Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains how T&L Companies LLC d/b/a True Standard Fitness ("True Standard Fitness," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our websites, mobile and web applications, coaching tools, SMS and email programs, and related services (collectively, the "Services").
Please read this Policy before using the Services. Certain features ask for a separate permission before processing particular information or sending optional marketing. Accepting our Terms of Service does not itself authorize marketing.
1. Who we are
The controller and operator of the Services is T&L Companies LLC d/b/a True Standard Fitness, 6222 NW Gisela St, Port St Lucie, FL 34986. Questions and privacy requests may be sent to [email protected].
2. Scope and age requirement
This Policy applies to the Services and our communications with you. It does not control an independent third party's website or service. The Services are intended only for adults age 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor provided information to us, please contact us so we can investigate and delete it as appropriate.
3. Information we collect
3.1 Information you provide
- Identity and contact information: first and last name, email address, phone number, mailing address if needed, and account credentials.
- Fitness and health-related information: goals, limitations, workout history, exercise performance, nutrition and food information, body measurements, progress information, medications or health context you choose to disclose, and answers to intake forms, quizzes, and check-ins.
- Content and communications: coaching chats, AI conversations, support messages, notes, progress photos, uploaded files, and other content you submit.
- Transactions: plan, purchase, subscription, billing status, and transaction identifiers. Payment card information is handled by Stripe, and we do not store full payment card numbers.
- Permissions and consent receipts: the permission selected, date and time, form or feature, disclosure or policy version, source page, and technical evidence such as IP address and browser or device information used to document the request.
3.2 Information collected automatically
- Device and usage information: IP address, user agent, browser type, device type, operating system, pages viewed, feature interactions, timestamps, approximate location inferred from IP address, and security or diagnostic events.
- Cookies and local storage: identifiers used to maintain sessions, remember preferences, prevent abuse, and understand use of the Services.
- Attribution information: referring URL, landing page, campaign and source parameters, ad and click identifiers such as fbclid or gclid, and related first-touch and conversion details. A click identifier identifies an advertising interaction and is not treated as a verified social-media identity.
3.3 Information from other sources
We may receive transaction status from Stripe, delivery and opt-out status from communications providers, campaign attribution from advertising or analytics services, and information from an integration you choose to connect. Verified Facebook or Instagram profile identifiers, when a feature supports them, come from the applicable platform or an authenticated integration rather than from an unverified public form field.
4. How we use information
- Provide accounts, coaching, fitness and nutrition tools, check-ins, requested resources, customer support, and other Service features.
- Personalize workouts, nutrition guidance, reminders, progress views, and coaching responses.
- Process purchases, manage subscriptions, authenticate users, and send receipts and security notices.
- Send service messages and, when separately authorized, marketing by the channel you selected.
- Record and honor permissions, channel preferences, unsubscribe requests, and account deletion requests.
- Measure campaign performance using attribution data, improve the Services, troubleshoot errors, prevent fraud and abuse, and protect users.
- Comply with law, enforce our agreements, and establish, exercise, or defend legal claims.
5. Artificial intelligence processing
Some features use an AI processor to create coaching responses, workout or nutrition suggestions, summaries, or other content. Depending on the feature that is enabled, the processor may be Anthropic, OpenAI, or Google Gemini. The applicable provider processes the prompt and relevant context on our behalf to return an output.
An AI system is not a human coach or healthcare professional. It can misunderstand context and produce inaccurate or incomplete information. AI output is not a diagnosis, treatment, medical advice, or emergency service. Do not use an AI feature for an emergency. Consult a qualified healthcare professional before acting on information that could affect your health.
Personal or health-related information is sent to an AI processor only after feature-specific permission where applicable law or the nature of the feature requires it. You may choose not to use an AI feature. We do not represent that True Standard Fitness is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), and this Policy does not claim HIPAA coverage or compliance.
6. Communications, separate permissions, and consent records
6.1 Transactional messages
We may send messages needed to provide a service you request, such as authentication links, security alerts, receipts, booking confirmations, appointment reminders, support replies, and essential account notices. Transactional messages are separate from optional marketing permissions.
6.2 Optional SMS marketing
If you separately opt in, T&L Companies LLC d/b/a True Standard Fitness may send recurring automated marketing and promotional text messages to the phone number you provided. Consent is not a condition of purchase. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. See our SMS Terms for the complete program terms and additional opt-out methods.
We do not share mobile information, text messaging originator opt-in data, or consent with third parties or affiliates for their marketing or promotional purposes. We may disclose it to providers and aggregators that help us deliver and administer the messaging program, but not for their own marketing.
