The vendor really needs to get its act together and secure the app. Currently it is trivial to get personal information of other users from an arbitrary account. Until then, beware of disclosing personal details on the app.
Update: Should the fix not be implemented by the next iteration, I would publicly disclose the vulnerability. The vendor really needs to wake up and learn some sense of accountability..
Update 2: Security flaw in WiFi hotspot captive login at gyms too. Unbelievable how these chaps are so lax.
Rustybrain about ActiveSG