Your data. Our duty.

Privacy Policy

Effective 7 June 2026

TrainMate ("we", "us", "our") is an Australian software product built for personal trainers. This policy explains what personal information we collect, why, how we protect it, and the rights you (and your clients) have under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We take these obligations seriously.

1. Who is the data controller?

When you sign up for TrainMate as a personal trainer, you are the data controller for your clients' information. TrainMate acts as your data processor. We store and secure the information you upload on your behalf, but we do not use it for our own purposes.

2. What we collect

From you (the trainer): name, email, Google account identifier, profile picture, business name, ABN, phone number, default hourly rate, timezone (locked to Australia/Sydney), and currency (locked to AUD). Collected at sign-up and when you edit your Settings.

About your clients (uploaded by you): name, phone number, email, fitness goal, free-text notes, session history, and package purchase history. This information is stored exclusively against your trainer account and is never combined with data from other trainers.

Automatically: login timestamps, session cookies, browser type, IP address at login, and standard server logs. These are used only for security and troubleshooting and are rotated regularly.

3. Why we collect it

To provide the TrainMate service: authenticating you securely, showing you your clients and schedule, generating GST-compliant invoices under Australian Taxation Office rules, tracking session packs, and (when you enable it) sending invoice PDFs to your clients by email.

We do not sell your data. We do not build advertising profiles. We do not use your clients' contact details for marketing.

4. GST & tax record retention (ATO requirement)

Under Australian tax law, invoice records must be retained for a minimum of five (5) years from the date they are issued. TrainMate retains all invoice data (including line items, GST amounts, ABN, client name and totals) for this period even after you delete a client, in order to comply. You remain able to view and export them from the Invoices tab at any time.

5. Where your data lives

All data is hosted in secure cloud infrastructure managed by Emergent, our platform provider. Databases are encrypted at rest, all traffic is TLS-encrypted in transit, and automatic backups run on a rolling schedule (hourly for 7 days, daily for 7 days, weekly for 4 weeks, monthly for 12 months, yearly for 1 year) with a continuous 7-day point-in-time recovery window.

6. Sub-processors

We use a small number of well-known service providers to run TrainMate. They handle data only as strictly needed to deliver their piece of the service:

  • Emergent: hosting, database (MongoDB), authentication session exchange
  • Google: sign-in only (we receive your email, name, profile picture; we never see your Google password)
  • Resend: transactional email delivery for invoices (only when you send an invoice)

Additional sub-processors (e.g. Stripe for payments) will be added to this list before any new integration goes live.

7. Cookies

TrainMate uses a single essential session cookie (session_token) to keep you logged in. It is httpOnly, secure, samesite=none, and expires after 7 days. We do not use tracking, advertising, or analytics cookies.

8. Your rights (APPs 12 & 13)

You may at any time:

  • Access all information we hold about you. Most of it is visible directly in the app under Settings, Clients, Sessions, and Invoices.
  • Correct any information. Go to Settings and edit any field.
  • Export your data. Email us and we'll provide a JSON export within 30 days at no cost.
  • Request deletion. See the Data Deletion page for the exact process and timelines.
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

9. Security (APP 11)

Data is encrypted at rest and in transit. Passwords are never used or stored. Sign-in is Google-only. Sessions rotate every 7 days. Administrative access to the production database is restricted to a single trainer account (the founder) via a hardcoded allowlist. Automatic backups run continuously.

10. International transfers

Some sub-processors (Google, Resend) may process metadata outside Australia. Where this occurs it is limited to what is necessary to deliver the service, is contractually protected, and does not include your clients' full contact records.

11. Children

TrainMate is not intended for anyone under 18. If you (a trainer) upload information about a minor client, you warrant that you have obtained the appropriate consent from the parent or legal guardian.

12. Changes to this policy

We will update the Effective date at the top of this page whenever the policy changes. Material changes will be notified to you by in-app banner at least 14 days before taking effect.

13. Contact

Privacy questions, access requests, or complaints: privacy@trainmate.au. We aim to acknowledge within 2 business days and respond substantively within 30 days.