Privacy policy
Last updated: July 30, 2026
Boltt Pty Ltd (ACN: 688 767 062) — Perth, Western Australia, Australia
Introduction and Scope
This Privacy Policy explains how Boltt collects, uses, stores, shares, and deletes personal information in connection with the Boltt platform, including our website at https://bolttband.com, the Boltt wearable tracker, the Boltt athlete mobile application, coach features, backend APIs, dashboards, and related services (together, the "Services").
At Boltt, our mission is to give athletes insight into their performance and recovery—but we believe that insight does not need to be shared with everyone. This policy explains what we collect, why we collect it, and the choices and rights you have over your data.
Boltt processes personal information in accordance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. This Privacy Policy is modeled on the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where Boltt provides Services to individuals in the European Economic Area (EEA), the United Kingdom, or the United States, personal information is also processed in accordance with the General Data Protection Regulation (GDPR), UK GDPR, and applicable US state privacy laws, as relevant.
If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
Definitions
- Athlete: A user who tracks their own activity, sleep, and readiness data through the Services.
- Coach: A user granted access to an athlete's data through an accepted coach-athlete relationship, subject to the athlete's explicit sharing permissions.
- Health and Fitness Data: Biometric and physiological data including sleep, activity, heart rate, HRV, stress, SpO2, and derived scores such as DALI and Voltage.
- DALI and Voltage: Proprietary, algorithmically derived readiness and recovery indicators calculated from synced and manually entered data.
- Personal Information / Personal Data: Information that identifies or is reasonably capable of being linked to an identified or identifiable individual.
- Sensitive Information / Special Category Data: Health, biometric, and similar categories of information that receive heightened protection under the Privacy Act 1988, the GDPR, and applicable global privacy laws.
Controller and Contact Information
For the purposes of applicable data protection laws, including the GDPR, the controller responsible for the collection and processing of your personal information is:
Boltt Pty Ltd
184a Balcatta Road, Balcatta, WA 6021, Australia
Contact: Info@bolttband.com
Published Privacy Policy URL: https://bolttband.com/policies/privacy-policy
Information We Collect
The kind of personal and sensitive information we collect depends on how you interact with our website, the Boltt device, and our applications. Where practicable, you may browse parts of the Boltt website without identifying yourself; however, use of the Boltt device and application requires account registration.
Biometric and physiological data collected by the Boltt device constitute health information under the Privacy Act 1988 and are treated as Sensitive Information. This data also constitutes Special Category Data under the GDPR. Such information is only processed where you have provided explicit consent or where processing is otherwise permitted under applicable law.
|
Category |
Examples |
Source |
|
Account and profile |
Full name, username, email, password (stored as a secure hash), role, country, date of birth or age, gender, phone number, mailing address, profile photo, sport, weight, coach subscription status. |
Provided directly by you during signup, profile updates, or OTP verification. |
|
Verification and security |
Email/phone OTP status, authentication tokens, session state, account status, rate-limit/cooldown records, audit and security logs. |
Generated automatically when you register, log in, verify identity, or use protected APIs. |
|
Health and fitness data |
Sleep logs, sleep stages, duration, efficiency and goals; steps, activity time, sedentary time; heart rate, resting heart rate, HRV, stress, SpO2, skin temperature; DALI, Voltage, and other derived trend scores. |
Synced from the wearable device or app, or calculated by Boltt backend services. |
|
Coach-athlete sharing |
Coach/athlete relationship and invite status, linked profile snapshot, and sharing permissions for DALI, HRV, sleep metrics, stress, and resting heart-rate variance. |
Created when coaches invite athletes and athletes accept, reject, or adjust sharing permissions. |
|
Device and app operations |
Device identifiers, Boltt strap serial number, IP address, operating system and app version, Bluetooth identifiers, FCM push token, API request metadata, diagnostic and error logs, cookie identifiers. |
Collected automatically from the device, app, and backend infrastructure for operation, notifications, troubleshooting, and security. |
|
Payment data |
Stripe customer ID, checkout session ID, order ID, payment status, amount, currency, payment intent reference, billing address, transaction history. |
Processed through Stripe for coach payments and store purchases; full card details are handled by Stripe and are not stored by Boltt. |
|
Support and communications |
Messages, emails, issue details, feedback, and survey responses. |
Provided by you when you contact support or participate in surveys. |
|
Marketing and preferences |
Marketing preferences, promotional engagement, referral program participation. |
Provided by you, or inferred from your interaction with marketing communications. |
|
Analytics / crash reporting |
Device model, OS version, crash stack traces, unique installation UUIDs, coarse usage events, app interaction, and screen navigation patterns. |
Collected automatically through integrated tools including Firebase Analytics and Firebase Crashlytics. |
|
Inferred or derived data |
Performance analytics, recovery insights, and training recommendations generated by Boltt algorithms. |
Derived by Boltt from the categories above. |
How We Collect Information
Direct Collection: Information you provide when you create an account, complete forms, purchase devices or subscriptions, communicate with customer support, or participate in surveys.
