Legal

Privacy Policy

Last updated: July 2026

2orQ is a gym-management platform operated in Egypt. This policy explains what personal data the 2orQ app and dashboard collect, why, and the choices you have. It applies to gym members and trainers using the mobile app, and to gym owners and staff using the dashboard. Our full Terms & Conditions also apply.

01

What we collect

Account & profile: name, email, phone number, date of birth, emergency contact, optional profile photo, and login credentials (passwords are stored only as salted hashes; we never store them in plain text).

Identification: your gym may record a government ID (Egyptian National ID or passport number) and an ID document image, used to verify identity for membership administration and transfers.

Membership activity: plan, membership dates, gym check-ins, class bookings, personal-training sessions, freezes, invitations, and transfers.

Payments: amounts, dates, and status of payments. Card payments are processed by Paymob; we never see or store your full card number.

Device: a push-notification token if you enable notifications. We do not collect your location.

02

How we use it

To run your membership: check-ins, bookings, payments, notifications about your membership and sessions, and messages or offers your gym sends you (including retention outreach). We do not sell personal data and we do not use it for third-party advertising.

03

Who can see it

Your gym's owner and authorized staff see the data needed to run your membership. Data is isolated per gym — one gym can never see another gym's members. Service providers that process data on our behalf: Supabase (database & file storage), Paymob (payments), Expo (push delivery), and Resend (email). Each receives only what its function requires.

04

Retention & deletion

Your data is kept while your membership is active. You can delete your account at any time from the app (Profile → Login & Security → Delete account). Deletion removes your identifying information — contact details, credentials, government ID and documents, photos, notification history and message content — immediately and permanently. Anonymous business records your gym must keep (e.g. that a payment of a given amount occurred) are retained without any link to your identity.

05

Security

Data is encrypted in transit (TLS), access is restricted per gym and per role, check-in codes are short-lived and signed, and payment callbacks are cryptographically verified. No system is perfectly secure; we work to protect your data proportionally to its sensitivity.

06

Your rights & contact

Consistent with Egypt's Data Protection Law 151/2020, you may access, correct, or delete your personal data — in the app, through your gym, or by contacting us at sales@2orq.fit. Material changes to this policy will be reflected by the date above.

This is a general template and not legal advice. 2orQ is made in Egypt, for Egyptian gyms.