Privacy Policy

Effective 18 August 2026.

This policy explains how Gareth Holton, trading as BoxOp (“BOXOP”, “we”, “us”), of Halifax, West Yorkshire, HX3 7SA, United Kingdom, collects, uses, and protects personal data through boxop.co.uk and the BOXOP dashboard and member app.

1. Who this policy covers

BOXOP is a software platform used by independent gyms and studios (“gym operators”) to run their business, and by their members (“members”) to book classes, train, and communicate with their gym.

For member data entered into the platform by a gym (bookings, attendance, programming, payments, messages), the gym operator is the data controller and BOXOP acts as a data processor on their instructions — see our Data Processing Agreement. For account and usage data about gym owners, staff, and platform administrators, BOXOP is the controller.

2. What we collect

  • Account data — name, email, password (hashed via Supabase Auth), role, and phone number where given.
  • Date of birth and gender — asked once when a member sets up their account. Gender includes an option to decline, and a member who picks “other” can describe themselves in their own words. Both feed the gym's demographic reports only (see §4).
  • Gym/member profile data — membership status, class bookings, waitlists, attendance, workout results and benchmarks, coach comments, PT programme enrolment.
  • Payment data — handled directly by Stripe; we store subscription/transaction status and references, not full card numbers.
  • Communications — in-app messages between members and gyms, and email/WhatsApp notifications where a gym has enabled them.
  • Device data — push notification tokens, device/browser type, IP address, and basic usage logs for security and reliability.
  • Approximate location— only in the member app, only while you are using it, and only if you tap “use my current location” on the gym search. It is used once, there and then, to sort gyms by how far away they are: the app asks the phone for a rough fix, sends it with that one search, and never collects it in the background or keeps a location history. Decline and the search still works — it just cannot sort by distance.
  • Photos, videos and voice notes — attachments you choose to send in a message to your personal trainer, from your camera, your photo library or the microphone. The app only ever reads the one file you pick; it does not browse your library. These are stored privately and are readable only by you and that trainer, through links that expire.
  • Records of agreement — which version of our terms you accepted and when, with the IP address and browser that accepted it. This is what makes consent evidenced rather than assumed.
  • AI feature inputs — draft prompts submitted by gym staff to generate social posts or emails (see §6).

3. Health and other special category data

Some categories of data get extra protection under Article 9 UK GDPR — health being the one that matters for a gym. Our position on it is deliberately narrow:

  • We don't ask for health data. There is no field in BOXOP for medical conditions, injuries, medication or a health questionnaire, and we do not infer health from training data. A logged lift is a performance record, not a diagnosis.
  • Gender is not special category data under Article 9, which covers sexual orientation rather than gender. We still treat it as sensitive: it is optional to disclose, and it only ever leaves the gym as a count (see §4).
  • Free text is the exception, and it is the gym's to manage.Coach comments, member notes and in-app messages accept whatever is typed into them, so health information can end up there. Where it does, the gym operator is the controller of it and needs its own Article 9 condition — usually the member's explicit consent. We ask gyms not to use BOXOP free-text fields as a medical record, and to keep par-Q and screening paperwork in the system built for it.

4. Why we process it

  • To provide the core service — scheduling, bookings, programming, messaging, payments.
  • To send transactional notifications (booking confirmations, class reminders, payment receipts) — legitimate interest / contract necessity.
  • To give gyms demographic reporting — age bands and gender splits across memberships, bookings and programmes, on the gym's instructions as controller. These are counts only: exact ages are never shown, and any group of fewer than five people is suppressed rather than reported, because “the most common demographic” in a class of three is just naming them.
  • To maintain security, prevent abuse, and enforce rate limits on the platform.
  • To improve the product — aggregated, non-identifying usage analysis only.
  • To evidence acceptance of our terms, and to meet our own legal and accounting obligations.
  • Where a gym enables it, to send marketing communications on the gym's behalf — the gym is responsible for its own marketing consents.

5. Cookies and similar technologies

We use only what is strictly necessary to make the service work: storage in your browser that keeps you signed in, and remembers your theme and similar preferences. That is exempt from consent under the Privacy and Electronic Communications Regulations, which is why you have never seen a cookie banner from us.

We set no analytics, advertising, profiling or cross-site tracking cookies, and we run no third-party tracking scripts on boxop.co.uk or in the dashboard. There is no advertising network, data broker or social pixel in the product. If that ever changes, we will ask for consent first rather than update this page and hope you don't read it.

6. Who we share data with

We use the following processors to run the service. Each is bound by its own data processing terms; a full sub-processor list is in our Data Processing Agreement.

