Product

Security and GDPR: EU Hosting and a Data Processing Agreement

How Sparekey handles your customers' data: our servers in the EU, a data processing agreement, minimal data collected and door codes that expire.

Sparekey runs on our servers in the EU under the GDPR and the UK GDPR. We sign a data processing agreement with you and collect only what is needed to let a customer in and invoice them.

Who is responsible for what

You are the controller: you decide why customer data is collected and how long it is kept, publish your privacy notice and answer customers’ requests. We are the processor: we handle the data only to run the system for you.

  • We sign a data processing agreement before launch: what we process, why, for how long and with which services.
  • We use the data only for bookings, door codes, messages, invoices and statistics. We never sell it.
  • Other services involved: Stripe, the text message provider, the e-mail service and, where your lock uses one, the lock maker’s service.

Where the data is kept

On our servers in the EU. UK data protection law allows personal data to be kept there.

What a booking collects

  • the customer’s name, phone number (for the code) and e-mail (for the confirmation and invoice);
  • the location, date and time they booked;
  • whether the payment went through, and the invoice.

Card details never reach Sparekey: customers pay on Stripe’s page and we only receive the result. No health data, no fingerprints or face scans.

Door codes that expire

Each booking gets its own code, valid only for the booked slot. A forwarded code does not open the door on another day.

Your data is yours

Export your bookings and revenue at any time, free of charge.

What stays with you as the operator

Whatever system you use:

  • A camera needs a notice for customers, a reason for recording and a limit on how long recordings are kept. See cameras in an unstaffed gym.
  • Your privacy notice and booking terms tell customers what you collect and why. We help with the parts that concern the system.
  • Customers’ requests to see or delete their data come to you. Where the system holds the data, we handle it for you.

FAQ

Do you sign a data processing agreement?

Yes, with every gym, before launch.

Where is the data stored?

On our servers in the EU.

Do you see my customers’ card details?

No. Customers pay on Stripe’s page.

Can I export my bookings?

Yes, at any time and at no cost.

How does a customer get their data deleted?

They ask you, as the controller. We delete it on your request, keeping invoices as tax rules require.

Demo and consultation

See it on a demo, then decide.

Write by e-mail or WhatsApp with your town, your space and your door. We set a time for a free call and go through hours, slots, doors and payments.