Legal & Privacy Notice

Fitemy Privacy Policy

  • Version: 1.0 (English)
  • Effective date: 12 August 2026

This Privacy Policy explains how Global Trade Network Ltd, trading as Fitemy, collects and uses personal information through fitemy.com, the Fitemy iOS and Android applications, and related coaching services.

Fitemy is designed for an international community of adults. Clients use Fitemy to receive remote personalised fitness coaching from a selected personal trainer. Trainers provide that coaching as Fitemy's subcontractors. Availability of particular Trainers, features, payment methods and services may vary by location and applicable law.

Private coaching information is not intentionally published in profiles or directory listings. Section 8 explains the current access limitation for coaching media links. We do not sell personal information or use private coaching, health or body-progress information for advertising.

1. Who is responsible for your information?

Global Trade Network Ltd is the controller of the personal information described in this policy.

  • Company number: 12460056
  • Registered office: 69a Manchester Road, Swinton, Manchester, M27 5FX, United Kingdom
  • Privacy contact: support@fitemy.com

2. Who does this policy cover?

This policy covers:

  • clients and prospective clients;
  • trainers and trainer applicants;
  • visitors to the Fitemy website;
  • people who contact support, submit feedback or request account deletion; and
  • other people whose information is provided to us in connection with the service.

Fitemy is not intended for anyone under 18.

3. Information we collect

We collect only information relevant to operating, protecting and improving Fitemy.

Account and profile information

This may include your Supabase user ID, name, email address, telephone number, username, date of birth, gender, language, role, profile image, address, account status and feedback preferences. Authentication may be handled through email one-time codes, Google or Apple. Fitemy does not receive your Google or Apple password.

Trainer and trainer-applicant information

This may include biography, motto, education, qualifications, certificates, experience, areas of expertise, specialties, social links, gallery images, promotional video, location, service address, latitude and longitude, application answers and correspondence.

Approved trainers also provide payout-account information, which may include the account and routing details required for the available payout method. Payout information is not included in the public trainer profile.

Trainer profiles are intended to help clients discover and assess trainers. Website visitors and signed-in Fitemy users may see the trainer's first name and last initial, image, professional information, public media and service area; signed-in users may also see age derived from date of birth, gender and precise map coordinates. Fitemy stores the trainer's full submitted name, address and precise coordinates for application review, account administration and location matching. A trainer's full surname and street address are not intentionally included in Client-facing website or app profiles, directory listings or programme screens; the displayed written location is limited to district, city and optional region.

Client location information

If a client grants foreground-location permission, the app reads the device's precise location to centre the map and show the client's position alongside trainer markers. We rely on consent for this optional processing. The client can withdraw permission in device settings, although the location feature will then stop working. The current client flow does not save those coordinates as part of the client's Fitemy profile. Map, device and network providers may still receive map requests, IP addresses or approximate location information as part of providing their services.

Coaching and fitness information

This may include:

  • workout, cardio, nutrition, meal and supplement plans;
  • programme schedules, notes, calorie and macro targets;
  • workout, cardio, meal and supplement activity uploads;
  • front, side and back Monthly Progress Review photographs;
  • client notes, trainer feedback and accountability statistics;
  • private programme questions and trainer answers; and
  • meal reviews and other programme feedback.

This information may reveal health, body condition, diet, habits or physical progress and may therefore include special-category health data under UK data-protection law and sensitive health information under other applicable privacy laws.

Payments and subscriptions

Stripe processes checkout and payment-card information. Fitemy receives records such as Stripe customer, checkout, subscription, invoice, payment, refund and dispute identifiers; the selected plan and trainer; currency and amounts; payment status; and subscription dates. Fitemy does not receive your full card number or card security code.

Reviews, reports and other content

We collect Trainer Review ratings and text, review eligibility and editing information, content reports and moderation records. Approved Trainer Reviews may be displayed on Fitemy. Private Monthly Progress Reviews are a separate coaching feature and are not public Trainer Reviews.

Communications, forms and bookings

We collect information submitted through contact forms, trainer applications, support requests, feedback, reports and account-deletion requests. Where an onboarding call is booked, Google Calendar and Google Meet may receive the client and trainer email addresses, booking time, time zone, event details and meeting link.

Notifications

With device permission, we collect a push token, platform and user association. We also store notification inbox content, delivery status, provider receipts and errors so that we can deliver and troubleshoot service notifications.

Analytics, diagnostics and technical information

Versions of Fitemy distributed to users use PostHog and Sentry.

PostHog may receive an account identifier, role, language, app lifecycle and screen activity, feature interactions, checkout stages, trainer or service identifiers, device and network information, IP-derived location and masked session replays. Text inputs, images and sandboxed views are configured to be masked, but the analytics is linked to an account identifier and is not described as anonymous.

Sentry may receive an account identifier, role, language, device and app information, logs, errors, traces, network context and other default personally identifiable diagnostic information. Screenshots and view-hierarchy capture are not enabled in the current configuration.

