How we access studio data
AIRLAB connects to a studio's booking platform only through that platform's official, approved integration path. We do not scrape, automate staff logins, or share credentials. Access is granted by the studio, scoped to the specific data our features need, and can be revoked by the studio or the platform at any time.
We follow the principle of least privilege: we request the narrowest set of endpoints required to deliver the features a studio has chosen, and nothing more. Where a platform requires review and approval of integrations, we operate only within the scope that has been reviewed and approved.
Our security controls
Encryption in transit
All connections use TLS. Data moving between the studio's platform, AIRLAB, and the studio's team is encrypted end to end.
Encryption at rest
Stored data is encrypted at rest by our infrastructure providers, who maintain independent, audited security programs.
Per-studio isolation
Each studio's data is logically isolated with row-level access controls. One studio's users can never read another studio's data.
Secret management
API keys and platform credentials are stored as encrypted secrets, never committed to code, and never exposed in the product interface.
Role-based access
Within a studio, access is granted per person and per feature. Team members see only what their role permits.
Authenticated access only
Every part of the product sits behind authentication. There are no public data endpoints and no anonymous access to studio information.
How we use the data
AIRLAB uses studio data for one purpose: to deliver the features a studio has enabled, on that studio's behalf. We do not sell studio or member data. We do not combine one studio's data with another's. We do not use member data to train models offered to unrelated parties.
AIRLAB surfaces suggested messages a studio's team can use when they reach out; the studio sends communications through its own tools, under its own consent practices. Members can opt out at any time, and those preferences are respected.
Data retention and deletion
We retain studio data only as long as needed to provide the service, plus any period required for legitimate business or legal reasons. When a studio ends its relationship with AIRLAB, its data is deleted or anonymized on request, in accordance with our agreement and applicable law.
Infrastructure and subprocessors
AIRLAB runs on established cloud infrastructure providers that maintain their own audited security and compliance programs, including physical, network, and platform security. We use a small set of subprocessors for hosting, database, email, and messaging delivery, each selected for their security posture. A current list is available to customers on request.
Responsible disclosure
If you believe you have found a security issue in AIRLAB, we want to hear from you. Please contact us at info@airlabfitness.com. We will acknowledge your report, investigate promptly, and keep you informed. We ask that you give us a reasonable opportunity to resolve an issue before any public disclosure.
Questions
For security questionnaires, subprocessor lists, or details on any of the practices above, reach us at info@airlabfitness.com or through our contact page.