide when scheduling.
Data sharing

We do not resell your data. We do not share it with third parties for marketing. We do not train models on your gym's data.

Messaging and consent

WhatsApp messages are sent on behalf of your gym, using your WhatsApp Business number. You are responsible for ensuring your leads have consented to receive communications. Retenr provides automatic opt-out mechanisms for leads who request it.

Retention and deletion

We retain data as needed to operate the service. You can request complete deletion of your gym's data by contacting us.

Member rights (GDPR Art. 15-22)

Members of the gyms can exercise their rights over their personal data. The gym is the controller and handles requests; Retenr provides the tooling to fulfil them:

  • <strong>Portability (Art. 20)</strong>: the gym downloads a JSON file with the member's full history from the member detail page.
  • <strong>Erasure (Art. 17)</strong>: the gym permanently deletes all member data. After deletion, an opaque marker (hash) is recorded to prevent re-import from external systems such as AimHarder or CSV.
  • <strong>Right to object</strong>: if a member replies STOP, UNSUBSCRIBE or similar via WhatsApp, Retenr automatically marks the profile "do not contact" and halts all automated outreach.
  • <strong>Audit log</strong>: every export, erasure and consent-state change is logged with timestamp and actor so the gym can demonstrate compliance.

To exercise any of these rights, members should contact their gym directly. The gym is the data controller; Retenr acts as data processor (GDPR Art. 28).

Contact

For privacy questions, use the contact page.

Go to Contact →