6.3 Email delivery and follow-up
When a public form clearly states that submission includes email follow-up, submitting the form records that email choice. We may email the requested result and relevant educational, product, or promotional information described next to the form. Each marketing email provides an unsubscribe method. Unsubscribing from email marketing does not opt you out of SMS, and opting out of SMS does not unsubscribe you from email. Essential transactional email may continue when needed to operate your account or complete a transaction.
6.4 Consent receipts
We maintain records of electronic acceptances and channel permissions. A consent receipt may include the selected permission, disclosure text or version, page and form, timestamp, attribution, IP address, and user agent. We use these records to honor your choices, demonstrate what was requested, and prevent messages after an opt-out.
6.5 Messaging preference center
You can review and change your messaging choices at any time. Signed-in members manage channel and notification preferences in the member app under Account > Notifications, and can review deletion and export tools under Account > Legal. You can also reply STOP to any marketing text to opt out of SMS, use the unsubscribe link in any marketing email to opt out of email, or email [email protected] and we will update your preferences. An opt-out from one channel does not opt you out of a different channel, and essential transactional messages may continue while your account is active.
7. How we disclose information
We disclose personal information only for the purposes described in this Policy:
- Service providers and processors: Cloudflare for infrastructure, Stripe for payments, Twilio for SMS, Resend for email, and Anthropic, OpenAI, or Google Gemini for an enabled AI feature. A provider receives only the information reasonably needed to perform its function.
- Authorized personnel: personnel and contractors who need access to provide support, coaching, security, or operations and who are subject to confidentiality obligations.
- Advertising and measurement platforms: Meta Platforms, Inc. (Facebook and Instagram) receives limited non-health attribution and conversion event information through its advertising pixel and Conversions API so we can measure whether an ad resulted in a visit or conversion. This is limited to non-health signals such as page views, lead submissions, and purchases, is subject to your browser and platform controls, and is described further in the next section. We do not send coaching chats, progress photos, or workout or nutrition details to Meta or any advertising platform.
- Legal and safety: information reasonably necessary to comply with law, legal process, or valid government requests, or to protect rights, safety, users, and the integrity of the Services.
- Business transaction: information involved in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and applicable law.
8. Sale, advertising, and sensitive-data restrictions
We do not sell personal information. We do not use or disclose consumer health data for targeted advertising. We do not disclose coaching chats, progress photos, workout or nutrition details, or other consumer health data to advertising networks. We may use non-health attribution information to measure campaign performance. Mobile information and text opt-in data are excluded from all third-party marketing and promotional disclosures.
Meta advertising measurement. We use the Meta pixel and Meta Conversions API to measure advertising performance. When enabled, we may share a limited set of non-health events (for example, a page view, a lead form submission, or a purchase) with Meta Platforms, Inc., along with technical identifiers such as a hashed email or phone number, IP address, and browser or device information used to match the event to an advertising interaction. We send these events only when advertising measurement is active and you have not opted out, we never include health-related content, and Meta processes them subject to its own terms. You can limit or stop this measurement using your browser cookie settings, the ad and privacy controls in your Facebook or Instagram account, and the opt-out choices described in Your choices and rights below. To opt out of this advertising measurement, email [email protected] and we will suppress your information from Meta advertising events.
9. Do Not Track and Global Privacy Control
Some browsers can send a "Do Not Track" (DNT) signal. There is no common industry standard for how to interpret a DNT signal, so, like most operators, we do not currently respond to DNT signals in a way that differs from the choices and controls described in this Policy. This disclosure is provided under California Business and Professions Code section 22575 (the California Online Privacy Protection Act).
Where required by law, we treat a recognized opt-out preference signal, such as the Global Privacy Control (GPC), as a valid request to opt out of the "sale" or "sharing" of personal information for the browser or device that sends it. Because we do not sell personal information and do not use or disclose consumer health data for targeted advertising, an opt-out preference signal does not change how we handle that information. You can still use the cookie, browser, and platform controls, and the opt-out methods, described in this Policy at any time.
10. Consumer health data
Fitness, nutrition, body, coaching, and related information may qualify as consumer health data under some state laws. Our separate Consumer Health Data Privacy Policy explains the categories, sources, purposes, processors, restrictions, and rights that apply to that information.
11. Retention
We retain personal information only for as long as reasonably necessary for the purposes described here, including while an account or subscription is active, and as needed for legal, tax, accounting, fraud-prevention, safety, dispute, and enforcement obligations. Retention periods vary by data type and purpose. A one-way suppression token may be retained to continue honoring an opt-out without retaining the email address or phone number in readable form.
Verified deletion and backups. When a verified deletion request applies, covered personal and health data is removed from active TSF records and raw source history. This includes person-specific consent receipts, signed agreements, purchase and billing events, security and request events, messages, calendar details, photos, workout and nutrition history, intake, and coaching content. A one-way restore block takes effect before active deletion begins so an older backup cannot recreate the account. Backup scrubbing and external-processor actions are tracked separately, and the request is not marked complete until every required action is terminal. A processor may retain limited information where law requires it or during a documented backup or risk-control window.
