Back to Trainpath

Privacy Policy

Last updated: 22 July 2026

This Privacy Policy describes how Trainpath (“we”, “us”, “our”) collects, uses, and shares information when you use our platform. By using Trainpath, you agree to the practices described here.

1. Information we collect

  • Account information: name, email, password (hashed), business name, profile photo.
  • Client and coaching data: workout logs, measurements, goals, photos, nutrition logs, messages, and any other content you or your clients submit.
  • Health information: injuries, medical conditions, medical-clearance status, and — where a trainer provides exercise-physiology, physiotherapy, or NDIS-funded services — clinical and treatment notes. This is sensitive information; see Section 5.
  • Payment information: processed by Stripe. We never store full card numbers.
  • Usage data: log entries, IP addresses, device and browser metadata, and feature usage.

2. How we use information

  • To provide, maintain, and improve the platform.
  • To process payments and manage subscriptions through Stripe.
  • To send transactional emails (booking confirmations, password resets) and product notifications you have opted into.
  • To analyse usage and prevent fraud or abuse.
  • To comply with legal obligations.

3. Subprocessors

We share data with the following service providers strictly to operate Trainpath: Supabase (database, auth), Stripe (payments), Anthropic (AI features), Mux (video), Resend (email), OneSignal (push notifications), and our hosting provider. Each operates under their own privacy and security commitments.

4. Trainer and client relationships

If you are a client, the trainer who invited you can access the data you create within Trainpath for the purpose of delivering coaching services. We act as a data processor on behalf of trainers for client-submitted data.

5. Sensitive and health information

Coaching and allied-health services involve health information — for example injuries, medical conditions, medical-clearance status, measurements, and (where a trainer provides exercise-physiology, physiotherapy, or NDIS-funded services) clinical and treatment notes. Under the Australian Privacy Act 1988 (Cth), health information is“sensitive information” and attracts a higher standard of protection.

  • We collect and handle health information only to operate the platform and to enable your trainer to deliver their services to you.
  • Your trainer is responsible for obtaining your consent to collect and use your health information, and you may withdraw that consent at any time (see “Your rights” below).
  • We do not use health information for marketing, and we do not sell it.
  • Health information is subject to the safeguards in the Security section below, and access is restricted to your trainer and to staff who need it to operate or support the service.

Trainpath is an Australian product. We do not represent that the platform meets the requirements of the United States Health Insurance Portability and Accountability Act (HIPAA); trainers operating in markets with specific health-data regimes are responsible for their own compliance in those markets.

6. Your rights

Trainpath is operated from Australia and handles personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You have the right to access the personal information we hold about you, ask us to correct it if it is inaccurate, request a copy of your data, and ask us to delete it — subject to any legal obligation we have to retain it. To exercise these rights, contact us using the details below. If you are not satisfied with how we handle a privacy request, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Depending on where you are located, you may also have rights under other regimes such as the EU or UK GDPR, or the California Consumer Privacy Act (CCPA). Where those laws apply to you, we will honour the equivalent rights of access, correction, portability, and deletion.

7. Data retention

We keep account and coaching data for as long as your account is active. If you close your account, we delete or anonymise personal data within 90 days, except where we are legally required to retain it.

8. Security

We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, role-based access controls, and row-level security in our database. No system is perfectly secure; please use a strong password and notify us of any suspected unauthorised access.

9. Children

Trainpath is not intended for users under 16. Trainers are responsible for any minors they coach and must obtain appropriate parental consent before adding them as clients.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.

11. Contact

Questions about this policy or your data: privacy@trainpath.app.