Skip to main content

Security and Data Protection

Last updated: July 25, 2026

This page describes how ClassFlow handles studio and member data. It is written to be read by a studio owner rather than a security team, with concrete controls, data flows, ownership, and assurance scope. If you need something in writing for your own attorney, insurer, or landlord, email info@classflow.studio and we will answer in writing.

Payments and card data

Card details are entered directly into Stripe, which is certified as a PCI DSS Level 1 service provider. Card numbers do not reach ClassFlow servers and are not stored in the ClassFlow database. Because of that architecture, ClassFlow's own PCI scope is limited to SAQ A, the smallest assessment category.

Member payments run as Stripe Connect direct charges. They settle into your Stripe account, in your studio's name. ClassFlow's software agreement and any optional products are billed separately under the terms your studio accepts, and payment processing is disclosed separately. ClassFlow is not a payment facilitator and does not pool member payments. If you ever stop using ClassFlow, your Stripe account and its payment history remain yours and keep working.

Optional instructor payouts and partner-offer revenue splits use separately configured Stripe transfer workflows. Both are opt-in and remain distinct from member payments, which settle directly into the studio's Stripe account.

Where your data lives

Studio and member records are stored in a PostgreSQL database hosted by Supabase in the United States. Our web applications are served from Cloudflare's network. The ClassFlow API runs on dedicated Linux servers we manage at a United States data center, behind nginx with TLS certificates from Let's Encrypt. Production infrastructure is United States based.

Data is encrypted in transit over TLS. Data at rest uses database and hosting provider platform encryption, with stored third-party integration credentials encrypted separately.

Who can see your data

ClassFlow scopes studio and member records to a single studio, enforced by a database query filter applied centrally to studio-scoped models plus per-endpoint access checks. Your members, bookings, notes, and financial records are not visible to other studios through the ClassFlow application.

Within your own studio, access is governed by staff roles, so front desk staff, instructors, and administrators see different information. Member notes containing health or injury details are restricted to staff roles granted permission to view member health details, notes marked private require an administrator-only permission by default, and sales or administrative notes are hidden from instructor-only roles.

ClassFlow maintains an audit log covering administrative and financial actions including sales, checkout links, coupons, product changes, payments, and fee collection, recording the acting user, the affected record, the originating IP address, and a timestamp. Audit coverage continues to expand as additional operational workflows are added.

Authorized ClassFlow personnel can access studio data only when necessary to operate, support, or debug the service. Access is limited to the task and is covered in the data processing addendum.

Your data is yours

You own your studio's data. ClassFlow claims no ownership of it and uses it only to provide the Services to you.

Member records and financial records, including purchase, payout, and 1099 reports, can be exported to CSV while your account is active. Signed waiver records are also available as a self-service CSV export in Legal settings, including the exact text, signature evidence, consent, timestamp, checksum, IP address, and device user agent. Contact support when you need a booking or attendance-history export that is not available in the product.

Stored payment credentials move between platforms through Stripe's secure card-migration process. ClassFlow coordinates the available processor handoff as part of migration planning.

If there were a security incident

ClassFlow stores member names, email addresses, phone numbers, addresses, booking and attendance history, membership status, waiver records, studio-authored member notes, and Stripe customer references. It does not store card numbers.

If we became aware of a breach affecting your data, we would notify you without undue delay so that you can meet your own state's notification deadline, tell you what was affected, and support your notice to your members. Because your members are your customers, notice to them comes from you; we supply the facts and the affected records. We will commit to a specific notification window in a data processing addendum.

Messaging and consent

SMS is sent under your studio's own registered sender identity. ClassFlow registers each studio's A2P 10DLC brand and campaign with the carriers using your legal business name, your authorized representative, and your opt-in description, rather than routing every studio through a shared number. Carrier registration requires you to supply a published privacy policy URL and terms URL.

ClassFlow records consent per phone number per studio, separating transactional consent for class reminders, cancellations, and waitlist notices from marketing consent, each with a source and a timestamp. Opt-out replies are honored across the platform. You remain responsible for how you collect consent from your own members, including never importing purchased or scraped contact lists.

Waiver records

When a member signs a waiver in ClassFlow, we store the exact text that was presented, a checksum of that text, the waiver version, the typed signature, the name it was matched against, the acceptance timestamp, the signer's IP address, and the device user agent. That record is designed to show what was shown, to whom, and when.

