Privacy Policy
Last updated .
RepTap provides NFC workout tracking for gyms. This policy explains what we collect, why, and what you can do about it. It covers both gym members using the tracking interface and gym operators using the RepTap platform.
Who is responsible for your data
RepTap is the data controller for member accounts and workout records. Your gym is a separate controller for its own membership records; this policy covers RepTap only.
What we collect
If you are a gym member
- Account details — your email address, a securely hashed password, and your first name if you choose to give one.
- Workout records — the sets, weights, reps, times and speeds you log, and which machine they were logged against.
- Tap events — which machine you tapped and when, used to produce usage statistics for your gym.
- Custom exercises — any exercises you create, which are private to you at that gym.
We do not ask for your height, weight, age, gender, fitness goals or training history, and there is no need to give them.
Before you create an account
You can log workouts without an account. Those workouts are stored in your own browser on your own device and are not sent to us. They stay there until you either create an account, at which point they are transferred to it, or clear your browser data, at which point they are gone.
If you make an enquiry
- Your name, email address, phone number if given, gym or company name, and the details of your enquiry.
- The IP address the enquiry came from, used to limit abuse of the form.
What we do not do
- We do not sell your data.
- We do not use your data for advertising or share it with advertisers.
- We do not track you across other websites.
- We do not use analytics or advertising cookies.
Cookies
RepTap sets only the cookies it needs to work: one to keep you signed in, and one anonymous identifier so a tap can be attributed correctly before you sign in. Both are strictly necessary, so no consent banner is required.
What your gym can see
Your gym can see how its equipment is used: tap counts, how many members are active, and which machines are busy. Where an individual member's activity is shown to a gym operator, it is limited to the account name, email address and the workouts logged at that gym.
Other gym members cannot see your workouts, your history or your custom exercises. There are no leaderboards, public profiles or social features in RepTap, and none are planned.
How long we keep it
- Workout records — for as long as your account exists.
- Tap events — retained to produce usage reporting for your gym.
- Enquiries — kept while we are in contact and deleted when no longer needed.
- If a gym leaves RepTap — that gym's installation and the workout records logged at it are deleted with it. Your account itself is not deleted, and records from other gyms are unaffected.
Your rights
If you are in the UK or EU you have the right to access your data, correct it, have it deleted, restrict or object to how it is used, and receive a copy in a portable format. You can also complain to the Information Commissioner's Office.
To exercise any of these, email privacy@reptap.com. We will respond within one month. Self-service export and deletion are on our roadmap; until then we will handle these requests manually.
Security
- Passwords are hashed with PBKDF2 and are never stored or transmitted in readable form.
- Session tokens are stored hashed, so a copy of our database does not hand over live sessions.
- Session cookies are HTTP-only, so scripts cannot read them.
- Operator access is protected on the server, not just hidden in the interface.
No system is perfectly secure, but we design so that a single failure does not expose everything.
Children
RepTap is not intended for under-16s. If a gym admits younger members, the gym is responsible for obtaining any consent its own rules require.
Changes
If we change this policy we will update the date above. Material changes affecting members will be shown in the member interface.
Contact
This policy describes how the RepTap software handles data. Before launch it should be reviewed by a qualified adviser and completed with your registered company name, address and any Data Protection Officer details.