Una de las cuatro cosas de abajo la decides tú. Apagado significa que la etiqueta nunca se carga: no se le pide nada a la empresa que hay detrás, así que no hay nada que pueda ver ni cookie que pueda poner. Las otras tres funcionan para todo el mundo, y cada una aparece con lo que sí la detiene en lugar de con un interruptor que no. Puedes cambiar tu respuesta cuando quieras desde el enlace Opciones de privacidad del pie de página.

Medición

Siempre activa

Google Analytics, más los conteos de página sin cookies de Vercel: cuánta gente llegó al sitio, de dónde vino y cuántas personas terminaron una reserva. Esta funciona de todas formas. La política de cookies explica cómo detenerla desde tu navegador.

Publicidad

Siempre activa

El píxel de Meta para Facebook e Instagram. Informa de vuelta que un anuncio llevó a una reserva, y permite que después se te muestre un anuncio de STEPFIT en otros sitios. Este funciona de todas formas y aquí no hay interruptor para él — la política de cookies explica qué sí lo detiene desde tu navegador.

Identificación de visitantes

Siempre activa

retention.com cruza señales de tu visita contra una base de datos construida a partir de otros sitios, y donde encuentra una coincidencia puede decirnos que estuvo aquí una persona con nombre y apellido — aunque nunca hayas escrito nada. Esta funciona para todo el mundo y aquí no hay interruptor para ella. Lo que recibimos se guarda y queda marcado como procedente de la identificación, y puede usarse para correos de marketing — todavía no hemos enviado nada, y todo lo que enviemos lleva un enlace de baja de un solo clic.

Desactiva retention.com en todos los sitios que la usan — app.retention.com/optout

Microsoft Clarity reproduce cómo se usó una página — por dónde se movió el puntero, en qué se hizo clic, hasta dónde bajaste. Se mantiene apagada en la página del acuerdo, en el formulario de empleo y en el de contacto, y esa exclusión está escrita en el código de este sitio, no configurada en el panel de Microsoft.

Saltar al contenido
STEPFITEnglish
Reservar una clase

Privacy policy

Rev. 27 August 2026 (fourth revision)

Who we are

STEPFIT runs fitness classes in Tampa, Florida. This policy covers getstepfit.com and the booking system on it. If you have a question about anything here, use the contact page.

What we collect when you book

Booking a class stores:

  • Your first and last name
  • Your email address
  • Your phone number
  • Confirmation that you are 18 or over
  • If you are booking for someone under 18: their name and age
  • An emergency contact name and phone number
  • Whether you opted in to text messages
  • The class you booked and when you booked it
  • Your IP address and browser user-agent, recorded with your waiver acceptance

The liability waiver and your signature

Before a booking is completed you read and sign the informed consent and liability waiver. We store your signature — either the image you drew or the name you typed — along with the version of the document you agreed to, the date and time, your IP address, and your browser user-agent.

We keep this because it is the record of what you agreed to. The waiver is a standing agreement covering all future STEPFIT classes until you revoke it in writing, so if you book again we carry your existing signature forward rather than asking you to sign again.

You can revoke the waiver in writing at any time through the contact page. We record the revocation against your signature, with the date and who actioned it, and from that moment the signature no longer covers a future class — if you book again you are asked to sign again first.

Revoking does not delete the record. The signed acceptance is the evidence of what you agreed to on a particular day, and we keep it for the period set out below whether or not it is still in force; the revocation is a fact added to it, not a replacement for it. Revoking also does not cancel a class you have already booked — we will contact you, and either you sign again or the booking is cancelled and refunded. You cannot take part in a class without a signature in force.

Payments

Card payments are handled by Stripe on Stripe’s own hosted checkout page. Your card details are entered on Stripe, never on getstepfit.com, and we never see or store them.

From Stripe we store the amount you paid, when it was paid, and the identifier of the checkout session, so we can match a payment to a booking.

Stripe’s own privacy policy governs what they collect: stripe.com/privacy

Email and text messages

Your booking confirmation and class reminder are transactional — you are giving us an address so we can tell you about a class you booked, not subscribing to marketing. Every one of those emails carries a one-click link to cancel your spot.

If you tick the box to receive text messages, that is a separate, optional consent for messages about classes, registration and promotions. It is never required to book. We store the date and time you consented. Reply STOP to any message to stop them, and we record that too.

