This Privacy Policy explains how Progress Core Sdn. Bhd. (“Progress Core”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data when you use the Progress Core mobile application, web portal, and supporting APIs (together, the “Service”).
Progress Core is a software platform that lets independent personal trainers manage their clients, training sessions, packages, invoices, and retention workflows. Most of the personal data we process belongs to the trainer’s own clients — the trainer is the data controller of that information, and Progress Core acts as the data processor on the trainer’s behalf.
We comply with the Personal Data Protection Act 2010 of Malaysia (“PDPA”) and apply equivalent safeguards for users outside Malaysia.
01 Who this policy applies to
The Service has three categories of users, and the data we hold differs for each:
- Trainers — personal trainers who sign up directly for a Progress Core account (trial, lifetime, founder, or paid subscription).
- Clients — individuals invited into the Service by a trainer to track sessions, packages, and invoices with that trainer.
- Visitors — anyone who browses our marketing pages, joins the waitlist, or contacts us without creating an account.
02 What personal data we collect
Account & identity
- Name, email address, mobile phone number, password (stored only as a one-way hash).
- Role (trainer / client / admin), account status, locale, and timezone.
- Email verification timestamp and password-reset tokens.
Trainer profile
- Business or brand name, specialisation, biography, and avatar image.
- Service areas (state, city, area, sub-area) you choose to advertise.
- Gyms you operate at (name, location, contact phone).
Client profile (entered by the trainer or the client)
- Date of birth, gender, height, weight, training goals, injuries or medical notes, avatar.
- WhatsApp number used for follow-ups and renewal nudges.
Training & commercial records
- Sessions logged (date, type, duration, remarks), packages purchased, attendance, streaks, and retention metrics.
- Invoices, payment status, payment method (card, FPX bank transfer, cash recorded manually), refund history.
- Payout bank details for trainers — we store the bank name, the account holder’s name, and the last four digits of the account number. The full account number is sent directly to Rapyd and never persisted in our database.
Device & usage
- Firebase Cloud Messaging (FCM) push notification tokens issued by your device.
- API access tokens issued by Laravel Sanctum when you sign in.
- IP address, browser, and user-agent — logged when you submit a helpdesk ticket and in standard server access logs for abuse prevention.
- Calendar feed token used to subscribe an external calendar app to a read-only iCalendar (ICS) feed of your training schedule.
- If you opt in from the mobile app, copies of your upcoming sessions written locally to your device's native calendar through Apple's EventKit / Android's CalendarContract APIs. This is a device-only interaction — we do not transmit anything to Apple or Google's calendar servers ourselves, and you can revoke calendar access at any time from your device settings.
Marketing & support
- Waitlist sign-ups (name, email, WhatsApp, business context).
- Helpdesk tickets you submit (category, message body, contact details snapshot).
We do not intentionally collect special categories of data such as racial origin, political opinions, religious beliefs, or genetic data. Health-adjacent fitness data (weight, injuries, goals) is collected only because it is essential for the trainer’s coaching workflow; you may leave these fields blank.
03 How we use your data
| Purpose | Lawful basis |
|---|---|
| Provide the Service: authenticate sign-in, render dashboards, sync sessions, generate invoices. | Performance of contract with you. |
| Process trainer subscriptions via Stripe (lifetime, monthly, annual) and trainer-to-client billing via Rapyd. | Performance of contract; legitimate interest in operating the platform. |
| Send transactional email (verification, password reset, payment receipts, invoice delivery) and push notifications (session reminders, renewal nudges, streak alerts). | Performance of contract. |
| Compose pre-filled WhatsApp messages that open in the trainer’s installed WhatsApp app for client nudges and invoice handoffs. The message is sent by the trainer, from the trainer’s own WhatsApp account — Progress Core does not transmit message contents to Meta servers. | Performance of contract; legitimate interest of the trainer. |
| Compute retention scores, streaks, and nudge suggestions so the trainer can act on at-risk clients. | Legitimate interest of the trainer (controller); processor instruction. |
| Triage helpdesk tickets and reply to support requests. | Performance of contract. |
| Detect, prevent, and investigate fraud, abuse, and security incidents. | Legitimate interest; legal obligation. |
| Comply with tax, accounting, and anti-money-laundering obligations in Malaysia. | Legal obligation. |
| Send product announcements and beta invitations to trainers and waitlist signups (unsubscribe in any email). | Consent. |
We do not use your data to train third-party machine-learning models, and we do not sell, rent, or trade personal data to advertisers or data brokers.
04 Who we share data with
We rely on a short list of trusted sub-processors to operate the Service. Each has been selected for its security posture and contractually limited to using your data only for the purpose stated below.
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe Payments Singapore Pte Ltd | Trainer subscription billing (lifetime / monthly / annual) and card processing. | Singapore / EU / US |
| Rapyd Financial Network | Trainer-to-client payment collection and payouts in MYR (FPX, cards). | Singapore / EEA |
| Google Firebase Cloud Messaging | Push notification delivery to the Flutter mobile app. | United States |
| Mailgun (Sinch Email) | Transactional and product email delivery (account verification, password reset, invoices, helpdesk replies). | United States or EU region, depending on Mailgun account provisioning. |
| Cloud hosting provider | Application hosting, database, file storage, server logs. | Asia-Pacific region |
WhatsApp / Meta is not a sub-processor of Progress Core. When a trainer taps “Send via WhatsApp” on a nudge or invoice, the mobile app opens the trainer’s installed WhatsApp client with a pre-filled message and recipient number. The message is then sent by the trainer, from the trainer’s account, using WhatsApp’s own infrastructure under WhatsApp’s privacy policy. Progress Core does not transmit the recipient’s phone number or message content to Meta on the trainer’s behalf.
