Privacy Policy
Last updated: August 2026
Get Up Get Out Get Fit (the “Site”) is a fitness website operated from the United Kingdom. This policy explains what personal data we collect, why we collect it, how long we keep it and what you can ask us to do with it. It is written to the UK GDPR and the Data Protection Act 2018.
The short version: you can read this entire site without giving us anything. There are no accounts, no sign-up wall, and no analytics at all unless you press Accept on the cookie banner. We only hold data you deliberately hand over.
1. Who we are
The data controller is the operator of getupgetoutgetfit.com. You can reach us at contact@getupgetoutgetfit.com, or through the contact form. We do not have a Data Protection Officer, and are not required to appoint one.
2. What we collect, and why
If you join the email list
We store your email address and a random token used to confirm and later unsubscribe you. The list is double opt-in: nothing is ever sent to an address that has not clicked the confirmation link, and an unconfirmed address is never used for anything else.
Lawful basis: consent. Every email contains a one-click unsubscribe link, which deletes your record immediately.
If you use the contact form, or email us
We store the name, email address and message you send, and forward a copy to our own mailbox with your address set as the reply-to. Mail sent directly to our published addresses is handled the same way.
Lawful basis: legitimate interests — answering someone who has contacted us.
If you become a supporter
Payment is taken by Stripe, not by us. We never see or store your card details. Stripe tells us your email address and a customer reference, and we store those alongside the access code we issue you and the date it runs until.
Lawful basis: performance of a contract, and our legal obligation to keep records of sales.
If you accept analytics cookies
Only then do we load Google Analytics 4, which sets cookies and records which pages you visit, which calculators you use and whether you unlocked a guide. If you decline, or simply ignore the banner, the Google script is never loaded at all — no cookie is set and no request reaches Google. We deliberately do not use the “denied” consent mode that still contacts Google before you have agreed.
Lawful basis: consent. You can withdraw it at any time using the Cookie settings link in the footer.
Server logs
Our content delivery network records standard request logs, which include IP addresses, timestamps, the page requested and your browser’s user-agent string. These are used to keep the site up and to investigate abuse and errors. They are deleted automatically after 30 days.
Lawful basis: legitimate interests — security and reliability.
3. Storage in your own browser
Some things are kept in your browser and never sent to us. They are not cookies and are not shared with anyone:
gugogf_cookie_consent— whether you accepted or declined analytics.gugogf_theme— your light or dark preference.gugogf_access— your supporter access code and its expiry, so you are not asked for it on every guide.
Clearing your browser data removes all of them.
4. Who else processes your data
- Amazon Web Services — hosting, storage and email delivery.
- Stripe — payment processing. Stripe is the controller of your payment data; see their own privacy policy.
- Google Analytics — only if you accepted analytics cookies.
We do not sell your data, and we do not share it for advertising.
5. Where your data is held
Our infrastructure runs in Amazon Web Services’ US East (Northern Virginia) region, so data is stored in the United States. Transfers outside the UK are covered by the UK International Data Transfer Addendum and AWS’s standard contractual clauses. Google and Stripe also process data outside the UK under equivalent safeguards.
6. How long we keep it
- Email list: until you unsubscribe, which deletes the record.
- Messages you send us: kept while we may still need them to deal with your query.
- Supporter records: kept for six years after the transaction, which is how long HMRC requires sales records to be retained.
- Server logs: 30 days, deleted automatically.
- Analytics: retained by Google under their own policy.
7. Your rights
Under the UK GDPR you can ask us to:
- give you a copy of the data we hold about you;
- correct anything that is wrong;
- delete your data;
- restrict or object to how we use it;
- provide it in a portable format;
- withdraw consent, at any time, where consent is the basis.
Email contact@getupgetoutgetfit.com and we will respond within one month. There is no charge.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first so we can put it right.
8. Children
This site is not aimed at children and we do not knowingly collect data from anyone under 13. If you believe a child has given us their details, tell us and we will delete them.
9. Changes to this policy
We may update this page as the site changes. The date at the top always reflects the current version. Material changes affecting how we use data you have already given us will be notified by email where we hold an address for you.
10. Related pages
See also our Terms of Service and our Disclaimer, which covers the health and fitness limitations of everything published here.