Wellness Club · Origins

Privacy Policy

Last updated · 28 August 2026

This policy explains what URĀ collects about you, why, who else sees it, how long it is kept and what you can ask us to do with it. It covers the URĀ mobile app and the website at claphouse.co. It is written to be read, not to be survived; if anything in it is unclear, write to us and we will explain it in plain words.

01Who we are

The data controller is BUILD ACTIVITY SL, trading as URĀ, at Avinguda des Cap Martinet, 07819 Punta Martinet, Illes Balears, Spain. You can reach us at info@claphouse.club or on +34 686 52 21 80. The same company is the counterparty to your membership agreement, where it is named as CLAP HOUSE (trade name), BUILD ACTIVITY SL (company name).

This policy sits alongside the membership agreement, not instead of it. Where the agreement's data-protection clauses and this policy describe the same thing, this policy is the detailed version.

02Who you are to us

We collect the details a club has to hold to let a named person through a door and to bill them. You give them to us when you join, when reception registers you at the desk, and when you edit your profile in the app.

  • Your name, email address and telephone number. The email address is also how you sign in.
  • Your passport or NIE number, nationality, gender and date of birth. Spanish clubs have to be able to identify a member, and age governs which areas and activities you may use.
  • Your postal address, and — if you are a minor — your guardian's name and identity document.
  • Your bank details, where you pay by SEPA direct debit: the account holder's name and the IBAN. We never hold a card number — see Payments below.
  • Your membership: which pass you hold, when it runs from and to, what you paid, and whether it is active, pending, frozen or expired.

Legal basis: performance of your membership contract, and our legal obligations as a licensed sports and wellness facility. Without these details we cannot admit you to the club.

03Your photograph

The app asks for a photograph of you, taken with the camera or chosen from your photo library. It has one purpose: reception sees it beside your name when you arrive, so the person at the desk can recognise the member in front of them. It is stored with your member record and it is not published anywhere, not used for facial recognition, and not shown to other members.

You can replace it or remove it at any time from your profile in the app. The camera and photo-library permissions are asked for at the moment you use them and are used for nothing else.

Using your image for promotion — on the website, on social media, in a video — is a separate question and needs your separate consent. Accepting the membership agreement does not give it.

04Health information

Your profile has room for what you are training towards, any injuries or conditions you want the club to know about, and an emergency contact with their telephone number. Health data is a special category under Article 9 of the GDPR and we treat it as one: it is visible to the club's own staff and trainers who need it to keep you safe, and to nobody else.

Giving it is your choice. You can leave those fields empty, and you can clear them at any time from the app. Legal basis: your explicit consent, and — for the emergency contact, at the moment it is used — protection of your vital interests.

05Being in the building

Your pass is a code your phone shows to the reader at the turnstile. The reader asks our server whether to open, and every time it asks we record who, which gate, which direction, when, and whether it opened. That is how the club knows who is inside during an evacuation, how your visit history in the app is built, and how a lost or shared pass is spotted.

We also keep what you book and what you use: classes, treatments, workshops, waiting-list places, the guests you invite, your monthly allowances, and what you order at the pool club. Legal basis: performance of the contract, and our legitimate interest in the security and capacity of the building.

06Location — and what leaves your phone, which is nothing

The URĀ app asks for precise location, and on Android for background location, for exactly one feature: the arrival notice. It is switched off until you switch it on.

Here is how it works, in full. Your phone's own operating system watches a single circle drawn around the house at Cap Martinet. When you cross into it, the operating system wakes the app and the app raises a notification on your phone, so your pass is ready before you reach the gate. The comparison is done by iOS or Android, on the handset. The app is handed one fact — that you have arrived — and it sends that fact nowhere.

Your location is never sent to the club. There is no coordinate in the club's database, no request in the app that carries one, and no way for anybody at URĀ to see where you are or where you have been. So that you are not told twice in a day, your phone stores the date of your last arrival note; that date stays on your phone, and switching the feature off deletes it.

You can withdraw the permission at any time, in the app or in your phone's settings, and the feature simply stops.

One exception, and it is on the website rather than in the app. If the club switches on the browser's “open the door” button and you press it, your browser asks your permission and sends one position to our server, which checks only whether you are within 150 metres of the entrance before releasing the turnstile. The coordinate is used for that check and is never stored; what we keep is the same entry record we would keep if you had scanned your pass at the reader.

07Notifications

If you allow notifications, your phone issues a push token — an address for that handset — and the app sends it to us with the device's name (so you can tell your two phones apart) and the app's version number. We use it to tell you a waiting-list place has come free, that a booking changed, or that reception has replied to you.

