Privacy Policy
Last updated: 11 August 2026
This Privacy Policy explains how Locked In Co. and Adam James Louison ("Locked In", "we", "us") collect, use, and protect personal data in connection with our fitness tracking, coaching, retreats, events, and related online services (together, the "Service"), including the website at thelockedinco.com. We are committed to processing personal data lawfully, fairly, and transparently in accordance with the UK GDPR and the Data Protection Act 2018.
For questions about this policy or to exercise your rights, contact us at adam@thelockedinco.com.
1. Who we are
Locked In Co., operated by Adam James Louison, provides digital fitness tracking, weekly check-ins, 1:1 coaching, specialty programming, referrals, and in-person experiences such as retreats and events. We are the data controller for account, billing, platform, and service-delivery data. The Service's digital product was built by Beyond Business (the company behind Bruce Leads); Beyond Business / Bruce Leads are not the data controller for Locked In client data under this policy unless acting strictly as a sub-processor under our instructions for technical support of the build.
Where a coach uses the Service to deliver coaching to a client, coaches may access client data necessary to deliver that coaching under our instructions and policies.
2. The personal data we process
- Account data — name, email address, login credentials, profile details, and communication preferences.
- Health and fitness data — daily logs, training and nutrition information, weight and circumference metrics, check-in notes, goals, and related coaching context. This may include special-category health data under UK GDPR.
- Progress media — progress photos and check-in videos or voice notes you upload.
- Wearable data — if you connect a device (for example Whoop, Oura, or Garmin), we receive activity, recovery, sleep, or similar metrics you authorise us to sync.
- Billing data — subscription tier, purchase history, and payment status. Card payments are processed by Stripe; we do not store full card numbers.
- Enquiry and lead data — information you submit via enquiry forms, waitlists, or marketing communications.
- Usage data — logs, device/browser information, and interactions with the Service, used to operate and secure the platform.
3. Where the data comes from
We collect personal data from the following sources:
- Directly from you, when you create an account, log activity, message a coach, upload media, or book an experience.
- From wearable providers you choose to connect, under their terms and your authorisation.
- From payment processors (Stripe) in connection with checkout and subscription management.
- From authentication providers (for example Google) if you choose to sign in with them.
4. Why we process it, and our lawful basis
- To provide the Service (accounts, tracking, plans, check-ins, coaching messaging, bookings) — lawful basis: performance of a contract.
- To process health and fitness data for coaching and tracking — lawful basis: explicit consent and/or necessary for the health-related service you request. You may withdraw consent where processing is consent-based, which may limit features that depend on that data.
- To take payment and manage subscriptions — lawful basis: performance of a contract and legal obligation.
- To secure, maintain, and improve the platform (including limited AI-assisted drafting tools used by coaches) — lawful basis: legitimate interests.
- To send service and product updates related to your account — lawful basis: legitimate interests and, where required, consent.
- To comply with legal obligations — lawful basis: legal obligation.
5. Who can see your data
Your coach and authorised Locked In staff may access the client data needed to deliver coaching, support, billing, and operations. We do not sell personal data. We share data with trusted service providers ("sub-processors") who process it on our behalf under contract, including:
- cloud hosting and databases (including Supabase);
- payment processing (Stripe);
- email delivery and authentication providers;
- wearable platforms you connect;
- AI/large-language-model providers used to assist coaching workflows;
- where needed for technical support of the digital product, Beyond Business (the company behind Bruce Leads), acting only as a processor under our instructions.
We may disclose data where required by law or to protect our legal rights, users, or the public.
6. International transfers
Some sub-processors may process data outside the UK/EEA. Where that happens, we rely on appropriate safeguards such as UK adequacy regulations or Standard Contractual Clauses (with the UK Addendum) to protect the data.
7. Retention
We keep personal data only for as long as necessary to provide the Service, meet legal and accounting requirements, resolve disputes, and enforce our agreements, after which it is deleted or anonymised. You may request deletion of your account; some records may be retained where we are legally required to keep them.
8. Security
We apply appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and restricted coach/admin access. No system is perfectly secure, but we work to protect data against unauthorised access, loss, or misuse. Progress photos and health logs are sensitive — treat shared devices carefully and use a strong unique password.
9. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw consent at any time. To exercise any of these rights, email adam@thelockedinco.com and we will respond within the time limits required by law.
10. Cookies
The Service uses essential cookies and local storage required for authentication, session security, and core functionality (including theme and preference storage). We do not use third-party advertising cookies.
11. Children
The Service is intended for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a minor has provided data, contact us and we will take appropriate steps to delete it.
12. Complaints
If you have concerns about how we handle your personal data, please contact us first. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent version. Material changes will be communicated through the Service where appropriate.
14. Contact
Locked In Co. / Adam James Louison — adam@thelockedinco.com
See also our Terms & Conditions.