We use this information to understand product use, diagnose faults, protect the service and improve reliability. This processing is subject to the right to object described below. Where consent is required for a particular storage or access technology, we ask for it separately from acknowledgement of this policy.

4. Where information comes from

We receive information:

  • directly from you;
  • from the client or trainer involved in your programme;
  • from your device and your use of Fitemy;
  • from authentication, payment, communications, analytics and infrastructure providers; and
  • from records Fitemy creates when operating subscriptions, entitlements, moderation, support and security processes.

5. Why we use information and our lawful bases

  • Create accounts, authenticate users and provide Fitemy
    • Typical information: account, profile, authentication and role information.
    • Lawful basis: contract and steps requested before a contract.
  • Assess and onboard trainers
    • Typical information: application, identity, qualification, profile and correspondence information.
    • Lawful basis: steps requested before a contract and legitimate interests in operating a suitable trainer network.
  • Deliver personalised coaching
    • Typical information: Programme, schedule, communications, uploads, progress and feedback information.
    • Lawful basis: contract, together with any additional condition required by applicable law for sensitive information.
  • Operate trainer discovery and public profiles
    • Typical information: Trainer profile, media, qualifications and location.
    • Lawful basis: contract and legitimate interests in enabling discovery and presenting Trainer services.
  • Process subscriptions, refunds and Trainer payouts
    • Typical information: payment, Subscription, payout and transaction records.
    • Lawful basis: contract, legal obligations and legitimate interests in fraud prevention and financial reconciliation.
  • Provide the optional Client-location map feature
    • Typical information: precise Client device location.
    • Lawful basis: consent.
  • Provide calls and service notifications
    • Typical information: booking, contact, device and push-token information.
    • Lawful basis: contract, legitimate interests in service communications and device permission where required to deliver a notification.
  • Publish and moderate Trainer Reviews and Content
    • Typical information: review, report, moderation and account information.
    • Lawful basis: contract and legitimate interests in trustworthy reviews, safety and enforcement.
  • Answer enquiries and handle rights or complaints
    • Typical information: form, support, feedback, deletion and complaint information.
    • Lawful basis: contract, legal obligations and legitimate interests in support and dispute handling.
  • Analyse and secure Fitemy
    • Typical information: usage, replay, device, network, error, log and security information.
    • Lawful basis: legitimate interests in improving, securing and maintaining Fitemy, and consent where required by law.
  • Meet legal and regulatory duties
    • Typical information: relevant account, transaction, safety, moderation and correspondence records.
    • Lawful basis: legal obligations, legal claims and legitimate interests in demonstrating compliance.

Our legitimate interests include operating a reliable coaching service, preventing misuse, protecting users, improving features, handling complaints and maintaining accurate business records. We balance those interests against users' rights and expectations.

6. Information you must provide

Information needed to create an account, verify eligibility, enter a subscription, pay a trainer or deliver a core programme is required for the relevant service. If it is not provided, we may be unable to create the account, approve a trainer, process payment or provide the requested feature.

Optional profile fields, location permissions and coaching uploads can be withheld, although some discovery or personalised-feedback features may then be unavailable or less useful.

7. Who we share information with

We share only what is reasonably required for the relevant purpose.

  • Your selected Trainer or assigned Client: deliver the Programme, communicate, review progress and provide feedback.
  • Supabase: authentication, database and account services.
  • Cloudflare, including Workers, R2, Queues and Turnstile: API processing, media storage, communications, security and infrastructure.
  • Stripe: checkout, Subscriptions, payments, refunds, disputes and customer-portal services.
  • Google: OAuth, Android maps, Calendar and Meet onboarding calls.
  • Apple: Apple authentication and native Apple platform or map services where used.
  • Expo Push Service, Apple Push Notification service and Firebase Cloud Messaging: device push notifications and delivery processing.
  • Brevo: transactional and administrative email delivery.
  • PostHog: product analytics and masked session replay.
  • Sentry: error, log, trace and diagnostic monitoring.
  • Professional advisers, insurers, banks, regulators, courts and law-enforcement bodies: advice, payment, legal claims, compliance and lawful requests.
  • A buyer or successor to the business: a genuine corporate transaction, subject to confidentiality and data-protection requirements.

Trainers receive only the client information needed for their assigned Fitemy programme and must follow contractual confidentiality and data-use restrictions. They must not use private client information for unrelated marketing or their own separate purposes.

8. Public and private information

The following is intended to be public or visible within Fitemy:

  • approved trainer profiles, galleries, professional information and service-location presentation;
  • aggregate trainer ratings and review counts; and
  • approved Trainer Reviews, within the audience supported by the product.

The following is not intentionally published in profiles or directory listings:

  • client programme plans and schedules;
  • activity evidence and Monthly Progress Review photographs;
  • private client notes, questions, trainer answers and feedback;
  • trainer payout details; and
  • support, deletion, report and moderation records.

