Privacy Policy
How FitPhoneAI collects, uses and protects data across our apps. This policy covers all of our apps; each app's specific data is listed below.
Last updated: 20 June 2026
1. Who we are
The apps are provided by Fitness Industry Sales Ltd, registered in England and Wales (company number 11101867), 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom, trading as FitPhoneAI. Contact: support@fitphone.ai. We are subject to the UK GDPR and the Data Protection Act 2018.
2. Controller and processor roles
For the business data you connect through an app (your contacts, calls, conversations, sales and similar), you are the data controller and we act as your processor, handling that data on your instructions to provide the app. For our own business records — for example the email you use to contact support, and operational logs — we act as a controller. This policy explains both.
3. Data we process
Depending on which apps you use, we process:
- Connection & account data: the identifiers of the sub-accounts (locations) and company you install on, and OAuth access/refresh tokens for the connected platforms. Tokens and connected-service credentials are encrypted at rest.
- Contact data: names, email addresses, phone numbers and related contact fields, where an app reads or writes contacts.
- Communications content: call transcripts and metadata, and chat/SMS/email message content, where an app analyses or backs up communications.
- Commercial records: sales, purchases, appointments and opportunities, where an app reports on or syncs them.
- Configuration you enter: settings, mappings, business-registration details (A2P Copilot) and connected-service logins (for example a Mindbody staff login for MBO Sync).
- Operational data: logs, error records and usage metrics used to run, secure and meter the apps.
The precise data per app is listed in the per-app details below. We do not intentionally collect special-category personal data and ask that you do not configure the apps to send it.
4. How we use data
- To provide each app's core function — syncing, reporting, scoring, parsing, backing up or validating, as described in the Documentation.
- To analyse calls and conversations for quality (including AI-assisted analysis of items that are escalated for review).
- To secure the apps, prevent abuse, meter usage and provide support.
- To maintain backups and idempotency records so data is not lost or duplicated.
We do not sell personal data, and we do not use your Customer Data to train third-party AI models. AI sub-processors are used only to process the specific content sent for analysis, on a transient basis.
5. Legal bases
Where we act as processor, you are responsible for the legal basis for the underlying processing. For our own controller processing, we rely on: legitimate interests (operating, securing and improving the apps and supporting customers), performance of a contract (providing the apps you install), and legal obligation (for example, financial record-keeping). You are responsible for obtaining any consents required for the communications and contacts you process through the apps.
6. Sub-processors
We use a small number of trusted providers to deliver the apps. Each is bound by data-protection obligations consistent with this policy.
| Sub-processor | Purpose | Used by |
|---|---|---|
| Amazon Web Services | Database hosting and encrypted object storage | All apps |
| Heroku (Salesforce) | Application hosting | All apps |
| Anthropic | AI analysis of escalated calls/conversations/emails (transient) | AI Supervisor, Messenger Supervisor, Mailhook |
| Mindbody | The integrated booking platform the app syncs with | MBO Sync |
Your CRM/marketplace platform is the source and destination of much of the data and is a separate controller/processor in its own right under its own policies. We will give notice of material changes to our sub-processor list.
7. International transfers
Our infrastructure and some sub-processors may process data outside the UK/EEA (for example, certain providers based in the United States). Where data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or Standard Contractual Clauses, and adequacy where applicable.
8. Retention
We retain Customer Data only as long as needed to provide the relevant app. When you uninstall an app for a location, we stop processing for it; cached operational data ages out, and stored Customer Data is deleted or anonymised within a reasonable period unless we must keep it to comply with law. Vault backups are retained per the app's schedule and are removed after a grace period when a location is offboarded. You can request deletion at any time (see Your rights).
9. Security
- OAuth tokens and connected-service credentials are encrypted at rest using AES-256-GCM; data in transit is protected with TLS.
- Each app uses its own isolated database and credentials.
- Access to production systems is restricted and webhooks are signature-verified.
- Apps fail safe — for example, MBO Sync will not book a sale without a configured non-charging payment method, and never charges a card.
No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the data we process.
10. Your rights
Subject to applicable law, individuals have rights to access, correct, delete, restrict or object to processing of their personal data, and to data portability. Because we usually process personal data as your processor, requests from individuals are normally directed to you as the controller; we will assist you in responding. To exercise rights regarding data we control, or to ask us to help with a request, email support@fitphone.ai. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
11. Per-app details
AI Supervisor
Data: voice-call transcripts and metadata, AI agent prompts, call outcomes and cost/usage metrics. Purpose: scoring call quality, flagging issues, and suggesting prompt improvements. AI sub-processor: Anthropic analyses escalated calls. Suggestions are never applied automatically.
Call Reporting
Data: call metadata and usage metrics (read-only). Purpose: agency-wide call reporting. No AI analysis; never writes to your agents.
Messenger Supervisor
Data: chat/SMS/email message content and contact identifiers from monitored conversations. Purpose: conversation quality scoring and escalation. AI sub-processor: Anthropic analyses escalated conversations.
Mailhook
Data: the content of lead emails you forward and the contact details parsed from them. Purpose: turning lead emails into contacts. AI sub-processor: Anthropic assists only with unfamiliar email formats; recognised formats are parsed without AI.
MBO Sync
Data: client/contact demographics and sale/purchase records exchanged between Mindbody and your CRM, plus the Mindbody Site ID and staff login you enter (the login is encrypted at rest; we issue short-lived Mindbody tokens from it). Purpose: two-way client and sales sync. Third party: Mindbody.
A2P Copilot
Data: business-registration details you enter (such as legal name and EIN) and the content of the opt-in page URL you provide for validation. Purpose: checking your A2P 10DLC registration before submission. We fetch the opt-in page you specify to validate it.
Vault
Data: backups of your contacts, conversations, opportunities, appointments and basic settings. Purpose: nightly backup and offboarding export. Backups are stored encrypted with a checksum manifest and removed after a grace period on offboarding.
History Search & Export
Data: message and note history pulled live from the CRM at request time; only a metadata-only audit log is retained (location, contact ID, export kind, mode, filter parameters, counts, session user ID). Purpose: per-contact history search and export for compliance and data-subject requests. Storage: no message or note content is stored server-side. Exports stream directly from the CRM API to your browser. On uninstall, audit log records are deleted immediately.
12. Changes
We may update this policy; the "last updated" date reflects the current version. Material changes will be reflected here.
13. Contact
For privacy questions or requests, email support@fitphone.ai, or write to Fitness Industry Sales Ltd, 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom.