Start your 14-day free trial — no credit card required.

    Privacy Policy

    What we collect, who we share it with, how long we keep it, and what you can ask us to do about it.

    Last updated: August 18, 2026

    1. Who we are

    FitFloww is a client relationship management platform for fitness professionals. It is operated as a sole proprietorship based in California, United States.

    Data controller

    FitFloww (sole proprietorship)

    San Francisco, California, United States

    Email: privacy@fitflowwcrm.com

    This policy explains what we do with personal data. It applies to our website, the coach application, and the client portal.

    2. When we are a controller, and when we are a processor

    This distinction decides who you should contact, and it is the part most privacy policies get wrong. FitFloww plays two different roles depending on whose data is involved.

    DataWho decides how it is usedOur role
    Your coach account, billing, support tickets, marketing contact detailsFitFlowwController — this policy governs it, and you exercise your rights against us.
    Records a coach stores about their clients: profiles, measurements, progress photos, session notes, messagesThe coachProcessor — we act on the coach’s instructions. This policy describes how we handle it, but the coach decides what is collected and why.

    If you are a client of a coach who uses FitFloww

    Your coach decides what to record about you and how long to keep it. Send access, correction, and deletion requests to your coach first — they control the data and can act on it directly. If they cannot be reached, contact us at privacy@fitflowwcrm.com and we will help route the request.

    Coaches subject to GDPR need a written processing agreement with us. Our Data Processing Agreement satisfies Art. 28 and applies automatically to every account.

    3. Information we collect

    What we do not collect

    • We do not collect precise GPS location. Location is inferred from IP address at city level only, for security.
    • We do not collect biometric identifiers. Progress photos are stored as images and are never converted into a faceprint or other biometric template.
    • We do not buy personal data from data brokers.
    • We never see or store your password — our authentication provider hashes it.
    • We never store payment card numbers. Stripe handles them directly.
    • We do not use advertising cookies or run cross-site behavioural advertising.

    Account and business data

    • Name, email address, phone number.
    • Professional credentials, certifications, business name, specialisations.
    • Profile photo and branding you upload.
    • Subscription plan, billing history, and invoices.

    Client records (we process these for your coach)

    • Client contact details and profile information.
    • Fitness goals, body measurements, workout history, and assessment results.
    • Progress photos.
    • Nutrition plans and food logs.
    • Session notes, injury notes, and messages.

    Some of this is health data

    Measurements, injury notes, nutrition records, and progress photos describe someone’s physical condition. Under GDPR this is special category data (Art. 9) and under Washington’s My Health My Data Act it is consumer health data. It gets extra protection, and it is covered in more detail in our Consumer Health Data Privacy Notice.

    Technical and usage data

    • IP address, browser and device type, operating system.
    • Pages visited and features used — collected by PostHog only if you accept optional cookies.
    • Error reports and stack traces when something breaks, with text and media masked.
    • Server access logs.

    Marketing and lead data

    If you fill in a form on our website, request a demo, or subscribe to updates, we collect the contact details you provide and use them to send you information about FitFloww. Every marketing email has an unsubscribe link, and unsubscribing takes effect immediately.

    4. How we use information, and our legal basis

    PurposeData usedLegal basis (GDPR Art. 6)
    Providing the platform — accounts, scheduling, programmes, messaging, the client portalAccount data, client recordsPerformance of a contract (Art. 6(1)(b))
    Taking subscription payments and issuing invoicesBilling dataPerformance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c))
    Keeping the service secure, investigating abuse, debugging failuresLogs, error reports, IP addressLegitimate interests (Art. 6(1)(f)) — running a service that stays up and is not abused
    Product analyticsPseudonymous usage eventsConsent (Art. 6(1)(a)) — collected only if you accept optional cookies
    Support chatChat messages, contact detailsConsent (Art. 6(1)(a)) for the widget; legitimate interests for handling the request
    Marketing email about FitFlowwContact details, engagement eventsConsent (Art. 6(1)(a)) where required; otherwise legitimate interests, with opt-out in every message
    Processing client health records on a coach’s behalfClient recordsThe coach’s instruction under our Data Processing Agreement. The coach is responsible for holding an Art. 9 condition — normally the client’s explicit consent.