Automatic Collection: Information collected automatically through the operation of the Boltt device and Services, including biometric sensor data recorded by the wearable device, tracking synchronisations, device telemetry, and cookies.
Third Parties: From our service providers who enable our underlying technology, as well as our business or marketing partners.
Why We Use Your Information and Our Legal Bases
|
Purpose |
Description |
Legal Basis |
|
Service delivery |
Operate the wearable service, synchronise device data, provide performance insights, process purchases and subscriptions, manage your account, arrange shipping, facilitate returns and exchanges. |
Contractual necessity |
|
Biometric and performance analysis |
Generate recovery insights, performance scores, and training recommendations (DALI, Voltage, trends) from synced and manually entered health data. |
Explicit consent |
|
Coaching and data sharing |
Let athletes voluntarily share selected metrics with coaches through the coaching portal. |
User consent |
|
Security and fraud prevention |
Authenticate accounts, provide a secure payment and shopping experience, detect and investigate fraudulent or unsafe activity. |
Legitimate interests / legal obligation |
|
Product improvement |
Analyse aggregated or de-identified data to improve platform functionality and device accuracy. |
Legitimate interests |
|
System communications |
Send service notifications, firmware updates, and safety communications. |
Legitimate interests / contractual necessity |
|
Marketing |
Send promotional communications and show relevant advertising. |
Consent (withdrawable at any time) |
|
Legal reasons |
Comply with applicable law, respond to valid legal process, enforce our terms and policies. |
Legal obligation |
Coach Portal Data Processing
Athletes may voluntarily share selected metrics with coaches or trainers through the Boltt coaching portal. Once shared, a coach acts as an independent controller of that data for their own coaching purposes. While Boltt requires all coaches to contractually agree to strict data protection standards via our Coach Terms of Service, users acknowledge that recipients they direct us to share data with are responsible for their own subsequent handling of that information.
SMS and Text Messaging
By providing your mobile phone number, you consent to receive text messages from Boltt, including one-time passcodes and verification codes for account security and authentication. Message and data rates may apply, and message frequency varies. You can opt out of SMS messages at any time by replying STOP to any message, or by contacting Info@bolttband.com for help. No mobile information is shared with third parties or affiliates for marketing or promotional purposes, and mobile opt-in/consent data is not shared with any third party for any other purpose.
Health and Fitness Data Commitments
- Feature Limitation: Health and fitness data is used only to provide fitness, recovery, and coaching features visible to you.
- No Commercial Data Sales: We do not sell health or fitness data.
- No Advertising Transfers: We do not transfer health or fitness data to advertising networks, data brokers, or information resellers.
- No Unrelated Profiling: We do not use health or fitness data for personalised advertising, creditworthiness assessment, lending, insurance underwriting, or employment decisions.
- Data Minimisation: We request only the minimum health, fitness, device, and notification permissions needed for the feature you choose to use.
- Consent Withdrawal: Sensitive biometric information is only collected with your explicit opt-in consent, which you can withdraw at any time by no longer wearing your device. Withdrawing consent may limit the functionality of the Boltt service.
Coach Sharing and User Controls
Athletes may choose to connect with coaches. A coach receives athlete data only through an accepted coach-athlete relationship, and only for the specific categories the athlete has enabled for sharing. Supported sharing categories include Voltage, DALI, HRV, sleep metrics, stress, and resting heart-rate variance.
Athletes may change sharing permissions or disconnect a coach relationship from the app at any time. When sharing is disabled for a category, the coach no longer receives that category through coach-facing APIs.
