ClassMargin
Log in

Privacy Policy

Last updated 16 September 2026 · Questions: support@classmargin.com

1Who we are

ClassMargin is a subscription service that reconciles booking revenue and staff costs for fitness studios. It is operated by Toby Huntington-Whiteley, an individual trader established in France, at 13 rue de la Sourdière, 75001 Paris.

A company is being formed to take over the operation of ClassMargin. When it is registered, this policy will be updated to name it, and we will email every customer before that change takes effect.

For anything in this policy, write to support@classmargin.com.

2Our role depends on whose data it is

This is the most important thing to understand about how ClassMargin handles data, and it changes what we are allowed to do and who you should contact.

Whose dataOur roleWhat that means
The studio owner — our direct customerData controllerWe decide why and how their account and billing data is used, and we answer to them directly.
Coaches employed or contracted by a studioData processorThe studio decides; we process on its instructions.
End clients — the people who attend classesData processorThe studio decides. We have no relationship with these people and no way to identify or contact them independently.

In plain terms: a studio uploads its own booking and payroll exports to us. The names of coaches and class attendees arrive inside those files. We hold that data on the studio's behalf, and the studio remains responsible for it.

3What we hold

About the studio owner: email address, password (stored hashed by our authentication provider, never by us in readable form), and — if they sign in with Google — the identity Google discloses. Billing is handled by Stripe; we store only Stripe's customer and subscription identifiers. We never see or store card numbers.

About coaches: name, email address where the studio provides one, display name, pay and session figures drawn from the studio's payroll exports, uploaded invoice documents, and the text of any client reviews the studio records against them.

About end clients: first and last name, which class they attended, when, through which booking channel, and whether they cancelled or did not turn up. We also store a short one-way fingerprint of the moment a booking was made, used only to tell two bookings by the same person for the same class apart. We do not hold end clients' email addresses, telephone numbers or payment details. This has been confirmed directly against our production database rather than assumed.

We also retain the original files a studio uploads — booking exports, payroll files, invoices — in their uploaded form.

4The free revenue check

Anyone can upload a booking export to our public revenue calculator without creating an account. Those files are read in memory and never stored. Nothing is written to our database or our file storage, and nothing about that upload survives the request. If you want your figures kept, you have to create an account.

5Why we hold it, and on what basis

DataPurposeLawful basis
Studio owner account and billingProviding and billing for the servicePerformance of a contract
Coach names, pay and session dataCalculating the margin, cost and fill-rate figures the studio subscribes forLegitimate interests of the studio, with ClassMargin acting on its instructions
Sending a coach their own monthly reportGiving a coach their own performance figuresLegitimate interests — a coach has no direct relationship with us and so cannot meaningfully consent to us
End client names and attendanceCounting clients and first-timers, and attributing attendance to a coachLegitimate interests of the studio, with ClassMargin acting on its instructions

6Who else sees it

We use the following sub-processors. Each receives only what it needs to do its job.

ProviderWhat it receivesWhere
SupabaseOur database, authentication and file storage — all data described aboveEuropean Union (eu-west-1)
VercelHosting; sees request metadata including IP addressesUnited States
StripeStudio owners' billing and payment detailsUnited States
ResendRecipient addresses and the full content of emails we sendUnited States
AnthropicThe content of AI requests — see section 7United States
GoogleSign-in identity, only where a studio owner chooses Google sign-inUnited States

Where a provider is outside the European Economic Area, transfers are made under the European Commission's Standard Contractual Clauses, which form part of our agreement with each of them. Several are additionally certified under the EU–US Data Privacy Framework; we do not rely on that certification alone.

7Artificial intelligence features

Three features send data to Anthropic's Claude API: the in-app assistant that answers questions about a studio's own figures, the monthly written summary, and the motivational summary generated for individual coaches.

What is sent varies by feature and includes coach names, venue names and revenue figures. The coach summary may also include the text of client reviews, which studios sometimes record verbatim and which may therefore contain a client's own words about themselves.

We do not use anyone's data to train AI models, and our provider does not train on it either.

8How long we keep it

End clients. A client's name is removed once they have not attended a class for 24 months. A studio can set a shorter period for its own account, and should set it to match whatever it has published to its own clients.

Removal is done by anonymisation, not deletion. The attendance record itself stays, with the name replaced by a token that identifies nobody. This is deliberate: those rows carry the counts and the euro figures behind a studio's historical months, so deleting them would retroactively change what a past month reported. The identifying information goes; the arithmetic survives.

Studio accounts. Account and figure data is kept for as long as the subscription is active. A studio owner can delete their account and everything in it at any time, from the Account page, and that deletion is immediate and permanent.

Accounting records that we are required by French law to retain are kept for the period the law requires, regardless of the above.

9Your rights

Anyone whose data we hold has the right to ask for a copy of it, to have it corrected, to have it deleted, to object to our processing it, and to complain to a supervisory authority — in France, the CNIL.

If you are a studio owner, you do not have to ask. On your Account page you can download everything ClassMargin holds for your studio, and you can delete your studio and all of its data outright. Both are self-serve and immediate.

If you are a coach or a class attendee, contact the studio, not us. They decided to upload your data and they remain responsible for it. We will act on any request a studio forwards to us, and we will help the studio answer it. Where erasure is requested for a class attendee, we honour it by anonymising as described in section 8.

10How we protect it

Every studio's data is isolated at the database level, so one studio cannot read another's. Passwords are managed by our authentication provider and are never stored by us in readable form. Payment card details never reach our systems at all — card entry happens on Stripe's own hosted page.

11Changes

If we change this policy in a way that materially affects our customers, we will email them before it takes effect. The date at the top of this page is always the date of the current version.