technology

Member Data Export: Who Owns Your Studio's Client List?

Learn how to export member data from gym software, who owns your studio's client list, and how to move contacts, contracts and card data safely.

The Zatrovo TeamThe Zatrovo Team· September 27, 2026· 11 min read

Your contract with your vendor decides who owns your client list, not the software itself. Many agreements say the data is yours, but ownership only counts if you can actually move it. Use the 3C Export Test: can you pull Contacts, Contracts and Cards out cleanly, today, without asking anyone's permission?

Who legally owns your studio's client list?

You usually do, but your vendor's terms of service decide what "your data" covers and how long you can still reach it after canceling.

Asking who owns the list is less useful than asking whether you can get to it. Open your vendor's terms and search for four words: "customer data," "termination," "export" and "retention." You are looking for three answers.

First, the definition. Does "customer data" include attendance history, instructor notes and signed waivers, or only names and emails? Second, the window. How many days after cancellation can you still log in? Third, the format. Is export self-serve CSV, or a support ticket that someone else processes when they get to it?

The trap is timing. Say you give notice on the 1st, the account locks when the billing cycle ends, and your new system needs three weeks to import. Now you are migrating from a locked account. Export first, give notice second.

What does the 3C Export Test check?

It checks the three layers every studio needs to keep running after a move: Contacts, Contracts and Cards. Each one leaves your system by a different route.

Contacts are the easy layer. Contracts are where studios lose money. Cards are where studios lose members. Many "we exported everything" stories only cover the first.

The 3C Export Test, plus history. Paths vary by vendor, so confirm each row in writing before you give notice.

History is the quiet fourth layer. Lose it and every member looks brand new on day one, which blinds any at-risk member detection you depend on to catch people drifting away.

Why is card data the layer most studios lose?

Card industry rules (PCI DSS) keep saved cards out of spreadsheets, so they only move between compliant payment processors, and only when both sides cooperate.

Stripe's documentation on payment data exports sets out how this works in practice. Stripe will only transfer card data to another PCI DSS Level 1 compliant processor. It needs that processor's Attestation of Compliance and a public encryption key. The same page says the export file does not include payment history or subscriptions. You pull those separately through the dashboard or API.

So the question to ask on day one with any software is simple: whose merchant account are the cards on? If the cards live on your own processor account, you control the transfer. If they live on the vendor's account, you depend on the vendor agreeing to hand them over.

If you are rethinking payment methods anyway, a move is a good time to compare ACH and credit card billing for studios, because bank details bring their own transfer rules.

What should a clean member export actually contain?

One row per member, including frozen and paused accounts, with correct phone formats, readable dates, remaining credits and the next billing date on each row.

Default reports lie by omission. Say your dashboard shows 340 active members and the export returns 312 rows. The missing 28 are often frozen or paused members, dropped by a filter set to "active only." Those are the people most likely to come back, and they are the ones you just lost.

Open every CSV in a spreadsheet before you trust it. Check these five things:

  • Phone numbers kept their leading zeros and country codes
  • Dates came through in one consistent format, not a mix of US and day-first styles
  • Class pack credits show the real remaining balance, not the original pack size
  • Waivers exist as signed PDFs, not just a "waiver: yes" column
  • Marketing consent is a separate field from account email, so you don't email people who opted out

If your vendor offers an API, a scripted pull is more reliable than clicking through reports. It's the same plumbing covered in our guide to API booking integration for studios.

How do you run a quarterly export fire drill?

Pick a fixed date each quarter, pull every report, reconcile counts, spot-check five members by hand, then store one encrypted copy and delete the old one.

Call it the Quarterly Export Fire Drill. Put it in the calendar for the first Monday of January, April, July and October.

  1. Pull every member, plan, payment, attendance and waiver report.
  2. Match the member row count to the dashboard. Chase every gap.
  3. Pick five members at random, including one frozen member, one on a class pack and one on autopay. Compare their rows field by field against their live profiles.
  4. Save the files to one encrypted folder that only the owner can open.
  5. Delete the previous quarter's copy.

The first run takes an afternoon. After that it's routine. The real payoff is that you find a broken report in a calm week, not in the week you've given notice.

What do privacy laws say about member data exports?

Privacy laws give members rights over their own data, and some of them only apply above certain size thresholds. Most independent studios sit below those lines.

In California, the Attorney General's CCPA overview says the law applies to for-profit businesses that meet at least one threshold. Two of them are gross annual revenue over $25 million (a figure adjusted periodically for inflation), or buying, selling or sharing the personal information of 100,000 or more California residents or households. Covered businesses must respond to consumer requests within 45 calendar days, and can extend that to 90 days if they notify the consumer.

If you serve members in the EU, Article 20 of the GDPR gives people the right to receive the data they provided "in a structured, commonly used and machine-readable format" and to have it sent to another controller where technically feasible. Whether or not a law applies to you, it's a useful standard to hold your own vendor to.

What contract clauses decide whether you can leave?

Four clauses decide it: the data definition, the export format and fee, the post-termination access window, and a written confirmation that your data was deleted.

Negotiate these when you sign, because that's when the vendor most wants your business. At renewal or exit, you have far less pull. Ask for:

  • Definition: customer data explicitly includes attendance, notes, waivers and purchase history.
  • Format and fee: self-serve CSV at no charge, plus help with a card transfer to a compliant processor.
  • Access window: read-only login for a set period after cancellation. Get the number of days in writing.
  • Deletion: written confirmation once your data is purged from their systems.

If a vendor won't put any of these in writing, treat that as your answer.

How do you switch software without losing members?

Run an overlap month. Export while the old system is still live, move the cards, tell members before their first new charge, and cancel last.

The sequence that avoids surprise charges:

  • Week 1: Run the full Quarterly Export Fire Drill. Request the card transfer and name your new processor.
  • Week 2: Import the data and reconcile credits and next bill dates for every member on autopay.
  • Week 3: Email members at least 14 days before their first charge on the new system. Name the date, the amount and the new descriptor they'll see on their statement.
  • Week 4: Run both systems side by side for bookings. Cancel the old one only once the first billing run on the new system reconciles.

A charge with an unfamiliar name on a statement looks like fraud to a member. A clear notice email ahead of the first charge heads off many disputes before they turn into chargebacks.

What should you delete instead of exporting?

Anything you don't need to run the studio. Every extra field you keep is a liability if a laptop, an inbox or a shared drive gets compromised.

The FTC's guide to protecting personal information puts it plainly: "Keep only what you need for your business," and dispose of the rest properly. At a studio that usually means:

  • No card numbers in spreadsheets or notebooks, ever
  • Old quarterly export files deleted once the new one checks out
  • Paper intake forms shredded once they're scanned, subject to your waiver retention rules
  • Former staff removed from admin access the day they leave

Ask your insurer or lawyer how long you must keep signed waivers. That's the one record where deleting too early can hurt you more than keeping it.

Zatrovo

Run your studio on Zatrovo

Keep your member list, plans and attendance history in one place you control and can export on your terms.

Start 14-Day Free Trial
See it in Zatrovo
The Zatrovo Team
Written by
The Zatrovo Team
Studio operations research

We write playbooks for studio operators — based on data from thousands of studios running on Zatrovo across pilates, yoga, lash, nail, massage, salon, dance, and fitness.

Related reading