Privacy policy

Last updated: 16 July 2026

This privacy policy explains how SessionLedger collects, uses, stores, and protects information when gym Managers, PTs, and authorised business users use SessionLedger.

1. Who this policy applies to

This policy applies to people who use SessionLedger, including business account owners, Managers, PTs, and anyone else given access to a SessionLedger account. If you use SessionLedger for a gym, studio, or other business, you should also follow that business's own privacy and data handling rules.

2. Information we collect

SessionLedger may collect and store the following types of information:

  • Account information, such as name, email address, role, account status, user ID, and login-related details.
  • Business information, such as business name, business settings, pricing defaults, session types, PT rates, client-specific pricing settings, super settings, and gym rent settings.
  • Client and session information, such as client names, optional client notes, trainer-client links, default session types, session types, session durations, session dates, number of sessions, week-ending dates, paid payroll week status, pricing override reasons, and financial calculations generated from those records.
  • Security and activity information, such as password reset and password change activity, account access status, sign-in timestamps, dashboard activity timestamps, and audit records for important business or account actions.
  • Technical and usage information, such as browser, device, page views, basic analytics, and logs collected through hosting and analytics tools.
  • Business administration information, such as billing or commercial arrangement details where SessionLedger is provided under a paid plan or other business arrangement.

3. Information users should not enter

SessionLedger is designed for session tracking and business reporting. Users should not enter sensitive personal information unless it is genuinely needed for their business records. This includes health information, medical notes, government identifiers, bank details, tax file numbers, or other highly sensitive information.

4. How information is collected

Most information is collected directly from users when they sign in, create accounts, update settings, add PTs, maintain client records, enter session records, or contact support. Some information may be entered by Managers or authorised business users when they create or manage accounts for their business. Some information is collected automatically when the app is used, including technical logs, analytics data, activity timestamps, and security records needed to operate, secure, and improve the service.

5. How we use information

SessionLedger uses information to:

  • provide login, authentication, password reset, and account management features;
  • allow Managers to create and manage PT accounts;
  • store client records, client-specific pricing settings, and session entries, then calculate session, wage, super, rent, revenue, and profit figures;
  • display dashboards, reports, filters, and business summaries;
  • record activity and audit history for security, support, and operational review;
  • maintain security, prevent misuse, troubleshoot errors, and improve reliability;
  • communicate with business account owners and authorised users about support, product updates, billing, or administrative matters; and
  • meet legal, accounting, security, or compliance obligations where required.

6. Who can see information

Access is limited by account role and business membership. Managers can access business-level information for their business, including team members, client records, settings, session records, and reporting. PTs can access their own client records, session workflow, and relevant account information. SessionLedger administrators may access information when needed to provide support, maintain the service, investigate misuse, or meet operational, security, or compliance obligations.

7. Service providers

SessionLedger uses service providers to run the app. This currently includes Supabase for authentication and database storage, Vercel for hosting, deployment, and analytics, GitHub for source code and project operations, and email/support services for support communications. These providers process information only as needed to provide their services to SessionLedger. GitHub is not used as the normal storage location for customer app data.

8. Overseas storage and processing

As at the date above, SessionLedger's core app database and authentication services are provided through Supabase infrastructure in Sydney, Australia, and Vercel functions are configured to run in Sydney, Australia. SessionLedger's service providers may also process information in other countries or regions where they operate, including for hosting, backup, security, analytics, maintenance, support, and related operational purposes.

9. Analytics and cookies

SessionLedger may use necessary cookies, browser storage, and similar technologies to keep users signed in, protect accounts, and operate the app. SessionLedger may also use analytics and similar technologies to understand page views and usage patterns. This helps improve the app and identify issues. SessionLedger does not sell analytics data.

10. Security

SessionLedger takes reasonable steps to protect information, including authentication, role-based access controls, database security rules, password requirements, encrypted transport where supported by hosting providers, audit records for important actions, and restricted access to service credentials. No online service can guarantee absolute security, so users must also protect their own login credentials and devices.

11. Data accuracy

Managers and authorised users are responsible for the accuracy of information entered into their business account. SessionLedger performs calculations based on the data entered by users and the settings configured by Managers.

12. Access, correction, and deletion

If you need personal information accessed, corrected, or deleted, contact the Manager or business account owner who gave you access to SessionLedger. Some account details can be updated in the app where that feature is available. Business account owners can access support details from the Support tab after signing in. Requests will be handled within a reasonable time, subject to security, backup, accounting, and business record-keeping requirements.

13. Data retention

SessionLedger keeps information for as long as it is needed to provide the service, support the relevant business account, maintain backups, resolve issues, meet accounting or compliance requirements, or protect the service. Deleted information may remain in backups for a limited period before being overwritten or removed.

14. Data incidents

If SessionLedger becomes aware of a data incident affecting user information, it will investigate and take reasonable steps to contain and remediate the issue. Where required or appropriate, affected users, business account owners, or relevant regulators will be notified.

15. Questions and support

If you have a privacy question, concern, or complaint, authorised users can access support details from the Support tab after signing in. If you cannot sign in, contact the business Manager or account owner who gave you access to SessionLedger. Privacy concerns should explain the issue and the outcome being requested. They will be reviewed and responded to within a reasonable time, usually within 30 days where practical. If a privacy concern cannot be resolved directly, you may be able to contact the Office of the Australian Information Commissioner or another relevant regulator.

16. Changes to this policy

This policy may be updated as SessionLedger changes. The updated version will be made available in the app. Continued use of SessionLedger after an update means the updated policy applies from its stated date.

Back to loginView terms