How we handle your data
Version v1.0 · Last updated 25 September 2026
This policy explains what personal data 404 Fitness Group Ltd (“404”, “Point One”, “we”) collects through https://www.404ldn.com and the 404 app, why we collect it, who we share it with and what your rights are. We collect only what we need to run the community, sessions, trips and Point One services you ask for.
Passport and travel details for trips are covered by a separate, more detailed Travel Data notice.
1Who we are
404 Fitness Group Ltd, registered at 1508 Aviator Point, 1 Odyssey Way, London, SW18 1EH, is the data controller. Contact us about anything in this policy at bookings@404ldn.com.
2What we collect, and why
We only collect data you give us directly or that is generated by you using the site. We do not buy data or track you across other websites.
| When | What | Why | Legal basis |
|---|---|---|---|
| You create an account | Name, email address, profile picture (if you add one or sign in with Google), a unique account ID. Sign-in is provided by Clerk. | To give you an account, sign you in, and show you as you in rosters and leaderboards. | Contract |
| You fill in your dashboard | Training background, goals, target events, notes to your coach, personal bests you enter. | To personalise programming and coaching. | Contract |
| You book a free session | Which session, when you booked, waitlist position, attendance. | To manage capacity and waitlists and remind you. | Contract |
| You buy a ticket or trip place | Name, email, what you bought, amount paid, Stripe payment reference. We never see or store your card number: payment is taken by Stripe. | To fulfil and record your booking and send confirmations. | Contract; legal obligation (accounting) |
| You join a trip waitlist | Name, email, phone (optional), when you joined. | To offer you a place in order. | Contract (steps before a contract) |
| You submit travel details for a trip | Passport details, emergency contact and, with your consent, dietary or medical needs. Encrypted at rest. | To arrange accommodation, activities and, where included, flights. | Contract; explicit consent for health data. See the Travel Data notice. |
| You apply for an athlete trial | Name, date of birth, email, phone, Instagram handle, city, sporting history and answers to the application questions. | To assess your application and contact you about it. | Legitimate interests (recruitment) and steps before a contract |
| You join the Point One waitlist | Name, email, phone (optional), which Point One services you are interested in, your marketing choice. | To tell you when the services you picked open. | Consent |
| You book performance testing | Name, email, phone, slot booked, payment reference, and your answers to the pre-test form. Encrypted at rest. | To run your test and prepare for it. | Contract |
| You submit a leaderboard score | Your name, discipline, score and date. | To display community leaderboards. Your name is shown publicly on the leaderboard. | Consent (you choose to submit) |
| You turn on notifications in the app | A device push token and your notification preferences. | To send session, booking and event notifications you have chosen. | Consent |
| You tick a marketing box | Your choice and the date you made it. | To send you news and offers only if you have said yes, and to prove you did. | Consent |
| You visit the site | Server logs (IP address, browser, pages requested) kept briefly by our hosting provider for security and error diagnosis. No analytics or advertising trackers. | To keep the site secure and working. | Legitimate interests |
3Marketing
We only send news and offers if you have ticked the marketing box, which is never pre-ticked. One answer covers both 404 and Point One. You can change your mind at any time on your profile page, by filling in a form again, or by replying to any email. Transactional messages about something you have booked, such as confirmations, reminders and waitlist offers, are not marketing and are sent regardless.
4Who we share it with
We share personal data only with providers who process it on our instructions, and only what each needs. We do not sell data.
- —Clerk: account and sign-in.
- —Stripe: payment processing. Stripe is an independent controller for the payment itself; see Stripe’s privacy policy.
- —Fixr: ticketing for some sessions and events. When you buy through Fixr you are dealing with Fixr under Fixr’s terms and privacy policy.
- —Sanity: our content and data store.
- —Vercel: hosting.
- —Resend: sending email.
- —OneSignal: app push notifications, only if you enable them.
- —Trip providers: accommodation, activity providers and, where flights are included, the airline. Only the details they need for your booking.
- —The 404 coaching and testing team, for the services you use. Access is limited by role.
We may also disclose data where the law requires it.
5International transfers
Some providers above store data in the United States. Where that happens it is under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy arrangement, so your data keeps UK-standard protection.
6How long we keep it
- —Account and dashboard data: for as long as you have an account. Ask us to delete your account and it is removed within 30 days, except records we must keep by law.
- —Booking, payment and ticket records: 6 years, for accounting and legal obligations. This does not include card details, which we never hold.
- —Passport and travel details: deleted 30 days after the trip ends (automatically).
- —Athlete trial applications: 12 months after the recruitment round closes, then deleted.
- —Trip and Point One waitlists: 12 months after the waitlist launches or you are removed, unless you become a customer.
- —Performance testing answers: 12 months after your test, unless you are on a Point One programme that uses them.
- —Marketing consent records: until you withdraw consent, then a record of the withdrawal.
- —Leaderboard scores: until you ask us to remove them.
7How we protect it
- —Everything is served over HTTPS.
- —Passport numbers, travel details, performance testing answers and Point One waitlist contact details are encrypted at rest with a key held separately from the database.
- —Access to personal data inside 404 is limited by role: admins, coaches and the testing team see only what their role needs.
- —Payments are handled entirely by Stripe; card details never touch our systems.
- —We do not use analytics, advertising or social-media tracking scripts.
8Your rights
You can ask us to access, correct or delete your data, to restrict or object to how we use it, to withdraw consent, and to receive a copy of data you gave us in a portable format. Email bookings@404ldn.com and we will respond within one month. You can also complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you raised it with us first.
9Children
Our services are for adults. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
10Cookies
We use only the cookies needed to sign you in and remember choices you make. Details are in the Cookie Policy.
11Changes
We will post any changes here with a new version and date. If a change materially affects how we use your data we will email account holders.