Privacy Policy
What we collect, who we share it with, how long we keep it, and what you can ask us to do about it.
Last updated: August 18, 2026
1. Who we are
FitFloww is a client relationship management platform for fitness professionals. It is operated as a sole proprietorship based in California, United States.
Data controller
FitFloww (sole proprietorship)
San Francisco, California, United States
Email: privacy@fitflowwcrm.com
This policy explains what we do with personal data. It applies to our website, the coach application, and the client portal.
2. When we are a controller, and when we are a processor
This distinction decides who you should contact, and it is the part most privacy policies get wrong. FitFloww plays two different roles depending on whose data is involved.
| Data | Who decides how it is used | Our role |
|---|---|---|
| Your coach account, billing, support tickets, marketing contact details | FitFloww | Controller — this policy governs it, and you exercise your rights against us. |
| Records a coach stores about their clients: profiles, measurements, progress photos, session notes, messages | The coach | Processor — we act on the coach’s instructions. This policy describes how we handle it, but the coach decides what is collected and why. |
If you are a client of a coach who uses FitFloww
Your coach decides what to record about you and how long to keep it. Send access, correction, and deletion requests to your coach first — they control the data and can act on it directly. If they cannot be reached, contact us at privacy@fitflowwcrm.com and we will help route the request.
Coaches subject to GDPR need a written processing agreement with us. Our Data Processing Agreement satisfies Art. 28 and applies automatically to every account.
3. Information we collect
What we do not collect
- We do not collect precise GPS location. Location is inferred from IP address at city level only, for security.
- We do not collect biometric identifiers. Progress photos are stored as images and are never converted into a faceprint or other biometric template.
- We do not buy personal data from data brokers.
- We never see or store your password — our authentication provider hashes it.
- We never store payment card numbers. Stripe handles them directly.
- We do not use advertising cookies or run cross-site behavioural advertising.
Account and business data
- Name, email address, phone number.
- Professional credentials, certifications, business name, specialisations.
- Profile photo and branding you upload.
- Subscription plan, billing history, and invoices.
Client records (we process these for your coach)
- Client contact details and profile information.
- Fitness goals, body measurements, workout history, and assessment results.
- Progress photos.
- Nutrition plans and food logs.
- Session notes, injury notes, and messages.
Some of this is health data
Measurements, injury notes, nutrition records, and progress photos describe someone’s physical condition. Under GDPR this is special category data (Art. 9) and under Washington’s My Health My Data Act it is consumer health data. It gets extra protection, and it is covered in more detail in our Consumer Health Data Privacy Notice.
Technical and usage data
- IP address, browser and device type, operating system.
- Pages visited and features used — collected by PostHog only if you accept optional cookies.
- Error reports and stack traces when something breaks, with text and media masked.
- Server access logs.
Marketing and lead data
If you fill in a form on our website, request a demo, or subscribe to updates, we collect the contact details you provide and use them to send you information about FitFloww. Every marketing email has an unsubscribe link, and unsubscribing takes effect immediately.
4. How we use information, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the platform — accounts, scheduling, programmes, messaging, the client portal | Account data, client records | Performance of a contract (Art. 6(1)(b)) |
| Taking subscription payments and issuing invoices | Billing data | Performance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c)) |
| Keeping the service secure, investigating abuse, debugging failures | Logs, error reports, IP address | Legitimate interests (Art. 6(1)(f)) — running a service that stays up and is not abused |
| Product analytics | Pseudonymous usage events | Consent (Art. 6(1)(a)) — collected only if you accept optional cookies |
| Support chat | Chat messages, contact details | Consent (Art. 6(1)(a)) for the widget; legitimate interests for handling the request |
| Marketing email about FitFloww | Contact details, engagement events | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests, with opt-out in every message |
| Processing client health records on a coach’s behalf | Client records | The coach’s instruction under our Data Processing Agreement. The coach is responsible for holding an Art. 9 condition — normally the client’s explicit consent. |
5. Artificial intelligence
We use Anthropic (Claude) for generating marketing and content copy through internal tooling.
- Your data is not used for training. Data sent to our AI provider through the API is not used to train their models.
- Health records are not sent to AI providers. Client health records, progress photos, and private messages are not sent to any AI provider.
- No automated decisions about you. No automated decision with a legal or similarly significant effect is made about you. Scheduling suggestions and programme recommendations are suggestions — a human chooses whether to act on them.
