Colossus
HomeFeaturesAboutBlogContact
MarketplaceBook a DemoCoach LoginStart Risk-Free
HomeFeaturesAboutBlogContactMarketplaceBook a DemoCoach LoginStart Risk-Free
Legal

Privacy Policy

Last updated: July 14, 2026

1. Overview

Colossus Coaching Systems (Pty) Ltd (registration number 2026/335857/07), a private company incorporated in the Republic of South Africa with its registered office in Stellenbosch, Western Cape 7600, South Africa ("Colossus", "we", "us", "our"), operates the colossus.fit website, web application, mobile applications, and administrative dashboard (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, in accordance with the Protection of Personal Information Act, 2013 (POPIA), the Electronic Communications and Transactions Act, 2002 (ECTA), and other applicable South African laws.

Our designated Information Officer for POPIA purposes is Matthew Castle, who can be contacted at hello@colossus.fit.

2. Who Uses the Service

The Service is used by three categories of people, and the data we collect differs for each:

  • Coaches who run a coaching business through Colossus (solo or as part of a Studio team account).
  • Clients (athletes) who train under a coach using our web or mobile app.
  • Prospects (leads) who interact with a coach before signing up, for example by submitting a public lead form, booking a discovery call, or browsing a coach's storefront. Prospect data is collected on behalf of, and visible to, the relevant coach.

3. Information We Collect

Account Information. When you create an account, we collect your name, email address, username, and password (stored as a salted hash, we never store passwords in plaintext). Coaches may optionally provide a bio, phone number, profile photo, brand colour, and brand logo.

Sign-In Providers. You may sign in or register using Google or Apple. When you do, we receive only the basic profile information you authorise the provider to share, typically your name and email address. We do not receive your Google or Apple password.

Health, Fitness & Biometric Data. As part of the Service you may provide:

  • Date of birth, sex, height, and activity level (used for BMR, TDEE, and body-composition calculations)
  • Body weight and body composition measurements
  • Strength logs (exercises, sets, reps, weights)
  • Cardio logs (duration, distance, average and maximum heart rate, calories, elevation gain, pace, perceived effort)
  • Nutrition logs (foods, calories, macronutrients, scanned product barcodes)
  • Water intake and habit tracking
  • Sleep sessions and sleep-quality scores, and resting heart rate
  • Menstrual-cycle data, if you choose to enable cycle tracking: period start, end, and spotting dates, positive ovulation-test dates, your typical cycle and period length, and your selected contraception method. Cycle tracking is off by default, opt-in, and separately consented.
  • Check-in notes, progress photos, and other media you upload

Health Data Sync (Apple Health & Health Connect). If you choose to connect Apple Health (iOS) or Health Connect (Android) to the mobile app, we import the data you authorise the operating system to share, which may include cardio activities, step counts, sleep, and (if you enable cycle tracking) menstrual-cycle events. Permission is granted and revoked through the operating system; we never receive health data without that explicit grant. We do not store an OAuth token for these sources, only a record of which sources you have enabled and the timestamp of the last successful sync.

Communications. Direct messages, group messages, and reactions exchanged through the platform, including text, images, and voice notes (audio recordings) attached to those messages, as well as posts, comments, and reactions you contribute to a coach-led community.

Live Calls. The Service supports live one-to-one and group video and voice calls, between a coach and their clients and, for discovery calls, between a coach and a prospect. Call audio and video are streamed in real time through our self-hosted media servers to connect the participants; we do not record or store the contents of your calls. We retain only call metadata (such as participants, start and end times, and call status) to operate the feature and show call history.

Coach Business Data. If you operate as a coach, we additionally store: bank-account details required to receive payouts (bank name, account holder name, and the last four digits of the account number, the full account number is held by Paystack, not by us); subscription and billing history; client lists and assignments; and, on Studio team accounts, team-membership records and a team activity audit log.

Lead & Prospect Data. When you submit a coach's public lead form, request a discovery call, or otherwise interact with a coach's sales pages, we collect the data you provide (typically name, email, phone, and any custom form-field responses), together with: the form or page you submitted from, any UTM parameters, the referring URL, the country derived from your IP address, your selected timezone, and any message text you enter. This data is collected on the relevant coach's behalf and is visible to that coach.

Payment Data. Card and bank-account details used for purchases and subscriptions are collected and stored by our payment processor, Paystack. We receive only a payment reference, the last four digits of the card or account, and the outcome of each transaction. Coaches' bank-account details for payouts are held by Paystack as a Paystack subaccount; we retain only the descriptive fields listed above.

