Last updated: 16 July 2026
This privacy policy explains how SessionLedger collects, uses, stores, and protects information when gym Managers, PTs, and authorised business users use SessionLedger.
This policy applies to people who use SessionLedger, including business account owners, Managers, PTs, and anyone else given access to a SessionLedger account. If you use SessionLedger for a gym, studio, or other business, you should also follow that business's own privacy and data handling rules.
SessionLedger may collect and store the following types of information:
SessionLedger is designed for session tracking and business reporting. Users should not enter sensitive personal information unless it is genuinely needed for their business records. This includes health information, medical notes, government identifiers, bank details, tax file numbers, or other highly sensitive information.
Most information is collected directly from users when they sign in, create accounts, update settings, add PTs, maintain client records, enter session records, or contact support. Some information may be entered by Managers or authorised business users when they create or manage accounts for their business. Some information is collected automatically when the app is used, including technical logs, analytics data, activity timestamps, and security records needed to operate, secure, and improve the service.
SessionLedger uses information to:
Access is limited by account role and business membership. Managers can access business-level information for their business, including team members, client records, settings, session records, and reporting. PTs can access their own client records, session workflow, and relevant account information. SessionLedger administrators may access information when needed to provide support, maintain the service, investigate misuse, or meet operational, security, or compliance obligations.
SessionLedger uses service providers to run the app. This currently includes Supabase for authentication and database storage, Vercel for hosting, deployment, and analytics, GitHub for source code and project operations, and email/support services for support communications. These providers process information only as needed to provide their services to SessionLedger. GitHub is not used as the normal storage location for customer app data.
As at the date above, SessionLedger's core app database and authentication services are provided through Supabase infrastructure in Sydney, Australia, and Vercel functions are configured to run in Sydney, Australia. SessionLedger's service providers may also process information in other countries or regions where they operate, including for hosting, backup, security, analytics, maintenance, support, and related operational purposes.
SessionLedger may use necessary cookies, browser storage, and similar technologies to keep users signed in, protect accounts, and operate the app. SessionLedger may also use analytics and similar technologies to understand page views and usage patterns. This helps improve the app and identify issues. SessionLedger does not sell analytics data.
SessionLedger takes reasonable steps to protect information, including authentication, role-based access controls, database security rules, password requirements, encrypted transport where supported by hosting providers, audit records for important actions, and restricted access to service credentials. No online service can guarantee absolute security, so users must also protect their own login credentials and devices.
Managers and authorised users are responsible for the accuracy of information entered into their business account. SessionLedger performs calculations based on the data entered by users and the settings configured by Managers.
If you need personal information accessed, corrected, or deleted, contact the Manager or business account owner who gave you access to SessionLedger. Some account details can be updated in the app where that feature is available. Business account owners can access support details from the Support tab after signing in. Requests will be handled within a reasonable time, subject to security, backup, accounting, and business record-keeping requirements.
SessionLedger keeps information for as long as it is needed to provide the service, support the relevant business account, maintain backups, resolve issues, meet accounting or compliance requirements, or protect the service. Deleted information may remain in backups for a limited period before being overwritten or removed.
If SessionLedger becomes aware of a data incident affecting user information, it will investigate and take reasonable steps to contain and remediate the issue. Where required or appropriate, affected users, business account owners, or relevant regulators will be notified.
If you have a privacy question, concern, or complaint, authorised users can access support details from the Support tab after signing in. If you cannot sign in, contact the business Manager or account owner who gave you access to SessionLedger. Privacy concerns should explain the issue and the outcome being requested. They will be reviewed and responded to within a reasonable time, usually within 30 days where practical. If a privacy concern cannot be resolved directly, you may be able to contact the Office of the Australian Information Commissioner or another relevant regulator.
This policy may be updated as SessionLedger changes. The updated version will be made available in the app. Continued use of SessionLedger after an update means the updated policy applies from its stated date.