LF

LongLife Fitness

1:1 personal training & nutrition coaching

Privacy Notice

Privacy Notice

Effective 2026-05-20

Who we are

This privacy notice explains how LongLife Fitness ("we", "us", "our") collects and uses personal data when you use the LongLife Fitness website, member portal, or mobile app to book personal training sessions, manage your coaching plan, or set up payments.

LongLife Fitness is the data controller for that personal data.

LongLife Fitness is registered with the Information Commissioner's Office (ICO) as a data controller.

For any data protection question, including to exercise your rights, longlife.fitness@outlook.com.

Who hosts and operates this platform

The website, member portal, and mobile app you are using are built and operated for LongLife Fitness by Smart Property Software Ltd, our hosting and platform provider — trading as SmartGyms, a Smart Property Software product.

Smart Property Software Ltd is registered in England and Wales under company number 17126256, with registered office at 17 Watling Street West, Towcester, NN12 8LD.

Smart Property Software Ltd is registered with the Information Commissioner's Office (ICO) as a data controller under reference ZC149472 (https://ico.org.uk/ESDWebPages/Entry/ZC149472).

Smart Property Software Ltd acts as a data processor on behalf of LongLife Fitness for the personal data you enter into the portal — meaning we choose what to collect and how it's used, and Smart Property Software Ltd stores and processes it on our instructions. Smart Property Software Ltd is the data controller for its own platform-level records (the LongLife Fitness tenant account, billing relationship, and support tickets opened with their team) and you can contact them about that separately at hello@smartpropertysoftware.com.

What personal data we collect

Account and contact details: name, email, phone, date of birth, postal address, login credentials (passwords are stored only as hashes), and any emergency contact you choose to provide.

Coaching and booking activity: the personal training package you've signed up to, sessions booked with your coach, attendance history, workout-plan and meal-plan assignments, and progress photos you choose to share.

Health and fitness data (only if you choose to use these features): body measurements, weight, workouts you log, nutrition diary entries, and any data you choose to sync from Apple Health or Android Health Connect.

Payment data: limited card metadata (last four digits, card brand), direct debit mandate references, and the customer / mandate / subscription identifiers issued by Stripe or GoCardless. We never store full card numbers or bank account numbers — those are held by the payment provider.

Technical data: device identifiers, IP address, browser type, app version, push notification tokens, crash diagnostics, and aggregated analytics events.

Communications: messages exchanged with your coach through the portal, support tickets, and feedback submitted through the site or app.

How we use your data

To deliver the contract between you and us — operating your coaching relationship, taking payments, scheduling sessions, and providing the features you use in the app (UK GDPR Article 6(1)(b)).

To meet our legitimate interests in running the studio safely and securely — fraud prevention, dispute handling, accounting records, and improving the service (Article 6(1)(f)).

To meet our legal obligations — including HMRC record-keeping, payment regulations, and accessibility requirements (Article 6(1)(c)).

Health, fitness, and progress-photo features are only used where you have explicitly opted in through your portal settings (Article 9(2)(a) explicit consent for health data).

Direct marketing — including newsletters or session reminders not tied to your active bookings — is only used where you have given consent and can be withdrawn at any time from your account settings (Article 6(1)(a)).

Who we share your data with

Service providers acting on our instructions and bound by data-processing agreements: hosting and email delivery providers, our payment processors (Stripe and GoCardless), analytics and error-reporting providers, and any SMS or push-notification provider used to communicate with you.

Professional advisers, accountants, and regulators where required by law.

We do not sell your personal data and we do not share it for cross-context behavioural advertising.

Where your data is stored

Member-portal data is stored on infrastructure located within the United Kingdom or the European Economic Area, with backups held in the same region.

Some service providers (notably Stripe, GoCardless, and email-delivery providers) may process data in jurisdictions outside the UK. Where they do, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision recognised by the UK Government.

How long we keep your data

Member account and coaching records: for the lifetime of your relationship with us and for six years after it ends, to comply with HMRC record-keeping obligations and to defend potential legal claims.

Payment and mandate records: for at least six years after the last transaction or mandate cancellation, in line with UK financial record-keeping requirements.

Health, fitness, and progress-photo data: deleted within 30 days of you closing your account, unless you ask us to delete it sooner from your portal settings.

Marketing-consent records: kept for as long as your consent is active and for 12 months after withdrawal so we can evidence that the withdrawal was respected.

Your rights

You have the right to be informed (this notice), to access your personal data, to rectify inaccuracies, to erase data we no longer need (right to be forgotten), to restrict processing, to object to processing for direct marketing or legitimate interests, to data portability, and to withdraw any consent you've given.

To exercise any of these rights, please contact us at the email above. We will respond within one month and may extend by up to two further months where the request is complex or where you have submitted several requests.

Deleting your data

You can request deletion of your account and personal data at any time from the "Delete my data" link in your account settings — or by emailing longlife.fitness@outlook.com. No reason is required.

Once you submit a deletion request, we will acknowledge it within seven days and complete it within one month. Active direct debit mandates are cancelled as part of the process so no further payments are taken.

Some records must be retained even after a deletion request — invoices and payment records for six years to comply with HMRC obligations, and a minimum record of the deletion itself so we can evidence we've honoured your request. Where we retain data on these grounds, we restrict it from operational use and delete it as soon as the retention period ends.

Cookies and tracking

We use a small number of cookies to keep you signed in, remember your preferences, and understand how the site is used so we can improve it. You can manage your preferences from the cookie banner shown on your first visit.

We do not use cookies for cross-site advertising tracking.

Children

The portal and app are intended for users aged 16 or over. Under-16s can train at the studio with their parent or guardian's involvement, but only the parent or guardian holds the account on the portal.

Changes to this notice

We may update this notice from time to time. The effective date below shows the last material change. Where the change materially affects your rights or how we use your data, we will tell you in the app or by email before it takes effect.

Effective date: 2026-05-20.

How to make a complaint

If you believe we have not handled your personal data properly, please contact us first — longlife.fitness@outlook.com — and we will acknowledge your complaint within 30 days and aim to resolve it as quickly as possible.

You can also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not have to contact us first to use the ICO route.