24/7 Gym Member App With Mobile Door Access
A member app for unstaffed 24/7 gyms: phone-based door entry, anti-passback, class booking, membership freezes, live occupancy and staff alerts.
An example of how we'd build this for a company in this niche: the plan, the architecture and the targets we'd start from. Not a specific client's story.
- Target
- < 2 s
- from QR scan to door release at the pilot club, verified before roll-out
- Target
- < 5 min
- for a cancelled or frozen membership to lose door access, from launch
- Target
- –30%
- access-related support requests within six months of launch
Who this is for
Picture an operator of 8–15 gyms that are open 24/7 but staffed only at peak times, where members get in with key fobs and book classes in a separate app. Every lost fob, failed payment and shared login lands on a small ops team, and the door system has no idea who has actually paid. The goal is one member app that opens the door, follows membership status in real time and alerts staff remotely when something at the door looks wrong.
What makes it hard
- Tailgating and credential sharing cost unstaffed clubs revenue, and a door that simply unlocks can't tell one member from three.
- The access controller, billing system and booking tool each keep their own member list, so a cancelled or frozen member can often still get in for days.
- Many clubs sit in basements or retail units with weak mobile signal, and the door still has to open for a paying member at 5 a.m.
- Failed direct debits, freezes and upgrades should change door access automatically, without staff chasing members one by one.
- With nobody on site, someone still has to hear about a panic button, a door propped open or a room over capacity.
What we'd build
Phone-based door entry
Rotating QR codes in the app, plus Bluetooth or NFC unlock where the installed readers support it, all checked against the gym's access controller through its API. Codes are short-lived, so a screenshot passed around later opens nothing.
Anti-passback & tailgating rules
Anti-passback per club, one-person-per-entry logic for turnstiles or airlock doors, and optional face verification at entry for clubs that choose it. Odd patterns, such as one membership entering two clubs ten minutes apart, raise a flag for staff rather than an automatic ban.
Membership & billing hooks
Members can freeze, upgrade or cancel in the app, and door access follows the membership state in the billing system. A failed payment can start a short grace period before access pauses, with the rules set by the operator.
Class booking
Timetables, waitlists and late-cancellation rules, with the booking checked at the studio door where a club wants that.
Live occupancy
A live count of people in each club from entry and exit events, shown in the app so members can pick a quieter time. Capacity limits can hold new entries when a club or studio is full.
Remote staff alerts
A door propped open, forced entry, a panic button or repeated denied attempts go straight to the on-call staff phone. Each alert links to the matching CCTV footage where the camera system allows it, with one-tap remote unlock or entry lockout.
Architecture
From the people who use it down to the hardware and third-party systems it talks to.
- Apps
- Member app (iOS & Android)
- Staff app with remote unlock
- Operator web dashboard
- Platform
- Member & entitlement service
- Access rules engine (anti-passback, capacity)
- Booking & timetable service
- Alerting & audit log
- Integrations
- Access controller API
- Billing & direct-debit provider
- Existing gym management software
- CCTV / video management system
- On site
- Door controllers & readers
- Turnstiles or airlock doors
- Panic buttons & door sensors
- Local gateway for offline entry
Delivery plan
The same four phases as every project we run - see how we work.
- Weeks 1–2
Discovery
Walk the entry flow at two clubs, inventory the controllers, readers and billing setup, and agree which membership states open which doors.
- Weeks 3–5
Design & architecture
Member and staff app flows, the entitlement model and the offline plan for when a club's internet drops. The controller API is tested on a bench setup before we commit to it.
- Weeks 6–16
Build
Two-week sprints with a pilot club wired up in the first month, so door behaviour is tested on real hardware, not only in staging.
- Weeks 17–18
Launch & handover
Club-by-club roll-out with fobs kept as a fallback, staff training and runbooks, and handover of the code and infrastructure.
The team
- Product-minded tech lead
- Mobile engineers (iOS & Android)
- Backend engineer
- Access-control integration engineer
- UX/UI designer
- QA engineer (incl. door hardware tests)
Compliance & security
- Entry logs show where a person was and when, so they're personal data under GDPR; retention periods and staff access would be agreed with your DPO.
- Optional face verification processes biometric data under GDPR Art. 9: it needs explicit opt-in consent, a non-biometric way in, and very likely a DPIA.
- Fire and building codes require free exit, so the software controls entry only; exit hardware and fire-alarm release stay as your installer set them up.
- Online sign-ups and day passes may need PSD2 strong customer authentication, handled by a payment provider such as Stripe or Adyen, so card data stays out of the gym's platform.
Tech stack
- Swift
- Kotlin
- TypeScript
- NestJS
- PostgreSQL
- Redis
- React
- MQTT
- AWS
Questions we usually get
Can you work with the door controllers we already have?
Usually, if the controller has an API or an integration protocol we can reach through the cloud or a small local gateway. Access-control integration is core work for us, and discovery starts with a bench test on your actual hardware; if a model can't be integrated safely, we'll say so and price the alternatives.
What happens when a club's internet goes down?
Members with a valid credential still get in: where the controller supports it, codes are signed and checked on site against a cached member list, and entry events sync back when the connection returns. Sign-ups and membership changes wait for the connection, and staff can see that the club is running offline.
Do members have to use face recognition?
No. We'd treat face verification as an opt-in for clubs that want it, with QR or NFC as the standard way in. Biometric data needs explicit consent and usually a DPIA under GDPR, so it's a decision for you and your DPO, not a default.
Services behind this blueprint
More on the Access Control & PropTech industry.
Building something like this?
30 minutes with the engineers who'd build it. We'll test this plan against your situation: scope, integrations and budget.