Privacy Policy
Last updated: 20 May 2026 · Version 2.1
This Privacy Policy explains how Beinfit Limited ("BeInFit", "we", "us", "our") collects, uses, shares and protects personal data when you use the BeInFit platform as a tutor/coach, a customer, a website visitor, a prospective user we contact, or a person whose data is uploaded to the platform by a tutor.
Plain-English summary
We collect the information we need to run a fitness-tutor marketplace: who you are, how to reach you, what you teach or book, what you pay, and how you use the app. We also contact independent teachers who may benefit from BeInFit. We work with carefully chosen suppliers (payments, messaging, AI, analytics, advertising) and only share what they need. We do not sell personal data. You have strong rights over your data, including the right to ask us to delete it.
1. Who we are & controller identity
BeInFit is operated by Beinfit Limited, a company registered in England and Wales under company number 15335692 (the "Controller"). Beinfit Limited determines the purposes and means of the processing of personal data described in this Policy and is responsible for compliance with the UK GDPR, the Data Protection Act 2018, the EU GDPR (where applicable), and PECR.
When a tutor/coach uses BeInFit to manage their own customer records (CRM features such as customer profiles, booking history, voice notes and messaging), the tutor acts as an independent controller of that customer's personal data. BeInFit acts as a processor for the tutor in relation to that data.
2. Scope & definitions
This Policy applies to: visitors to beinfit.app and any subdomain; tutors and coaches who register to offer fitness classes, sessions or packages; prospective tutors and partners we contact through marketing or outreach; customers who create an account or whose details are entered into a tutor's CRM; administrators; users of any AI-assisted feature; and recipients of transactional emails, SMS messages and platform notifications.
3. Personal data we collect
3.1 All users — account & technical data
3.2 Tutors & coaches — profile, business & tax data
3.3 Customers — account & activity data
3.4 Prospective users & marketing contacts (outreach)
Where you are an independent teacher, studio or wellness professional we believe may benefit from BeInFit, we may collect limited business-contact data to reach out to you: name, public social handle (e.g. Instagram), business or public email, website, city, discipline, and publicly available professional details. We collect this from public profiles, business directories, and reputable enrichment/lead-generation tools, or where you have publicly invited contact (e.g. a "for collaborations" email in your bio). We contact you at a human pace, always identify ourselves, and every message includes a way to opt out. If you ask us to stop or object, we will not contact you again and will delete your details.
4. Sources of data
We receive personal data from: you (when you register, complete your profile, book a class, message, upload content, contact support, or respond to our outreach); tutors (if a tutor adds you as a customer in their CRM); customers (if a customer books with you as a tutor); service providers — Stripe, Twilio, SendGrid, Google Maps, HMRC, Meta; public sources and enrichment/lead-generation tools (for outreach to prospective users); AI tools; and automatically from your device when you use the platform.
5. Purposes & lawful bases
We process your personal data for the following purposes under the UK GDPR:
- • Provide the platform & your account — Contract basis
- • Process bookings & payments — Contract basis
- • HMRC MTD income & expense reporting — Legal obligation
- • Send transactional emails & SMS reminders — Contract basis
- • Analytics & product improvement — Consent or legitimate interest
- • AI features — Contract basis
- • Security, fraud prevention & rate limiting — Legitimate interest
- • Marketing to existing users — Consent (with opt-out in every message)
- • Outreach to prospective tutors/partners — Legitimate interest (assessed via a Legitimate Interests Assessment; you may object at any time)
- • Advertising & lead capture (e.g. Meta lead forms) — Consent given at the point you submit the form (which includes a link to this Policy)
6. Special category (health) data
Some information you or your tutor add may amount to special category data under Article 9 of the UK GDPR — in particular, data relating to your physical or mental health, injuries, training limitations or pregnancy. We rely on your explicit consent given at the point the data is entered. You can withdraw consent at any time by deleting the relevant entry, asking your tutor to remove it, or contacting privacy@beinfit.app.
7. Children's data
BeInFit is intended for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has registered or that we hold data about a child, contact privacy@beinfit.app and we will delete the data promptly.
9. Sub-processors & third parties
We work with the following sub-processors to deliver our service:
We do not sell personal data and do not share it for cross-context behavioural advertising beyond the consented advertising measurement described in Section 8.
10. International data transfers
Personal data is primarily stored and processed in the EU/UK. Some sub-processors are based outside the UK/EEA or may transfer data to the US. We rely on UK or EU adequacy decisions, SCCs, and supplementary measures (encryption, pseudonymisation, contractual zero-retention for AI).
11. Data retention
- • Active account — Lifetime of account
- • Tax records — 7 years from end of tax year
- • Booking & payment metadata — 7 years
- • Analytics data — Up to 13 months, then aggregated
- • Session recordings — 30 days
- • Support tickets — 3 years
- • Prospective-contact / outreach records — up to 12 months from last contact, then deleted (or on objection)
12. Your rights
Under the UK GDPR you have the right to: access your data, rectification of inaccurate data, erasure (subject to legal retention obligations), restrict processing, data portability, object to processing (including outreach and direct marketing), withdraw consent at any time, and lodge a complaint with the ICO.
13. How to exercise your rights
For most requests, use self-service controls in Settings. For anything you can't do in-app, email privacy@beinfit.app with the subject "Data subject request". We respond within one calendar month.
14. Marketing & communications
We send three categories of emails: transactional (booking confirmations, receipts — essential, no unsubscribe), service updates (material changes), and marketing (news, offers — consent required, unsubscribe link in every email). Separately, we may send business-to-business and outreach messages to prospective tutors and partners on the basis of legitimate interest; every such message identifies us and offers an easy opt-out, and we honour opt-outs immediately.
15. Automated decision-making & AI
BeInFit uses AI to assist users — not to make decisions about them. We do not use AI to make decisions producing legal effects without human review. We do not use your data to train third-party AI models.
16. How we protect personal data
- • Zero-trust frontend — all sensitive operations gated by backend functions
- • Encryption — TLS 1.2+ in transit; encrypted at rest
- • Secret management — API keys stored on backend only, never exposed to frontend
- • PCI-DSS scope minimisation — card data handled by Stripe only
- • Webhook integrity — HMAC signatures verified on all webhooks
- • Access control — least privilege; admin actions audit-logged
17. Data breach notification
For confirmed personal data breaches we: contain the incident, investigate scope and affected entities, notify the ICO within 72 hours if there is a risk to your rights and freedoms, and notify affected users without undue delay if there is a high risk.
18. Complaints & supervisory authority
Contact privacy@beinfit.app first. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
19. Changes to this policy
We may update this Policy. Material changes get email + in-app notice at least 14 days before they take effect. The version and effective date at the top always reflect the latest.
