Skip to main content
    All case studies
    BlueprintFitness & 24/7 gyms

    24/7 Gym Member App With Mobile Door Access

    A member app for unstaffed 24/7 gyms: phone-based door entry, anti-passback, class booking, membership freezes, live occupancy and staff alerts.

    An example of how we'd build this for a company in this niche: the plan, the architecture and the targets we'd start from. Not a specific client's story.

    Target
    < 2 s
    from QR scan to door release at the pilot club, verified before roll-out
    Target
    < 5 min
    for a cancelled or frozen membership to lose door access, from launch
    Target
    –30%
    access-related support requests within six months of launch
    The situation

    Who this is for

    Picture an operator of 8–15 gyms that are open 24/7 but staffed only at peak times, where members get in with key fobs and book classes in a separate app. Every lost fob, failed payment and shared login lands on a small ops team, and the door system has no idea who has actually paid. The goal is one member app that opens the door, follows membership status in real time and alerts staff remotely when something at the door looks wrong.

    The hard part

    What makes it hard

    • Tailgating and credential sharing cost unstaffed clubs revenue, and a door that simply unlocks can't tell one member from three.
    • The access controller, billing system and booking tool each keep their own member list, so a cancelled or frozen member can often still get in for days.
    • Many clubs sit in basements or retail units with weak mobile signal, and the door still has to open for a paying member at 5 a.m.
    • Failed direct debits, freezes and upgrades should change door access automatically, without staff chasing members one by one.
    • With nobody on site, someone still has to hear about a panic button, a door propped open or a room over capacity.
    The product

    What we'd build

    Phone-based door entry

    Rotating QR codes in the app, plus Bluetooth or NFC unlock where the installed readers support it, all checked against the gym's access controller through its API. Codes are short-lived, so a screenshot passed around later opens nothing.

    Anti-passback & tailgating rules

    Anti-passback per club, one-person-per-entry logic for turnstiles or airlock doors, and optional face verification at entry for clubs that choose it. Odd patterns, such as one membership entering two clubs ten minutes apart, raise a flag for staff rather than an automatic ban.

    Membership & billing hooks

    Members can freeze, upgrade or cancel in the app, and door access follows the membership state in the billing system. A failed payment can start a short grace period before access pauses, with the rules set by the operator.

    Class booking

    Timetables, waitlists and late-cancellation rules, with the booking checked at the studio door where a club wants that.

    Live occupancy

    A live count of people in each club from entry and exit events, shown in the app so members can pick a quieter time. Capacity limits can hold new entries when a club or studio is full.

    Remote staff alerts

    A door propped open, forced entry, a panic button or repeated denied attempts go straight to the on-call staff phone. Each alert links to the matching CCTV footage where the camera system allows it, with one-tap remote unlock or entry lockout.

    Under the hood

    Architecture

    From the people who use it down to the hardware and third-party systems it talks to.

    1. Apps
      • Member app (iOS & Android)
      • Staff app with remote unlock
      • Operator web dashboard
    2. Platform
      • Member & entitlement service
      • Access rules engine (anti-passback, capacity)
      • Booking & timetable service
      • Alerting & audit log
    3. Integrations
      • Access controller API
      • Billing & direct-debit provider
      • Existing gym management software
      • CCTV / video management system
    4. On site
      • Door controllers & readers
      • Turnstiles or airlock doors
      • Panic buttons & door sensors
      • Local gateway for offline entry
    The plan

    Delivery plan

    The same four phases as every project we run - see how we work.

    1. Weeks 1–2

      Discovery

      Walk the entry flow at two clubs, inventory the controllers, readers and billing setup, and agree which membership states open which doors.

    2. Weeks 3–5

      Design & architecture

      Member and staff app flows, the entitlement model and the offline plan for when a club's internet drops. The controller API is tested on a bench setup before we commit to it.

    3. Weeks 6–16

      Build

      Two-week sprints with a pilot club wired up in the first month, so door behaviour is tested on real hardware, not only in staging.

    4. Weeks 17–18

      Launch & handover

      Club-by-club roll-out with fobs kept as a fallback, staff training and runbooks, and handover of the code and infrastructure.

    The team

    • Product-minded tech lead
    • Mobile engineers (iOS & Android)
    • Backend engineer
    • Access-control integration engineer
    • UX/UI designer
    • QA engineer (incl. door hardware tests)

    Compliance & security

    • Entry logs show where a person was and when, so they're personal data under GDPR; retention periods and staff access would be agreed with your DPO.
    • Optional face verification processes biometric data under GDPR Art. 9: it needs explicit opt-in consent, a non-biometric way in, and very likely a DPIA.
    • Fire and building codes require free exit, so the software controls entry only; exit hardware and fire-alarm release stay as your installer set them up.
    • Online sign-ups and day passes may need PSD2 strong customer authentication, handled by a payment provider such as Stripe or Adyen, so card data stays out of the gym's platform.

    Tech stack

    • Swift
    • Kotlin
    • TypeScript
    • NestJS
    • PostgreSQL
    • Redis
    • React
    • MQTT
    • AWS

    Questions we usually get

    Can you work with the door controllers we already have?

    Usually, if the controller has an API or an integration protocol we can reach through the cloud or a small local gateway. Access-control integration is core work for us, and discovery starts with a bench test on your actual hardware; if a model can't be integrated safely, we'll say so and price the alternatives.

    What happens when a club's internet goes down?

    Members with a valid credential still get in: where the controller supports it, codes are signed and checked on site against a cached member list, and entry events sync back when the connection returns. Sign-ups and membership changes wait for the connection, and staff can see that the club is running offline.

    Do members have to use face recognition?

    No. We'd treat face verification as an opt-in for clubs that want it, with QR or NFC as the standard way in. Biometric data needs explicit consent and usually a DPIA under GDPR, so it's a decision for you and your DPO, not a default.

    Building something like this?

    30 minutes with the engineers who'd build it. We'll test this plan against your situation: scope, integrations and budget.