Privacy Policy

Privacy Policy

Last updated: July 20, 2026

This Privacy Policy explains how Servicios Digitales GO1, S.A.P.I. de C.V. ("Ollynk", "we", "us", or "our") collects, uses, and protects personal data in connection with the Ollynk website (ollynk.io) and the Ollynk platform and services (the "Services").

Ollynk provides software for fitness, wellness, and similar businesses ("Studios") to manage bookings, memberships, payments, loyalty, and communications, including white-label applications for the Studios' own clients.

Two roles. For data about our own customers and website visitors, Ollynk acts as the data controller (responsible). For the personal data of a Studio's end-clients that we process on the Studio's behalf through the platform, the Studio is the controller and Ollynk acts as a data processor under the Studio's instructions. If you are a member or client of a Studio, please refer first to that Studio's privacy notice.

This Policy is issued in compliance with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and other applicable data protection laws in the jurisdictions where we operate.

1. Data we collect

Account and contact data. Business/Studio name, contact person's name, email, phone, role, and login credentials (passwords are stored encrypted).

Billing data. Subscription plan, invoicing details, and transaction records. Card payments are processed by our payment processor (Stripe); Ollynk does not store full card numbers.

Platform usage data. Configuration, activity logs, features used, and technical/diagnostic data (device, browser, IP address, timestamps).

Website data. Information collected through cookies and analytics tools when you visit ollynk.io, and any data you submit through forms (e.g., demo requests, contact, newsletter).

Communications. Messages, support requests, and records of our interactions with you (by email, chat, or WhatsApp).

End-client data processed on behalf of Studios. When a Studio uses the platform, we process data about its members and clients (e.g., name, contact details, bookings, attendance, purchases, loyalty activity) strictly as a processor on the Studio's instructions.

We do not collect sensitive personal data for purposes other than operating the Services.

2. How we use data

  • Provide, operate, maintain, and secure the Services.
  • Create and administer accounts and authenticate users.
  • Process subscriptions, payments, and invoicing.
  • Provide customer support and respond to requests.
  • Send service and transactional communications.
  • Improve and develop the Services, including analytics and diagnostics.
  • Send commercial or marketing communications where permitted (you may opt out at any time).
  • Comply with legal, tax, and regulatory obligations, and prevent fraud or abuse.

4. Sharing and third parties

We share data with service providers who act on our behalf and are bound to confidentiality and security, including:

ProviderPurpose
StripePayment processing
Cloud hosting and infrastructure providersHosting and operation of the platform
Meta / WhatsApp Business (via authorized providers)Messaging and notifications
Email and analytics providersTransactional email, product analytics, diagnostics

We do not sell or rent personal data. We may disclose data when required by law or a competent authority, or to protect our rights, users, or the security of the Services.

5. International transfers

Some providers may process data outside your country. In such cases we apply contractual and technical safeguards requiring an equivalent level of protection.

6. Retention

We retain personal data for as long as an account is active and for any additional periods required by tax, accounting, and legal obligations. Afterwards, data is securely deleted or anonymized. Data we process on behalf of a Studio is retained and deleted according to that Studio's instructions and our agreement with it.

7. Security

We implement reasonable administrative, technical, and physical safeguards, including encryption in transit, access controls, and secure payment authentication, to protect data against loss, misuse, or unauthorized access.

8. Your rights (ARCO and others)

You may access, rectify, cancel, or object (ARCO) to the processing of your personal data, and where applicable withdraw consent, request deletion, or portability. To exercise these rights, contact us at the address in Section 12. If you are an end-client of a Studio, please direct your request to the Studio; we will support the Studio as processor.

9. Cookies

The ollynk.io website uses cookies and similar technologies for functionality, preferences, and analytics. You can manage cookies through your browser settings or our cookie banner where available.

10. Minors

The Services are directed to businesses and their authorized staff, and are not intended for minors. We do not knowingly collect data from minors through our own website.

11. Changes to this Policy

We may update this Policy from time to time. Changes take effect when published at this address, and we will notify you of material changes through the Services or by email. The "last updated" date indicates the current version.

12. Contact

Servicios Digitales GO1, S.A.P.I. de C.V. (Ollynk)

  • Email: contacto@ollynk.mx
  • Website: https://ollynk.io
  • Data protection requests: contacto@ollynk.mx