If you ask us to email you when a new class is posted, that is a separate opt-in list and anything we send from it carries an unsubscribe link.

Email addresses that reached us through visitor identification rather than from you are not on any of these lists. They are handled separately, and may be used for marketing email on the terms set out in its own section below — including a one-click unsubscribe on every message.

Email is sent through Resend, which delivers via Amazon SES. Text messages are sent through Textbelt. Your address or phone number and the content of the message pass through those systems.

The contact form

The contact form sends us your name, email address and message by email. We do not publish an email address on this site, which is why the form exists. Messages are kept so we can follow up.

The form uses a hidden field and a timing check to catch automated submissions, and limits how many messages can be sent from one network address. It also uses Cloudflare Turnstile, which checks that a submission comes from a person rather than a script; making that check sends your IP address and a one-time token to Cloudflare.

Asking for a different day or time

The class landing page has a short form for people who want a class but cannot make the one that is scheduled. It asks for your first and last name, your email address, your phone number, the days of the week that would suit you, a time for each of those days if you want to give one, and anything you write in the free-text box.

We use it for one thing: deciding which nights to run classes on, and telling you when one lands on a day you asked for. It is not added to any marketing list, it is not shared outside STEPFIT, and the phone number is there so we can text you about a class you asked for rather than because we intend to call you about anything else.

Submitting it does not book you anything and does not commit us to scheduling a class. It is a request, and it is recorded as one.

The form uses the same protections as the contact form: a hidden field and a timing check to catch automated submissions, a limit on how many can be sent from one network address, and Cloudflare Turnstile, which checks that a submission comes from a person rather than a script and sends your IP address and a one-time token to Cloudflare to do it.

Requests are reachable only by a signed-in administrator. If you want yours deleted, ask through the contact page.

If you apply for a job

The careers page has an application form, and it asks for more than a booking does: your name, email address, phone number, home address, whether you have taught before and where, and anything you write in the free-text fields.

We use it to consider you for the role you applied for and to contact you about it. It is not used for marketing, it is not added to any mailing list, and it is not shared outside STEPFIT.

Applications are stored separately from bookings and are reachable only by a signed-in administrator. If you want yours deleted, ask through the contact page.

Analytics and advertising

This site loads measurement and advertising tools through Google Tag Manager: Google Analytics, and a Meta pixel for Facebook and Instagram.

These run for everyone who visits. There is no box to tick, and we would rather say that plainly than put a switch on the page that does not switch anything. STEPFIT advertises on Instagram and Facebook, and the pixel is how the studio can tell whether the money spent on an advert brought anyone in. That is the reason, and you are entitled to weigh it. The cookie policy sets out what stops these tags in your own browser, which is a real answer and not a formality.

Google Analytics tells us how many people reached the site, where they came from, which pages they read and how many finished a booking. The Meta pixel reports that an ad led to a booking, and lets an advert for STEPFIT be shown to you elsewhere afterwards. That one is cross-site: Meta receives a record of your visit here and also sees you in many other places.

A third tool runs for everyone as well, and it is different enough to have its own section below: retention.com, which tries to work out who an anonymous visitor is. It does not wait for an answer either, and the section headed "Being identified as a visitor" says what it does and what you can do about it.

One tool out of the four is different — session recording does not load at all unless you allow it. A banner asks on your first visit, and the Privacy choices link at the bottom of every page changes the answer afterwards.

Vercel Analytics and Speed Insights measure page views and loading speed without cookies, do not identify you, and do not follow you to other sites.

None of what you type into the booking form — your name, email, phone, emergency contact, a minor’s details or your signature — is sent to any advertising or analytics tool. None of these run on the admin area. The cookie policy lists each one, the cookies it sets and how to stop it.

Session recording

This is the one that waits for you, and since 26 August 2026 it is the only one. Clarity does not load unless you allow it on the banner or in Privacy choices, and off means it is never requested at all — nothing leaves your browser for Microsoft, so there is nothing for it to record and no cookie for it to set.

What it does when it is allowed: Microsoft Clarity records how pages are used — pointer movement, clicks, scrolling, and a replay of the page as it appeared on screen. It is a reconstruction of the page, not a recording of your camera or microphone, and it is held on Microsoft’s systems under Microsoft’s privacy statement.

It is kept off the pages where you type anything that matters. The booking flow, the careers form and the contact form are excluded from recording, because those are the pages carrying a signature on a liability waiver, a child’s name and age, an emergency contact’s phone number, a home address and whatever you write to us. Excluded, not merely masked — a recording of somebody signing a waiver should not depend on a setting being right.

It does not run on the admin area either.

Being identified as a visitor

This one is different from analytics and we would rather explain it than list it.

STEPFIT uses a third-party identity resolution service called retention.com. Until 26 August 2026 it waited for your permission. It does not any more: it loads on your first page view, before you have answered anything, the same as the analytics and advertising tags. That is a decision the studio made rather than an oversight, and this page says it here rather than leaving you to notice. What you can do instead of the switch is three specific things, set out at the end of this section.

What it does. Analytics counts visits anonymously. This service attempts the opposite: it takes signals from a visit and matches them against a database assembled from many other websites and sources, and where it finds a match it can tell us that a named person, with an email address, was on this site — even if you never typed anything here and never booked.

What happens to a match. When the service identifies somebody, it sends their name and email address to us and we keep them. They are stored on their own, on a marketing record, marked as having come from identity resolution rather than from you, and that marking is permanent — it stays on the record even if you later book a class or write to us. If you ever ask where we got your address, the answer is a field next to it rather than something anybody has to reconstruct from memory.

What we may do with it, and this is the paragraph to read twice. These addresses may be added to our marketing list and used to send you email from STEPFIT about classes, schedules and offers. You did not give us the address, so you are entitled to read that we might use it before anything arrives rather than to work it out afterwards. Every message we send this way carries a subject line that says what it is, a postal address for the studio, and an unsubscribe link that works on one click — no account, no login, no reply required. Those are not aspirations; they are the terms this policy publishes and anything sent has to meet them.

Where that stands as this revision goes up. Nothing has been sent to these addresses. The part of the system that sends email cannot currently reach them at all, and that is the honest description of today rather than a promise about next month. The paragraph above is the permission and this one is the date stamp on it. It is written this way round on purpose: the fair moment to tell you is before the first message, while opting out still costs you nothing, not in the same week as the campaign.

Whether or not we ever send, none of it applies to you if you leave. The three ways out below work the same before the first message and after it, and asking to be deleted removes the address rather than marking it.

The three things you can do. First, and most complete: retention.com runs its own opt-out covering every website that uses them, at app.retention.com/optout. That stops you being matched in the first place, here and everywhere else, which is more than this site could offer you even when it had a switch. Second: if your browser sends a Global Privacy Control signal, this service is not loaded on this site at all — that is checked before anything runs, it needs no click from you, and it did not change when the permission did. Third: if we already hold a match for you, ask through the contact page and we will delete the record — not flag it, delete it — and add your address to the list that stops it being added back. That list is checked when a contact arrives, not only when a message is about to go out, so the service offering us your address again cannot put you back on. An unsubscribe link, if you have ever been sent one, does the same thing on one click.

It is still a different proposition from measurement, because the information does not come from you and you were not asked for it. It comes from a third party that already held it. We would rather write that sentence down than have you work it out.

It runs on the public pages only. It is not on the booking flow, not on the careers form, and not on the admin area. That exclusion does not depend on anything you do, and it did not depend on the permission that used to be asked for. The browser controls in the cookie policy interfere with it directly as well.

Maps

The Tampa page can show a Google map of the venue. It does not load until you press the button to load it — if you never do, nothing is requested from Google and nothing is set on your device.

Who else your information reaches

We use these services, and your information reaches them only as described:

  • Supabase — the database holding bookings and waiver records, hosted in the United States
  • Vercel — hosting for the website and its server code, including standard request logs
  • Cloudflare — the domain’s DNS, and the network your request passes through to reach the site, which means it handles your IP address and standard request information
  • Resend — sending confirmation, reminder and contact-form email
  • Textbelt — sending text messages, if you opted in to them
  • Stripe — card payments, on their own hosted page
  • Google — Tag Manager, Analytics and Ads, on the public pages, for every visitor; and Maps only if you load it
  • Meta — the Facebook and Instagram advertising pixel, on the public pages, for every visitor
  • Microsoft — Clarity session recording, only if you allow it, and then on the public pages only, never on the booking flow or the careers form
  • retention.com — visitor identification, on the public pages, for every visitor, but never on the booking flow or the careers form; where it identifies you it sends your name and email address to us, and we keep them as described above

Selling and sharing

We do not sell your personal information for money, and we never have. We do not sell or rent the booking list, the waiver records, the contact form messages, the class-day requests or the job applications to anybody, and nothing you type into this site is passed to an advertising company.

