Privacy Policy
What we collect, why, and how to control it. Plain language. No tracking maze. Last updated: April 27, 2026 · Effective date: April 27, 2026
Who runs this site
This website is operated by Fit Beyond Sight LLC, founded by Mario Bonds, based in Maryland with operations in Georgia. The website is fbs.fit. For privacy questions, contact us at info@fitbeyondsight.com. This policy covers everything that happens on this website and the member-only areas. Coaching engagements may have their own additional confidentiality terms — those are spelled out in your coaching agreement separately.
What we collect
We collect only what we actually use. Nothing extra, nothing speculative.
Account data (when you become a member)
Held in our own database:
- Your name and email address
- A password (hashed — we never see it in readable form), or a connected third-party login (Google or Facebook — see below)
- Your active membership plan and subscription status
- The date you joined and the date of your most recent login
- Which third-party login providers you have connected to your account
Third-party login (Google, Facebook)
If you choose "Continue with Google" or "Continue with Facebook" instead of creating a password, the provider returns to us:
- Your name and email address (or the proxy address you authorized the provider to share)
- A stable account identifier so we can recognize you on future visits
We do not receive your contacts, friends, files, posts, photos, or any other data from the provider account. The connection is one-way — Fit Beyond Sight learns nothing about the rest of your Google or Facebook activity, and the provider learns only that you’re authenticating with us. You can revoke the connection at any time from your provider’s account settings, or from your Fit Beyond Sight account page .
Payment data (when you buy something)
Stripe handles all payments. Your card number, CVV, and billing address go directly from your browser to Stripe — they never touch our servers. From Stripe we receive:
- Confirmation that a payment succeeded or failed
- The last four digits of your card and its brand (so you can identify it on your account page)
- Your email address and billing country
- Records of past invoices for the customer portal
Contact form submissions
When you write to us through the contact form, we receive your name, email address, and the message you sent. Our application delivers it to Mario directly; the message is stored so he can reply. We keep these messages so we have a thread of context if you write again later.
Newsletter sign-ups
If you subscribe to the newsletter, your email address goes to Beehiiv (our newsletter provider). We may also tag your subscriber profile with which membership tier you’re on, so we can send tier-relevant content. You can unsubscribe from any newsletter email at any time.
Vault playback (members only)
When you play tier-gated video or audio from the vault , our streaming function records minimal information server-side for security and abuse-prevention purposes:
- Your member ID (so we can verify your tier matches the content you’re requesting)
- The content ID you requested
- The timestamp of the request
We do not record IP addresses, browser fingerprints, or watch-time analytics. Each playback session uses a short-lived signed token (5 to 15 minutes) tied to one content item; tokens cannot be reused or shared across accounts. The video player also displays your email address as a semi-transparent overlay on top of the video. This is a deterrent against unauthorized sharing — recordings of vault content are traceable back to the account they were streamed to.
Phone numbers & SMS
If you provide a phone number — at signup, on your account page, after purchase, or on a booking form — we store it on your member record in our own database. Phone numbers are used for two distinct purposes:
- Appointment reminders (transactional). When you book a session through our native scheduler and provide a phone number with texting consent, our application (via Twilio) sends confirmation and reminder texts for that booking.
- Marketing texts (only if you’ve opted in). If you ticked the SMS opt-in checkbox, we may text you motivation drops, content alerts, and promotional offers. If we begin sending these ourselves, your number is passed to a US-registered SMS provider (Twilio or equivalent) for delivery.
We also store an audit record of when and how you consented (timestamp, page, version of the consent text), so you can verify what you agreed to. If you opt out, we keep the audit record but stop the messages immediately. Full SMS-specific terms — frequency, cost language, opt-out mechanics — live on the SMS Terms page.
You can update or remove your phone number at any time from your account communications settings .
If you’ve consented to analytics through the cookie banner on your first visit, Google Analytics 4 records anonymized usage data — pages visited, session duration, country (not city), referrer. IP addresses are anonymized. We use this in aggregate to understand what’s working on the site, not to identify individuals.
Full details — including the four cookie categories and how to control each — live on the Cookie Policy .
What we don’t collect
- We don’t collect data from third-party tracking pixels or ad networks (we don’t run ads)
- We don’t sell or rent personal data to anyone, ever
- We don’t fingerprint your browser, track you across other sites, or build profiles for resale
- We don’t collect health information through this website (any health information you share with Mario during coaching is separate and covered by the coaching agreement)
How we use what we collect
- To run the membership — log you in, give you access to the right tier of content, send billing receipts and renewal notices.
- To deliver what you bought — Buddy Sessions, Life Coaching, Fitness Coaching, store orders. Each requires the relevant minimum data to fulfil.
- To respond when you contact us — your message goes to Mario directly.
- To send what you signed up for — newsletter content, tier-specific drops, member announcements.
- To improve the site — anonymized analytics tell us which pages work and which don’t, so we can fix the friction.
- To protect against abuse — security measures, fraud detection on payments, basic logging of admin actions.
Third parties we work with
Each of these has its own privacy policy and handles a specific job. We pick vendors with strong track records on data handling.
