Privacy Policy

Last updated: 20 May 2026 · Version 2.1

This Privacy Policy explains how Beinfit Limited ("BeInFit", "we", "us", "our") collects, uses, shares and protects personal data when you use the BeInFit platform as a tutor/coach, a customer, a website visitor, a prospective user we contact, or a person whose data is uploaded to the platform by a tutor.

Plain-English summary

We collect the information we need to run a fitness-tutor marketplace: who you are, how to reach you, what you teach or book, what you pay, and how you use the app. We also contact independent teachers who may benefit from BeInFit. We work with carefully chosen suppliers (payments, messaging, AI, analytics, advertising) and only share what they need. We do not sell personal data. You have strong rights over your data, including the right to ask us to delete it.

1. Who we are & controller identity

BeInFit is operated by Beinfit Limited, a company registered in England and Wales under company number 15335692 (the "Controller"). Beinfit Limited determines the purposes and means of the processing of personal data described in this Policy and is responsible for compliance with the UK GDPR, the Data Protection Act 2018, the EU GDPR (where applicable), and PECR.

Legal entity Beinfit Limited
Company number 15335692 (England & Wales)
Registered office 2nd Floor College House, 17 King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE
Trading name BeInFit
Website beinfit.app
Data protection contact privacy@beinfit.app
ICO registration [ICO registration reference — insert number]

When a tutor/coach uses BeInFit to manage their own customer records (CRM features such as customer profiles, booking history, voice notes and messaging), the tutor acts as an independent controller of that customer's personal data. BeInFit acts as a processor for the tutor in relation to that data.

2. Scope & definitions

This Policy applies to: visitors to beinfit.app and any subdomain; tutors and coaches who register to offer fitness classes, sessions or packages; prospective tutors and partners we contact through marketing or outreach; customers who create an account or whose details are entered into a tutor's CRM; administrators; users of any AI-assisted feature; and recipients of transactional emails, SMS messages and platform notifications.

3. Personal data we collect

3.1 All users — account & technical data

Identifiers User ID, email address, hashed authentication token
Device & technical IP address, user agent, browser, OS, language, timezone, approximate geo-location from IP
Session Login timestamps, RSVP tokens, signed webhook payloads
Communications Email, SMS and in-app notification logs
Support Messages you send to support@beinfit.app and any attachments

3.2 Tutors & coaches — profile, business & tax data

Profile Display name, bio, profile photo, website, social links, phone, languages, experience, training, target audience, base hourly rate
Business & tax Business name, business address, UK UTR, VAT number, VAT scheme, tax year start
Stripe Connect Identity verification status, account ID, payout schedule, charges/payouts enabled flags
Class & package data Titles, descriptions, capacities, locations, prices, recurrence rules, generated assets
Earnings & expenses Income records, manually-added expenses, OCR-extracted receipt data, VAT calculations
CRM content Customer notes, voice notes (audio + transcript), messaging history that the tutor controls

3.3 Customers — account & activity data

Contact details Name, email, phone (when booking SMS reminders), home or session address
Booking activity Class bookings, attendance, RSVP status, package purchases, credits remaining
Communications Messages with tutors, booking and class reminders
Preferences Communication preferences, class type preferences, discount eligibility flags
Payments Payment intent IDs, amount, currency, status, last four digits of card

3.4 Prospective users & marketing contacts (outreach)

Where you are an independent teacher, studio or wellness professional we believe may benefit from BeInFit, we may collect limited business-contact data to reach out to you: name, public social handle (e.g. Instagram), business or public email, website, city, discipline, and publicly available professional details. We collect this from public profiles, business directories, and reputable enrichment/lead-generation tools, or where you have publicly invited contact (e.g. a "for collaborations" email in your bio). We contact you at a human pace, always identify ourselves, and every message includes a way to opt out. If you ask us to stop or object, we will not contact you again and will delete your details.

4. Sources of data

We receive personal data from: you (when you register, complete your profile, book a class, message, upload content, contact support, or respond to our outreach); tutors (if a tutor adds you as a customer in their CRM); customers (if a customer books with you as a tutor); service providers — Stripe, Twilio, SendGrid, Google Maps, HMRC, Meta; public sources and enrichment/lead-generation tools (for outreach to prospective users); AI tools; and automatically from your device when you use the platform.

5. Purposes & lawful bases

We process your personal data for the following purposes under the UK GDPR:

  • Provide the platform & your account — Contract basis
  • Process bookings & payments — Contract basis
  • HMRC MTD income & expense reporting — Legal obligation
  • Send transactional emails & SMS reminders — Contract basis
  • Analytics & product improvement — Consent or legitimate interest
  • AI features — Contract basis
  • Security, fraud prevention & rate limiting — Legitimate interest
  • Marketing to existing users — Consent (with opt-out in every message)
  • Outreach to prospective tutors/partners — Legitimate interest (assessed via a Legitimate Interests Assessment; you may object at any time)
  • Advertising & lead capture (e.g. Meta lead forms) — Consent given at the point you submit the form (which includes a link to this Policy)

6. Special category (health) data

Some information you or your tutor add may amount to special category data under Article 9 of the UK GDPR — in particular, data relating to your physical or mental health, injuries, training limitations or pregnancy. We rely on your explicit consent given at the point the data is entered. You can withdraw consent at any time by deleting the relevant entry, asking your tutor to remove it, or contacting privacy@beinfit.app.

7. Children's data

BeInFit is intended for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has registered or that we hold data about a child, contact privacy@beinfit.app and we will delete the data promptly.

8. Cookies, analytics, advertising & session recording

We use cookies and similar technologies to keep you signed in, secure the service, measure how the platform is used, improve it, and measure our advertising. Non-essential cookies and advertising/measurement tools are loaded only after you provide consent via the cookie banner.

Strictly necessary Authentication, security, load balancing, RSVP tokens — No consent required
Functional Remember preferences — Requires consent
Analytics PostHog (EU cloud, no US transfer) — Requires consent
Advertising & measurement Meta Pixel / Conversions API and custom/lookalike audiences — Requires consent
Search indexing Google Search Console — Legitimate interest

9. Sub-processors & third parties

We work with the following sub-processors to deliver our service:

Stripe — Payment processing, payouts to tutors, KYC and AML checks
Twilio — SMS class reminders and customer/tutor onboarding messages
SendGrid — Transactional and marketing email delivery
OpenAI — AI features (bio generation, voice transcription, tag suggestions)
PostHog — Product analytics, funnel analytics, session recording (EU cloud)
HMRC — Statutory Making Tax Digital submissions
Meta Platforms — Advertising delivery and lead-form capture
Digitalista — Marketing & go-to-market services provider, acting as our processor under a data processing agreement (campaign delivery, outreach, CRM)
CRM & lead-enrichment tools — Managing prospect and lead records for outreach and follow-up

We do not sell personal data and do not share it for cross-context behavioural advertising beyond the consented advertising measurement described in Section 8.

10. International data transfers

Personal data is primarily stored and processed in the EU/UK. Some sub-processors are based outside the UK/EEA or may transfer data to the US. We rely on UK or EU adequacy decisions, SCCs, and supplementary measures (encryption, pseudonymisation, contractual zero-retention for AI).

11. Data retention

  • Active account — Lifetime of account
  • Tax records — 7 years from end of tax year
  • Booking & payment metadata — 7 years
  • Analytics data — Up to 13 months, then aggregated
  • Session recordings — 30 days
  • Support tickets — 3 years
  • Prospective-contact / outreach records — up to 12 months from last contact, then deleted (or on objection)

12. Your rights

Under the UK GDPR you have the right to: access your data, rectification of inaccurate data, erasure (subject to legal retention obligations), restrict processing, data portability, object to processing (including outreach and direct marketing), withdraw consent at any time, and lodge a complaint with the ICO.

13. How to exercise your rights

For most requests, use self-service controls in Settings. For anything you can't do in-app, email privacy@beinfit.app with the subject "Data subject request". We respond within one calendar month.

14. Marketing & communications

We send three categories of emails: transactional (booking confirmations, receipts — essential, no unsubscribe), service updates (material changes), and marketing (news, offers — consent required, unsubscribe link in every email). Separately, we may send business-to-business and outreach messages to prospective tutors and partners on the basis of legitimate interest; every such message identifies us and offers an easy opt-out, and we honour opt-outs immediately.

15. Automated decision-making & AI

BeInFit uses AI to assist users — not to make decisions about them. We do not use AI to make decisions producing legal effects without human review. We do not use your data to train third-party AI models.

16. How we protect personal data

  • Zero-trust frontend — all sensitive operations gated by backend functions
  • Encryption — TLS 1.2+ in transit; encrypted at rest
  • Secret management — API keys stored on backend only, never exposed to frontend
  • PCI-DSS scope minimisation — card data handled by Stripe only
  • Webhook integrity — HMAC signatures verified on all webhooks
  • Access control — least privilege; admin actions audit-logged

17. Data breach notification

For confirmed personal data breaches we: contain the incident, investigate scope and affected entities, notify the ICO within 72 hours if there is a risk to your rights and freedoms, and notify affected users without undue delay if there is a high risk.

18. Complaints & supervisory authority

Contact privacy@beinfit.app first. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.

19. Changes to this policy

We may update this Policy. Material changes get email + in-app notice at least 14 days before they take effect. The version and effective date at the top always reflect the latest.

20. Contact

Data controller Beinfit Limited (company no. 15335692)
Privacy contact privacy@beinfit.app
Postal address 2nd Floor College House, 17 King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE
ICO registration [insert number]
Supervisory authority UK Information Commissioner's Office (ico.org.uk)