Privacy Policy

Last updated: 11 August 2026

TrainerLink respects your privacy. In this Privacy Policy, we explain which personal data we process, why we do so, with whom we share data, how long we retain data and what rights you have.

TrainerLink is an online platform that enables adults to find, book, pay for, review and rebook personal trainers.

1. Who are we?

TrainerLink is offered by Olympus Performance, trading under the name TrainerLink. For this Privacy Policy, Olympus Performance is the data controller.

For privacy questions or requests, you can contact us at support@trainerlink.nl.

2. Who is TrainerLink intended for?

TrainerLink is intended for users aged 18 and over.

Minors cannot create an account and cannot book training through TrainerLink. We currently also do not offer parents or guardians the option to book training for minors.

3. Which personal data do we process?

We process personal data needed to provide TrainerLink, enable bookings, process payments, support users and keep the platform secure.

Account data: such as name, email address, login details, account type, account status and data needed to log in securely.

Customer data: such as name, email address, location or postcode area, fitness goal, fitness level, bookings, messages, reviews and notification preferences.

Trainer data: such as name, email address, profile photo, profile text, specialisations, services, prices, availability, training locations, Chamber of Commerce number, business details, certification information, insurance information, onboarding status and payment/payout status.

Some trainer data is publicly visible on the profile, such as name, profile photo, profile text, specialisations, general location, services, reviews and badges. Non-public data, such as the Chamber of Commerce number, internal notes and payment/verification data, is accessible only insofar as necessary.

Booking and payment data: such as selected trainer, selected service, date, time, price, location option, booking status, payment status, refund status, commission, payout status, cancellations, no-shows, disputes and QR check-in status.

Payments, refunds and payouts are processed through a payment service provider. TrainerLink does not retain full payment card details, IBANs or identity documents.

Messages and reviews: we process messages between customers and trainers, any voice messages, reviews, notifications and moderation data.

Messages may be automatically checked for prohibited or unwanted content, such as telephone numbers, email addresses, external payment requests, external booking links, spam or fraud.

Reviews are linked to a completed paid booking. Reviews are not anonymous and may show the customer's first name and the label 'verified booking'.

Location data: we process location data for search, map display, bookings and QR check-in. This may include city, postcode area, optional GPS location, a trainer's service area, training location or customer address if the training takes place at the customer's location.

Public map locations are approximate and intended to avoid making private addresses public.

For QR check-in, we preferably retain only the time, status and a pass/fail check. Exact GPS coordinates are not ordinarily retained unless this is needed for a dispute, safety report, fraud investigation or legal claim.

Support, complaints and incidents: if you contact support, submit a complaint, open a dispute or report an incident, we process the data needed to handle it.

An incident report may contain health information if you report an injury or safety incident yourself. We use that information only for handling the incident, support, safety, insurance, legal claims or legal obligations.

Technical and analytical data: we process technical data such as IP address, browser data, device data, server logs, security logs, cookie preferences and limited analytics.

We may use Sentry for error monitoring. The purpose is to find and resolve technical errors, abuse signals and security problems. We do not enable session replay by default, send no standard PII and, where possible, filter cookies, tokens, contact details, payment data, chat content, addresses and health data out of error reports.

For product analytics, we may, only after analytics consent where required, use limited first-party analytics, PostHog EU and Vercel Speed Insights. We use only pre-approved, broad event properties for this purpose and no payment card data, IBANs, chat messages, health data, private addresses, exact GPS locations, uploads or raw free text.

At launch, we do not use advertising pixels, retargeting pixels, heatmaps, session recordings, PostHog autocapture, PostHog session replay or A/B testing tools.

4. Health data

TrainerLink is not a medical service and does not provide medical advice, diagnosis, treatment or physiotherapy.

We do not ask for a medical intake or an injury or health questionnaire through the platform. Do not share medical information in your profile, chat, review or booking message unless it is strictly necessary for an incident report, dispute or safety issue.

Trainers themselves remain responsible for their professional assessment of whether training is appropriate and safe.

Public entry analytics after consent

We may use public entry analytics to understand which public page families visitors view and to evaluate public SEO efforts. Analytics consent is the legal basis for this processing (GDPR Article 6(1)(a)). These analytics are always off before you give analytics consent.

