Privacy Policy

Last updated: 5 August 2026

A few words of introduction

This Privacy Policy explains how SyncSpot collects, uses and protects personal data when you use our website, applications and platform.

This Policy is designed to meet our obligations under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. SyncSpot is aimed at users in the United Kingdom. If we begin offering the Service to users in the European Economic Area, the EU GDPR may also apply and we will update this Policy accordingly.

Personal data means information relating to an identified or identifiable individual.

SyncSpot provides fitness management software that allows independent studios and fitness businesses to manage bookings, memberships, payments, communications and other studio operations. This Policy concerns three groups of people:

  • Visitors — people who visit our website.
  • Partners — studio owners, managers and staff using the SyncSpot platform.
  • Members — customers of studios using SyncSpot to book classes and manage memberships.

1. Who we are

SyncSpot is operated by Redridge Software Ltd, a company registered in Northern Ireland under company number NI740307, with its registered office at 179 Ballynakilly Road, Dungannon, Northern Ireland, BT71 6HG.

Redridge Software Ltd acts as a data controller when processing personal data relating to website visitors, studio partners and users of our platform where we determine how and why information is used.

When SyncSpot processes Member data on behalf of a fitness studio, SyncSpot acts as a data processor. The studio remains the data controller and is responsible for deciding how Member information is used.

2. Our role under UK GDPR

For Partners, SyncSpot controls the processing of information required to provide and manage the SyncSpot service.

For Members, the studio you attend determines the purposes and lawful basis for processing your personal data. SyncSpot provides the technology platform that allows the studio to manage bookings, memberships and related services.

If you are a Member, we recommend reviewing the privacy policy of the studio you attend because it explains how that studio uses your information.

3. How we collect your data

We collect personal data in three main ways:

  • Directly from you — when you create an account, contact us, book a demo or use the platform.
  • Automatically — through cookies and similar technologies when you use our website and platform (see section 8).
  • From your studio — where you are a Member, the studio provides your information so we can deliver the Service on its behalf.

4. Why do we use your data?

The table below explains the purposes for which personal data may be processed, the information involved, who it relates to, the lawful basis and retention periods.

PurposePersonal dataData subjectsLawful basisRetention
Provide access to the SyncSpot platform, including account creation, authentication, security and essential functionality.Name, email address, password or authentication information, IP address, device information, browser information, operating system and login activity.Visitors, Partners.Performance of our contract with Partners and our legitimate interest in providing a secure and reliable Service.While your account remains active and for up to 3 years afterwards where required for legal, security or dispute purposes.
Manage studio accounts, subscriptions and billing.Name, business details, contact information, subscription details, invoices and payment information processed by our payment providers.Partners.Performance of our contract and compliance with legal obligations relating to financial records.Up to 7 years where required for accounting and legal purposes.
Provide booking, membership and studio management functionality.Member name, contact details, booking history, membership status, attendance records and information provided by the studio.Members.SyncSpot processes this information as a processor on behalf of the relevant studio. The studio determines the lawful basis for processing Member data.Determined by the relevant studio according to their own retention policies. SyncSpot deletes or returns data according to our agreement with the studio.
Provide customer support and respond to enquiries.Name, email address, telephone number, account information and correspondence history.Visitors, Partners.Performance of our contract with Partners and our legitimate interest in responding to enquiries and providing support.Up to 3 years after our last interaction unless longer retention is required for legal purposes.
Improve and optimise the SyncSpot platform, including analytics and service performance monitoring.Platform usage information, feature usage, navigation data, performance information and aggregated statistics.Visitors, Members, Partners.Our legitimate interest in improving, securing and developing our Service. Optional analytics cookies are used only with consent where required.According to our cookie policy and analytics provider settings.
Send service updates, product information and marketing communications.Name, email address, communication preferences and correspondence history.Partners.Consent where required, or our legitimate interest in communicating with business customers about our products and services.Until you unsubscribe or your account is deleted, unless we need to retain records for legal purposes.
Protect our Service against fraud, misuse and security threats.Login activity, IP addresses, device information, access logs and security events.Visitors, Members, Partners.Our legitimate interest in maintaining the security and integrity of our platform.For as long as reasonably necessary for security and investigation purposes.
Handle complaints, disputes and legal claims.Any information relevant to the complaint, dispute or legal matter.Visitors, Members, Partners.Our legitimate interest in protecting and defending our legal rights.Until the matter is resolved and any applicable limitation periods have expired.
Respond to requests relating to your data protection rights.Identity information, contact details and the personal data relevant to your request.Visitors, Members, Partners.Compliance with our legal obligations under applicable data protection laws.Records of requests may be retained for up to 6 years where necessary to demonstrate compliance.

