Privacy Policy
Last updated: 3 September 2026
This policy explains how Train With Moe ("we", "us") collects, uses and protects your
personal data when you use trainwithmoe.com, apply for coaching, buy a training programme, or train with us.
We are the data controller for the information described here. Contact:
hello@trainwithmoe.com.
What we collect, and why
| When | What | Why (lawful basis) |
| You browse the site |
First-party analytics: pages viewed, time on page, how you arrived (e.g. from Instagram), a random
visitor identifier, approximate device type, your IP address and browser type. Advertising trackers
only run if you accept them in the cookie banner; see the cookies section below. |
Understanding what works on the site and keeping it secure (legitimate interests). You can decline
non-essential analytics in the cookie banner. |
| You arrive from one of our ads |
The click identifier that Google or Meta adds to the ad link, stored with your visit so we can tell
which ad brought you here. |
Measuring which ads work (consent, given via the cookie banner). If you later buy a programme, we
confirm the purchase to the ad platform as described in the cookies section. |
| You apply for coaching |
Name, email, phone number, Instagram handle (optional), training goal, and what's holding you back. |
Handling your application and replying to you (steps prior to a contract). |
| You tell us about injuries or health conditions |
Any injury or health information you choose to share in the application or during coaching. |
This is special category (health) data. We process it only with your
explicit consent, given by ticking the consent box on the application form, and we
use it solely to coach you safely. You can withdraw consent at any time by emailing us. |
| You book a call |
Name, email, phone, chosen time, timezone, and where you want the call (Google Meet, Zoom or phone). |
Running the call you asked for (contract), and sending confirmations and reminders. |
| You buy a programme or coaching |
What you bought, when, and the amount. We never see or store your card details;
payment is handled by Stripe or FITR, our payment and training-delivery providers. |
Fulfilling your purchase (contract) and accounting duties (legal obligation). |
| You're a client |
Weekly check-ins: weight (if you share it), sessions completed, and your notes. |
Delivering the coaching you're paying for (contract). Health-related details are covered by the same
explicit consent as above. |
| You train on our app |
Account details, your programme, the sessions and sets you log, check-ins, progress photos and
videos you upload, messages with your coach, nutrition entries, and any wearable or training data
you choose to connect (see wearables and connected apps). |
Delivering the coaching you're paying for (contract). Health-related information, including
wearable data, is processed only with your explicit consent, which you can withdraw at any time by
disconnecting the service or emailing us. |
| You sign up for free training or emails |
Email address and name. |
Sending what you signed up for (consent). Every email includes a one-click unsubscribe. |
Wearables and connected apps
Clients on our training app (app.trainwithmoe.com) can connect wearables and training services to feed
their coaching. Every connection is optional, started by you from inside the app, and you can disconnect it
yourself at any time. These connections only read data into Train With Moe. We never send your data back to
them, never sell it, and never share it with anyone beyond your own coach.
- WHOOP: if you connect your WHOOP, we read your daily recovery score, heart rate
variability, resting heart rate and sleep performance, so you and your coach can see how recovered you
are and shape training around it. If we add workout syncing in a future update, we would also read
workouts you record on WHOOP (sport, date, duration, heart rate and WHOOP's strain measure) so a workout
you did could be matched to a session your coach prescribed and marked complete. WHOOP asks for your
approval on its own screen before we could read workouts, so nothing changes without you agreeing to it
first. This is health data, and we process it only with the explicit consent you give on WHOOP's own
connect screen. We keep a rolling 90 days of WHOOP data; older days are deleted automatically, and if
workout matching arrives, the record that you completed a prescribed session would stay part of your
training history like any other logged session. Disconnecting deletes everything we hold from WHOOP
immediately and revokes our access with WHOOP. How WHOOP itself handles your data is described in
WHOOP's privacy policy.
- Strava: if you connect Strava, we read your cardio activities (sport, date, duration,
distance and average heart rate) so the training you did shows against the plan your coach set.
Disconnecting stops the syncing and removes our access straight away; activities already pulled remain
part of your training record and are deleted with your account, or sooner if you ask.
- Apple Health: if you enable it on your iPhone, the app sends us daily totals only:
weight, steps, sleep minutes and exercise minutes. You control exactly what is shared in your phone's
Health settings, and you can turn it off there at any time.
Wearable data follows the same rights as everything else in this policy: you can ask for a copy of what
we hold or have it deleted at any time, and deleting your account removes all of it.
Cookies and analytics
We use a small number of cookies and similar storage, and nothing non-essential loads unless you
accept the cookie banner:
- Analytics identifier (first-party): a random ID that lets us see how visits flow
through the site. It is not linked to your name unless you later apply or sign up.
- Plausible (page-view counting): loads on every page, before and regardless of the
cookie banner. It sets no cookies, stores nothing on your device and builds no profile of you, which
is why it is outside the banner's scope. It counts the page, where the visit came from and a rough
device type, and nothing that identifies you. We rely on legitimate interests for it, and you can
object by emailing us.
