This Privacy Policy explains how FitDesk handles personal data under the UK GDPR and the Data Protection Act 2018. It applies to anyone who uses our website, mobile app or services.
1. Who is the data controller?
- When you sign up directly with FitDesk (as a Trainer or as an end user of fitdesk.co.uk), FitDesk is the controller of your account data.
- When a Trainer uses FitDesk to manage their Clients (bookings, notes, plans, payments), the Trainer is the controller of their Clients' data and FitDesk acts as a processor on the Trainer's behalf, see our Data Processing Agreement.
2. What we collect
- Account data: name, email, phone, password hash, role.
- Profile and branding: photo, bio, specialties, business branding.
- Booking and training data: sessions, attendance, workouts, exercise logs, body measurements and progress photos (if uploaded).
- Payment data: invoice metadata, Stripe customer IDs and payout references. Card numbers are never stored by us, they are handled by Stripe.
- Communications: in-app messages, attachments, email notifications and push notification tokens (when you enable push on the mobile app).
- Technical data: IP address, device, browser, log and diagnostic data.
3. Why we use it (lawful bases)
- Contract: to provide the Service you signed up for.
- Legitimate interests: to keep the Service secure, prevent fraud and improve the product.
- Legal obligation: tax, accounting and responding to lawful requests.
- Consent: for optional marketing emails and (on iOS) push notifications, you can withdraw at any time in your device settings.
4. Sharing
We share data only with vetted sub-processors that help us run the Service, including:
- Supabase (database, auth, storage hosting)
- Stripe (payments and Connect payouts)
- Resend / our email provider (transactional email)
- Cloudflare (edge hosting, DDoS protection)
- Apple Push Notification service (delivery of push notifications on iOS)
A current list of sub-processors is available in our DPA. We do not sell personal data and we do not share it for cross-context behavioural advertising. None of the SDKs we embed in the iOS app perform cross-app or cross-site tracking as defined by Apple's App Tracking Transparency framework, so the app does not present an ATT prompt. If this ever changes we will request your permission through the standard iOS ATT prompt before any tracking begins.
5. Apple App Store disclosures
For users of our iOS app, the following Apple-specific disclosures apply:
- App Privacy labels: the data types declared on our App Store listing ("App Privacy" / nutrition labels) match the categories described in section 2 of this policy. The data is linked to your user account and used only to operate the Service.
- Apple first-party frameworks: FitDesk does not use Sign in with Apple, HealthKit, HomeKit, CarPlay, Game Center or any other Apple first-party data framework. We do not read from or write to Apple Health.
- Push notifications: if you grant permission, we use Apple Push Notification service to deliver booking reminders, message alerts and account notifications. You can disable these at any time in iOS Settings → Notifications → FitDesk.
- Tracking: we do not track you across apps or websites owned by other companies and we do not share data with data brokers.
6. International transfers
Some sub-processors are based outside the UK/EEA. Where data is transferred internationally we rely on UK IDTAs, EU Standard Contractual Clauses or adequacy decisions, and we apply additional safeguards such as encryption in transit and at rest.
7. Retention
We keep personal data only as long as needed for the purposes above. Account data is kept while the account is active and for up to 12 months after closure (longer where required by law, e.g. financial records for 6 years). You can request deletion at any time.
8. Your rights
You have the right to access, correct, delete, restrict or port your data, and to object to certain processing. You can exercise most of these from Settings → Account, or by emailing privacy@fitdesk.co.uk. You can also complain to the UK ICO at ico.org.uk.
9. Security
We use Row Level Security in our database, encrypted backups, TLS in transit, hashed passwords, optional two-factor authentication, audit logging and least-privilege access for staff. No system is perfectly secure, please report suspected issues to security@fitdesk.co.uk.
10. Progress photos and body data
Progress photos, body measurements and similar fitness data are sensitive to you even where they do not meet the strict UK GDPR definition of "special category" data. We treat them with extra care:
- Stored in private, access-controlled storage with Row Level Security so only you and your Trainer can view them.
- Transmitted over TLS and encrypted at rest by our storage provider.
- Never used to train machine-learning models, never shared for advertising, and never sent to any third party other than the infrastructure sub-processors listed in section 4 that store or transmit the file on our behalf.
- Deletable at any time from within the app, with deletion propagated to backups on our standard backup rotation.
11. Age restriction and children
FitDesk is intended for adults. You must be 18 or older to create a FitDesk account, whether as a Trainer or as a Client signing up directly. We do not knowingly collect personal data from anyone under 18 through direct sign-up.
Where a Trainer wishes to record a minor as a Client in their own roster, the Trainer (as controller of that Client's data) is responsible for obtaining verifiable parental or guardian consent and for entering into a separate written agreement with the parent or guardian. We may suspend or remove minor Client records that do not meet this requirement.
If you believe a person under 18 has created an account directly with us, please contact privacy@fitdesk.co.uk and we will remove the account.
12. Changes
We will notify you of material changes by email or in-app and ask you to re-accept where required.