5. Special category data

Some information handled through the platform, such as class attendance or fitness activity, may reveal information about a person's health, which is a special category of data under UK GDPR.

Where this relates to Members, the studio is the data controller and is responsible for identifying an appropriate condition for processing special category data and for obtaining any consent required. SyncSpot processes this information only on the studio's instructions.

6. Who do we share your data with?

Your data is only shared with trusted parties who are strictly authorised to process it, and these recipients are bound by strict confidentiality obligations. We share your personal data with:

Authorised internal personnel who need it for the purposes set out in section 3, such as our:

  • sales team;
  • technical team;
  • customer service team.

External recipients, such as:

  • the fitness studio you are a Member of, where applicable;
  • public authorities to whom we must disclose data to comply with legal obligations or to protect our rights or those of others;
  • our service providers, including:
    • hosting and infrastructure providers;
    • payment service providers;
    • communication service providers (email / SMS).

7. International data transfers

Some of our service providers may process personal data outside the United Kingdom or European Economic Area.

Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements, UK Addendums to Standard Contractual Clauses, or European Commission Standard Contractual Clauses where applicable.

8. Cookies and analytics

We use cookies and similar technologies to operate SyncSpot, maintain security, remember preferences and understand how users interact with our website and platform.

Essential cookies are required for the operation of the Service. Optional analytics and marketing cookies are only used where consent is required under applicable laws.

A separate Cookie Policy may provide additional information about the cookies we use and how you can manage your preferences.

9. Security

We take reasonable technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure or destruction.

These measures may include access controls, authentication requirements, encryption, monitoring and secure infrastructure practices.

No online service can guarantee absolute security, but we continuously review and improve our security practices.

10. Automated decision-making

We do not use your personal data to make solely automated decisions that produce legal effects or similarly significant effects on you, and we do not carry out profiling of that kind.

11. Account deletion and data retention

Partners may request deletion of their SyncSpot account by contacting us at privacy@syncspot.app.

When an account is deleted, we remove or anonymise personal data unless we need to retain certain information to comply with legal obligations, resolve disputes, prevent fraud, or maintain security records.

Where SyncSpot processes Member information on behalf of a studio, deletion requests are handled according to our agreement with that studio and the studio's instructions.

12. Your data protection rights

Depending on the circumstances, you may have the following rights under data protection law:

  • Access and obtain a copy of the personal data we hold about you.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of your personal data where applicable.
  • Object to certain processing activities, including direct marketing.
  • Request restriction of processing in certain circumstances.
  • Request portability of your personal data in a structured, commonly used, machine-readable format.
  • Withdraw consent where processing relies on consent.

If you are unhappy with how we process your personal data, you have the right to complain to the Information Commissioner's Office (ICO) in the UK: ico.org.uk. We would appreciate the opportunity to address your concerns before you contact the ICO, so please contact us first where possible.

13. Children's data

The SyncSpot website and platform are not directed at children. Where a studio collects information about Members under the age of 18, the studio is the data controller and is responsible for handling that data appropriately, including obtaining any consent required.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, legal requirements or business practices.

Where changes are significant, we will provide appropriate notice before they take effect.

15. Contact

If you have questions, concerns or requests relating to this Privacy Policy or your personal data, contact us at privacy@syncspot.app.

SyncSpot is operated by Redridge Software Ltd. Retention periods and lawful bases in this policy are indicative and should be confirmed by a qualified data protection adviser before publication.