Similarly, the device-calendar sync (Apple Calendar / Google Calendar) described in § 02 is performed locally on the device through the operating system’s calendar API. Apple and Google are not sub-processors of Progress Core for this purpose — the data flows from your device to your own calendar account.
We may also disclose personal data when required to do so by a valid court order, regulator, or law-enforcement request under Malaysian law, or where necessary to enforce our Terms of Service or protect the rights, property, or safety of Progress Core, our users, or the public.
If Progress Core is involved in a merger, acquisition, or sale of assets, we will notify trainers in advance and ensure that any successor entity is bound by privacy obligations no less protective than this Policy.
05 Trainer ↔ client relationship
When you sign up as a trainer, you become the data controller for the personal data of clients you invite into your account. Progress Core is the data processor — we hold and process that data only on your instructions, as expressed through your use of the Service.
As a trainer, you are responsible for:
- Obtaining your client’s consent (including consent to be contacted via WhatsApp, SMS, email, or push) before adding them to the Service.
- Keeping client records accurate and deleting them when the coaching relationship ends.
- Responding to your client’s privacy requests (access, correction, deletion) within statutory timeframes.
If you are a client and want to update or remove your data, please contact your trainer first. You may also email us at privacy@progresscore.app and we will route the request appropriately.
06 How long we keep your data
- Active accounts — retained while your account is in use.
- Closed accounts — personal identifiers (name, email, phone, WhatsApp, DOB, gender, height, weight, goals, injuries, avatars, bio, brand name) are anonymised on account deletion. Aggregate training records (sessions, packages, invoices) are retained in anonymised form for statistical and tax purposes.
- Financial records — invoices and payment records are retained for at least seven (7) years to satisfy Malaysian tax law (Income Tax Act 1967 and Goods and Services Tax record-keeping requirements where applicable).
- Server and security logs — retained for up to 90 days unless required longer for an active investigation.
- Marketing & waitlist data — retained until you unsubscribe or request deletion.
07 How we secure your data
- All traffic between your device and our servers is encrypted in transit using TLS 1.2 or higher.
- Passwords are stored as one-way bcrypt hashes — we cannot recover the plaintext, even for you.
- API access uses short-lived bearer tokens issued by Laravel Sanctum; tokens are revoked immediately on logout or account deletion.
- Payment-card data and full bank-account numbers never touch our servers — they are tokenised by Stripe and Rapyd respectively.
- Stripe and Rapyd webhook payloads are verified using signed secrets before being acted upon.
- Access to production data is restricted to a small number of authorised engineers, logged, and protected by multi-factor authentication.
No system can be guaranteed 100% secure. If we become aware of a personal-data breach that is likely to result in significant harm to you, we will notify affected users without undue delay and, where required, the relevant authorities.
08 Your rights under the PDPA
You have the right to:
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or out of date — most fields can be edited directly in the app.
- Withdraw consent for any processing that relies on consent (such as marketing emails).
- Limit our processing of your personal data in certain circumstances.
- Delete your account, which triggers our anonymisation routine for personal identifiers.
- Lodge a complaint with the Personal Data Protection Commissioner of Malaysia if you believe your rights have been infringed.
To exercise any of these rights, write to privacy@progresscore.app. We will respond within twenty-one (21) days. We may ask you to verify your identity before acting on a request.
09 International transfers
Some of our sub-processors (notably Stripe, Firebase, and email providers) process data outside Malaysia. We rely on contractual safeguards equivalent to PDPA standards — including the providers’ standard data-processing agreements — before transferring data abroad.
10 Cookies and similar technologies
The marketing site and web portal use a strictly necessary first-party session cookie to maintain your sign-in state and a CSRF token cookie to protect form submissions. We do not currently deploy third-party advertising or cross-site tracking cookies. If we add analytics in the future, we will update this Policy and surface a cookie banner where required.
11 Children
Progress Core is intended for adult trainers and their clients. Trainers must be at least eighteen (18) years old to register an account — see § 01 of the Terms of Service.
Where a trainer onboards a minor (for example, a junior athlete) as a client, the trainer must obtain verifiable consent from the minor’s parent or legal guardian before entering personal data into the Service. We do not knowingly process personal data of children under sixteen (16) without such consent. If you believe we hold personal data of a child without proper guardian consent, contact us at privacy@progresscore.app and we will delete it.
12 Changes to this Policy
We may update this Policy from time to time. The “Last updated” date at the top of this page will reflect the most recent revision. Material changes will be communicated by email to active trainers and via an in-app banner at least fourteen (14) days before they take effect.
13 Contact us
Progress Core Sdn. Bhd.
Kuala Lumpur, Malaysia
Privacy enquiries: privacy@progresscore.app
General contact: hello@progresscore.app