Within Fitemy, private coaching information is intended for the client, the assigned trainer, authorised Fitemy personnel and providers that need it to operate or secure the service. Current coaching photographs and videos are stored at unlisted, hard-to-guess URLs. Anyone who obtains one of those URLs can retrieve the media until it is deleted, so users must not share those links with unauthorised people. We do not grant a licence to use private coaching content for advertising.

9. International processing and transfers

Fitemy is established in the United Kingdom and operates internationally. Personal information may be processed in the United Kingdom and in other countries where a selected Trainer or Fitemy's providers are located.

Where UK law treats a transfer initiated by Fitemy as restricted, Fitemy relies on an applicable adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another transfer mechanism permitted by UK law. We also use any additional safeguard required by other privacy law applicable to the transfer. You may contact us for information about the safeguard relevant to a particular provider.

10. How long we keep information

We use the following retention criteria:

  • Accounts and profiles: while the account is active and while reasonably needed to administer the relationship. A verified deletion request is processed manually and confirmed within 28 days, subject to justified legal retention.
  • Private programme media: activity evidence and Monthly Progress Review media is queued for deletion after the related subscription reaches a terminal state. Abandoned uploads are cleared separately.
  • Other coaching records: while needed to provide the programme, preserve appropriate account history, resolve a complaint or claim, or complete a verified deletion request.
  • Trainer applications and support: while the application or enquiry is assessed and for as long as reasonably required for follow-up, complaints, safety or legal claims.
  • Trainer Reviews and moderation: while the review is published or the record is required to establish eligibility, authenticity, moderation decisions or legal claims. Content may be removed or irreversibly anonymised where appropriate.
  • Payments, contracts and payouts: for the periods required by tax, accounting, fraud-prevention, consumer and legal-claims obligations.
  • Notifications, analytics and diagnostics: for the operational or provider-configured period reasonably needed to deliver messages, investigate faults, secure Fitemy and understand product use.
  • Backups: until replaced through the applicable secure backup cycle.

We minimise or delete information when its purpose and any lawful retention requirement end.

11. Account deletion and subscription cancellation

An authenticated account-deletion request made in the app or at fitemy.com/account-deletion disables new sign-ins while Fitemy manually reviews the account, subscriptions, providers, storage and records. Existing technical sessions may take time to expire. We delete or irreversibly anonymise information unless a specific legal or contractual basis requires limited information to be retained for a defined period. We send confirmation when the process is complete, within 28 days of the request.

Account deletion is separate from subscription cancellation. A deletion request does not itself cancel or refund a Stripe subscription. Clients should cancel future renewal through the Stripe Customer Portal before requesting deletion. Statutory cancellation and refund rights are unaffected.

12. Security

We use proportionate technical and organisational safeguards, including authenticated in-app access, database access policies, role-based service boundaries, encrypted connections, provider access controls, upload validation, monitoring and deletion procedures. In-app access to private coaching information is limited to people and providers that need it for the service. The unlisted-media-link limitation is described in section 8.

No internet or storage system is completely secure. Users should protect access to their email account and device and contact us promptly if they believe their Fitemy account or information has been compromised.

13. Your rights

UK data-protection law and, depending on where you live, other applicable privacy laws may give you the right to:

  • receive information about how we use your information;
  • request access to it;
  • correct inaccurate or incomplete information;
  • request erasure;
  • restrict processing;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests or direct marketing; and
  • withdraw consent at any time where processing relies on consent.

Withdrawing consent does not make earlier processing unlawful.

To exercise a right, email support@fitemy.com. We may need to verify your identity and may retain limited evidence that the request was handled.

You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address your concern first.

Depending on where you live, you may also have the right to complain to your local data-protection or privacy regulator.

14. Automated decisions

Fitemy does not currently make decisions based solely on automated processing that produce legal or similarly significant effects. We use automation to support functions such as subscription status, programme entitlements, reminders, moderation queues and fraud or security checks, but material decisions can be reviewed by a person.

15. Marketing and service messages

Operational emails, inbox messages and push notifications may be sent when needed to provide or protect Fitemy. We send direct marketing only where permitted by law and provide a simple way to opt out. Opting out of marketing does not prevent essential service messages.

16. External links

Fitemy may link to third-party websites or services. Their privacy practices are governed by their own policies. Review those policies before providing information directly to them.

17. Changes to this policy

We may update this policy when Fitemy's services, providers or legal obligations change. We will update the version and effective date and provide appropriate notice before a material new use of personal information. Where a change requires new consent, we will request it separately.

18. Contact us

Questions, requests and complaints may be sent to:

  • Global Trade Network Ltd, trading as Fitemy
  • 69a Manchester Road
  • Swinton, Manchester
  • M27 5FX
  • United Kingdom
  • support@fitemy.com