    5. Artificial intelligence

    We use Anthropic (Claude) for generating marketing and content copy through internal tooling.

    • Your data is not used for training. Data sent to our AI provider through the API is not used to train their models.
    • Health records are not sent to AI providers. Client health records, progress photos, and private messages are not sent to any AI provider.
    • No automated decisions about you. No automated decision with a legal or similarly significant effect is made about you. Scheduling suggestions and programme recommendations are suggestions — a human chooses whether to act on them.
    • Output can be wrong. AI models are probabilistic. Anything they generate should be checked before you rely on it.

    Data sent to our AI provider is also subject to their privacy policy.

    6. Cookies

    Essential cookies are set because the service cannot work without them. Everything else stays off until you accept it in the cookie banner. You can change your mind at any time from the Cookie Policy.

    CookieProviderCategoryPurposeDuration
    sb-<project>-auth-tokenSupabase (first party)EssentialKeeps you signed in. Mirrored to an HttpOnly cookie so the token is not readable by scripts.Session, refreshed up to 1 hour
    fitfloww_cookie_consentFitFloww (first party)EssentialRemembers your cookie choice so you are not asked on every visit.6 months
    sidebar_stateFitFloww (first party)EssentialRemembers whether the app sidebar is expanded or collapsed.7 days
    crisp-client/*Crisp (third party)FunctionalKeeps your support chat history so a conversation survives a page reload. Set only after you accept optional cookies.6 months
    ph_<key>_posthogPostHog (third party)AnalyticsMeasures which features are used so we can prioritise work. Set only after you accept optional cookies.1 year

    We do not use advertising cookies, and we do not track you across other websites. We do not currently respond to browser Do Not Track signals, because there is no agreed standard for what a site should do when it receives one. We do honour Global Privacy Control signals as an opt-out of sale or sharing, as California requires.

    7. Who we share data with

    We do not sell your personal information

    We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have never done so.

    These are every third party that processes personal data on our behalf:

    ProcessorPurposeData handledRegionPrivacy policy
    SupabaseApplication database, authentication, file storage, edge functionsAccount data, client records, progress photos, measurements, messages, session notesUnited StatesView
    CloudflareWebsite hosting, CDN, edge functions, DDoS protectionIP addresses, request metadata, cached page contentGlobal edge networkView
    StripeSubscription billing, and payment processing between coaches and their clientsBilling name, email, payment card details (held by Stripe, never by FitFloww)United States, IrelandView
    PostHogProduct analytics — only loaded after you accept analytics cookiesPseudonymous usage events, device and browser type, coarse locationUnited StatesView
    ResendTransactional and marketing email deliveryEmail address, name, message content, delivery and open eventsUnited StatesView
    CrispLive chat support widget — only loaded after you accept optional cookiesChat messages, email address, name, phone number, avatar, and the pages you viewed before opening the chatEuropean UnionView
    AnthropicAI text generation for content and marketing toolingPrompt text submitted to the feature. Client health records are not sent to this service.United StatesView

    The current list always lives at Sub-processors, where you can also subscribe to notice of changes. We give 30 days’ notice before adding a new processor that handles customer data.

    Beyond those processors, we disclose data only when:

    • The law requires it — a valid court order, subpoena, or equivalent legal process. We tell you unless legally prohibited from doing so.
    • It is necessary to protect someone’s safety or to investigate fraud or abuse.
    • The business is sold or merged. You will be told before your data moves, and the new operator is bound by this policy until it gives you notice of a change.
    • You have asked us to.

    8. How long we keep data

    Deletion is not instant, because encrypted backups roll over on a schedule. The table below is what we can actually honour.

