EFFECTIVE AUGUST 2026

Privacy, without the vague language.

SMB Performance collects only the information needed to evaluate a request, deliver an agreed service, support coaching, maintain safety, process business records, and communicate the next step. This notice describes the current SMB-owned website and client workflow.

Information collected

Before a consultation, SMB may collect contact details, location and time zone, goals, service interests, schedule constraints, investment readiness, communication choices, and application answers. After acceptance and verified payment, SMB may request a deeper performance intake, exercise-readiness information, training and nutrition history, injuries or limitations, DEXA information, progress files, and optional personal coaching preferences.

How information is used

  • Prepare for consultations and determine the appropriate service scope.
  • Administer agreements, payments, scheduling, onboarding, coaching, and client support.
  • Build and adjust training, nutrition, recovery, and performance recommendations within SMB's scope.
  • Maintain operational records, consent history, workflow status, and security audit records.
  • Send transactional messages. Marketing messages require separate optional consent.

Sensitive information and files

Detailed health-related answers and uploaded files are stored separately from ordinary prospect notes and are protected in private storage. SMB does not ask for card numbers in questionnaires. DEXA reports, progress photos, medical-clearance documents, and similar files should be submitted only through the secure onboarding workflow—not by public form, ordinary text message, or unencrypted email.

Couples and group participant privacy

For a paid couples or small-group physical service, each adult participant receives a separate private readiness link and submits an individual encrypted record. The purchaser may enter participant names and email addresses after confirming that each person agreed to receive the service invitation. The purchaser portal shows who was invited and whether a response was received; it does not show health answers, safety responses, restrictions, review outcomes, or another participant's private link.

SMB's authorized owner view can open individual answers for service preparation and safety review. Participants should not forward personal intake links or complete another person's form. A participant who did not agree to take part should not use the link and should contact SMB through the verified business channel.

First-party website measurement

SMB uses a limited, first-party measurement system to understand whether visitors can find a service, complete the Path Finder, submit a request, book a consultation, and progress through the client journey. It records allowlisted events, page paths without query strings, an anonymous session identifier stored in a same-site session cookie, referring website host, and campaign tags such as UTM source or medium when present.

This system does not store names, email addresses, phone numbers, IP addresses, device fingerprints, questionnaire answers, health information, secure onboarding tokens, participant-intake paths, or raw free-form metadata in analytics events. The anonymous session value is irreversibly hashed before storage. No third-party advertising pixel or cross-site tracker is used. Browser Global Privacy Control or Do Not Track signals disable this measurement and remove the session cookie.

Verification and abuse prevention

SMB may verify control of an email address before opening self-service scheduling and applies request limits to public forms, private links, and file uploads. The abuse-control system converts limited network, contact, and capability identifiers into keyed one-way hashes before storage; it does not store the raw identifier in the rate-limit table. These security records are kept only as long as needed to enforce the active limit window and investigate misuse.

Service providers

SMB may use replaceable infrastructure providers for website hosting, payment processing, scheduling, video calls, email, SMS, and DEXA-location discovery. Those providers receive only the information needed for their function and operate under their own terms. Payment providers process payment credentials; SMB stores payment status and references, not full card details.

Access, correction, deletion, and retention

Clients may request access to, correction of, or deletion of information by contacting SMB through their secure portal or replying to the transactional contact used for their engagement. SMB may retain records needed for active service delivery, financial and contractual documentation, safety, dispute handling, legal obligations, and security. Requests are evaluated against those requirements; data is not promised to be deleted where retention is required.

Choices and communications

Transactional communications are used to handle a requested application, appointment, purchase, or engagement. Optional marketing consent can be withheld or withdrawn without affecting a purchase. SMS recipients may reply STOP to opt out of text messages. Standard carrier rates may apply. Visitors may enable Global Privacy Control or Do Not Track in a supported browser to opt out of first-party website measurement.

Important scope note

SMB applies privacy and security controls appropriate to the information collected, but does not claim that every service or vendor relationship is covered by HIPAA. Coaching and educational services are not a substitute for medical diagnosis, treatment, or emergency care. If immediate help is needed, call 911 or the appropriate local emergency service.

Questions

Use your secure client portal or the same verified business channel used for your SMB engagement. Privacy or data requests are reviewed before action is taken so identity and scope can be confirmed.

Return to the Performance Fit Application →