← builtbykpis.org
Built By KPIs

Privacy Policy

Last updated: September 12, 2026 · Questions: [email protected]

This Privacy Policy explains how Built By KPIs ("we", "us", "our") collects, uses, shares and protects information when you use the Built By KPIs platform at builtbykpis.org and app.builtbykpis.org (the "Service"). Built By KPIs is a business platform for fitness coaching companies: it tracks leads, sales calls, clients, check-ins and payments for a coaching business and its team. By using the Service you agree to the practices described here.

  1. Information we collect
  2. Google Calendar and Google user data
  3. Other connected services
  4. How we use information
  5. How we share information
  6. Data retention
  7. Security
  8. Cookies
  9. Your rights
  10. GDPR and CCPA
  11. Children
  12. Changes to this policy
  13. Contact

1. Information we collect

Account information

When you sign up we collect your name, email address, organization name, role and authentication identifiers. If your organization subscribes, billing details are processed by our payment provider; we do not store full card numbers.

Records entered by your organization

Coaches and their team members enter business records into the Service: lead and client names, emails, phone numbers, program details, check-ins, agreements, notes, call outcomes and similar coaching data. The organization that enters this data controls it; Built By KPIs processes it on that organization's behalf.

Payment metadata

When an organization connects its payment account, we store the account identifier and receive payment event metadata (payment IDs, amounts, currency, payer email, timestamps, descriptions) so payments can be matched to client records. We do not store passwords, full bank details or full card data.

Data from services you connect

If you connect a third-party service to your workspace (see sections 2 and 3), we receive the data needed to provide that integration, only after you authorize it.

Usage and technical data

We collect log data, IP address, browser type, device identifiers and pages viewed for security, debugging and improving the Service.

2. Google Calendar and Google user data

The Service offers an optional, read-only Google Calendar connection so a team member can see their own schedule inside the platform, and so an organization's founders and admins can see the availability of the closers on their team when coordinating sales calls. You connect your Google account yourself, through Google's own sign-in and consent screen, and you can disconnect at any time.

What we request from Google

We do not request permission to create, change or delete anything in your Google account.

What we access and how we use it

Who can see it

Your own calendar data is visible to you. If you belong to an organization on the Service, the founders and admins of that organization can view the events of the calendars you chose to share, on the team calendar pages. Members of other organizations cannot see your calendar data. We do not use Google user data for advertising, and we do not sell it.

How Google user data is stored

Retention and how to disconnect

Google tokens and your calendar selection are kept until you disconnect or your account is deleted. Disconnecting in the Service (the Disconnect button on your calendar settings) revokes our access with Google and deletes the stored tokens and calendar list immediately. You can also remove Built By KPIs from your Google account at any time at myaccount.google.com/permissions, after which we can no longer read your calendar.

Limited Use disclosure. Built By KPIs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Other connected services

Your organization can also connect other services it already uses, such as GoHighLevel (leads, contacts, pipelines, conversations and calendar bookings), Slack (notifications to your workspace) and a payment account (payments and payouts). Each connection is made by an authorized member of your organization through that service's own authorization flow, and only the data needed for the integration is exchanged. Data received from a connected service is stored in your organization's workspace under the same rules as data your team enters directly. Your use of those services is governed by their own privacy policies.

4. How we use information

Where GDPR or similar laws apply, we rely on contract performance, our legitimate interest in operating and securing the Service, your consent where you have given it (for example when you connect an integration), and legal obligations.

5. How we share information

We do not sell personal information. We share data only with:

6. Data retention

We retain account and workspace data while your account is active. After cancellation or termination we typically keep data for up to 90 days so it can be recovered, then delete or anonymize it, unless a longer period is required for legal, tax or accounting reasons. Integration credentials, including Google tokens, are deleted when you disconnect the integration. You can request earlier deletion (section 9).

7. Security

Data is encrypted in transit (HTTPS/TLS). Stored data, including integration credentials, is protected with access controls, audit logging and least-privilege access for our team, and backups are kept in a separate location. No system is completely secure, and we cannot guarantee absolute security.

8. Cookies

We use an essential session cookie required to keep you signed in and to run core Service functionality. We do not use third-party advertising cookies. If we add optional analytics in the future, we will ask for your consent first where the law requires it.

9. Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent where processing is based on consent. To exercise these rights, email [email protected]. If you are a client of one of the coaching businesses using the Service, please contact that business directly, as it controls your data inside the Service.

10. GDPR and CCPA

EU, UK and Switzerland. You have the rights described in section 9 and the right to lodge a complaint with your local data protection authority. Where we transfer data outside your region we rely on appropriate safeguards such as Standard Contractual Clauses.

California. You have the right to know what personal information we collect, to request deletion, to opt out of the sale of personal information (we do not sell personal information) and to not be discriminated against for exercising these rights. Contact us at the address in section 13.

11. Children

The Service is not directed to children under 18 and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new "Last updated" date. Material changes will be communicated through the Service or by email.

13. Contact

For questions or requests about this Privacy Policy, contact us at [email protected].

Terms of Service · Back to builtbykpis.org