Legal
Last updated: 1 September 2026
This Privacy Policy explains how MembrBase (“we”, “us”) collects, uses, and shares information when you use our membership management software, our website, and our mobile apps (together, the “Service”). It applies to everyone who uses MembrBase: the business owners and managers who run a gym, club, studio or coworking space, and the members who belong to one.
If you are a business owner or manager, MembrBase is the controller of your account information and we process it to provide the Service to you.
If you are a member of a business that uses MembrBase, that business decides what member information to collect and how to use it. They are the controller of that information and MembrBase processes it on their behalf. Requests about how your gym or club uses your data should go to them first; we will help where we can.
We use no third-party advertising or analytics SDKs in our mobile apps, and we do not track you across other companies’ apps or websites.
We do not sell your personal information, and we do not share it for advertising.
MembrBase is operated from Pakistan and our servers are hosted in Europe. If you use the Service from elsewhere, your information is transferred to and processed in those locations, which may have different data protection laws than your own country.
We keep information for as long as your account is active. Membership and payment-approval records are kept while the related business account exists, because businesses rely on them as their own records. When an account is deleted we remove or anonymise personal information within 30 days, except where we must keep it longer to meet a legal obligation.
You can ask us to delete your MembrBase account and its personal information at any time. Email privacy@membrbase.com from the address on your account and we will action it within 30 days. Deleting your account removes your profile, your uploaded payment proof and your messages. Records your business must retain for its own accounting may remain with that business.
Traffic between the apps and our servers is encrypted in transit with HTTPS. Passwords are stored hashed, never in plain text, and access tokens are held in the secure storage the operating system provides. Access to production systems is limited to people who need it. No system is perfectly secure, but we take these safeguards seriously and will notify you and the relevant authority if a breach affects your information.
MembrBase is not directed at children. The Service is intended for people aged 16 and over, and we do not knowingly collect information from children under 16. A business that enrols a minor as a member is responsible for obtaining any consent required from a parent or guardian. If you believe a child has given us information, contact us and we will delete it.
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal information, to object to certain processing, and to complain to your data protection authority. To exercise any of these, contact us at the address below. We do not charge for this and we will not treat you differently for asking.
If we change this policy we will update the date at the top of this page, and tell you in the app or by email when the change is significant.
Questions about this policy, or a request about your data? Email privacy@membrbase.com.