Privacy Policy
Version 1.0 · Effective 1 November 2026
BoxPass is operated by BoxPass Ltd, a company registered in England and Wales (company number 17487634) with its registered office at Unit 2a Swordfish Close, Burscough, Ormskirk L40 8JW ("BoxPass", "we", "us"). We are the data controller for the personal data described in this policy. You can contact us about anything in it at team@boxpass.co.uk or by post at the address above.
This policy explains what personal data we collect when you use boxpass.co.uk and the BoxPass app (the "Platform"), why we collect it, who we share it with, how long we keep it and the rights you have. It applies to athletes, gym owners and their staff, ambassadors and visitors. We've written it to be read, not skimmed, so it's in plain English with no surprises.
1. The data we collect
When you create an account — your name, email address, a password (stored as a hash we cannot read) or a sign-in link, and your role (athlete, gym owner, team member, ambassador). Optionally a phone number, a profile photo and an Instagram handle.
When you book a class — the gym, class, date and time, the price and booking fee, your booking reference, and a Stripe payment reference. We never see or store your card number; payment is taken by Stripe directly.
When you sign a gym's waiver — the name you type, the date and time, your IP address, your device and browser string, the exact text you agreed to and a fingerprint (hash) of the waiver file you signed. We keep a PDF copy of the signed waiver on your profile and email it to you. This is the evidence that you agreed to the gym's terms, and it is held on behalf of the gym and its insurer.
When you use the map — if you allow it, your device's location, which we use to show distances and draw a route to a gym. Your location is sent to our routing provider to calculate the route and is not stored by us.
When you review a class, leave feedback or contact us — what you write, and the booking it relates to.
If you're a gym owner — your gym's name, address and postcode, photos, facilities, prices, timetable, affiliation evidence you upload, your waiver PDF, your bank/payout details (held by Stripe, not by us), and, if you connect your booking software, the credentials you authorise (encrypted, see section 6) and the class schedule it returns.
If you're an ambassador — your name, email, the code we issue you, and which gyms and athletes signed up through your link.
Automatically — standard server logs (IP address, pages requested, timestamps, browser type) and the minimum cookies needed to keep you signed in and remember your preferences (section 8). We do not use advertising cookies or tracking pixels.
We do not ask for and do not want special category data such as health information. If a gym's waiver asks you about medical conditions, that information is between you and the gym; BoxPass stores only the signed document, not a structured record of your answers.
2. Why we use it and our lawful basis
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Creating and running your account; taking and confirming bookings; sending booking, cancellation and waiver emails; paying gyms | Contract — we can't provide the service without it |
| Recording waiver signatures with IP and device details | Contract and legitimate interests (yours, the gym's and ours in having reliable evidence of agreement) |
| Showing distances and routes from your location | Consent — you choose whether to share location, and can turn it off in your device settings at any time |
| Service emails about problems with your booking or gym listing, and help from our team when onboarding goes wrong | Legitimate interests (running the service properly); you can't opt out of essential service messages, but we keep them to what's needed |
| Post-class feedback requests, availability alerts and product news | Consent — every email has an unsubscribe link and your preferences are in Account → Notifications |
| Reviews shown on gym pages | Legitimate interests — helping athletes choose, and gyms improve; reviews show your first name and initial only |
| Ambassador referral tracking and commission | Contract with the ambassador; legitimate interests for recording how you found us |
| Fraud prevention, security, abuse prevention, server logs | Legitimate interests |
| Keeping records we're legally required to keep (tax, accounting, disputes) | Legal obligation |
Where we rely on legitimate interests we have balanced them against your rights and concluded they don't override them; you can ask us for that assessment.
3. Who we share it with
Gyms you book with. When you book, the gym sees your name, email, the class you've booked, whether you've signed their waiver, and your signed waiver. They need this to let you in, run their class and meet their insurance obligations. Each gym is an independent controller of that data once they have it, and their own privacy practices apply to what they do with it.
