Privacy & cookies.
Last updated 26 July 2026This notice explains the personal data used by the current Christian Marshall Fitness website and client portal. It also explains the choices available for optional analytics and marketing tools.
Who handles your data
Christian Marshall Fitness, operated from Malta, is responsible for the personal data described in this notice. Questions or data-rights requests can be sent to chrismarshallbookings@gmail.com or made through the contact form. You may also call +356 79640967.
What the website handles and why
| Activity | Data involved | Purpose and basis |
|---|---|---|
| Contact requests | Name, email address, message and any information you include. | To answer your request and take steps you ask for before a service, or for the legitimate interest of handling enquiries. |
| Consultation booking and rescheduling | Name, email address, mobile number, referral code if supplied, verification status, booking date and time. | To verify the requester, arrange or change a consultation, prevent duplicate bookings and send service emails. This is necessary to take requested steps and administer the booking. |
| Purchases and payment records | Email address, Stripe Checkout identifier, selected plan, amount, currency and payment status. Card details are entered on Stripe and are not stored by this website. | To start and confirm the purchase, prevent duplicate charges, keep transaction records and deliver the purchased service. This supports the contract and applicable accounting or legal duties. |
| Custom-program intake | Name, checkout email, age, height, weight, goal, experience, training location, availability, notes, and optional injury, limitation, allergy or dietary information. | To create and deliver the program you bought. The form asks for explicit consent before optional health-related information is processed and records when that consent was given. |
| Client portal and coaching | Account details, password hash, assigned workout and nutrition plans, workout sets/repetitions/weight, meal completion, progress, points and badges. | To secure the account, provide coaching, record progress and administer the coaching relationship under the service agreement. |
| Referrals | Sender name and email, friend’s email, optional message, consent confirmation and delivery status. | To send and record the requested referral. The sender must confirm that the friend agreed to receive it. The friend’s details come from the sender rather than directly from the friend. |
| Security and diagnostics | Session identifiers, request and error information, and technical data normally recorded by the web host, such as IP address, browser, time and requested page. | To protect accounts and forms, investigate failures, prevent abuse and operate the service. This is based on legitimate security and service-administration interests. |
| Optional measurement | Online identifiers and information about page visits, device/browser and interactions collected by Google Analytics or Meta Pixel. | Analytics or marketing measurement only after the corresponding consent choice. These tools are limited to public marketing pages. |
The website itself does not make decisions with legal or similarly significant effects using solely automated processing. Stripe may carry out its own fraud and payment checks under its privacy notice.
Health-related information
Injury, physical-limitation and allergy information can reveal health data. These fields in the custom-program intake are optional. If you choose to provide them, the form requires a separate, unchecked consent confirmation. You can withdraw that consent by contacting us, although withdrawal does not undo processing that was lawful before it was withdrawn. If you leave those fields blank, contact Christian Marshall Fitness directly about any safety information needed before training.
Who may receive data
- Christian Marshall and authorised site administrators who need it to provide or administer the service.
- The website and database host, which stores and serves the application and its records.
- The configured email-delivery provider (the application is designed for SMTP/Gmail) for verification, booking, payment, referral and service messages.
- Stripe for Checkout, payment confirmation, fraud prevention and payment records.
- Google, only with analytics consent, for Google Analytics. Website fonts are served directly by this website.
- Meta, only with marketing consent, for Meta Pixel measurement.
- OpenStreetMap, only when you press “Load interactive map”, for the studio-location map. Loading it sends ordinary network information such as your IP address, browser details and the requested map to that provider.
The OpenStreetMap URL is not attached to the map frame when the page first opens, so no map request is made unless you choose to load it. WhatsApp, Google Maps and the linked social platforms receive information only when you choose to follow an external link or use their service. Providers may process data outside Malta or the European Economic Area. Where this happens, the provider’s current privacy notice and transfer arrangements apply. Review those notices before using an external service.
How long data is kept
- Verification codes expire after 15 minutes; successful booking authorisation expires after one hour and is consumed by a completed booking action.
- Public email-form abuse counters use salted one-way identifiers for the submitted email and connecting address and are pruned after about two hours.
- Failed client-portal login counters use a one-way account identifier and are pruned after about 24 hours.
- Ordinary PHP session cookies end when the browser session ends, although server-side session cleanup depends on the host configuration.
- The saved browser privacy choice expires after 180 days and is then requested again.
- Google Analytics first-party identifiers are configured here for up to 180 days; Google’s service-side retention is managed separately.
- Emails remain subject to the configured mailbox’s retention and deletion settings.
- Bookings, payments, program intakes, referrals and portal/coaching records are kept while needed to deliver and administer services, maintain required financial or legal records, resolve disputes and establish or defend claims.
The current application does not impose one automatic deletion period across every business record. You may ask which records are held about you and request deletion where the law allows it.
Your choices and rights
Depending on the circumstances, you can ask for access to or a copy of your data, correction, deletion, restriction, portability, or object to processing. Where processing relies on consent, you can withdraw it at any time. Contact us using the details above; identity may need to be verified before account or service records are disclosed or changed.
You can also lodge a complaint with Malta’s Information and Data Protection Commissioner (IDPC). The official IDPC complaint page explains how to do this.
Keeping information safer
The application uses password hashing for portal credentials, server-side sessions, form tokens, email verification and Stripe-hosted card entry. No internet service can promise absolute security. Avoid including unrelated medical or other sensitive details in free-text fields, and contact us if you believe your account or information has been exposed.
Updates to this notice
This page should be reviewed whenever the website’s forms, providers, retention practices or tracking configuration change. Material updates will be reflected by the date at the top.