    CategoryRetentionNotes
    Coach account dataUntil deletion, then 30 daysDeleting your account starts a 30-day window during which it can be restored. After that it is removed from live systems.
    Client records, measurements, session notesUntil deleted by the coach, then 30 daysControlled by the coach who created them. Deleting a client removes their records on the same 30-day cycle.
    Progress photosUntil deleted by the coach, then 30 daysTreated as health data. Stored in access-controlled storage, not on a public URL.
    MessagesUntil deleted by a participant, then 30 daysEither participant deleting a conversation removes it for both.
    Encrypted database backupsUp to 30 daysPoint-in-time recovery. Deleted records can persist here until the window rolls over — this is why deletion is "within 30 days" and not instant.
    Server and access logs30 daysKept for security investigation and debugging, then discarded.
    Analytics events (PostHog)14 monthsOnly collected if you accept analytics cookies.
    Email delivery and engagement logs12 monthsBounce and unsubscribe records are kept longer so we do not email you again after you opt out.
    Support chat transcripts12 monthsHeld by Crisp. Only created if you accept optional cookies and open the chat.
    Billing and tax records7 yearsRetained because tax law requires it. This survives account deletion.

    9. Your rights

    Wherever you live, you can ask us to:

    • Access — get a copy of the personal data we hold about you.
    • Correct — fix anything inaccurate. Most account and client fields can be edited directly in the app.
    • Delete — remove your account and its data, subject to the retention table above. You can start this yourself from Settings.
    • Port — receive your data in a structured, machine-readable format.
    • Object or restrict — challenge processing we base on legitimate interests, or ask us to pause it.
    • Withdraw consent — for cookies, from the Cookie Policy; for marketing email, from the unsubscribe link in any message.

    How to make a request

    Email privacy@fitflowwcrm.com. We reply within 30 days. We may need to confirm your identity first, which normally means replying from the address on the account. There is no charge, and you will not be treated differently for asking.

    Export is currently handled by our team rather than a self-service button. Ask us and we will send you a machine-readable copy within the same 30 days.

    10. International transfers

    FitFloww is operated from the United States, and most of our processors are US-based. If you are in the EEA, the UK, or Switzerland, your data is transferred outside your country.

    We rely on:

    • The European Commission’s Standard Contractual Clauses, incorporated into our agreements with each processor that needs them.
    • The UK International Data Transfer Addendum for UK transfers.
    • The EU–US Data Privacy Framework, where the processor is certified under it.

    You can ask us for a copy of the safeguards that apply to a particular transfer by emailing privacy@fitflowwcrm.com.

    11. Children and young people

    You must be 18 or over to open a FitFloww account. We do not knowingly collect personal data directly from children.

    Coaches training under-18 clients

    A coach can record data about a client who is a minor. If you do, you are responsible for obtaining verifiable consent from a parent or guardian before entering that client’s details, and for complying with the age rules where you and the client live — 13 in the US, 13 to 16 in the EEA depending on the country, and 18 in India.

    If you believe a child’s data has reached us without proper consent, email privacy@fitflowwcrm.com and we will delete it.

    12. Security

    What is in place:

    • TLS 1.3 for all data in transit
    • AES-256 encryption at rest, applied by our database and storage provider
    • Session tokens mirrored into HttpOnly cookies so page scripts cannot read them
    • Row-level security policies so one coach cannot read another coach’s records
    • Passwords hashed by our authentication provider — we never see or store them
    • Card details handled by Stripe and never stored on FitFloww systems
    • Automated dependency and secret scanning on every build
    • Encrypted database backups with point-in-time recovery

    What is not in place

    Saying nothing about these would imply we have them. We do not, and you should factor that in when deciding what to store here.

    • FitFloww is not SOC 2 or ISO 27001 audited.
    • FitFloww is not HIPAA certified and does not sign Business Associate Agreements.
    • Messages are not end-to-end encrypted. They are encrypted in transit and at rest, and are readable by our database administrators.
    • Multi-factor authentication is not yet available.
    • Single sign-on (SAML/OIDC) is not yet available.

    If a breach affects your personal data and creates a risk to you, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where GDPR requires, and tell affected users without undue delay. To report a vulnerability, email security@fitflowwcrm.com.

    13. Changes to this policy

    • The "Last updated" date at the top changes whenever this policy does.
    • For changes that materially reduce your rights, we give 30 days’ notice by email or in-app notice before they take effect.
    • Continued use after a change takes effect means you accept the updated policy. If you do not accept it, you can delete your account before the effective date.
    • Where a change requires your consent under applicable law — for example a genuinely new purpose for existing data — we will ask for it rather than relying on notice.

