Policy 02 of 04

Privacy

The data you share with us is yours: contact details, training history, health information. This document explains what we collect, why, and how to exercise your rights over it.

Last updated · 15 May 2026

Who we are

APEX PERFORMANCE LABS (PVT) LTD (“Apex”, “we”, “us”) operates the website at trainatapex.com and the member-facing apps at app.trainatapex.com and console.trainatapex.com. Head office: B 05/05, Royal Park Condominium, 115 Lake Drive, Rajagiriya 10107, Sri Lanka. Members visit our gym branch at Alpha, Melbourne Avenue, 36 Melbourne Avenue, Colombo 4.

What we collect

  • Identity & contact. Name, email, WhatsApp number, postal address.
  • Training & health. Goals, training history, measurements, medical conditions, dietary preferences, bloodwork results where you opt into our medical assessment. This data is treated as sensitive and used only to design and deliver your programme.
  • Payment. We do not store full card numbers. Card data is captured directly by our payment processor (DirectPay Sri Lanka). We store the transaction reference, amount, and method.
  • Site analytics. Anonymised pageview data, referrer, and rough geographic region. Used to improve the site; not used to identify individuals.

How we use it

  • To respond to your enquiry and set up a consultation.
  • To deliver and personalise your programme and coaching.
  • To process payments, issue receipts, and meet our tax and accounting obligations.
  • To send service messages (booking confirmations, programme updates, refund acknowledgements). We do not send marketing email without explicit opt-in.
  • To improve our services. We may analyse aggregate, de-identified patterns of training and adherence to refine the protocols we offer.

Who we share it with

We share the minimum necessary data with the following partners, and only for the purpose of providing the service you signed up for:

  • DirectPay Sri Lanka. Card payment processing.
  • Supabase, Vercel, Resend. Infrastructure (database, hosting, transactional email).
  • Twilio. WhatsApp and SMS messaging.
  • Partner clinical labs. Where you opt into our medical assessment, your sample reference and report. We never share marketing data with these labs.

We do not sell, rent, or trade your data with any third party for advertising or unrelated commercial purposes.

How long we keep it

Active member data is kept for the duration of your membership and for seven (7) years after termination to meet legal record-keeping obligations. Marketing communications stop immediately on request.

Your rights

You have the right to access, correct, export, or request deletion of your personal data. Send a written request to info@trainatapex.com from your registered email address. We respond within thirty (30) days.

Security

All connections to trainatapex.com and our member apps are protected by TLS (HTTPS). Data at rest is encrypted by our cloud providers. Access to member records inside our team is gated by role and logged.

Cookies

This site uses only functional and analytic cookies. We do not use third-party advertising cookies or trackers.