Privacy Policy

Last updated: 23 February 2026

1. Who We Are

TrainerBio (“we”, “us”, “our”) is operated from the United Kingdom. We provide a platform for fitness professionals to create profile pages, sell digital products, and manage client enquiries at trainerbio.com.

For questions about this policy or your personal data, contact us at support@trainerbio.com.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and profile information you choose to provide (bio, qualifications, profile photo, work locations).

Payment Information

Payment processing is handled by Stripe. We do not store credit card numbers. Stripe collects and processes payment information under their own privacy policy. When you connect a Stripe account to receive payouts via Stripe Connect, Stripe collects identity verification data directly.

Enquiry Data

When visitors submit enquiry forms on trainer pages, we collect the information they provide (name, email, phone, and any custom form fields). This data is stored securely and made available to the trainer who owns the form.

Google Account Data

If you connect your Google account for Google Sheets sync, we store an OAuth access token and refresh token to create and update spreadsheets on your behalf. We only access Google Sheets and Google Drive files that TrainerBio creates. We do not read, modify, or delete any of your other Google data.

Uploaded Content

Trainers may upload digital product files (e.g. PDFs, images). These files are stored securely and delivered only to authorised purchasers via time-limited download tokens.

Usage Data

We collect anonymised usage data through Google Tag Manager to understand how the platform is used and to improve our service. This may include pages visited, features used, and device information.

3. How We Use Your Information

  • To provide and maintain the TrainerBio platform
  • To process digital product purchases and deliver files to buyers
  • To process payments and manage subscriptions via Stripe
  • To deliver enquiry notifications via email
  • To sync enquiry data to Google Sheets when you enable this feature
  • To send transactional emails (order confirmations, account verification)
  • To improve the platform based on usage patterns
  • To comply with legal obligations

We do not sell your personal data to third parties. We do not send marketing emails unless you have explicitly opted in.

4. Legal Basis for Processing (UK GDPR)

We process personal data under the following legal bases:

  • Contract: To provide the services you signed up for (account management, digital product delivery, payment processing).
  • Legitimate interest: To improve our platform, prevent fraud, and ensure security.
  • Legal obligation: To comply with applicable laws and regulations.
  • Consent: Where required, such as for optional marketing communications or connecting third-party accounts.

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Supabase — database hosting, authentication, and file storage
  • Stripe — payment processing and trainer payouts (Stripe Connect)
  • Google — only when you explicitly connect your Google account for Sheets sync
  • Vercel — application hosting
  • Resend — transactional email delivery
  • Upstash — rate limiting (Redis)
  • Google Tag Manager — analytics

Each service processes data in accordance with their own privacy policies. Data may be transferred outside the UK where these providers operate, with appropriate safeguards in place.

6. Google API Services

TrainerBio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only request access to Google Sheets and Google Drive (limited to files created by TrainerBio)
  • We use this access solely to create spreadsheets and append enquiry data when you enable sync
  • We do not use Google data for advertising or sell it to third parties
  • You can disconnect your Google account at any time from the form template settings, which immediately revokes our access

7. Data Security

We use industry-standard security measures including encrypted connections (HTTPS), row-level security on our database, secure file storage with token-based access, rate limiting on public endpoints, and input validation on all endpoints. OAuth tokens are stored encrypted in our database and automatically refreshed. However, no method of transmission over the internet is 100% secure.

8. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial record-keeping purposes. Enquiry data belongs to the trainer and is deleted when they delete their account.

Digital product order records and payment data may be retained for up to 7 years for tax and accounting purposes.

9. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your personal data (“right to be forgotten”)
  • Restrict processing of your data
  • Data portability — receive your data in a structured format
  • Object to processing based on legitimate interests
  • Disconnect third-party integrations (Google, Stripe) at any time
  • Export your enquiry data

To exercise any of these rights, email us at support@trainerbio.com. We will respond within 30 days.

10. Cookies

We use essential cookies for authentication and session management. We use analytics cookies (via Google Tag Manager) to understand how the platform is used. No advertising cookies are used. You can control cookie preferences through your browser settings.

11. Children

TrainerBio is not intended for use by anyone under the age of 16. We do not knowingly collect data from children.

12. Changes

We may update this policy from time to time. We will notify registered users of significant changes via email. Your continued use of TrainerBio after changes constitutes acceptance of the updated policy.

13. Contact

If you have questions about this privacy policy, contact us at support@trainerbio.com.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).