ClassFlow does not warrant that any particular waiver is enforceable. Whether a liability waiver holds up is a question of state law and it varies significantly by state, including for waivers signed on behalf of a minor. Please have your own attorney review your waiver text.

Health and injury notes

ClassFlow supports member notes so instructors can safely program around an injury, a pregnancy, or a movement restriction. Those notes stay within your studio, are governed by staff roles, can be marked administrator-only, and are not sold, not shared with advertising platforms for advertising purposes, and not used to train models. Where an AI feature needs context, only the content required for that specific request is sent to our AI provider under a commercial agreement.

A fitness studio is generally not a HIPAA covered entity, so HIPAA usually does not apply. Several state privacy laws do treat health information as sensitive, and a few give individuals a direct right to sue. Because of that, our Terms address this category explicitly rather than leaving it unaddressed, which is where most platforms in this category currently sit.

Our guidance, and what our Terms ask of you: record the least sensitive information that does the job. Loaded flexion contraindicated, second trimester, cleared by provider is what an instructor needs in order to program safely. A diagnosis, an imaging result, a prescription, or a treating provider's notes is a medical record, and it should not be entered into ClassFlow. Keeping notes operational protects your studio as much as it protects us.

ClassFlow supports operational movement restrictions and instructor safety context. It is not a healthcare provider or a clinical system of record and does not offer a HIPAA business associate agreement. HIPAA-regulated clinical records belong in a dedicated clinical system.

Subprocessors

ClassFlow uses the following service providers to deliver the Services. We will notify customers before adding a subprocessor that materially changes how member data is handled.

ProviderPurposeData involvedLocation
StripePayment processing, card storage, and studio payoutsCardholder data, member name and email, transaction recordsUnited States
SupabasePrimary application database and authenticationAll studio and member records stored in ClassFlowUnited States
CloudflareWeb application delivery and network protectionRequest metadata, IP addresses, cached static assetsUnited States (global edge network)
ContaboDedicated server hosting for the ClassFlow APIAll data processed by the API in transit through the applicationUnited States
TwilioSMS delivery and A2P 10DLC sender registrationPhone numbers, message content, delivery status, studio business identityUnited States
PostmarkTransactional and studio-authored email deliveryEmail addresses, names, message content, delivery statusUnited States
OpenRouterRouting layer for AI drafting and assistant featuresOnly the content submitted for a specific AI request, which may include member contextUnited States
ExpoMobile push notification delivery, via Apple and Google push servicesDevice push tokens and notification contentUnited States
Nominatim (OpenStreetMap)Address geocoding for location and travel-distance featuresMember addresses submitted for geocodingEuropean Union
Google AnalyticsMarketing website measurement onlyWebsite visitor and page-view data. Not used inside the studio application.United States
MetaConversion measurement for studios that enable itHashed contact identifiers and purchase events, only where a studio turns this onUnited States

Integrations you choose to connect yourself, including QuickBooks and Slack, receive data at your direction and under their own terms. Error monitoring runs on infrastructure we operate rather than a third-party service.

Address geocoding uses EU-operated Nominatim only when location features are used. The Meta integration is off by default and activates only when the studio enables it. Both flows are identified here so studios can evaluate optional data paths.

Assurance scope

The current assurance scope is explicit so a studio can evaluate written controls and procurement requirements together.

  • ClassFlow provides a written security overview, data processing addendum, and written questionnaire responses. SOC 2 and ISO 27001 attestations are not currently held.
  • Stripe is the PCI DSS Level 1 service provider. ClassFlow's own scope is SAQ A because card data never reaches ClassFlow servers.
  • Availability commitments are governed by the Terms of Service and any specific commitment in a signed order form.
  • ClassFlow is designed for studio operations and movement-safety context rather than regulated clinical records, and it does not offer a HIPAA business associate agreement.
  • No system is perfectly secure, and we describe safeguards rather than guarantees.

Studio groups with specific procurement requirements can submit them during evaluation for a written control and timeline review.

Questions, reports, and agreements

To request a data processing addendum, submit a security questionnaire, ask about a specific control, or report a suspected vulnerability, email info@classflow.studio. We ask that you report suspected vulnerabilities to us before disclosing them publicly, and we will not pursue action against good-faith security research that avoids privacy violations, data destruction, and service disruption.