Email Engagement Data. Outbound emails that coaches send to leads or clients through our sales tool may include an open-tracking pixel and rewritten click-tracking links. When the recipient opens such an email or clicks a link, we record the timestamp, open and click counts, the target URL, and the recipient's user agent. Email tracking can be disabled by the sending coach in their settings, and recipients can unsubscribe from marketing emails at any time using the link in those messages.

Newsletter. If you subscribe to our newsletter, we store your email address and the source of the subscription.

Contact Form. If you contact us through the website contact form, we collect your name, email address, subject, and message content.

Usage & Device Data. We collect information about how you interact with the Service, including pages visited, features used, browser and device characteristics, and IP address. We use this data for security, rate limiting, debugging, and product improvement.

Analytics. With your consent, we use Google Analytics for Firebase to record anonymous, aggregate usage events (such as page views and feature interactions) on our marketing website and web dashboard, so we can understand what is working and improve the Service. These events are not linked to your account identity, and we do not send a user identifier to the analytics provider. Analytics stays off until you accept our cookie banner, and you may decline it; see Section 8. We do not use advertising trackers or other third-party marketing analytics such as Mixpanel, PostHog, or Facebook Pixel.

4. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Enable communication between coaches and clients
  • Process program purchases, coach subscriptions, and Studio seat-overage charges
  • Settle coach payouts via Paystack subaccounts and produce related reporting
  • Generate analytics and progress tracking for individual users and for coaches in respect of their own clients
  • Send transactional and operational notifications about your account (in-app, on-device, and by email)
  • Power coach-defined sales workflows: lead capture, lead scoring, automation actions, discovery-call scheduling and reminders, and outbound webhook deliveries
  • Respond to your inquiries and support requests
  • Send marketing communications (with your consent)
  • Monitor, detect, and prevent fraud or abuse
  • Comply with legal, regulatory, and tax obligations

Lawful Basis for Processing. Under POPIA, we process your personal information on the following grounds: performance of a contract (providing the Service you signed up for); your consent (marketing communications, health data, and optional integrations such as Apple Health or Health Connect); legitimate interest (security monitoring, fraud prevention, and product improvement); and compliance with legal obligations.

Special Personal Information. Health, fitness, and biometric data (body weight, measurements, date of birth, workout logs, cardio logs including heart rate, sleep data, nutrition data, progress photos, and, where you enable it, menstrual-cycle data) is classified as special personal information under POPIA. We only process this data with your explicit consent, which you provide when creating your account and submitting such data through the Service. Cycle tracking is a distinct opt-in with its own consent, is off unless you turn it on, and is shared with your coach only if you separately enable coach sharing. By providing health and fitness data through the Service, you explicitly consent to the processing of such special personal information for the purposes described in this Privacy Policy. You may withdraw this consent at any time by deleting the relevant data, by turning off cycle tracking or coach sharing, by disconnecting the Apple Health or Health Connect integration in your device settings, or by deleting your account.

5. Data Sharing

We do not sell your personal information. We share data only in the following circumstances:

  • Coach–Client Relationship. When you are in a coaching relationship, your coach can see the data you log in their app: workouts, cardio, nutrition, sleep, check-ins, progress photos, habits, the messages and calls you have with them, and, only if you turn on cycle sharing, your menstrual-cycle data. Your coach's access to cycle data is recorded in an access audit log.
  • Studio Team Accounts. If your coach is part of a multi-coach Studio team account, the team owner and team admins may also access your assigned-client data and team-level activity logs in order to administer the team business. Other team coaches who are not assigned to you do not have access to your data.
  • Coach-Defined Webhooks. Coaches can configure outbound webhooks that deliver lead and discovery call events (for example "lead created" or "call booked") to external URLs they control, in order to integrate Colossus with their own CRM or automation tooling. The relevant payload data, including lead contact information, is transmitted to the coach's chosen endpoint over HTTPS, signed with HMAC-SHA256. Once data leaves our infrastructure to a coach-controlled endpoint it is governed by that coach's own privacy practices.
  • Legal Requirements. We may disclose information if required by law, regulation, court order, or legal process, or to protect the rights, property, or safety of Colossus, our users, or the public.
  • Business Transfers. If Colossus is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to the protections of this Policy.