How We Disclose Information
We do not sell personal information. We disclose personal information only as described below, and only to the extent needed for the stated purpose.
|
Recipient |
Purpose |
Data Involved |
|
Accepted coaches |
Provide coaching, roster, trends, and athlete metric views based on athlete permissions. |
Athlete profile snapshot and permitted health/fitness categories. |
|
Firebase / Google Cloud |
Authentication, database, cloud functions, storage, hosting/infrastructure, security, logging, and service operation. |
Account, app, and health/fitness data needed to operate backend services. |
|
Stripe |
Checkout, payment verification, customer/order status, receipts. |
Coach and store payment metadata and Stripe identifiers; full card data is not stored by Boltt. |
|
Email/SMS/push providers |
Deliver OTPs, transactional notices, invitations, and app notifications. |
Contact details, device push token, and message metadata needed for delivery. |
|
Support and operations staff |
Troubleshooting, security, user support, abuse prevention. |
Limited account and operational data, based on role and need. |
|
Business and marketing partners |
Provide marketing services and personalised advertising based on your online activity across merchants and websites (excludes health and fitness data). |
Contact and usage data as permitted by your marketing preferences and applicable opt-outs. |
|
Shopify and related vendors |
IT management, payment processing, data analytics, customer support, cloud storage, fulfilment, and shipping for the website store. |
Order, account, and device/usage data needed to provide the website Services. |
|
Corporate group / affiliates |
Internal business operations within our corporate group. |
As relevant to the business purpose. |
|
Business transactions |
In connection with a merger, acquisition, financing, or similar transaction, or bankruptcy. |
As relevant to the transaction, subject to confidentiality protections. |
|
Legal or safety recipients |
Comply with law, respond to valid legal process (including subpoenas or search warrants), enforce our terms, prevent fraud or security incidents, or protect users. |
Relevant information required for the specific request or incident. |
Our service providers act as data processors and are contractually required to process data only on our instructions, implement appropriate safeguards, maintain confidentiality, and delete or return personal information when their services conclude.
Our website store is hosted by Shopify, which collects and processes personal information about your access to provide the e-commerce interface. To learn more about how Shopify uses your personal information, visit the Shopify Consumer Privacy Policy at https://www.shopify.com/legal/privacy/app-users.
Cookies, Mobile Identifiers, and Analytics
Boltt uses cookies and similar technologies to operate and improve our website and applications. These include essential cookies required for core functionality, analytics cookies measuring usage, and functionality cookies that store your preferences. Where required by law, you will be provided with a cookie consent mechanism allowing you to accept or decline non-essential cookies. If you visit our website with the Global Privacy Control (GPC) opt-out signal enabled, we treat this as a request to opt out for that device and browser.
Our mobile application utilizes mobile analytics and crash-reporting tools—specifically Firebase Analytics and Firebase Crashlytics—to monitor application performance and stability. These tools collect device identifiers, coarse usage events, and crash diagnostics. These analytics tools do not collect health or fitness data, and we do not use advertising SDKs to build profiles from your health data.
Automated Processing and Profiling
DALI, Voltage, and related trend scores are calculated automatically from synced and manually entered data using defined scoring rules. These are informational fitness and readiness indicators, not automated decisions that produce legal or similarly significant effects, and they do not determine eligibility for credit, insurance, employment, or any service outside the Services themselves.
Where automated analytics are used, you may request access to the underlying data used to generate insights, object to certain processing activities where permitted by law, and withdraw consent for biometric analysis. If you are located in a jurisdiction governed by the GDPR, you also have the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect concerning you.
Cross-Border Transfers
Boltt operates globally and may store or process personal information outside Australia, including in the United States, United Kingdom, and European Union, where our cloud infrastructure, vendors, or personnel operate.
Boltt takes reasonable steps consistent with the Australian Privacy Principles to ensure overseas recipients handle personal information consistently with the APPs. Where personal data from the European Economic Area (EEA) or United Kingdom is transferred internationally, we implement appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and equivalent contracts issued by the relevant UK authority, ensuring our cloud storage infrastructure (managed by Google Cloud) enforces industry-standard data safeguards.
Data Security and Retention
- Encryption: Personal and sensitive data is transmitted using modern cryptography such as HTTPS/TLS and is encrypted at rest.
