Legal
Privacy Policy
Last updated: September 27, 2026
Public page. No login is required. Canonical URL: https://www.dropinradar.com/privacy
This policy explains what DropInRadar collects and why, including when Muse calls our connector API. Support: support@dropinradar.com.
- Who we are
- Scope
- Roles
- Data
- Sources
- Purposes
- Sharing
- Muse
- Retention
- Security
- Transfers
- Your rights
- Children
- Cookies
- Changes
- Contact
01 Who we are
DropInRadar operates dropinradar.com. We provide software that helps gyms and studios fill last-minute class seats, and a public API that discovery clients, including Muse, can call. Contact support@dropinradar.com.
02 Scope
This policy covers:
- The DropInRadar website.
- The gym and studio SaaS product.
- The Muse connector and the public API that Muse and other authorized clients call.
It does not cover a gym’s own website, booking system, or payment processor. Those services have their own policies.
03 Roles
- Gyms and studios are our customers. They decide what inventory is published.
- Athletes are end users of discovery. They can find an opening and follow a link to the gym. They are not DropInRadar payment customers.
- Muse (a Meta product) is a client of our API when a person connects the DropInRadar connector. We process the request metadata needed to return openings. We do not receive Muse chat transcripts, and we do not receive the person’s Muse account password.
DropInRadar is not affiliated with Meta. If the connector is approved and listed in the Muse directory, that listing does not make Meta a party to a booking between an athlete and a gym.
04 Categories of data
Gym and business
Business name and contact details, account information, the schedule and openings a gym provides, API keys, and subscription status when a gym subscribes.
Athlete or consumer, via the connector
Location and other query parameters that the person, or Muse on their behalf, sends when searching for openings, and book-link click events. We do not create athlete payment accounts. We do not store payment card numbers.
Technical
IP address, user agent, timestamps, and similar logs, used for security and operations.
05 Sources
- Gyms and their staff, when they create an account or publish inventory.
- Muse and other API callers, when they send a search or related request.
- You, when you email us or otherwise contact us through the website.
06 Purposes
- Provide discovery and the openings API.
- Operate the gym SaaS, including the inventory a gym chooses to publish.
- Authenticate requests and protect the service.
- Answer support requests.
- Understand whether the product is working and improve it.
- Comply with law.
07 Sharing
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not share athlete payment data, because we never hold it.
Processors may handle data only as needed to run DropInRadar:
- Vercel: hosting.
- Resend: email.
- Whop: gym subscription payments, when that checkout is live. Not athlete class fees.
- Mindbody Public API: schedule sync, when a gym connects it.
We may also disclose information if the law requires it, or to protect the service and its users. Gym booking pages are third-party sites. Once someone follows a deep link, that gym’s policy applies.
08 Muse connector
The connector discovers gym class openings. It does not accept payments in Muse. There is no Stripe Link and no athlete checkout through DropInRadar.
Authentication uses an API key (GYM_API_KEY). In Muse, that key is stored in Muse’s Secure Credentials Store. DropInRadar receives authenticated API requests that present the key. We do not receive the user’s Muse account password.
When a person connects DropInRadar in Muse, Muse may send those authenticated requests with search criteria. We use the criteria to look up openings. Responses include the business inventory the gym has published (such as place, class, time, and availability) and deep links to the gym’s booking page. Booking and payment then happen on that gym’s system, under the gym’s own policies.
09 Retention
We keep gym account information while the account is active. We keep operational and security logs for a limited period after that, long enough to secure the service and handle support. You can ask us to delete or export personal information at support@dropinradar.com. We may retain what we must keep for legal, security, or accounting reasons.
10 Security
We encrypt traffic in transit with TLS. API access uses scoped keys, and we limit access to what is needed to operate the service. No method of transmission or storage is perfectly secure.
11 International transfers
DropInRadar is based in the United States. Hosting, email, and other processors may process information in the United States and in other countries where they operate. If you use the service from outside the United States, your information may be transferred there.
12 Your rights
Depending on where you live, you can ask us to access, correct, or delete personal information we hold about you. Email support@dropinradar.com. We will respond within the time the applicable law requires. We will not discriminate against you for making a request.
California. We do not sell personal information, and we do not share it for cross-context behavioral advertising. California residents may request access, deletion, or correction at the same address.
EEA, United Kingdom, and Switzerland. You may also have the right to restrict or object to certain processing, to receive a portable copy, and to lodge a complaint with a supervisory authority. Where those laws apply, we rely on contract (providing the service to a gym customer), legitimate interests (security and operating the discovery API), legal obligation, and consent where the law requires it.
13 Children
The service is not directed at children under 13, or under 16 where that higher age applies. We do not knowingly collect personal information from those children. If you believe we have, email support@dropinradar.com and we will delete it.
14 Cookies
We use essential cookies needed to operate the marketing site and, if we add an account portal, to keep a signed-in session. We do not use advertising cookies. We do not use optional analytics cookies on this site.
15 Changes
We may update this policy. The date at the top will change when we do. Continued use of the service after an update means you accept the revised policy.
16 Contact
DropInRadar
https://www.dropinradar.com
support@dropinradar.com
See also our Terms of Service.