Privacy Policy

Your privacy matters. Here's how we collect, use, and protect your personal information.

Last updated: 5 September 2026

BoxSafe Limited ("BoxSafe", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our health and safety platform for CrossFit gyms.

By using BoxSafe, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not use our services.

Section 1

Who We Are & Who Controls Your Data

Your gym is the data controller

When your gym uses BoxSafe to manage safety records, your gym decides what is collected and why — it is the data controller for your member records. BoxSafe Limited processes that data on your gym’s behalf. For your BoxSafe account itself (login, subscription, support requests), BoxSafe is the controller.

What this means for you

Questions about why your gym collects something should go to your gym owner first. Questions about how the BoxSafe platform stores and protects it can come straight to us.

Section 2

Information We Collect

Account information

Your name, email address, gym affiliation and role (member, coach or owner). Optionally a profile photo and phone number.

Health & safety data

With your explicit agreement via the Pre-Exercise Health Declaration: medical conditions, allergies, medications, emergency contacts and your GP. Your gym’s staff also record injuries and incidents involving you as part of their legal safety duties. Optional wellbeing features (status flags, wellbeing check-ins, menopause logging) are only visible to your gym’s staff, and your private mental-health journal is visible to no one but you.

Children’s information

If you enable Kids Zone, you (as parent or guardian) provide your child’s health declaration, emergency contacts and approved collection adults. Children do not have their own accounts; everything is managed through the guardian’s account with the guardian’s consent, including an explicit opt-out for photography.

Purchases

If you buy from the shop, payment is handled by Stripe — we never see your card details. We keep the order and shipping address.

What we do NOT collect

BoxSafe contains no advertising or analytics trackers. We do not record which pages you visit, how long you spend in the app, or your browsing elsewhere.

Section 3

How We Use Your Data

Safety and emergency response

Your health declaration powers your Emergency Action Card so staff and paramedics can help you fast. Injury and incident records give your gym the accident book the law requires it to keep.

Communications

Your gym can message you through the app (and by email/SMS if you keep those switched on in Settings). Safety-sensitive notifications are worded neutrally — the detail stays inside the app.

Aggregated safety analytics

Gym owners see safety trends built only from their own gym’s records. An optional AI-written summary is generated from anonymous aggregate numbers (counts and percentages) — no names or individual records are sent to the AI provider.

Lawful bases

We rely on: performance of a contract (running your account), your explicit consent (the health declaration and optional wellbeing features), and your gym’s legal obligations and legitimate interests (statutory accident and safety records). You can withdraw health-data consent at any time — see Your Rights.

Section 4

Who We Share Data With

Within your gym

Your gym’s coaches and owner can see the safety information they need for their role. Other members can never see your health information. Each gym’s data is fully isolated from every other gym.

Service providers (processors)

We use a small set of vetted providers: Supabase (database and file storage, hosted on AWS), Vercel (application hosting), Resend (email delivery), Twilio (SMS delivery), Stripe (payments), MoodleCloud (training courses — receives your name and email to create your training account), Anthropic (AI summaries — aggregate numbers only, never personal data), and browser push-notification services (e.g. Google, Apple, Mozilla). The AED Locator map uses OpenStreetMap-based services (CARTO map tiles, postcodes.io, Nominatim) which receive the locations you search.

International transfers

Some providers process data outside the UK (for example in the US and Australia). Where they do, transfers are protected by UK-approved safeguards such as the UK International Data Transfer Agreement or Addendum.

Emergency responders

If you enable your Emergency Action Card, anyone you give the card link or QR code to (for example a paramedic) can view your emergency information. You control this link and can disable or regenerate it at any time, and every view is logged for you to see.

Section 5

How We Protect Your Data

Encryption

All data is encrypted in transit (TLS) and at rest (AES-256) on our infrastructure providers.

Access controls

Row-level security enforces gym isolation and role-based access in the database itself, not just in the app. Optional two-factor authentication protects your account, and health data is additionally locked behind the two-factor check for accounts that enable it. Views of your Emergency Action Card are logged and visible to you.

Incident response

If a data breach affecting you is confirmed, we will inform the ICO within 72 hours as required by law and notify you without undue delay.

Section 6

How Long We Keep Data

While your account is active

Your records are kept while you have an account. Emergency-card view logs are deleted after 12 months, and read notifications after 90 days.

When you delete your account

Deletion requests are held for a 30-day cooling-off period (signing back in cancels the request), after which your personal data is permanently erased by an automated process. Records your gym must keep by law — such as its accident book — are retained with your identity removed.

Section 7

Your Rights

Access & portability

Download a complete copy of your data — including your children’s records, health information and the log of who viewed your emergency card — any time from Settings, in a machine-readable format.

Correction & deletion

Update your information directly in the app, or request account deletion from Settings (see retention above for how the 30-day erasure works).

Consent withdrawal

You can withdraw your health declaration at any time from the declaration page. This deactivates your Emergency Action Card and removes the declaration from staff view. You can also disable your emergency card link independently, and switch off any notification channel in Settings.

Complaints

You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk. We’d appreciate the chance to help first — contact details below.

Questions About Privacy?

If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer.

Email: privacy@boxsafe.co.uk

Contact Us