- Hashing: Passwords are stored as secure password hashes, never in plain text.
- Access Controls: Access to production data is strictly limited to authorised personnel with a genuine business need, governed by role-based authorisation controls.
- Sanitisation: Sensitive fields such as password hashes and push tokens are not returned in normal, sanitised user responses.
We retain account, health, fitness, coaching, payment, and operational records for as long as needed to provide the Services, maintain security, comply with legal obligations, resolve disputes, and enforce our agreements. Personal information is securely deleted, destroyed, or permanently de-identified once no longer required.
Account Deletion
You can request permanent account deletion by contacting info@bolttband.com. Deletion removes your account, related database records, coach-athlete relationships, authentication accounts, OTP records, and profile images, where technically possible. Regular database deletion occurs immediately, while backup server archives completely overwrite and purge data within a strict 30-day retention window.
Data Breach Notification
If Boltt experiences a data breach likely to result in serious harm to individuals, we will comply with the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth). Where required, we will notify affected individuals as soon as practicable, notify the Office of the Australian Information Commissioner (OAIC), and provide information about the nature of the breach and recommended steps. Where the GDPR applies, we will also notify relevant supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of a breach.
Your Rights and Choices
Depending on where you live, you may have some or all of the following rights in relation to your personal information. These rights are not absolute, may apply only in certain circumstances, and in certain cases we may decline a request as permitted by law.
- Access / Know: Request access to the personal information we hold about you.
- Correct: Request correction of inaccurate or outdated personal information.
- Delete: Request deletion of personal information we hold about you, including your account.
- Portability: Request a copy of your personal information, or that we transfer it to a third party.
- Opt Out: Opt out of the sale or sharing of personal information, or its use for targeted advertising, where applicable.
- Withdraw Consent: Withdraw consent for biometric tracking, coach data sharing, or marketing communications at any time.
- Manage Communication Preferences: Opt out of promotional emails using the unsubscribe link.
UK, EEA, and Switzerland
In addition to the rights above, you may have the right to object to or restrict our processing of your personal information for certain purposes, and lodge a complaint with your local data protection supervisory authority (accessible at https://edpb.europa.eu/about-edpb/about-edpb/members).
United States Rights (Including California CCPA/CPRA)
Residents of California and other states with comprehensive consumer privacy statutes (including Virginia, Colorado, Connecticut, and Utah) have the right to know, correct, delete, and opt out of targeted advertising. Furthermore, because precise GPS data is collected, US users retain the statutory right to Limit the Use of Sensitive Personal Information at any time through their native mobile operating system settings or in-app permissions.
You may exercise any of these rights by contacting us using the details in Section 3. We will respond to requests in a timely manner as required under applicable law, and will not discriminate against you for exercising any of these rights.
Children and Minors
The Services are intended for individuals who have reached the age of majority in their jurisdiction, or who use the Services with appropriate parent, guardian, school, club, or organisational consent. We do not knowingly collect personal information from children under the age of 13 in the United States (consistent with COPPA) or under the age of 16 within the EEA/UK without verifiable parental consent. If you are the parent or guardian of a child who has provided us with personal information without proper consent, you may contact us using the details in Section 3 to request its immediate deletion.
Third-Party Websites and Links
The Services may link to websites or platforms operated by third parties. We are not responsible for the privacy or security practices of sites we do not control, and encourage you to review their policies before providing information. Our inclusion of a link does not imply endorsement of that site or its operator.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, the Services, our vendors, or for other operational, legal, or regulatory reasons. We will post the revised policy on this website and within the app, update the "Last updated" date above, and provide notice as required by applicable law. Where a change materially affects your rights, we will provide reasonable advance notice through the app, website, email, or another appropriate channel before the change takes effect.
Complaints and Contact
If you have a complaint about how we handle your personal information, including a possible breach of the Australian Privacy Principles, please contact our Privacy Officer at info@bolttband.com.
We will acknowledge complaints within 7 business days, investigate the issue, maintain records of our findings, and aim to resolve complaints within 30 business days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC), or with your local data protection supervisory authority if you are located outside Australia.
Nothing in this Privacy Policy excludes, restricts, or modifies any rights you have under the Australian Consumer Law.