- Neon (PostgreSQL hosting) — member accounts, bookings, and transactional records; our application is the only party with access. Privacy policy →
- Google (Sign in with Google) — when you choose "Continue with Google" at signup or login, Google receives the fact that you’re authenticating with Fit Beyond Sight and returns to us your name, email address, and a stable account identifier so we can recognize you on future visits. We do not receive your contacts, Drive files, or any other Google account data. You can revoke this connection at any time from your Google Account → Security → Third-party access. Privacy policy →
- Meta (Facebook Login) — when you choose "Continue with Facebook" at signup or login, Meta returns to us your name, email address (or the proxy address you authorized), and a stable account identifier so we can recognize you on future visits. We do not receive your friends, posts, photos, or other Facebook data. You can revoke this connection at any time from Facebook Settings → Apps and Websites. Privacy policy →
- Stripe — payment processing, billing portal, invoices. PCI-DSS Level 1 compliant. Privacy policy →
- Google Analytics 4 — anonymized site analytics (only with your consent). Privacy policy →
- Beehiiv — newsletter delivery and subscriber management. Privacy policy →
- Resend — transactional email delivery. Vercel — application hosting and edge delivery. Privacy policy →
- Tally — coaching application form (when you apply for Fitness Coaching). Privacy policy →
- Twilio — appointment confirmation and reminder texts, only with your explicit consent. Pusher — realtime in-app updates. Privacy policy →
- Twilio (or equivalent SMS provider) — used to deliver marketing SMS to members who have opted in. As of the last update of this policy, we have not yet begun sending marketing SMS ourselves; this entry exists so that consent at signup covers the future enablement. Privacy policy →
How long we keep things
- Active member accounts — for as long as your membership is active, plus 90 days after cancellation in case you come back (then archived).
- Payment records — kept by Stripe per their policies; we keep the corresponding receipts for 7 years to meet US tax record-keeping obligations.
- Contact form messages — kept as long as the conversation thread is useful; deleted on request.
- Newsletter subscriptions — kept until you unsubscribe; once unsubscribed, your address is suppressed (so we don’t accidentally re-add you) but the suppression record itself stays on file.
- Phone numbers and SMS consent records — kept while your account is active, and the consent + opt-out audit trail is retained to demonstrate compliance even after you opt out.
- Analytics data — Google Analytics 4 retains data per your account settings; we keep it at the default 14-month retention.
Your rights
You have the right to:
- Access — ask what personal data we hold about you. We’ll send it within 30 days.
- Correct — fix anything that’s wrong. Most details (name, email) you can edit yourself in your account.
- Delete — ask us to delete your data. We’ll honor this except where we’re required by law to keep records (mainly payment records for tax purposes).
- Export — request a copy of your data in a portable format.
- Withdraw consent — change your cookie consent any time via the Cookie Preferences link in the footer. Unsubscribe from emails via the link in any newsletter.
- Object — tell us to stop using your data for any non-essential purpose.
To exercise any of these, write to info@fitbeyondsight.com with "Privacy request" in the subject. We’ll respond within 30 days, often sooner.
California residents (CCPA & CPRA)
If you live in California, in addition to the rights above you have the right to:
- Know what categories of personal information we collect, the purposes, and the third parties we share with
- Opt out of any "sale" or "sharing" of personal information — though to be clear, we don’t sell or share your personal information for behavioral advertising or any other purpose
- Limit the use of sensitive personal information — we don’t use sensitive PI for anything beyond providing the service you bought
- Be free from retaliation for exercising any of these rights
To exercise California-specific rights, email us with "California privacy request" in the subject. You can also designate an authorized agent to make a request on your behalf.
EU/UK residents (GDPR)
If you’re in the EU or UK, GDPR applies. Our lawful bases for processing your data are:
- Contract — to deliver the membership or coaching service you bought
- Legitimate interest — to run the business, prevent fraud, and improve the site (balanced against your rights)
- Consent — for analytics cookies and newsletter subscriptions; you can withdraw consent at any time
- Legal obligation — for payment records we’re required to keep
You have the right to lodge a complaint with your local data protection authority if you believe we’ve handled your data improperly.
Children (COPPA)
Fit Beyond Sight is not intended for anyone under 13, and we don’t knowingly collect personal data from children, in line with the U.S. Children’s Online Privacy Protection Act (COPPA). Coaching services for minors require a parent or guardian to set up the account. If you believe a child has signed up directly without parental consent, write to us and we’ll delete the account.
International transfers
Some of our third-party providers (Stripe, Google, Neon, Vercel, Resend, Twilio, Beehiiv) are based in the United States. If you’re outside the US, your data may be transferred to and processed in the US. These providers maintain appropriate safeguards (Standard Contractual Clauses, EU-U.S. Data Privacy Framework participation where applicable) to protect data transferred internationally.
Security
We use industry-standard practices: HTTPS everywhere, hashed passwords, PCI-compliant payment processing, secure third-party providers, and access controls. No system is bulletproof — if a breach happens that affects you, we’ll notify you within 72 hours of becoming aware, in line with applicable law.
Changes to this policy
We update this page when we add new vendors, change practices, or when laws change. The "last updated" date at the top reflects the most recent change. For significant changes (new vendors handling personal data, expanded use of data, or changed retention), we’ll notify members by email at least 30 days before the change takes effect.
Contact
For any privacy question, request, or concern: info@fitbeyondsight.com . We read every message; expect a response within two business days.