    14. Contact us

    Privacy enquiries

    FitFloww (sole proprietorship)

    San Francisco, California, United States

    Email: privacy@fitflowwcrm.com

    We respond within 30 days. We have not appointed a statutory Data Protection Officer, because we do not meet the criteria in GDPR Art. 37 that make one mandatory; privacy questions go to the address above.

    15. EEA and UK supplement

    This section applies in addition to the rest of the policy if you are in the EEA or the UK.

    • Legal bases. Set out per purpose in §4.
    • Your rights. Articles 15 to 22 — access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions.
    • Special category data. Health data is processed on the instruction of the coach who is the controller for it. The coach is responsible for the Art. 9(2) condition, which is normally the client’s explicit consent.
    • Complaints. You can lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve it first.
    • Article 27 representative. We have not yet appointed EU and UK representatives. Until we do, direct all enquiries to privacy@fitflowwcrm.com.

    16. California supplement

    This section is our notice at collection under the CCPA as amended by the CPRA. It applies to California residents.

    CategoryCollectedExamplesPurpose
    A. IdentifiersYesName, email address, phone number, IP address, account IDAccount creation, authentication, support, billing
    B. Customer records (Cal. Civ. Code §1798.80)YesBilling name and address, payment card details held by StripeProcessing subscription payments
    C. Protected classificationsYesAge or date of birth, and sex where a coach records it for programmingCalculating training and nutrition targets, at the coach’s direction
    D. Commercial informationYesPlan, billing history, session and package purchasesBilling, support, business reporting for the coach
    E. Biometric informationNoWe do not collect fingerprints, faceprints, or voiceprints. Progress photos are stored as images and are never converted into a biometric identifier.Not applicable
    F. Internet or network activityYesPages viewed, features used, error reportsSecurity, debugging, and — only with consent — product analytics
    G. Geolocation dataYesCoarse city or country inferred from IP addressSecurity and fraud prevention. We do not collect precise GPS location.
    H. Sensory dataYesProgress photos and any images a coach or client uploadsProgress tracking, at the coach’s direction
    I. Professional or employment informationYesCertifications, business name, specialisationsBuilding the coach profile and client-facing booking pages
    J. Education informationNoWe do not collect education records.Not applicable
    K. InferencesYesSuggested scheduling slots and programme recommendations derived from activityFeature functionality. These inferences are not used to profile you for advertising.
    L. Sensitive personal informationYesHealth and fitness data: measurements, injuries, nutrition, progress photosDelivering coaching services at the coach’s direction. We do not use or disclose it for any purpose requiring a right-to-limit offer under CPRA.

    We disclose the categories above to the service providers listed in §7 for the business purposes described there. We keep each category for the periods in §8.

    Do Not Sell or Share My Personal Information

    FitFloww does not sell personal information and does not share it for cross-context behavioural advertising. Because we do not, there is nothing to opt out of — but we still honour Global Privacy Control signals. No financial incentive is offered in exchange for personal information.

    Sensitive personal information

    We collect health and fitness data, which is sensitive personal information under the CPRA. We use it only to deliver the service at the coach’s direction — never to infer characteristics about you. That means the right to limit its use does not arise, but you can still ask us to delete it under §9.

    Your California rights

    • Know what we collect, use, disclose, and how long we keep it.
    • Delete personal information we collected from you, subject to legal exceptions.
    • Correct inaccurate personal information.
    • Opt out of sale or sharing — not applicable, as we do neither.
    • Not be discriminated against for exercising any of these rights.

    Submit a request to privacy@fitflowwcrm.com. An authorised agent may act for you with written permission that we can verify. We respond within 45 days and may extend once where the request is complex.

    17. Other US state privacy laws

    Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, sale, and profiling with legal effects. We do not conduct any of those three activities.

    Some of these states give you a right to appeal a refused request. If we decline your request, our response explains how to appeal, and we answer appeals within 45 days.

    Washington and Nevada residents: see the Consumer Health Data Privacy Notice, which carries additional rights over health data.

    This policy describes our actual practices and is not legal advice. If you are a coach working out your own obligations to your clients, talk to a qualified lawyer in your jurisdiction.