Privacy Policy

bash is a gym-management platform built and operated by We Break Desks Pte. Ltd. (UEN 202514905R), a company incorporated in Singapore (“bash”, “we”, “us”). This policy explains what personal data we collect, how we use and share it, and the rights you have, in line with Singapore’s Personal Data Protection Act 2012 (PDPA).

Last updated: 12 July 2026

Who this covers

This policy applies to everyone whose personal data bash handles: the operators and staff of the studios, gyms, and boxes that use bash to run their business, and the members who train at those venues and use bash to book and pay. It applies to the bash web app, the member apps, and joinbash.app.

The personal data we collect

Account and identity: the email address you sign in with, your name, and — if you choose to sign in with Google or Apple — the basic profile they share (your name and email). A phone number where you provide one.

Operator and business data: for the people who run a venue — business name, your role, and the business and payout details needed to accept payments (such as a business registration number and the payout account identifiers held by our payment provider).

Member profile: what a venue records to run your membership — your name, contact details, date of birth, emergency contact, and the status of any waiver or health acknowledgement you sign.

Activity: schedules, class bookings, cancellations, attendance and check-ins, and credit and membership balances.

Payments: the amount, date, currency, reference, and status of a transaction. Full card or bank details never reach bash — they are captured by our payment provider on its own secure systems (see the “Who we share data with” section).

Technical and device data: IP address, device and browser type, app version, diagnostic and security logs, and — if you enable push notifications — a device push token.

Cookies: strictly-necessary cookies to keep you signed in and your session secure (see the “Cookies” section).

How we use your data

To run the service: create and secure your account, show schedules, take bookings, track credits and memberships, and process payments.

To communicate with you: send the service messages you need — sign-in links, booking confirmations, receipts, and important notices. We only send marketing where you have agreed, and you can opt out at any time.

To keep bash safe and working: authenticate you, prevent fraud and abuse, diagnose problems, and protect the platform and its users.

To meet our obligations: bookkeeping, tax, and legal or regulatory requirements.

We do not sell your personal data, and we do not use it for third-party advertising.

Our legal basis (PDPA)

We collect, use, and disclose personal data with your consent; on the basis of consent deemed given under the PDPA when you provide data to make a booking or run your membership; or where the PDPA otherwise permits — for example, to complete a transaction you asked for, for legitimate business purposes carried out in a reasonable manner, or to comply with the law. You may withdraw consent as described in the “Your rights” section.

Who we share data with

Your venue: if you are a member, the operator and staff of the venue you train at can see the member data needed to run your membership. bash keeps every venue’s data strictly separated — one venue can never see another venue’s members.

Our service providers, who process data only on our instructions and under their own security and privacy commitments: hosting and database — Supabase (data stored in Singapore, AWS ap-southeast-1); payments — HitPay, which captures and processes card and bank details on its own systems; sign-in — Google and Apple, if you choose them; push notifications — Google Firebase Cloud Messaging; and email delivery — Resend.

Legal and safety: authorities, regulators, or professional advisers where the law requires it, or to protect the rights, safety, and integrity of bash and its users.

Business transfers: if bash is involved in a merger, acquisition, or sale of assets, personal data may transfer to the successor, which will remain bound by this policy.

Who is responsible for your data

For your relationship with bash — your sign-in account and your use of the platform — bash is the organisation responsible for your data.

For the member data a venue records to run its own business, the venue is responsible for that data and bash handles it on the venue’s behalf and instructions. If you are a member and want your data corrected or removed, your venue is usually the fastest route; you can also contact us and we will help.

Where your data is stored

bash stores data with our database provider in Singapore (AWS ap-southeast-1), encrypted in transit and at rest. Some service providers (for example sign-in, email, and push notifications) may process limited data outside Singapore; where they do, we rely on their contractual and security commitments to protect it to a standard comparable to the PDPA.

How we protect your data

We protect personal data with encryption in transit and at rest, strict per-venue isolation enforced at the database level, encryption of sensitive secrets (such as a venue’s payout keys) using a dedicated key-management service, and access limited to what is needed to run the service. No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong.

If a data breach occurs that is likely to result in significant harm to affected individuals, or affects a significant number of individuals, we will notify the Personal Data Protection Commission and the affected individuals as the PDPA requires.

How long we keep it

We keep personal data for as long as your account or membership is active, and afterwards only as long as we need it for the purposes described here or to meet bookkeeping, tax, and legal obligations. We then delete or anonymise it.

Your rights

Under the PDPA you can ask what personal data we hold about you and how we have used or disclosed it, ask us to correct it, ask us to delete your account and the personal data we hold about you, and withdraw your consent to our use of it. Withdrawing consent or requesting deletion may mean we can no longer provide part of the service, and we may need to keep certain records where the law requires (see “How long we keep it”). For member data your venue controls, a deletion request may need to go through your venue. To make a request, contact us using the details below; we will verify your identity and respond within 30 days, telling you if we need longer.

Cookies

bash uses strictly-necessary cookies to sign you in and keep your session secure. We do not use advertising or cross-site tracking cookies.

Children and young members

bash is not directed at children. Where a venue enrols a minor, the venue is responsible for obtaining any parental or guardian consent required and for the accuracy of that member’s data.

Changes to this policy

We may update this policy as bash evolves or the law changes. We will post the updated version here with a new “last updated” date and, where changes are material, tell you in an appropriate way.

Contact us

Questions, requests, or complaints about your personal data — including any request to access, correct, or withdraw consent — can be sent to our Data Protection Officer at data@webreakdesks.com. If you are a member, you can also ask your venue. You may also lodge a complaint with Singapore’s Personal Data Protection Commission (PDPC).