1. Information collected
When you contact us or create an account, we may receive the information you choose to provide, such as your name, email address, phone number, service interest, preferred training setting and message. If online checkout is enabled and an order request is submitted, we may also process the selected products, belt size where relevant, quantities, product subtotal, chosen delivery or pick-up option, delivery address or area if supplied, and a payment-provider reference after integration.
If you create an account, we store your name, email, phone number, account category, company or team name where relevant, and a password hash. A parent or guardian may create a child profile with a first name and age band. Children do not receive a separate login. Our website checkout does not ask for or store payment-card numbers or security codes; a payment provider handles card credentials. Our forms do not request health records.
If you opt in to analytics, we record limited first-party event names and page paths. We do not send form contents, names or email addresses to analytics. Our request limiter stores a short-lived keyed hash of a network address—not the raw address—and removes inactive limiter entries after 48 hours.
2. How information is used
We use your information to respond to enquiries, discuss services, process orders after checkout is enabled, create and secure accounts, manage a guardian-controlled profile, reduce spam and maintain our website. If you opt in, we use optional analytics to understand broad page, contact and Shop interaction activity.
A contact form is an enquiry, not a confirmed booking. An online checkout submission does not confirm an order or payment until the payment provider confirms the result and the relevant fulfilment details are confirmed.
5. Data retention and security
We should keep information only as long as it is needed to handle an enquiry, maintain an account or meet a properly confirmed business requirement. We have not set a retention schedule yet and need to do so before launch.
We designed the production build to use HTTPS, server-side form validation, rate limiting and password hashing. These measures reduce risk but cannot guarantee absolute security. We still need to configure and test database access, backups, deletion processes and email delivery before launch.
6. Your choices and requests
You can contact us to ask about information you submitted or to request a correction or deletion. Before publication, we need to define an identity-check and response process with our privacy representative. This draft does not promise a specific statutory right or response period.
You can reject optional analytics or change your selection using “Cookie preferences” in the footer. Essential account/session storage remains necessary for secure sign-in.
7. Children and guardian-managed profiles
A child profile can only be created through an adult parent or guardian’s account; children do not sign in independently. In this design, we ask for a first name and age band only—not a child email, password, date of birth or health information. Before we activate this flow, our legal/privacy representative should review and approve it and any related data handling.
8. Policy updates and contact
We may update this draft as our website and providers change. After review, we should publish a clear effective date and explain material changes appropriately.
For privacy questions, contact us at info@bodyjusticefitness.com or bodyjusticefit@gmail.com, or write to us at The Imaara Mall, along Mombasa Road, Nairobi, Kenya.