GymSales & Messaging Consent

What's Happening?

ABC GymSales will soon require that a record of consent be recorded each time you capture a new lead and create a new profile. Existing leads will be unaffected.

Why is ABC GymSales Making this Change?

Global privacy regulations and standards now broadly apply to almost every region of the world and impact both ABC and our customers. The General Data Protection Regulation (GDPR) in the European Union, various state laws in the United States, including the California Consumer Privacy Act (CCPA), and other similar privacy laws around the world require that businesses obtain express consent from individuals before collecting, using, or sharing their personal information. In certain instances, express consent may also be needed before a company sends certain types of messages, such as marketing messages sent via SMS or via automatic dialers. This legal requirement helps ensure that individuals are aware of and agree to how their information will be used. In fact, many jurisdictions view personal information protection as a fundamental human right.

Ultimately, you, as the controller of the personal data ABC processes, are responsible to the individuals and regulators for appropriately obtaining an individual’s consent for both you and ABC to process their personal information. ABC, as the service provider or processor, may not be able to legally process someone’s personal information (or otherwise provide you our services) if you have not obtained appropriate consent from the individual.

To assist you in your obligations, ABC’s  consent strategy is to provide certain functions and tools that you can use to help with compliance with some of the usual and customary requirements that are included in most privacy laws, including requiring an individual “opt-in” for consent, rather than “opt-out”.

Failing to obtain consent can result in hefty fines, legal actions, and damage to a company’s reputation, which you (as the data controller) would be primarily responsible for. By ensuring that consent is properly obtained, businesses protect themselves from potential legal and financial consequences. Violating any privacy law can be very expensive and lawsuits and actions for violations have become very common:

  • €20 million or 20% of GLOBAL revenue or higher in certain instances per occurrence under GDPR.
  • $2,500 - $7,500 per occurrence can be charged under CCPA, which can add up quickly where large amounts of SMS are sent without consent.

In addition, the compliance concerns, obtaining “opt in” consent where appropriate both respects data subjects’ rights and builds trust through transparency.

What do I need to do?

The best way to record and pass in consent depends on your lead capture mechanism: capturing leads via a web form or importing leads from a third party system. These lead capture mechanisms are described below.

Capturing Leads via a Web Form

We recommend providing a checkbox on your web form alongside wording similar to the following (please consult a legal expert in your specific jurisdiction for help with the exact message):

I agree to receive text messages and/or emails from [Business Name]. I can opt out at any time.

Lead data can be passed from a web form to GymSales to create a new profile in one of two ways: email forwarding or capturing leads via an API. (For more details, please see "Capturing Leads From Your Website".) The two methods for passing lead data from a web form are described below.

  1. Email forwarding:  The following is an example of the accepted format.
    • Name: Jane Smith
    • Phone:  555 555 5555
    • Email:  [email protected]
    • Address: 22 Test St
    • Source: Website Campaign
    • Tags: Interested in weightlifting, wants to lose weight
    • Email Opted Out: Yes or No
    • SMS Opted Out: Yes or No

    “No” value will opt the lead IN for email/SMS in GymSales.

    “Yes” value will opt the lead OUT for email/SMS in GymSales.

    NOTE: If no value is passed or if either field is not included in the email body, the lead will by default be opted OUT of messaging for that channel.

  2. Capturing leads via an API: The peopleCreate method on the GymSales API can also be used to capture leads and create profiles. You can review our complete API documentation here: https://login.gymsales.net/api-docs.

    The parameters related to email and SMS consent are as follows:

    • sms_opted_out: TRUE or FALSE
    • email_opted_out: TRUE or FALSE

    “FALSE” value will opt the lead IN for email/SMS in GymSales.

    “TRUE” value will opt the lead OUT for email/SMS in GymSales.

    NOTE: If no value is passed (NULL) or if either parameter is not included in the API request body, the lead will by default be opted OUT of messaging for that channel.

Importing Leads from a Third-Party System

If you are importing leads from a third-party system, please note which Member Management Systems (MMS) automatically pass or do not pass a record of consent to GymSales. 

The following MMS automatically pass a record of consent to GymSales:

  • Circuit
  • Clubwise
  • DataTrak/M&O
  • Glofox
  • Hapana
  • Jonas Fitness
  • Jonas i4:
  • Mindbody

The following MMS do not pass consent to GymSales:

  • ASF
  • Club Automation
  • MotionSoft
  • Peak
  • Virtua Gym

If you are using an MMS that does not pass consent, we assume that consent has been recorded in that system. It is your responsibility to maintain a record of consent separately in GymSales if needed. 

To avoid this issue, we recommend sending new leads to GymSales first (i.e., from your website) and then exporting the lead from GymSales to your integrated MMS.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us