Service Providers. We use the following third-party service providers to operate the Service:

  • DigitalOcean, cloud hosting (Droplets), object storage (Spaces) for files, media, voice notes, and progress photos, and the self-hosted media servers that relay live video and voice calls in real time. Our primary storage region is London (UK).
  • Resend (via django-anymail), transactional and marketing email delivery, including bounce and delivery notifications.
  • Google Firebase Cloud Messaging (FCM), delivery of push notifications to your iOS and Android devices (on iOS, via Apple Push Notification service). We send your device push token and the notification content to be delivered.
  • Google Analytics for Firebase, anonymous, aggregate product analytics on our marketing website and web dashboard, loaded only after you accept the cookie banner. We do not send a user identifier; analytics is not tied to your account.
  • Paystack, payment processing for program purchases and coach subscriptions, and payouts to coaches via Paystack subaccounts. Paystack stores card and full bank-account data; we do not.
  • Sentry, error and crash monitoring on both the backend and the mobile applications. Error reports may incidentally include limited personal information present at the point of failure (such as a user identifier or request path).
  • Apple and Google, optional Sign in with Apple and Google sign-in identity providers (we receive your name and email only); and the Apple Health and Health Connect frameworks for optional on-device cardio data import.
  • Open Food Facts and the public USDA FoodData Central database, looked up at our backend when you scan a barcode or search for a food. Your identity is not sent; only the barcode or query string.

These providers process personal information on our behalf under written agreements (or, in the case of Apple/Google identity APIs and public food databases, under their published terms) that comply with applicable data protection laws.

6. Data Storage & Security

Your data is stored on secure servers and object storage hosted by DigitalOcean, with our primary region in London, United Kingdom. Your data is therefore typically transferred outside of South Africa. In accordance with POPIA Section 72, any cross-border transfer of personal information is subject to appropriate safeguards, including contractual agreements with service providers that ensure an adequate level of protection. The United Kingdom has data-protection laws substantially similar to POPIA. If you are in the European Economic Area or the United Kingdom, Section 11 (EU & UK Data Protection) explains how we handle international transfers under the GDPR and UK GDPR. We implement industry-standard security measures, including:

  • Salted, hashed passwords (never stored in plaintext)
  • TLS-encrypted connections for all web (HTTPS) and real-time (WSS) traffic
  • Rate limiting on API endpoints
  • Input validation and sanitisation
  • HMAC-SHA256 signing of outbound webhook deliveries so that receiving systems can verify authenticity
  • Regular security review of dependencies and code

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

Data Breach Notification. In the event of a data breach that affects your personal information, we will notify you and the Information Regulator where required by applicable law.

7. Your Rights

Under POPIA and applicable data protection laws, you have the right to:

  • Access: request a copy of your personal data
  • Correction: update or correct inaccurate data through your in-app profile and settings
  • Deletion: delete your account and associated data using the in-app "Delete account" tool, or by request
  • Export / Portability: export your data in a machine-readable format using the in-app "Export my data" tool, or by request
  • Object: object to the processing of your personal information on reasonable grounds
  • Withdraw consent: withdraw any consent you previously gave (for example by disconnecting Apple Health or Health Connect, or by toggling email tracking)
  • Opt out of marketing: unsubscribe from marketing emails at any time using the link included in those messages

Where data has been collected on a coach's behalf (for example lead-form submissions), the coach is the party who controls that record day to day; we will assist with deletion or correction requests on receipt of a verified request.

To exercise any of these rights, contact our Information Officer at hello@colossus.fit. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.

8. Cookies & Tracking

Essential cookies and storage. Our websites and web dashboard use cookies and browser local storage required for authentication, session management, and CSRF protection. These are always active because the Service cannot function without them.

Analytics cookies (consent-based). With your consent, we also set analytics cookies and storage for Google Analytics for Firebase, which records anonymous, aggregate usage events as described in Section 3. We request this consent through a cookie banner; analytics stays off until you accept, and you may decline or simply dismiss the banner without enabling it. We do not use third-party advertising cookies or marketing trackers such as Mixpanel, PostHog, or Facebook Pixel.

Email tracking. Outbound coach emails sent through our sales tool may contain a tracking pixel and click-tracked links, as described in Section 3. Coaches can disable tracking on their own outbound emails, and recipients can unsubscribe from marketing email at any time.

9. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law (for example, tax and accounting records relating to coach payouts and program purchases). We retain your account data while your account remains active. After account deletion, encrypted backup copies may persist for up to 30 days. We may retain aggregated or de-identified data indefinitely for analytics and product improvement.

Lead and prospect records are retained on the relevant coach's account until the coach deletes them or the lead unsubscribes and requests deletion.

10. Children's Privacy

The Service is not intended for children under 16, and we do not knowingly collect personal information from anyone under 16. Because a person under 18 is treated as a child under South African law (POPIA), where a user is under 18 we rely on the consent of their parent or legal guardian, given when the account is created, as the basis for processing their personal information, including any health and fitness data they choose to provide. A parent or legal guardian may contact our Information Officer at hello@colossus.fit to access, correct, or delete their child's information or to withdraw consent, after which the account will be closed. If we become aware that we have collected personal information from a child under 16, or from a child under 18 without the required consent, we will delete it promptly.