We are being narrower than the usual "we do not sell or share" sentence on purpose, because the advertising and visitor-identification tools described above do involve information about your visit reaching other companies, and under some states’ laws that counts as sharing even when no money changes hands. Saying "we never share anything" while running an advertising pixel would be the kind of sentence this policy exists to avoid.

It also runs the other way, and that belongs in this section rather than being left as something you notice. Where the identification service matches you — which it now attempts for every visitor, not only those who agreed — information about you reaches STEPFIT from a company you have never dealt with, holding details you did not give us. We do not buy or sell mailing lists and we do not pass what we receive on to anybody else — but a transfer is a transfer, and this is the same kind of thing the paragraph above describes, seen from the end that receives it.

If you live somewhere with a law that calls this kind of thing a sale or a share, that is the flow it is talking about, and the opt-outs are the ones already named: your browser’s Global Privacy Control signal, which we act on automatically, and retention.com’s own opt-out at app.retention.com/optout.

So: what you give us stays with us and the services listed above that we need to run the studio. What your browser gives to Google, Meta, Microsoft and retention.com while you read the public pages is set out above and in the cookie policy, along with how to stop it. And what retention.com gives us about you is kept the way that section describes and can be deleted on request.

How long we keep it

Waiver acceptances and the bookings attached to them are kept for five years. This is deliberate: the waiver exists to record what you agreed to before taking part in physical activity, and it needs to outlast the period in which a claim could be brought.

Class-day requests are kept for two years, the same as contact form messages — they are the same kind of thing, a message asking us for something, and a request from someone who wanted a Tuesday class is still worth reading when we are deciding next quarter’s schedule. Contact form messages are kept for two years. Job applications are kept for one year after we fill or close the role, so we can come back to you if something else opens up — ask us through the contact page and we will delete yours sooner. Email addresses on the new-class notification list are kept until you unsubscribe.

These three periods are settled policy, not estimates. A revoked waiver is kept for the same five years as a live one — revoking ends what it covers, it does not shorten how long the record of it is held.

Analytics, advertising and session-recording data sits with the companies that collect it and is kept under their own retention settings, which are shorter: Google Analytics data on a rolling window we set in the property, and Microsoft Clarity recordings for the period Clarity retains them. We do not keep our own copy of any of it.

Visitor identification is the exception to that last sentence and we would rather say so here than let it sit between two paragraphs. A name and email address received from retention.com is a copy we do keep, on our own systems, with the date it arrived, and since 26 August 2026 it can arrive for any visitor rather than only for somebody who agreed. There is no automatic expiry on it, so the way it ends is you asking: tell us through the contact page, or use an unsubscribe link if you have one, and the record is deleted rather than kept and marked.

Your choices

Session recording is yours to switch, at any time, from the Privacy choices link at the bottom of every page. Turning it off stops it being loaded at all from that point on. Measurement, advertising and visitor identification are not switches on that panel because they run either way — the panel lists them anyway, each with what does stop it, and the cookie policy sets out the browser settings and blockers in full. They work.

You can cancel any booking with the one-click link in your confirmation email. You can stop text messages by replying STOP, and unsubscribe from the notification list from any message it sends.

If you have been identified as a visitor and would rather we did not hold your details, ask through the contact page and we will delete them. An unsubscribe link, if you have been sent one, does the same on a single click. Either way we keep a note that you asked, and that note is what stops the same address being added back the next time it is offered to us — the check runs when a contact arrives, not only when a message is about to be sent. To stop the matching itself rather than what we hold, use retention.com’s own opt-out at app.retention.com/optout, which covers every site that uses them.

You can ask us what we hold about you, ask us to correct it, or ask us to delete it, through the contact page. Some records we cannot delete on request — a signed waiver for a class you attended is the record of an agreement you made, and we keep it for the period above.

Children

Classes are for adults 18 and over. Someone under 18 may attend with a parent or guardian, who does the booking and signs on their behalf. In that case we store the minor’s first name, last name and age, given to us by their parent or guardian. We do not knowingly collect information directly from anyone under 18.

Changes

If we change this policy we will update the date at the top. Continuing to use the site after a change means the updated policy applies.

Exoneración