After analytics consent, TrainerLink may record locally in your browser the first suitable public page observed thereafter. This is not necessarily the first page visited before consent and it is not evidence that your visit came from organic search results.

Local browser storage uses the localStorage key trainerlink.analytics.organicEntry.v1. The record contains only entry_path (a normalised public route template, for example /personal-trainers/[city], /trainers/[id] or /trainer/[id]/[slug]; the placeholders stand for the city, trainer number and slug; the exact city and query string are not stored), entry_family (the public page family), entry_locale (the language/locale) and entry_captured_at (the time of capture). Suitable current public pages are the homepage, the clean trainer discovery page, clean city pages for personal trainers and existing public trainer profiles. Trainer discovery and city pages with query, search or filter parameters are excluded. The first touch remains immutable until the record expires. The context can be used for a maximum of 90 days. After that period expires, an expired record is no longer usable and is deleted at the next local storage access (for example, a subsequent read, capture or similar action). If the browser remains closed, no guaranteed background deletion takes place.

The four safe fields may be added to selected existing analytics events through the current PostHog EU analytics pipeline. In this context, PostHog EU receives these fields as an analytics processor/recipient. No new event family or provider is added. We do not use profiling, session replay, heatmaps or automated decision-making for this purpose.

For this context, we do not send a URL query string, search or filter text, the full referrer URL, name, email address, account or trainer ID, exact address, GPS location, health data, booking, chat or payment content, uploads or free text.

If you withdraw analytics consent through the current Cookie Settings, that consent flow immediately triggers an attempt to delete this browser record and stops future analytics and enrichment. No automatic retroactive deletion of provider events already sent is promised. Your other privacy rights, such as access, erasure and objection, apply separately as described in section 12. The platform remains usable when you refuse or withdraw analytics; only non-essential measurement and enrichment then fall away.

5. Why do we process personal data?

Creating and managing an account: performance of contract.

Login and security: performance of contract; legitimate interest.

Searching for and displaying trainers: performance of contract; legitimate interest.

Processing bookings: performance of contract.

Processing payments, refunds, commissions and payouts: performance of contract; legal obligation; legitimate interest.

Trainer onboarding and verification: performance of contract; legal obligation; legitimate interest.

Enabling messaging and support: performance of contract; legitimate interest.

Moderation, safety, fraud and abuse prevention: legitimate interest.

QR check-in and session confirmation: performance of contract; legitimate interest.

Displaying reviews: performance of contract; legitimate interest.

Sending transactional emails and notifications: performance of contract; legitimate interest.

Sending marketing: consent.

Analytics and product improvement: consent where required; otherwise legitimate interest.

Administration, tax and accounting: legal obligation.

Handling claims, disputes and incidents: legitimate interest; legal claims; legal obligation where applicable.

6. Cookies

TrainerLink uses cookies and similar technologies to make the platform work properly, keep users logged in, enable bookings and payments, store cookie preferences and improve the platform.

Functional cookies do not require consent. For non-essential analytics, tracking or marketing, we ask for consent in advance. The public entry analytics described above are always consent-based.

You can adjust your cookie and analytics preferences through the cookie settings.

7. With whom do we share personal data?

TrainerLink handles personal data carefully and confidentially. Personal data is available only to us and to people working on our behalf, insofar as necessary to provide, secure and improve TrainerLink.

We share personal data with third parties only if this is necessary for our services, if we are legally required to do so or if we have your consent.

Trainers: if you request or complete a booking, we share the data needed for that booking with the relevant trainer. This may include your name, the booked service, date and time, location option, booking message, payment or confirmation status and, if the training takes place at your location, the address needed for that purpose.

Service providers: we use service providers for, among other things, hosting, database storage, account login, file storage, payments and payouts, email, push notifications, map display, analytics, security, logging and support. These parties process personal data only insofar as necessary for their task. Where they act as processors, we make agreements about security, confidentiality and the use of personal data.