Service providers (processors) who act on our instructions:
- Lovable Cloud / Supabase — hosting, database and file storage.
- Stripe — payment processing and gym payouts. Stripe is also an independent controller for payment data under its own privacy policy.
- Lovable email service — sending our transactional and notification emails from notify.boxpass.co.uk.
- OpenRouteService (HeiGIT) — route calculation when you ask for directions (receives coordinates only, no identity).
- Esri and OpenStreetMap contributors — map tiles.
- GitHub — source code hosting (no personal data of users).
- Gym booking platforms (TeamUp, Wodify, PushPress) — only where a gym has connected one. We read the gym's timetable from them; where write-back is enabled by the gym, we send that gym your name and email with your reservation so it appears in their system.
Others: professional advisers (accountants, lawyers, insurers) where necessary; authorities where the law requires; and a buyer or successor if BoxPass Ltd is sold or merges, who would be bound by this policy.
We do not sell personal data, and we do not share it with advertisers or data brokers.
4. International transfers
Our application, database and file storage are hosted by Lovable Cloud on Supabase in the European Union (AWS eu-central-1, Frankfurt, Germany). Some providers listed above process data in the United States. Where data leaves the UK we rely on the UK International Data Transfer Agreement or Addendum, or an adequacy decision, and on the providers' own safeguards. You can ask us for a copy of the relevant terms.
5. How long we keep it
- Account data — while your account is open, then deleted within 30 days of you closing it, except as below.
- Bookings and payments — 6 years after the booking, to meet accounting and tax rules and to deal with disputes and chargebacks; after you close your account these are anonymised so they no longer identify you.
- Signed waivers — the period the gym's insurance requires, which is typically up to 6 years after the class (or longer where a claim could still be brought). We keep these even after you close your account because they protect you, the gym and us if there's ever a dispute about what was agreed.
- Location — not stored.
- Server logs — 90 days.
- Reviews — until you delete them or close your account, at which point they're anonymised to "a BoxPass athlete".
- Support and onboarding help records — 12 months.
6. How we protect it
All traffic is encrypted in transit (TLS). The database enforces row-level security so each user and gym can only reach their own records. Gym booking-software credentials are encrypted at rest with AES-256-GCM using a key held outside the database, and are never shown to anyone, including our own staff. Files (waivers, photos, affiliation evidence) are in private storage reachable only through short-lived signed links. Admin access is limited to named staff with multi-factor authentication. No system is perfectly secure, so please use a strong, unique password and tell us straight away at team@boxpass.co.uk if you think your account has been accessed without permission.
7. Your rights
Under UK GDPR you can ask us to: give you a copy of your data (access); correct it; delete it; restrict or object to how we use it; move it to another service (portability); and withdraw consent where consent is the basis. Most of this you can do yourself in Account → Privacy (download my data, delete my account); otherwise email team@boxpass.co.uk and we'll respond within one month. We may need to confirm your identity first. Deleting your account does not delete signed waivers or booking records we must keep (section 5), but they are detached from your identity wherever the law allows.
If you're unhappy with how we've handled your data you can complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113. We'd appreciate the chance to put things right first.
8. Cookies and local storage
We use only what's needed: a sign-in session cookie, and local storage on your device to remember things like your chosen travel mode, map radius and which dashboard sections you keep open. None of these track you across other websites, so we don't show a cookie banner. Blocking them in your browser will stop the Platform working properly.
9. Children
BoxPass is for people aged 18 and over, because booking a class involves a contract and a liability waiver. We don't knowingly collect data from anyone under 18; if you believe we have, email team@boxpass.co.uk and we'll delete it.
10. Changes
We'll post any changes here with a new version number and effective date, and for significant changes we'll email account holders in advance. Continued use after the effective date means the new policy applies.
11. Contact
BoxPass Ltd, Unit 2a Swordfish Close, Burscough, Ormskirk L40 8JW · team@boxpass.co.uk · ICO registration: pending