What we collect, in plain English.
Three things live under this heading: this website, the product, and the Instagram connection a studio can switch on inside the product. They are treated differently and each is described below.
Last updated 24 September 2026. Fullroom is an Australian business and this policy is written to the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Fullroom makes the software, and answers for this policy.
Fullroom is operated by Thomas Paul James-Wallace (trading as Fullroom), ABN 39 899 578 716, South Australia. Fullroom runs the staff app at staff.fullroom.com.au and the member app at app.fullroom.com.au. Studios in the REVL Training network use them, and the Meta app a studio sees when it connects Instagram is called Fullroom Insights. It is our app, and this policy covers it.
Privacy questions, access and correction requests and deletion requests all go to privacy@fullroom.com.au.
The only thing this site collects is what you type into the demo form.
Your name, email, studio, number of sites, booking system and whatever you write in the notes field. It becomes an email to us and nothing else. There is no database behind that form. We do not add you to a mailing list and we do not sell it.
The one party it passes through is Resend, which delivers that email for us, and our own mail provider that receives it. Both are handling it in transit on our instruction. Nobody else sees it.
No advertising cookies, no third-party trackers.
The site stores one thing in your browser: whether you chose the light or dark theme. That never leaves your device. Fonts are requested from Google Fonts, which means Google sees the request. We intend to self-host them, which removes that.
Studio data belongs to the studio.
When a studio uses Fullroom, we process member data on that studio's instruction: attendance, membership state, training records and the check-ins members choose to enter. Each brand's data sits in its own database. Nothing is combined across brands and nothing is sold to anybody, ever.
We never receive or store card numbers. Payments stay in your booking system.
If a studio connects its Instagram, this is exactly what we read.
A studio manager can connect the studio's own Instagram professional account from Settings, Studio in the staff app. They sign in to Instagram and approve the Fullroom Insights app. Fullroom then reads that account's own posts and performance numbers and shows them to the studio, so it can see which posts reach people. That is the only thing the connection is for.
Two read permissions, and nothing that can post or message.
instagram_business_basic lets us read the account's username, its account id, its follower count and its list of posts. instagram_business_manage_insights lets us read the performance numbers Instagram already shows the account holder. We do not ask for permission to publish, comment, reply or send messages, so the connection cannot do any of those things.
The account, its posts, and their numbers.
| Data | Detail |
|---|---|
| The account | Instagram username, the professional account id, and whether it is a business or creator account (checked at connection, so a personal account is turned away). |
| Access token | The token Instagram issues when the studio approves the app, and when it expires. We never see or store the Instagram password; that is typed into Instagram, not into Fullroom. |
| Posts | For each of the account's own posts: its id, type, caption, link, thumbnail link and posting time. |
| Post numbers | Counts Instagram reports per post, such as reach, views, likes, comments, saves and shares. Captured once a day so the studio can see how a post performed over time. |
| Account numbers | Daily account-level totals, such as followers, reach and profile activity. |
| Who connected it | Which staff member connected the account, and when. |
The numbers are totals. We do not collect who liked, commented, followed or viewed, we do not read the text of comments, and we do not read direct messages. A caption can mention a person, because the studio wrote it; we store it as the studio wrote it and use it only to label the post.
Showing the studio its own performance. Nothing else.
Instagram data is used only to show the studio how its own account and posts are performing, inside its Fullroom dashboard. It is not sold, licensed or shared with anyone outside Fullroom and the studio's own network. It is not used for advertising, it is not combined with member records, and it is not used to build a profile of any person.
That studio's managers, and the head office that runs the network.
Inside Fullroom, a studio's Instagram numbers are visible to staff at studio manager level and above who are assigned to that studio, and to REVL Training head office staff who oversee every studio in the network. Coaches and members cannot see them. Fullroom staff can access them only to run, support and fix the service.
The token is encrypted, and never sent to a browser.
Access tokens are encrypted with AES-256-GCM before they are stored. The key is kept outside the database, so a copy of the database alone cannot be used to reach anyone's Instagram. Each token is bound to its own studio's record. No token is ever sent to a browser, including the browser of the manager who connected it. All traffic is encrypted in transit.
The token until it is disconnected. The history while the studio is with us.
The access token is kept until the studio disconnects, removes the app in Instagram, or asks for deletion, and it is deleted then. Instagram tokens last 60 days and we renew them automatically while the connection is in use.
Posts and numbers already collected are the studio's history, and are kept while the studio uses Fullroom so trends stay visible. They are deleted when the studio asks, when a deletion request arrives from Instagram, or within 30 days of the studio's Fullroom service ending.
Three ways, set out step by step.
Disconnect from Settings, remove the app in Instagram, or email us. Each is described, with what it deletes, on the data deletion page.
In Australia.
Product data, including Instagram data, is stored in a Supabase database in its Sydney region, and the product's servers run in Vercel's Sydney region. Both providers are companies based outside Australia and act on our instruction. Meta itself is outside Australia; data Instagram sends us comes from Meta's systems under Meta's own terms.
Ask us and we will tell you, correct it or delete it.
If you are a member of a studio that uses Fullroom, your studio is the first place to ask, because they control the account. If you would rather come to us, email privacy@fullroom.com.au and we will action it, including passing it to the studio where that is the correct route. We reply within 30 days.
If you are not happy with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
If this changes, the date at the top changes.
If we ever want to use Instagram data for anything beyond what is written here, we will change this policy first, and ask connected studios again.