  • Supabase — database hosting, authentication (EU region).
  • Stripe — payment processing and payouts.
  • Resend — transactional email delivery.
  • Twilio — SMS/WhatsApp notifications, where enabled by a gym.
  • Expo / Apple / Google — mobile push notification delivery.
  • Anthropic — generates AI-assisted social post and email drafts when a gym staff member requests one; prompts are not used to train Anthropic's models under our commercial terms.

Beyond those processors, there are three situations in which we may disclose personal data:

  • Where the law requires it — to a court, regulator, or law enforcement body responding to a valid request, or to establish, exercise or defend legal claims. We check that a request is lawful before answering it, and where we are allowed to tell the affected gym or member, we do.
  • To our professional advisers — accountants, insurers and lawyers, where they need it to advise us, under a duty of confidence.
  • If the business changes hands — if BOXOP is sold, merged, or transfers part of its business, personal data may transfer with it. Any buyer would be bound by this policy, or would have to obtain fresh agreement to a different one. Gym operators would be told before it happened, not after.

We do not sell personal data, and we do not share it with advertisers or data brokers.

7. International transfers

Some processors (e.g. Anthropic) are based outside the UK/EEA. Where personal data is transferred internationally, we rely on the UK International Data Transfer Addendum or equivalent Standard Contractual Clauses with that processor.

8. How long we keep it

  • Your account and profile — while the account is open. Closing it erases your login, name, email, phone, photo, date of birth, gender, app settings and personal bests. See Member Terms §10 for what closing an account does and does not reach.
  • Records a gym holds about its members— for as long as that gym's subscription is active, and then per DPA §8: exportable by the gym for a reasonable period after termination, and deleted after it. The gym decides earlier deletion, because the gym is the controller.
  • Financial records — payment references, invoices and transaction history are kept for six years, which is the period gyms themselves have to keep accounting records for HMRC. An erasure request does not override that.
  • Records of terms acceptance — kept while the account exists and for as long afterwards as we may need to evidence what was agreed.
  • Security and access logs — kept only as long as they are useful for investigating abuse and diagnosing faults, then discarded.
  • Backups— deleted data can persist in encrypted backups until they age out of our provider's rolling backup window. It is not restored to the live system except in a disaster recovery, and it ages out without further action.

9. Your rights

Under UK GDPR you have the right to access, correct, delete, or export your personal data, restrict or object to certain processing, and withdraw consent where processing is based on it. If BOXOP is the processor for your data (i.e. you're a gym member), please contact your gym directly in the first instance — they control the data. You can also contact us at hello@boxop.co.uk, and you have the right to lodge a complaint with the Information Commissioner's Office (ICO). Our ICO registration is in progress — a registration number will be published here once confirmed.

How a request is handled:

  • We answer within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you inside the first month if that happens, with the reason.
  • We may need to confirm who you are before releasing or deleting anything. That is a protection for you: the whole point of an access request is undermined if we hand your training history to somebody claiming to be you.
  • It's free. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive — for example the same request repeated without cause. We will explain the decision and you can complain to the ICO about it.
  • Where we are only the processor, we pass the request to the gym that controls the data and confirm to you that we have. We will not quietly drop it or send you round in circles.

10. Security and data breaches

Data is encrypted in transit (TLS) and at rest. Access to member data is restricted by tenant-level row security so one gym can never see another gym's data. We apply rate limiting and authentication checks on all data-access endpoints, and access to production data is limited to those who need it, under a duty of confidence.

We have procedures for handling a suspected personal data breach. Where one affects data we control and presents a risk to people, we notify the ICO within 72 hours of becoming aware, and tell affected individuals where the risk to them is high. Where the breach affects data we process on a gym's behalf, we notify that gym without undue delay so it can meet its own obligations as controller.

11. Age

A member must be 16 or over to create and hold their own BOXOP account, and we ask for a date of birth in part to check it. We do not knowingly collect data about under-16s who have signed themselves up.

Gyms do train younger athletes, so a gym operator can set up an account for a member under 16 with the agreement of a parent or guardian. In that case the gym is the controller and is responsible for obtaining that consent, and the adult who gave it is responsible for the member's use of the app. If you believe a child holds an account they shouldn't, tell us and we will remove it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified to gym operators by email, and the effective date at the top of this page will change. Each version we publish is recorded, so what you agreed to is always identifiable.

13. Contact

Gareth Holton, trading as BoxOp, Halifax, West Yorkshire, HX3 7SA, United Kingdom. Email: hello@boxop.co.uk.