Legal basis: your consent. Switching notifications off in the app removes the registration from our systems; signing out removes it too, which is deliberate — a phone that is sold or handed on must not keep receiving a stranger's messages.

08Payments, and your card

NO CARD NUMBER EVER REACHES THE APP OR THE CLUB'S SERVERS. When you pay for a class pass, a workshop, a session pack or a treatment, the app asks our server for a checkout link and opens Square's own hosted payment page. You type the card there, on Square's page, and Square tells us only whether it was paid.

If you save a card so lunch at the pool club can be charged to it, what the club holds is an identifier issued by Square, the card's brand, the last four digits and the expiry — never the number, and never anything that could be used to pay anywhere else.

What we do keep is what you bought, what it cost, when, and whether it was delivered — because that is an accounting record and Spanish law requires us to be able to produce it. Legal basis: performance of the contract, and our legal obligations.

09Talking to reception

Messages you send through the concierge, and the replies the desk sends back, are kept with your account so the conversation has a history and the next person on the desk knows what was already said. We also record that a transactional email was sent to you and whether it was delivered, so a member who says they never got their access link can be believed and helped.

10The website

The website counts page views through Vercel Analytics, which does not use cookies for it and does not build a profile of you. The app does not do this at all. The only cookies the site sets are the ones that keep you signed in and remember whether you chose English or Spanish and a 12- or 24-hour clock.

11Who else sees your data

We do not sell your data and we do not share it for anybody else's advertising. It is handled on our behalf by the following processors, each for one job and under a contract that limits them to it.

  • Neon — the club's database. Everything described above is stored there.
  • Vercel — hosts the website and the app's interface to the club, and keeps short-lived server logs.
  • Resend — sends the club's email: your access link, booking confirmations, approvals and receipts.
  • Expo — delivers push notifications to your handset. It receives the device token and the text of the notice.
  • Square — takes payments and holds the card you save. Square is also a controller in its own right for its own records of the payment.
  • Gantner — the turnstile controllers in the building. A reader sends the scanned code to our server; our server, not Gantner, decides whether the door opens.

We also disclose data where the law requires it — to the authorities, to our accountants and auditors, and to our lawyers if we ever have to defend a claim. Some of these providers operate outside the European Economic Area; where they do, transfers are made under the European Commission's standard contractual clauses.

12How long we keep it

For as long as you are a member, and afterwards only for as long as we have a reason. Your profile, your photograph, your health notes, your bookings and your entry history go when you leave or when you delete your account, whichever comes first.

Two things outlast that, and both are obligations rather than choices. Accounting records — invoices, payments, refunds and what was delivered for them — are kept with the name that was on them for six years under the Código de Comercio and four under Spanish tax law. And the club's audit log, the record that an action happened, is kept for security and accountability; the entry written when you delete your account names your member number and nothing else.

13Your rights

Under the GDPR you may ask us for any of the following, free of charge, and we will answer within one month.

  • Access — a copy of what we hold about you.
  • Rectification — correction of anything that is wrong. Most of it you can correct yourself in the app.
  • Erasure — deletion of your data, subject to the accounting records described above.
  • Objection — to processing we carry out on the basis of our legitimate interest, and to marketing at any time and without giving a reason.
  • Restriction — a pause on processing while a disagreement about it is resolved.
  • Portability — the data you gave us, in a machine-readable file you can take elsewhere.
  • Withdrawal of consent — for your health notes, your notifications and your location, at any time. Withdrawing it does not undo what was lawfully done beforehand.

To exercise any of them, write to info@claphouse.club from the address on your account. We may ask you to prove who you are before we act — which protects you from somebody else asking on your behalf. If you are not satisfied with our answer you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (www.aepd.es).

14Deleting your account

You can close your account and delete your data yourself, without asking anybody. In the app: You, then “Delete your account” at the bottom of the screen. In a browser, with or without the app installed: claphouse.co/account/delete. Both do exactly the same thing, immediately and permanently.

The deletion page lists in full what is removed and the two things the club has to keep. If you cannot sign in, write to us from the address on the account and we will do it by hand.

15Children

A member under 18 joins with the authorisation of a parent or guardian, whose name and identity document we record alongside theirs, and the club's age rules govern which areas and activities they may use. The app is not directed at children under 14.

16Changes to this policy

If what the club does with your data changes, this page changes with it and the date at the top is updated. A material change is announced in the app or by email before it takes effect.

17Contact

BUILD ACTIVITY SL · URĀ
Avinguda des Cap Martinet, 07819 Punta Martinet, Illes Balears, Spain
info@claphouse.club · +34 686 52 21 80

Delete your account and your data · Membership agreement

URĀ · Wellness Club · Talamanca, Ibiza