Skip to content

Privacy Policy

Last updated 17 July 2026

Draft — not yet legal advice. This is a starting template describing how TrainerBook works. It must be reviewed and finalised by a qualified solicitor, and the business details completed, before it’s relied upon.

This policy explains what personal data TrainerBook ("we", "us") collects, how we use it, and your rights. TrainerBook is operated by Lewis Stephen Crockford, a sole trader trading as Crocks Services (business address available on request; ICO registration in progress). If you have any questions, get in touch via the Contact page (/contact).

Who this covers

TrainerBook is a booking and membership platform that personal trainers ("Trainers") use to run their business, and that their clients use to book and manage sessions. This policy covers both Trainers and clients.

Importantly, for the client information a Trainer enters or manages in TrainerBook, the Trainer is the data controller and we act as their data processor (we only handle that data on their instructions). For a Trainer’s own account, we are the controller. See "Controllers and processors" below.

Data we collect

Depending on how you use TrainerBook, we may process:

  • Trainer account: name, email, password (stored hashed by our auth provider), business name, bio, branding, booking and cancellation preferences, and subscription/billing details.
  • Client records: name, email, phone, booking and attendance history (including any group-class bookings), membership and payment status, and the private notes, dated progress entries and progress photos a Trainer keeps about a client (photos are stored privately and have location data removed on upload).
  • Messages: the content, any attachments (images or files) and timestamps of chat messages sent between a Trainer and a client through the in-app messaging feature. Attachments are stored privately and shared only with the other person in that conversation.
  • Health information (special category data): the standard PAR-Q answers and signed waiver if a Trainer turns on intake forms, plus any health details (such as injuries) a Trainer chooses to record in their private notes, a client’s progress entries or progress photos. This is visible only to that Trainer, who is responsible for collecting it with the client’s consent.
  • Payment data: handled by our payment providers (Stripe for Trainer subscriptions; GoCardless for client Direct Debits). We do not store full card or bank details.
  • Technical data: IP address, device/browser information, and strictly-necessary cookies (see our Cookie Policy).
  • Usage analytics: aggregate, cookieless measurements of page views and which features are used (via Vercel Web Analytics), which do not identify you or track you across other websites.
  • Push notification token: if you use our mobile app and allow notifications, a device token (issued by Apple) so we can send you notifications such as session reminders. You can turn this off any time in Settings → Notifications or in your device’s settings.
  • In-app notifications: a feed of short notifications about activity on your account (for example a new booking, a group-class booking or cancellation, a standing-slot request or its outcome, a new message, a session reminder, or a gym request), each with its read/unread state. These are generated from your own activity and shown only to you, and you can turn them off in Settings → Notifications.
  • Security and audit logs: a record of sensitive actions (such as exporting or deleting your data) and of changes to records in the service (what changed, when, and by whom) — kept to keep the service secure and to meet our legal obligations. These are retained for up to 12 months and then automatically deleted. We do not store special-category health data (e.g. health-questionnaire answers) or secrets in these logs.

How we use it, and our lawful bases

We process personal data to:

  • Provide the service — accounts, bookings, calendars, memberships, reminders and payments (lawful basis: performance of a contract).
  • Send transactional emails such as booking confirmations, reminders and password resets (contract / legitimate interests).
  • Keep the service secure, prevent abuse, and maintain an audit trail of sensitive actions — rate limiting, bot protection and two-factor authentication (legitimate interests; for the audit trail, also compliance with our legal obligations).
  • Understand and improve how the service is used, through privacy-friendly, cookieless analytics that do not identify individual users (legitimate interests).
  • Handle health data only on the basis of the client’s explicit consent, captured by the Trainer through the intake form.

Controllers and processors

For a Trainer’s own account data, TrainerBook is the controller.

For the client data a Trainer enters and manages, the Trainer is the controller and TrainerBook is the processor — we process it only to provide the service on the Trainer’s behalf. Trainers are responsible for having a lawful basis to hold their clients’ data, for obtaining any necessary consent (particularly for health data), and for giving their own clients a privacy notice.

Sharing and sub-processors

We do not sell your data. We share it only with trusted providers who process it under our instructions and their own data-protection terms:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting, and privacy-friendly cookieless usage analytics (aggregate page views and feature usage; no cookies, no cross-site tracking, no personal profile).
  • Sentry — error diagnostics: when something in the app fails, the technical details of the error are recorded (with pseudonymous identifiers such as a user id — never names, training notes or payment details) so we can find and fix it. Hosted in the EU.
  • Stripe — Trainer subscription billing.
  • GoCardless — client Direct Debit collection (money settles to the Trainer’s own bank; it never passes through us).
  • Resend — sending transactional emails.
  • Twilio — sending SMS session reminders, only where a Trainer enables text reminders (a Pro feature).
  • Apple — delivering push notifications to the iOS app (Apple Push Notification service), only if you use the app and allow notifications.
  • Cloudflare — Turnstile bot/abuse protection on our forms.
  • Anthropic — AI features, only when a Trainer uses them. If a Trainer turns on AI session suggestions, a client’s pseudonymised training notes (without their name or email) are sent to Anthropic to generate a suggestion for the Trainer to review. If a Trainer uses Brand Studio’s AI design helpers (theme or logo), only their business name and the brand description they type are sent. Nothing sent is used to train models.

International transfers

Some of our providers may process data outside the UK/EEA. Where they do, the transfer is covered by appropriate safeguards such as UK adequacy decisions or Standard Contractual Clauses.

How long we keep it

We keep personal data while your account is active. When you delete your account (Settings → Data & privacy), we remove your data — though a Trainer who is the controller of their clients’ records may retain those for as long as they have a lawful reason to (for example, financial record-keeping obligations).

For security and to meet our legal obligations, we also keep a minimal audit record of certain sensitive actions (for example, that an account was deleted or its data exported) — limited to the action, its timestamp, the IP address and an email snapshot. This is retained even after the account itself is deleted, for up to 12 months, after which it is automatically purged.

Your rights

You have the right to access, correct, erase, restrict or object to the processing of your personal data, and to data portability. You can download your data or permanently delete your account from Settings → Data & privacy.

If your data is held by a Trainer (as controller), please contact that Trainer to exercise your rights over it. You also have the right to complain to the UK Information Commissioner’s Office (ICO).

Security

Access to data is enforced in the database with row-level security, traffic is encrypted in transit, passwords are checked against known breaches at sign-up, two-factor authentication is available, and we keep a tamper-resistant audit trail of certain sensitive actions. No system is perfectly secure, but we take reasonable measures to protect your data.

Cookies

We use only strictly-necessary cookies. See our Cookie Policy for details.

Changes to this policy

We may update this policy from time to time. The latest version will always be on this page, with the date it was last updated.