Privacy & Cookie Policy

Last updated: 7 July 2025

Welcome to gym2me – the flexible way to rent fitness kit and get moving at home. We want you to feel completely confident about how we look after your personal information. This page explains, in plain English first and then in legal detail, what we collect, why we collect it, and the rights you have.


Quick Read Snapshot

  • Who we are: gym2me Limited, company no. 16499991, 6‑7 Masonic Street, Llandudno, Conwy, LL30 2DU. Questions? Email [email protected] or ring 01492 200 345.
  • Why we collect data: To deliver/collect rented equipment, manage your account, take payments, run our online community, keep things safe and legal, and (with your permission) send you offers and tips.
  • Your key rights: Access, correction, deletion, portability, restriction, objection, withdraw consent, complain to the ICO.
  • How long we keep it: No longer than UK law (e.g. 6 years for tax records). Full timetable below.
  • Sharing: Only with trusted partners who help us run the service or where the law requires. We never sell your data.
  • Cookies: We use functional, analytics and advertising cookies. You choose to accept, reject or tailor them via our cookie banner.Want the detail? Read on.

1. Who we are

ItemDetails
Controllergym2me Limited (trading as gym2me)
Registered office6‑7 Masonic Street, Llandudno, Conwy, United Kingdom, LL30 2DU
Company number16499991
Telephone01492 200 345
Email[email protected]
Data Protection OfficerAndy Boyd ("DPO")

Throughout this document “we”, “our” or “us” means gym2me Ltd, and “you” means the person using our website or renting equipment.


2. The data we collect

Below is the information we currently gather or may gather in future. Items marked (optional) will only be collected if you choose to provide them. Any health‑related fields will only be introduced after a separate consent process.

CategoryExamplesSource
Account basicsFull name, email, telephone, billing & delivery addressesRegistration form / checkout
Identity checksDate of birth, driving‑licence or passport imageVerification form / credit‑reference agencies
Payment detailsCard token (stored by Stripe), last‑4 digits, payment historyStripe API
Order & membership infoOrder number, rental term, plan type, membership tier, delivery & collection datesBooqable platform
Website & device dataIP address, browser type, device identifiers, log filesAutomatic via cookies, server logs
Usage analyticsPage views, clicks, time on site, marketing attributionGoogle Analytics, Meta, TikTok, LinkedIn pixels
Marketing preferencesOpt‑in boxes, unsubscribe flagsForms / preference centre
Community interactions (future)Forum posts, likes, PT messages3rd‑party community platform
Automated decisionsCredit‑worthiness score, identity match scoreCredit‑reference & fraud‑prevention agencies

We do not currently collect health or fitness data, nor do we monitor physical usage of equipment.


3. How we collect your data

  1. Directly from you – when you register, place an order, upload ID, join the community or fill in a survey.
  2. Automatically – via cookies, pixels and similar tech on our site or emails.
  3. From third parties – payment provider (Stripe), identity and credit‑checking services, analytics providers, social networks (if you interact with our ads), couriers (delivery confirmations).

4. Why we use your data and our lawful bases

PurposeActivitiesLegal basisLegitimate interest (if applicable)
Provide the rental serviceCreate account, process orders, deliver & collect equipment, handle paymentsContract
Identity & credit checksVerify identity, assess credit risk, prevent fraudLegitimate interests / Legal obligationProtect business & customers from fraud
Customer supportAnswer queries, arrange repairs or replacementsContract
Membership community & contentGive access to videos, forums, PT check‑insContract / Legitimate interestsProvide value‑added services to members
MarketingEmail newsletters, SMS offers, social adsConsentGrow the business respectfully
Analytics & improvementsMeasure site performance, develop new featuresLegitimate interestsImprove user experience & service
Legal & tax complianceAccounting, HMRC, FCA, insurance claimsLegal obligation
Security & fraud preventionMonitor log‑ins, enforce MFA, detect abuseLegitimate interestsKeep platform and users secure

Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, we have balanced those interests against your rights and find them proportionate.

Automated decision‑making

If we make an automated credit or identity decision that significantly affects you, you have the right to request a human review before a final decision is made.


5. Who we share data with

We only disclose your information when strictly necessary and with written agreements in place.

CategoryTypical recipientsSafeguards
Core service platformsBooqable (rental software), Stripe (payments), web‑hosting & database providerUK/EU data centres or Standard Contractual Clauses (SCCs)
Delivery & logisticsCouriers / 3PL partnersUK only
IT & securityManaged‑service provider (MSP), cloud backup, email serviceISO‑certified suppliers
Analytics & advertisingGoogle, Meta, TikTok, LinkedInSCCs / adequacy
Professional advisersLawyers, accountants, insurersConfidentiality agreements
Group companiesOther 2Me brands for consolidated customer careIntra‑group agreement
Regulators & law enforcementHMRC, FCA, policeLegal obligation

A full up‑to‑date list of processors is available on request.


6. International transfers

Some suppliers are based outside the UK. When this happens, we ensure your information receives an equivalent level of protection through one of the following:

  • The destination country has an adequacy decision from the UK Government; or
  • We put in place Standard Contractual Clauses (SCCs) plus additional safeguards where needed.

7. How long we keep your data

Record typeRetention periodReason
Rental contracts & invoices6 years after the end of the tax yearHMRC record‑keeping
Identity documentation5 years from last transactionAnti‑fraud & KYC standards
Marketing records (consent logs)Until you opt out + 2 yearsDemonstrate compliance
Support tickets3 yearsResolve repeat issues
Website logs12 monthsSecurity & troubleshooting
Cookie identifiers13 months (analytics) / as set in bannerICO guidance

We then securely delete or anonymise the data.


8. Cookies and similar technologies

Our website uses:

  • Strictly necessary cookies – to remember your cart, keep you logged‑in, and process payments via Booqable.
  • Analytics cookies – Google Analytics, to understand how visitors find and use our site.
  • Advertising cookies – Meta, TikTok, LinkedIn pixels so we can show relevant ads and measure their performance.
  • Preference cookies – store your cookie choices and site settings.

Our cookie banner lets you accept all, reject all or customise. You can change your mind anytime via the “Cookie Settings” link at the bottom of this page.


9. How we keep your data secure

  • TLS encryption for all data in transit
  • Industry‑standard encryption at rest for databases
  • Multi‑factor authentication (MFA) for staff and admin accounts
  • Role‑based staff access on a need‑to‑know basis
  • Regular backups and penetration testing
  • Supplier due‑diligence and confidentiality clauses

10. Children

gym2me is for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.


11. Your rights

You can exercise the following rights under UK GDPR:

  1. Access – request a copy of your data.
  2. Rectification – correct inaccuracies.
  3. Erasure – ask us to delete data in certain circumstances.
  4. Restriction – limit how we use your data.
  5. Portability – receive your data in a machine‑readable format.
  6. Objection – object to processing based on legitimate interests or direct marketing.
  7. Withdraw consent – for any processing based on consent.
  8. Human review – of automated decisions.

How to make a request

Email [email protected] or write to the address above. We aim to respond within one calendar month. We may need to verify your identity first.


12. Complaints

If you are unhappy with how we handle your data, please tell us so we can put it right. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF – https://ico.org.uk – 0303 123 1113. Our ICO registration number: ZB909419.


13. Changes to this policy

We may update this notice from time to time; the latest version will always be posted here with the “Last updated” date. Significant changes will be highlighted on our website or emailed to active account holders.


Thank you for choosing gym2me. We’re here to keep your fitness journey smooth, secure and privacy‑friendly.