1. Who is responsible for information
AFXPT is the operator of afxpt.com, a sports and fitness organization management service based in Muscat, Oman. For website enquiries, demo requests, account administration, platform security, and AFXPT-operated backups, AFXPT determines how and why information is used.
For member, guardian, attendance, membership, payment, health, nutrition, and communication records entered by a club or academy, that organization decides which records to collect and how to use them. The organization is responsible for its notices and permissions. AFXPT provides the platform to store and process those records on the organization’s instructions. Members should contact their club first about its records; AFXPT can help route a request.
2. Information we collect
The information depends on the feature you or your organization uses. It can include:
- Account and profile details such as name, username, email address, phone number, language, country, nationality, date of birth, gender, resident identification number, profile image, and guardian or dependent details.
- Organization and membership records such as club and branch details, staff roles, membership plans, subscriptions, class schedules, bookings, attendance and check-in events, trainer assignments, and related notes.
- Payment records such as invoice and receipt details, amounts, transaction references, refund records, and bank-transfer or registration payment proof uploaded by a member. Card details for an online checkout are handled by the payment provider rather than stored as full card numbers by AFXPT.
- Health and nutrition information when those features are used, including body measurements, health goals, food diary entries, water tracking, diet plans, meal photographs, and AI-generated nutrition estimates. This information can be sensitive; only provide it when you choose to use those features and your organization is authorized to handle it.
- Communications and files such as support requests, demo-request details, in-platform messages, notification preferences, profile photographs, uploaded documents, and other content submitted through the service.
- Technical and usage information such as browser and device details, page addresses, referring pages, service events, security logs, and information needed to keep a signed-in session working. The browser stores authentication/session values and interface preferences in local storage or session storage.
3. Website enquiries and analytics
When you request a demo, we collect the club name, contact name, email address, and any optional phone number, city, club type, and message you submit. We use those details to respond to your enquiry and arrange a demonstration. We keep the request while it is active and for a reasonable period afterward for follow-up and business records.
The public website uses a self-hosted Umami analytics script at analytics.afxpt.com. It records page views and selected website events, such as a demo request being submitted or a sign-in event, to understand site use and maintain the service. Analytics is not used to sell personal information or build advertising profiles.
4. How we use information
We use information only for service and business purposes such as:
- Creating and managing accounts, organizations, branches, memberships, schedules, attendance, invoices, and member services.
- Providing customer support, responding to demo requests, delivering notifications, and communicating service or security notices.
- Processing payments and payment proof, reconciling transactions, maintaining account balances, and preventing fraud or misuse.
- Providing optional health, nutrition, meal-scanning, reporting, and AI-supported features requested by a user or organization.
- Protecting accounts and systems, enforcing permissions, investigating incidents, troubleshooting errors, and meeting applicable legal or contractual obligations.
- Maintaining service continuity through restricted operational backups and improving reliability using aggregated service and usage information.
5. Google Drive access and backup use
AFXPT uses an OAuth connection to Google Drive for an AFXPT-operator-controlled account to store operational backup archives of the AFXPT service. The backup process uses rclone to create and manage backup files in the designated AFXPT backup folder. An archive may contain copies of the platform data and uploaded files described in this policy.
This connection is used for backup and service recovery only. AFXPT does not ask club members to connect their personal Google Drive accounts, and it does not use Google Drive data for advertising, profiling, or training generative AI models. Access is limited to the operator’s authorized systems administrators. Google processes Drive data under its own terms and privacy policy. You can review or revoke the operator’s Google account access from that Google Account’s security settings.
6. AI and nutrition features
If you use meal scanning or an AI-supported nutrition feature, the meal image and the information needed to answer the request are sent to the AI provider configured for that feature. The platform supports providers such as Google Gemini, OpenAI, Anthropic, and compatible services; the provider in use can depend on the platform’s current configuration. The AI provider processes the request to return an estimate or suggestion under its own terms and privacy practices.
Nutrition estimates may be incomplete or inaccurate and are not medical advice, diagnosis, or treatment. Do not upload a photograph containing information you do not want analyzed. AFXPT does not use submitted meal photos to train its own general-purpose AI model.
7. When information is shared
We share information only as needed to provide and protect the service:
- With the organization that manages your account and its staff, coaches, or guardians who have permission to view the relevant records. Organizations control access to their member data through platform roles and permissions.
- With service providers that operate hosting, databases, file storage, email, analytics, AI, payment, or communications features. They receive only information needed for their service and must handle it under their applicable terms and safeguards.
- With Google Drive as described above, for AFXPT’s operational backup archives.
- With Paddle when an online card payment or platform-credit transaction is offered. Paddle handles checkout and payment-card data; AFXPT receives transaction and payment-status information needed to provide the service.
- With a person or authority where required by law, to respond to a valid legal request, to protect people or the service, or to investigate suspected fraud, abuse, or security incidents.
- As part of a business transfer, if the service or its assets are reorganized or transferred. We will take reasonable steps to protect information and notify affected users where required.
8. Retention and deletion
We keep information while an account or organization uses the service and for as long as needed for the purposes described here, including billing, dispute resolution, security, and legal recordkeeping. The organization that manages member records may set or request retention and deletion for its account data; contact that organization or support@afxpt.com to make a request.
When information is deleted from the active service, it may remain temporarily in restricted backup archives until the applicable backup rotation expires. Some records may be retained where required for legal, accounting, or security purposes. We do not publish a fixed backup-retention period because it depends on the current operational backup rotation.
9. Security and international processing
AFXPT uses access controls, role-based permissions, secure connections, and operational safeguards intended to protect information from unauthorized access, loss, or misuse. No internet service or storage method can be guaranteed completely secure.
AFXPT and its service providers may process information in countries where the service infrastructure or provider operates. Where required, we use appropriate contractual or other safeguards for cross-border processing.
10. Your choices and requests
You can review and update profile information through the platform where those controls are available. You can ask your organization to access, correct, export, or delete member records it controls. You may also contact support@afxpt.com for help, and we will coordinate with the responsible organization where appropriate.
You may stop using optional health, nutrition, or AI features. You can revoke Google Drive access for the AFXPT operator from Google Account security settings. Revoking that access will stop the connected backup process from using Drive until it is authorized again.
You can contact us to ask questions about your information or to request action under applicable data-protection law. We may need to verify your identity or refer a request to the organization that controls the record.
11. Children and dependents
Organizations may manage dependent or minor-member profiles through a parent or guardian. The organization and guardian are responsible for ensuring that they have authority and any required consent before submitting a minor’s information. Contact the organization or AFXPT if information about a child was submitted without appropriate authorization.
12. Changes and contact
We may update this policy when the service or its data practices change. We will post the current version here and update the date below. Material changes may also be communicated through the service or by email where appropriate.
Questions or privacy requests: support@afxpt.com. You can also contact AFXPT through WhatsApp at +968 7184 7986. AFXPT is based in Muscat, Sultanate of Oman.