Marginal Improvements Ltd ("Company", "we", "us", or "our") operates Backstage, a coaching management platform. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have over it. It applies to all users of our website and platform, including coaches and the clients they invite. We are committed to handling your data with transparency and care.
Marginal Improvements Ltd is the data controller for personal data collected through Backstage. If you are a coach using the Service and you process personal data relating to your clients through the platform, you are also a data controller for that data, and we act as your data processor. A Data Processing Agreement is available on request.
Our registered address and contact details are available at the bottom of this policy.
We collect personal data in the following ways:
Data you provide directly: Your name, email address, and password when you register. Profile information such as your avatar and display name. Payment details (processed by Stripe, we do not store card numbers). Any content you create or upload through the platform, including training plans, nutrition programmes, form responses, and progress data.
Data collected automatically: Log data including your IP address, browser type, pages visited, and timestamps. Device and usage information to help us improve the Service. Cookies and similar tracking technologies (see Section 8).
Data about your clients (if you are a coach): Any personal data you enter or import relating to your clients, including their names, email addresses, health and fitness data, and check-in responses. You are responsible for having a lawful basis to process this data and for informing your clients accordingly.
We use your personal data for the following purposes:
To create and manage your account and provide access to the Service.
To process payments and manage your subscription.
To send transactional emails such as account verification, password resets, and billing receipts.
To respond to your support enquiries and communications.
To monitor and improve the performance, security, and reliability of the Service.
To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal data to third parties. We do not use your data for advertising.
We process your personal data on the following legal bases under UK GDPR:
Contract: Processing necessary to provide the Service you have signed up for, including account management and billing.
Legitimate interests: Improving the Service, preventing fraud, and maintaining security.
Legal obligation: Retaining records as required by applicable law.
Consent: Where we rely on consent (e.g. optional communications), you may withdraw it at any time.
We work with a small number of trusted partners to deliver our Service. Here is exactly who has access to what.
Service
What they do for us
Provides our database, authentication, and file storage. Your account data, client records, and uploaded files are stored here.
Handles all payment processing and subscription billing. We do not store your card details, Stripe holds them under PCI-DSS compliance.
Hosts and serves our web application and API. All requests to Backstage pass through Vercel infrastructure.
Routes Spotter's requests to the AI model that answers them. Only the parts of your account Spotter needed in order to answer are sent, and only when you ask it something. See Section 6.
Sends transactional emails including account verification, password resets, and billing notifications.
Each provider operates under its own privacy policy, linked in the table above. We only share the minimum data necessary for each provider to perform their function.
Spotter is the assistant built into Backstage. It only does anything when you ask it something, and it only ever sees data from your own account.
What is sent: When you ask Spotter a question, your question and the records it needed in order to answer are sent to an AI model through OpenRouter, along with which page you were on. If the answer concerns a client, that means their data is part of what is sent. Nothing is sent when you are not using Spotter, and Spotter can only read the account you are signed in to.
What we store: Your Spotter conversations are saved to your account so you can reopen them, which means your questions and Spotter's answers, including any client details in them, are stored in our database. Deleting a conversation deletes its messages with it. There is no archive and no soft delete.
Training: We do not use your conversations or your client data to train any model, and we do not sell or share them. OpenRouter routes requests to underlying model providers who have their own policies, and whether a given provider may train on what is sent depends on the routing settings we configure. We will say plainly in this policy if that changes.
What Spotter cannot do: It cannot see another coach's account. It cannot send messages to your clients. It cannot delete anything. Anything that would change your data is shown to you first and does nothing until you confirm it.
Clients: Spotter is a coach-side feature. Your clients do not have an assistant, and no client can read your Spotter conversations.
We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
When you delete your account, we will delete or anonymise your personal data within 90 days, except where retention is required by law (for example, financial records which must be kept for 7 years under UK law).
Spotter conversations are kept until you delete them, or until your account is deleted, whichever comes first. Deleting a conversation removes its messages immediately.
Backup copies may persist for up to 30 days after deletion before being purged from our systems.
We take the security of your data seriously. We implement appropriate technical and organisational measures to protect against unauthorised access, accidental loss, destruction, or damage. These include encryption in transit (TLS), encryption at rest, access controls, and regular security reviews.
No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
We use essential cookies and similar technologies to operate the Service, for example, to keep you logged in and remember your session. We do not use advertising or tracking cookies.
You can control cookie settings through your browser. Disabling essential cookies may prevent some parts of the Service from functioning correctly.
Under UK GDPR, you have the following rights regarding your personal data:
Access: You can request a copy of the personal data we hold about you.
Rectification: You can ask us to correct inaccurate or incomplete data.
Erasure: You can request that we delete your personal data, subject to legal retention obligations.
Restriction: You can ask us to restrict processing of your data in certain circumstances.
Portability: You can request your data in a structured, machine-readable format.
Objection: You can object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@marginalimprovements.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
The Service is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
Some of our third-party providers operate outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR, such as Standard Contractual Clauses or adequacy decisions.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice within the Service. The date at the top of this page always reflects the most recent update. Continued use of the Service after changes constitutes acceptance of the revised policy.
If you have any questions about this Privacy Policy or how we handle your data, please contact us: