Skip to content
Privacy Notice

Privacy Notice

Effective 2026-05-20

Who we are

This privacy notice explains how Urban Gym Ltd ("we", "us", "our") collects and uses personal data when you use the Urban Gym Ltd website, member portal, mobile app, or gym facilities.

Urban Gym Ltd, company number 16001182 registered in England and Wales, registered office 22 Towcester Road, Old Stratford, Milton Keynes, Buckinghamshire, MK19 6AQ is the data controller for that personal data.

Urban Gym Ltd is registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZB934393.

For any data protection question, including to exercise your rights, [email protected].

What personal data we collect

Account and contact details: name, email, phone, date of birth, postal address, login credentials (passwords are stored only as hashes), member number, and any emergency contact you provide.

Membership and booking activity: plan, joining date, payment status, tours and inductions booked, classes attended, day passes purchased, personal training links, and check-in events.

Health and fitness data (only if you choose to use these features): body measurements, weight, progress photos, workouts logged, nutrition diary entries, and data you choose to sync from Apple Health, Android Health Connect, or Strava.

Door access events: the time and door of each scanned entry, recorded for safety, capacity, and incident review.

Payment data: limited card metadata (last four digits, card brand), direct debit mandate references, and a Stripe or GoCardless customer ID. We never store full card numbers or bank details — those are held by the payment provider.

Technical data: device identifiers, IP address, browser type, app version, push notification tokens, crash diagnostics, and aggregated analytics events.

Communications: messages you send us, support tickets, and feedback submitted through the site or app.

Why we use your data and the legal basis

To deliver the contract between you and us — operating your membership, processing bookings and payments, granting access to the gym, and providing the features you use in the app (UK GDPR Article 6(1)(b)).

To comply with legal obligations — including health and safety, tax and accounting records, and responding to lawful requests (Article 6(1)(c)).

For our legitimate interests — running the business, preventing fraud and abuse, keeping the facility safe, improving the app, and contacting members about service changes (Article 6(1)(f)).

With your consent — for marketing emails, optional health data sync (Apple Health / Health Connect), progress photos, and any feature you opt into. You can withdraw consent at any time from your profile or by contacting us (Article 6(1)(a)).

Where we process health-related data (body measurements, photos you mark as progress, fitness logs), we rely on your explicit consent under Article 9(2)(a).

Who we share your data with

Payment processors: Stripe Payments UK Ltd (one-off card payments) and GoCardless Ltd (recurring direct debit). They act as separate data controllers for the payment data they receive.

Access control: Ubiquiti Inc. (UniFi Access) — we share the encrypted access credential needed to open doors you are entitled to use.

Email delivery: our transactional email provider (Resend, or Microsoft 365 / Microsoft Graph where a gym sends from its own mailbox, or, in test environments, Mailpit) processes the contents of emails we send you on our behalf.

File storage: Cloudflare R2 (Cloudflare, Inc.) stores files you upload — progress photos, form-check videos, and any documents — encrypted in transit and at rest.

Push notifications: Expo (650 Industries, Inc.) relays push notifications to Apple (APNs) and Google (FCM). We send the notification text and your device push token only.

Wallet passes: Apple Inc. and Google LLC, where you choose to save a member pass to Apple Wallet or Google Wallet.

Health platforms: Apple Inc. (HealthKit) and Google LLC (Health Connect) — only if you opt in. Data flows are bidirectional only on your explicit request.

Third-party fitness apps: Strava Inc. (running, cycling, and workout activity) — only if you opt in via the Connected Apps page. We read your recent activity and basic profile, never write back, and you can disconnect at any time, which revokes our access at Strava. If you turn on "Share with my PT", your assigned personal trainer can see those activities until you turn it off.

Exercise reference data: the public-domain free-exercise-db dataset (Unlicense), served from a GitHub fork we maintain — we only pull catalogue data and images; no personal data is sent to GitHub.

Hosting and infrastructure: the platform is hosted on UK-based VPS infrastructure. Backups, error tracking (self-hosted GlitchTip), and operational logs are processed on the same infrastructure.

Professional advisers, regulators, and law-enforcement bodies where we are legally required to share data, or to protect our rights, members, or staff.

Progress photos and who can see them

Progress photos are private to you by default. Nobody — not your coach, not another member, not gym staff — can see them until you say so.

A coach has to ask. When they request access you get to approve or decline it, and an approval is limited to that one coach, lasts only for the period you agree, and can be withdrawn by you at any time from your profile. No other member, and no other coach, is ever given access to your photos, and a coach cannot see photos belonging to anyone who has not approved them.

Every time a coach opens your photos we record it, so there is a record of who looked and when.

Your photo files are stored in Cloudflare R2 — object storage operated by Smart Property Software Ltd on our behalf, in a private bucket with no public web address. Because Smart Property Software Ltd runs that storage account, their technical staff are able to access the underlying files where it is necessary to operate the service — for example to confirm an upload saved correctly, or to investigate a fault you have reported. That access is limited to those purposes, is not used to view your photos otherwise, and happens outside the in-app record described above.

You can delete any photo from the app at any time, and all of them are deleted when you close your account.

International transfers

Most personal data stays in the United Kingdom. Some of our processors (Stripe, Apple, Google, Ubiquiti, Cloudflare, Expo) are based outside the UK. Where personal data is transferred outside the UK, we rely on UK-approved transfer mechanisms — usually adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses — and on the processor's own compliance certifications.

How long we keep your data

Member account and booking records: for the lifetime of your membership and for six years after it ends, to comply with HMRC record-keeping obligations and to defend potential legal claims.

Door access logs: 12 months for safety and incident review, then deleted.

Fitness and nutrition logs, body measurements, and progress photos: kept while your account is active. You can delete any individual entry at any time from the app, and full deletion happens when you close your account.

Marketing preferences: kept until you unsubscribe or close your account.

Payment records: retained for six years to satisfy financial reporting and chargeback windows.

Backups: rolling encrypted backups overwrite within 30 days.

Your rights

Under the UK GDPR you have the right to: access the personal data we hold about you; ask us to correct it; ask us to delete it (the 'right to erasure'); restrict or object to our processing; receive a copy of the data you provided to us in a portable format; and withdraw any consent you have given.

Most of these you can exercise directly in the app — your profile screen lets you edit or delete entries, change marketing preferences, and request a full export.

For anything you cannot do yourself, contact us at [email protected]. We will respond within one month, and we will not charge you for exercising these rights.

Cookies and analytics

We use cookies strictly necessary to keep you signed in and to remember your preferences. These do not require consent.

If you opt in, we also use Google Analytics 4 to understand aggregate usage patterns. You can opt out at any time by declining the cookie banner or by clearing the analytics cookie in your browser.

Crash and error diagnostics are sent to our self-hosted error tracker (GlitchTip). Diagnostics include the path you were on, the error stack, and your account id so we can reach out if you experienced the failure.

Children

The app and member portal are intended for users aged 16 or over. Under-16s may attend the gym as part of a junior or family membership where supported by their parent or guardian, but only the parent or guardian holds the account.

Security

Passwords are hashed with Argon2. Access credentials are short-lived and rotate every 30 seconds. All connections to the website and app use TLS. Database backups are encrypted at rest. Access to production systems is limited to named engineers and audited.

Changes to this notice

We may update this notice from time to time. The effective date below shows the last material change. Where the change materially affects your rights or how we use your data, we will tell you in the app or by email before it takes effect.

Effective date: 2026-05-20.

How to make a complaint

If you believe we have not handled your personal data properly, please contact us first — [email protected] — and we will acknowledge your complaint within 30 days and aim to resolve it as quickly as possible.

You can also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not have to contact us first to use the ICO route.