Rampp

Privacy Policy

Effective 11 May 2026 · Last updated 2 July 2026

This policy explains what data the Rampp mobile app collects, why we collect it, where it is stored, and the rights you have over it. Rampp is provided by James Redmond ("we", "us", "the operator"). If you have questions about anything in this policy, email jredmond135@gmail.com.

If you operate Rampp through a registered business entity, replace "James Redmond" above with the legal entity name and registered address before you submit to the App Store.

1. Who this policy applies to

This policy applies to anyone who installs the Rampp app on iOS or Android, creates an account, or is invited into a team inside the app. It covers data we collect through the app itself. It does not cover third-party services you reach by leaving the app.

2. What we collect

We only collect what the app needs to work. We do not sell data, we do not run advertising trackers, and we do not share data with data brokers.

Account data

Training data you create

Team data

Technical data

We do not collect: precise location, contacts, browsing history, health data from Apple Health or Google Fit, biometric data, or financial information.

Notifications

RAMPP Nutrition marketing emails (optional)

3. Why we collect each item

DataWhy
EmailSign-in and account recovery.
Display name and roleSo your coach and teammates can identify you inside a team.
Session and set logsThe core function of the app — logging your training.
Daily check-insSo you and your coach can spot fatigue or wellness trends across a training block.
PhotosVisual proof that a session was completed ("training receipts").
Team memberships and invite codesSo coaches can manage who is in a team.
Reports and blocksContent moderation and user safety.
Crash diagnosticsFixing bugs and improving reliability.

4. Legal basis (UK and EU users)

Under UK GDPR and EU GDPR, we rely on:

You can withdraw consent at any time by deleting the relevant data in the app, or by deleting your account.

5. Where your data is stored

Rampp is built on Supabase, hosted in the EU-West-1 region (Ireland). Backups stay inside the EU.

Email delivery for sign-in codes goes through Resend (resend.com). Resend processes your email address solely to deliver the code to you.

If you explicitly opt in to marketing emails inside the app (the "RAMPP Nutrition deals" checkbox), your email address and display name are shared with Klaviyo (klaviyo.com), the service we use to send those emails. This only happens when you tick the box, and you can opt out at any time in the app or via the unsubscribe link in any email. If you never opt in, nothing is sent to Klaviyo.

Marketing emails (if you opted in) are sent via Klaviyo (klaviyo.com), which stores your email address and first name to deliver those campaigns. Klaviyo's privacy notice is at klaviyo.com/legal/privacy-notice.

We do not transfer your data outside the European Economic Area, except for marketing emails which use Klaviyo's US-based infrastructure (operating under the EU-US Data Privacy Framework).

6. Who can see your data

We do not share data with advertisers, analytics networks, or data brokers.

7. How long we keep your data

We keep your data for as long as your account exists. When you delete your account from inside the app (Account → Delete Account):

Backups containing deleted records are rotated out within 30 days.

8. Your rights

If you are in the UK, EU, or another jurisdiction with similar laws, you have the right to:

To use any of these rights, email jredmond135@gmail.com. We will respond within 30 days.

9. Children

Rampp is not directed at children under 13. We do not knowingly collect data from children under 13. If a coach intends to use Rampp with players under 13, the player's parent or guardian must consent and create the account on the player's behalf. In jurisdictions where the GDPR age is set higher than 13 (for example, 16 in some EU states), the local age applies.

If you believe a child has signed up without parental consent, email jredmond135@gmail.com and we will remove the account.

10. Security

Data in transit is encrypted with TLS. Data at rest in Supabase is encrypted. Row-level security policies in our database restrict every row to its owner and authorised team members.

No system is perfectly secure. If we ever detect a breach affecting your data, we will notify you and the Irish Data Protection Commission within 72 hours as required by GDPR.

11. Changes to this policy

If we make material changes to this policy we will update the "Last updated" date at the top and, where appropriate, notify you inside the app. Continuing to use Rampp after a change means you accept the updated policy.

12. Contact

James Redmond
Email: jredmond135@gmail.com

This is the address to use for any privacy question, data access request, deletion request, or complaint.