For telemetry and consent, these service providers may include Supabase for first-party analytics and consent auditing, Sentry for error monitoring, PostHog EU for product analytics after consent, Vercel Speed Insights after analytics consent, Cookiebot for consent management and Google Tag Manager for consent-controlled tags. Actual use depends on the environment and your consent.

Payment service providers: payments, refunds, verification of payout accounts and payouts to trainers are processed through a payment service provider. This party may also be independently responsible for certain processing, for example fraud prevention, legal checks, financial administration and compliance with payment laws.

Login and authentication services: if you log in with an external login method, such as Google or Apple, we receive the data needed to link your account and let you log in securely. The privacy policy of the relevant provider may also apply to your use of those services.

Professional advisers: we may share personal data with professional advisers, such as accountants, legal advisers, insurers or other advisers, insofar as necessary for administration, advice, disputes, claims or legal obligations.

Authorities and competent bodies: we may share personal data with regulators, tax authorities, judicial authorities, law enforcement authorities or other competent parties if we are legally required to do so or if this is necessary to protect our rights, users, safety, property or the platform.

We do not sell your personal data. Without your consent, we do not provide your personal data to third parties for their own commercial purposes.

8. International transfers

Some service providers may process personal data outside the European Economic Area. If this happens, we use appropriate safeguards, such as an adequacy decision, Standard Contractual Clauses, the EU-US Data Privacy Framework or other measures permitted under the GDPR.

You can contact us at support@trainerlink.nl if you want more information about the safeguards we use for international transfers.

9. How long do we retain data?

We do not retain personal data longer than necessary for the purposes for which we process it, unless longer retention is necessary for tax, accounting, security, fraud prevention, disputes, incidents or legal claims.

We retain account data for as long as your account is active.

We retain customer and trainer profiles for as long as needed to use the platform.

In principle, we retain booking, payment, refund, commission and payout data for 7 years.

We retain messages and voice messages for a maximum of 24 months after the last message, unless longer retention is necessary.

We retain reviews for as long as they are published; reviews may be anonymised when an account is deleted.

We retain support tickets for a maximum of 24 months after closure, unless longer retention is necessary.

Disputes, serious incidents and relevant audit logs may be retained for up to 7 years.

We retain QR check-in records for a maximum of 24 months, or longer if they are needed as evidence for a payment, dispute, fraud investigation or legal claim.

We retain security and server logs for a maximum of 90 days, unless longer retention is necessary for an investigation.

We retain analytics data for a maximum of 13 months.

We retain marketing and cookie consents for as long as needed to demonstrate consent or its withdrawal.

When data is no longer needed, we delete or anonymise it.

10. Security

We take appropriate technical and organisational measures to protect personal data. These include secure login, restricted access to private data, role-based admin rights, separate storage of public and non-public data, secure payment processing and logging of important admin and security actions.

No system is completely secure. Do you think your account has been misused or that there is a security problem? Contact us at support@trainerlink.nl.

11. Automated decision-making

TrainerLink does not make decisions that produce legal effects or similarly significantly affect you entirely automatically.

We do use search and ranking logic to display trainers. Factors such as location, specialisation, availability, reviews, response time, booking activity and platform safety status may be used for this.

We may also use automatic checks to detect prohibited contact details, external payment or booking links, spam, fraud or unsafe content. Human review may take place in the case of reports, disputes, suspensions or restrictions.

12. Your rights

Depending on the situation, you have the right to request access, have data corrected, have data deleted, restrict processing, object to processing based on legitimate interest, withdraw consent, request data portability, object to direct marketing and lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

You can send a request to support@trainerlink.nl. We may ask you to confirm your identity before handling your request.

13. Deleting an account

You can request that your account be deleted. Account deletion does not always mean that all data is deleted immediately. We may retain data if this is necessary for bookings, payments, refunds, tax, administration, fraud prevention, support, disputes, safety or legal claims.

15. Changes

We may amend this Privacy Policy. We will inform users of material changes through the platform, by email or in another appropriate manner.

16. Contact

For privacy questions, requests or complaints:

Olympus Performance / TrainerLink

Slinge 282, 3086 EN Rotterdam, The Netherlands

support@trainerlink.nl

Questions about this document? Email us at support@trainerlink.nl.