Draft v0.1 · Counsel review required

Privacy Policy

How Sailor Strong Fitness plans to collect, use, disclose, retain, and protect personal information.

Controller/operator: [OWNER LEGAL NAME / ENTITY]. Effective date: [DATE]. Privacy contact: [PRIVACY EMAIL]. This draft must be reconciled against the production configuration before publication.

Information we collect

  • Identity and account data: name, email, login identifiers, role, and account-security metadata.
  • Application and coaching data: goals, experience, equipment, availability, communications, and coach notes.
  • Fitness and wellness data: assigned programming, completed sets, weight, repetitions, effort, workout notes, check-ins, habits, optional body measurements, and optional progress photos.
  • Transaction and scheduling data: records supplied by payment or appointment providers if those features are enabled.
  • Technical data: device/browser information, approximate network metadata, security logs, and limited diagnostics.

Why we use information

We use information to evaluate inquiries, provide and personalize coaching, track client-reported progress, communicate, secure accounts, maintain legal acceptance records, process transactions, comply with law, and improve service reliability. We will identify the applicable legal bases where required by the final jurisdiction.

Service providers

Planned providers include Vercel for application hosting, Supabase for database/authentication/storage, Resend for transactional email, and—if enabled—Square for hosted invoice payment, a scheduling provider, Sentry for error monitoring, and limited analytics. The final notice will name enabled providers and link to their policies.

Fitness information and photos

Fitness and wellness data can be sensitive. We seek to collect only what is useful for coaching. Progress photos are optional and private by default. Separate express permission is required before using a client’s name, image, testimonial, or results for marketing.

Sharing

We do not plan to sell personal information. We may disclose information to contracted processors, at your direction, to protect safety or rights, in a business transfer subject to safeguards, or when legally required. The final policy must include any jurisdiction-specific “sale,” “sharing,” or targeted-advertising disclosures.

Retention and deletion

Retention periods are [TO BE APPROVED]. Account data may be deleted or de-identified when no longer needed, while payment, legal acceptance, dispute, and safety records may be retained when reasonably necessary or legally required. Users may request access, correction, export, or deletion at [PRIVACY EMAIL], subject to applicable exceptions.

Security and international processing

We use reasonable administrative and technical safeguards such as access controls, private storage, encrypted transport, and least-privilege service credentials. No system is perfectly secure. Provider infrastructure may process information outside your state or country; required transfer disclosures will be added after the business jurisdiction is confirmed.

Children

The service is not intended for children under [MINIMUM AGE]. Rules for minors, parental consent, and deletion requests must be finalized before accepting any minor client.

Contact

[BUSINESS LEGAL NAME]
[MAILING ADDRESS]
[PRIVACY EMAIL]