What may remain. We may keep genuinely non-linkable aggregate totals that cannot reasonably identify, single out, or be joined back to you. We also keep the minimum one-way markers needed to prevent restoration and continue honoring an opt-out without retaining a readable email address, phone number, or activity history. We do not keep a pseudonymous or de-linked per-person consent, agreement, financial, security, request, message, or activity timeline after verified erasure. If a legal hold or statutory preservation requirement limits a request, we address that exception before completing the request and provide any explanation or appeal right required by law.
12. Your choices and rights
- Access and export: request or use available in-app tools to obtain a copy of personal information associated with your account.
- Correction: correct inaccurate profile information through the app or by contacting us.
- Deletion: request deletion through Account > Legal in the app or follow the instructions on our Delete Your Account page.
- Withdraw a permission: stop future processing that depends on your permission, subject to legal and operational exceptions.
- Communications: unsubscribe from marketing email using the email link and opt out of SMS using the methods in our SMS Terms. Signed-in members can manage channel and notification preferences in the messaging preference center under Account > Notifications in the app.
- Advertising measurement: opt out of Meta advertising measurement using your browser cookie settings, your Facebook or Instagram ad and privacy controls, or by emailing us as described in Sale, advertising, and sensitive-data restrictions.
- Browser and platform controls: use browser cookie settings and the privacy controls made available by an advertising platform.
Additional rights may apply based on where you live. We may need to verify your identity before completing a request. We will not discriminate against you for exercising a privacy right. An authorized agent may submit a request when permitted by law, subject to proof of authority and identity verification. Contact [email protected] to submit a request or appeal a decision.
13. Your California privacy rights
This section applies to California residents and supplements the rest of this Policy under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). Fitness, nutrition, body, and coaching information may also be "sensitive personal information," and our separate Consumer Health Data Privacy Policy describes additional handling and rights for that information.
Categories we collect. In the past twelve months we have collected the following CCPA categories: identifiers (such as name, email, phone, and IP address); customer records and financial transaction information (such as billing status and transaction identifiers, with payment card data handled by Stripe); commercial information (plans and purchases); internet or network activity (such as usage, cookies, and attribution); geolocation inferred from IP address; audio, electronic, or visual information you submit (such as progress photos and messages); health-related and other information you provide (which may be sensitive personal information); and inferences drawn to personalize the Services. Sources and purposes are described in Information we collect and How we use information above.
Disclosures. We disclose the categories above to the service providers and other recipients listed in How we disclose information for the business purposes described there. In the past twelve months we have disclosed identifiers, commercial information, and internet activity to advertising and measurement platforms for advertising measurement, as described in Sale, advertising, and sensitive-data restrictions.
No sale or sharing; no sensitive-data inferences for advertising. We do not sell personal information and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information, including consumer health data, for targeted advertising or to infer characteristics. Because we do not sell or share, there is nothing to opt out of for those purposes, and we honor a recognized opt-out preference signal as described in Do Not Track and Global Privacy Control.
Your California rights. Subject to verification and legal exceptions, you may request to: know the categories and specific pieces of personal information we collected, the sources, the business purpose, and the categories of recipients; correct inaccurate personal information; delete personal information; and limit the use of sensitive personal information, which we already restrict to providing the Services. We will not discriminate or retaliate against you for exercising these rights.
How to exercise them. Use the tools under Account > Legal in the member app, or email [email protected]. We may need to verify your identity, and an authorized agent may submit a request with proof of authority. If we deny a request, you may appeal by replying to the decision or emailing the same address with the subject "California Privacy Appeal." California's "Shine the Light" law lets California residents request information about disclosures to third parties for their direct marketing; because we do not share personal information with third parties for their own direct marketing, no such disclosures occur.
14. Security and breach response
We use administrative, technical, and physical safeguards designed to protect personal information, including access controls and security monitoring. No system can guarantee absolute security. If we identify a security incident, we investigate, take reasonable containment and remediation measures, and notify affected people and authorities when required by applicable law.
15. United States operations
We operate from the United States. If you use the Services from another country, information may be processed in the United States and other locations where our processors operate, subject to applicable transfer requirements.
16. Changes to this Policy
We may update this Policy as our Services or legal obligations change. We will post the updated version with a new "Last updated" date and provide any additional notice required by law. A material change to a purpose that requires permission will not replace a separate permission required by law.
17. Contact us
T&L Companies LLC d/b/a True Standard Fitness
6222 NW Gisela St
Port St Lucie, FL 34986
Email: [email protected]