11. EU & UK Data Protection (GDPR / UK GDPR)

If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, or we otherwise offer the Service to you there, the EU General Data Protection Regulation (GDPR) and/or the UK GDPR also apply to our processing of your personal data. This section explains how, and adds to the rights set out in Section 7.

Who is responsible (controller and processor). Colossus is the controller for the data we process to operate the platform: your account, authentication, billing, security, and product analytics. When a coach uses Colossus to manage their own clients, the coach is the controller of that client data and Colossus acts as a processor on the coach's behalf under a data processing agreement. If you are a client, you can also raise data questions with your coach.

Legal bases for processing. We rely on:

  • Performance of a contract (Art. 6(1)(b)) to create and run your account and deliver the Service;
  • Explicit consent (Art. 9(2)(a)) for all health and fitness data, including body metrics, training, cardio and heart-rate, sleep, nutrition, check-ins, progress photos, and opt-in menstrual-cycle data, which you give at sign-up and per feature and can withdraw at any time in-app;
  • Consent (Art. 6(1)(a)) for analytics cookies and marketing email;
  • Legitimate interests (Art. 6(1)(f)) for security, fraud prevention, and keeping the Service reliable; and
  • Legal obligation (Art. 6(1)(c)) where we must retain records, for example tax records.

Your GDPR / UK GDPR rights. Section 7 already sets out your rights of access, correction, deletion, portability, objection, and consent withdrawal, all of which apply to you. Under the GDPR and UK GDPR you additionally have the right to restriction of processing and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such solely automated decisions about you; features such as adaptive nutrition targets and coach automations are assistive and remain under your or your coach's control.

International transfers. We store personal data primarily in the London (United Kingdom) region. Transfers between the UK and the EEA are covered by adequacy decisions in both directions. Some of our service providers are in the United States, and our own administration operates from South Africa; where a destination is not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer risk assessment. You can request a copy of the relevant safeguards from our Information Officer.

Our representatives. Because we are established outside the EEA, the UK, and Switzerland, we have appointed Data Protection Representative Limited (trading as “DataRep”) as our data protection representative under Article 27 of the GDPR (EU/EEA), Article 27 of the UK GDPR, and Article 14 of the Swiss FADP. You may contact DataRep on any matter relating to our processing of your personal data:

  • By email: datarequest@datarep.com, quoting “Colossus Fit” in the subject line;
  • Online: www.datarep.com/data-request; or
  • By post: in the EU: DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Ireland; in the UK: DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom; in Switzerland: DataRep, Leutschenbachstrasse 95, Zurich, 8050, Switzerland; or any other DataRep location listed at www.datarep.com. Please address your letter to “DataRep” (not to Colossus) and refer clearly to Colossus Fit in your correspondence, or it may not reach us.

DataRep handles data protection matters only. For general questions about the Service (your account, billing, coaching), contact us directly at hello@colossus.fit (Section 13).

EU Digital Services Act. We have also appointed Data Protection Representative Limited (trading as “DataRep”) as our legal representative in the EU for the purposes of Article 13 of the Digital Services Act (Regulation (EU) 2022/2065), including for reporting illegal content. Contact: digitalrequest@datarep.com, +353 (1) 919 8899, or DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Ireland.

Complaints. If you are in the EEA or the UK and believe we have not handled your personal data lawfully, you may lodge a complaint with your local data protection supervisory authority. In the UK this is the Information Commissioner's Office at ico.org.uk. This is in addition to your right to complain to the Information Regulator of South Africa (Section 7).

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For privacy-related questions or requests, contact our Information Officer at hello@colossus.fit. If you are in the EEA or the UK, you may also contact our Article 27 representatives named in Section 11.

Colossus

The coaching platform built for the whole client relationship. Programs, nutrition, check-ins, messaging, billing, video coaching, automations, communities, and a sales suite in one product.

Product

Compare

  • Trainerize Alternative
  • Kahunas Alternative
  • Everfit Alternative
  • TrueCoach Alternative
  • For Bodybuilding Coaches

Company

  • About
  • Blog
  • Guides
  • Contact

Support

  • Privacy Policy
  • Terms of Service
  • PAIA Manual
  • Delete Account

Get Started

  • Start Risk-Free
  • Book a Demo
  • Migrate to Colossus
  • Founding Coach Program
  • Marketplace
  • Coach Login
  • Download the App

Stay in the loop

Get the latest updates on features and coaching tips.

© 2026 Colossus Coaching Systems (Pty) Ltd. All rights reserved.

POPIA-compliant · Made in South Africa

PrivacyTermsPAIA