- Advertising measurement (Meta Pixel): if we are running ads and you accept the banner,
Meta's pixel loads and tells Meta which of our pages you visited and whether you signed up or applied,
so our ads can be measured and shown to people they're relevant to. Meta acts on this data as described
in Meta's privacy policy.
Choosing "Essential only" means the pixel never loads and nothing is shared with Meta.
- Advertising measurement (Google): if we are running Google ads and you accept the
banner, Google's tag loads so Google can measure which searches and ads lead to applications. Google
acts on this data as described in
Google's privacy policy.
Choosing "Essential only" means the tag never loads.
- Consent choice: remembers your cookie banner decision.
If you accepted advertising cookies and later buy a programme, we also confirm that purchase to the ad
platform directly from our server, so it can match the sale to the ad you clicked. That confirmation can
include your email address (in scrambled, unreadable form), the ad click identifier, and the IP address and
browser type recorded on your visit. It never includes your card details.
We never sell your data, and nothing beyond the advertising measurement described above is shared with
advertisers. Anonymous browsing data, including IP addresses and browser details, is deleted automatically
after 13 months.
Who we share data with
Only the services needed to run the business, under their own data protection commitments:
- Hostinger: hosts the website and database.
- The training app host (a dedicated Hostinger server): runs
app.trainwithmoe.com and holds your training and health data, including check-ins, progress photos
and videos, messages with your coach, and any wearable data you connect.
- Stripe: processes card payments. Stripe may transfer data outside the UK under
approved safeguards (standard contractual clauses).
- FITR: delivers your training programme and app access after purchase.
- Zapier: carries the notice that a FITR sale happened from FITR to us, so your
purchase reaches your record. It sees your name, email and what you bought, never card details.
- Plausible: counts page views on every page of this site. Cookieless, and it
receives no name, email or identifier of yours.
- jsDelivr: serves the international phone-number field on the application form. Your
browser fetches that file directly, so the request carries your IP address and browser type to
jsDelivr. Nothing you type in the form is sent there.
- Anthropic: powers AI drafting and summaries inside the coach's own admin, for
example drafting a reply for Moe to edit. Application answers about injuries are excluded by
default, and we send only what the draft needs.
- Google Meet / Zoom: hosts your intro call if you choose a video call.
- Meta: only if you accept advertising cookies in the banner, and only the ad-measurement
signals described in the cookies section above.
- Google: only if you accept advertising cookies in the banner, and only the
ad-measurement signals described in the cookies section above.
We never sell your data. We disclose it beyond the above only if the law requires it.
How long we keep it
- Anonymous browsing analytics: deleted after 13 months. IP addresses and browser details are removed
after 13 months for everyone, including clients.
- Applications and lead details: kept while we're in contact; deleted on request at any time.
- Unsuccessful applications: deleted 12 months after they are declined, and the lead record is
anonymised at the same time unless you are also a client.
- Client records: for the duration of coaching plus a reasonable period afterwards, and as long as tax
law requires for purchase records (6 years).
- WHOOP data: a rolling 90 days, with older days deleted automatically, and all of it deleted the moment
you disconnect WHOOP.
- Backups: taken nightly, encrypted on the server before they leave it with a key that is not kept on
the server, and copied to two separate providers. Daily copies are kept for 30 days, and one copy per
calendar month is kept as a longer-term archive.
Your rights
Under UK data protection law you can ask us at any time to:
- Access the personal data we hold about you;
- Correct anything inaccurate;
- Delete your data ("right to be forgotten");
- Receive a copy of your data in a portable format;
- Object to or restrict how we use it;
- Withdraw consent, including for health information and marketing emails, at any time,
without affecting anything done before you withdrew it.
Email hello@trainwithmoe.com and we'll respond within one month.
If you train on our app you can also delete your whole account from inside it, which removes your training
history, photos, videos and messages.
Complaints
If something we have done with your data is wrong, tell us first: email
hello@trainwithmoe.com with what happened and we will look into
it and reply within one month. Putting it right ourselves is faster for everybody.
If you are not happy with our answer, or you would rather not come to us at all, you have the right to
complain to the Information Commissioner's Office. They take complaints at
ico.org.uk/make-a-complaint or on
0303 123 1113. Going to them costs you nothing and does not stop you also raising it with us.
ICO registration: [number pending]
Security
The site runs over HTTPS everywhere. Access to your data is protected by two-factor authentication, and
role-based permissions limit what any team member can see. Card details never touch our servers. Every time
your coach opens your health data, that access is recorded.
The full detail, in plain words, is on our security page: how data is protected
in transit and at rest, who can reach it, how long each kind is kept, and what we do if something goes
wrong.
Changes
If this policy changes in a way that matters, we'll update this page and the date at the top.