- Output can be wrong. AI models are probabilistic. Anything they generate should be checked before you rely on it.
Data sent to our AI provider is also subject to their privacy policy.
8. How long we keep data
Deletion is not instant, because encrypted backups roll over on a schedule. The table below is what we can actually honour.
| Category | Retention | Notes |
|---|---|---|
| Coach account data | Until deletion, then 30 days | Deleting your account starts a 30-day window during which it can be restored. After that it is removed from live systems. |
| Client records, measurements, session notes | Until deleted by the coach, then 30 days | Controlled by the coach who created them. Deleting a client removes their records on the same 30-day cycle. |
| Progress photos | Until deleted by the coach, then 30 days | Treated as health data. Stored in access-controlled storage, not on a public URL. |
| Messages | Until deleted by a participant, then 30 days | Either participant deleting a conversation removes it for both. |
| Encrypted database backups | Up to 30 days | Point-in-time recovery. Deleted records can persist here until the window rolls over — this is why deletion is "within 30 days" and not instant. |
| Server and access logs | 30 days | Kept for security investigation and debugging, then discarded. |
| Analytics events (PostHog) | 14 months | Only collected if you accept analytics cookies. |
| Email delivery and engagement logs | 12 months | Bounce and unsubscribe records are kept longer so we do not email you again after you opt out. |
| Support chat transcripts | 12 months | Held by Crisp. Only created if you accept optional cookies and open the chat. |
| Billing and tax records | 7 years | Retained because tax law requires it. This survives account deletion. |
9. Your rights
Wherever you live, you can ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate. Most account and client fields can be edited directly in the app.
- Delete — remove your account and its data, subject to the retention table above. You can start this yourself from Settings.
- Port — receive your data in a structured, machine-readable format.
- Object or restrict — challenge processing we base on legitimate interests, or ask us to pause it.
- Withdraw consent — for cookies, from the Cookie Policy; for marketing email, from the unsubscribe link in any message.
How to make a request
Email privacy@fitflowwcrm.com. We reply within 30 days. We may need to confirm your identity first, which normally means replying from the address on the account. There is no charge, and you will not be treated differently for asking.
Export is currently handled by our team rather than a self-service button. Ask us and we will send you a machine-readable copy within the same 30 days.
10. International transfers
FitFloww is operated from the United States, and most of our processors are US-based. If you are in the EEA, the UK, or Switzerland, your data is transferred outside your country.
We rely on:
- The European Commission’s Standard Contractual Clauses, incorporated into our agreements with each processor that needs them.
- The UK International Data Transfer Addendum for UK transfers.
- The EU–US Data Privacy Framework, where the processor is certified under it.
You can ask us for a copy of the safeguards that apply to a particular transfer by emailing privacy@fitflowwcrm.com.
11. Children and young people
You must be 18 or over to open a FitFloww account. We do not knowingly collect personal data directly from children.
Coaches training under-18 clients
A coach can record data about a client who is a minor. If you do, you are responsible for obtaining verifiable consent from a parent or guardian before entering that client’s details, and for complying with the age rules where you and the client live — 13 in the US, 13 to 16 in the EEA depending on the country, and 18 in India.
If you believe a child’s data has reached us without proper consent, email privacy@fitflowwcrm.com and we will delete it.
12. Security
What is in place:
- TLS 1.3 for all data in transit
- AES-256 encryption at rest, applied by our database and storage provider
- Session tokens mirrored into HttpOnly cookies so page scripts cannot read them
- Row-level security policies so one coach cannot read another coach’s records
- Passwords hashed by our authentication provider — we never see or store them
- Card details handled by Stripe and never stored on FitFloww systems
- Automated dependency and secret scanning on every build
- Encrypted database backups with point-in-time recovery
What is not in place
Saying nothing about these would imply we have them. We do not, and you should factor that in when deciding what to store here.
- FitFloww is not SOC 2 or ISO 27001 audited.
- FitFloww is not HIPAA certified and does not sign Business Associate Agreements.
- Messages are not end-to-end encrypted. They are encrypted in transit and at rest, and are readable by our database administrators.
- Multi-factor authentication is not yet available.
- Single sign-on (SAML/OIDC) is not yet available.
If a breach affects your personal data and creates a risk to you, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where GDPR requires, and tell affected users without undue delay. To report a vulnerability, email security@fitflowwcrm.com.
13. Changes to this policy
- The "Last updated" date at the top changes whenever this policy does.
- For changes that materially reduce your rights, we give 30 days’ notice by email or in-app notice before they take effect.
- Continued use after a change takes effect means you accept the updated policy. If you do not accept it, you can delete your account before the effective date.
- Where a change requires your consent under applicable law — for example a genuinely new purpose for existing data — we will ask for it rather than relying on notice.
14. Contact us
Privacy enquiries
FitFloww (sole proprietorship)
San Francisco, California, United States
Email: privacy@fitflowwcrm.com
We respond within 30 days. We have not appointed a statutory Data Protection Officer, because we do not meet the criteria in GDPR Art. 37 that make one mandatory; privacy questions go to the address above.
15. EEA and UK supplement
This section applies in addition to the rest of the policy if you are in the EEA or the UK.
- Legal bases. Set out per purpose in §4.
- Your rights. Articles 15 to 22 — access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions.
- Special category data. Health data is processed on the instruction of the coach who is the controller for it. The coach is responsible for the Art. 9(2) condition, which is normally the client’s explicit consent.
- Complaints. You can lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve it first.
- Article 27 representative. We have not yet appointed EU and UK representatives. Until we do, direct all enquiries to privacy@fitflowwcrm.com.
16. California supplement
This section is our notice at collection under the CCPA as amended by the CPRA. It applies to California residents.
| Category | Collected | Examples | Purpose |
|---|---|---|---|
| A. Identifiers | Yes | Name, email address, phone number, IP address, account ID | Account creation, authentication, support, billing |
| B. Customer records (Cal. Civ. Code §1798.80) | Yes | Billing name and address, payment card details held by Stripe | Processing subscription payments |
| C. Protected classifications | Yes | Age or date of birth, and sex where a coach records it for programming | Calculating training and nutrition targets, at the coach’s direction |
| D. Commercial information | Yes | Plan, billing history, session and package purchases | Billing, support, business reporting for the coach |
| E. Biometric information | No | We do not collect fingerprints, faceprints, or voiceprints. Progress photos are stored as images and are never converted into a biometric identifier. | Not applicable |
| F. Internet or network activity | Yes | Pages viewed, features used, error reports | Security, debugging, and — only with consent — product analytics |
| G. Geolocation data | Yes | Coarse city or country inferred from IP address | Security and fraud prevention. We do not collect precise GPS location. |
| H. Sensory data | Yes | Progress photos and any images a coach or client uploads | Progress tracking, at the coach’s direction |
| I. Professional or employment information | Yes | Certifications, business name, specialisations | Building the coach profile and client-facing booking pages |
| J. Education information | No | We do not collect education records. | Not applicable |
| K. Inferences | Yes | Suggested scheduling slots and programme recommendations derived from activity | Feature functionality. These inferences are not used to profile you for advertising. |
| L. Sensitive personal information | Yes | Health and fitness data: measurements, injuries, nutrition, progress photos | Delivering coaching services at the coach’s direction. We do not use or disclose it for any purpose requiring a right-to-limit offer under CPRA. |
We disclose the categories above to the service providers listed in §7 for the business purposes described there. We keep each category for the periods in §8.
Do Not Sell or Share My Personal Information
FitFloww does not sell personal information and does not share it for cross-context behavioural advertising. Because we do not, there is nothing to opt out of — but we still honour Global Privacy Control signals. No financial incentive is offered in exchange for personal information.
Sensitive personal information
We collect health and fitness data, which is sensitive personal information under the CPRA. We use it only to deliver the service at the coach’s direction — never to infer characteristics about you. That means the right to limit its use does not arise, but you can still ask us to delete it under §9.
Your California rights
- Know what we collect, use, disclose, and how long we keep it.
- Delete personal information we collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of sale or sharing — not applicable, as we do neither.
- Not be discriminated against for exercising any of these rights.
Submit a request to privacy@fitflowwcrm.com. An authorised agent may act for you with written permission that we can verify. We respond within 45 days and may extend once where the request is complex.
17. Other US state privacy laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, sale, and profiling with legal effects. We do not conduct any of those three activities.
Some of these states give you a right to appeal a refused request. If we decline your request, our response explains how to appeal, and we answer appeals within 45 days.
Washington and Nevada residents: see the Consumer Health Data Privacy Notice, which carries additional rights over health data.
This policy describes our actual practices and is not legal advice. If you are a coach working out your own obligations to your clients, talk to a qualified lawyer in your jurisdiction.