Privacy Policy

Who we are

We are Stumble, an online directory connecting clients and PTs.
Our website address is:

What personal data we collect and why we collect it

Comments and Reviews

When visitors leave comments on the site we collect the data shown in the comments and reviews form, and also the visitor’s IP address and browser user agent string to help spam detection.

You have the option to opt-in to marketing communications from us such as Newsletters and Offers. If you decide to opt-in, your name and email address will be sent securely to our email marketing database hosted at MailChimp. You are able to opt out of marketing communications any time by either emailing us (see below), or by clicking ‘unsubscribe’ in any marketing material you receive from us.

For more information on the privacy policy of MailChimp, please visit:


If you upload images to the website/App, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Contact and Messaging forms

With Stumble, you have the ability to contact Customers or PT/Classes/Gyms through our messaging system. Your messages are stored securely on our site for you to come back to them at a later date. As part of the messaging system, the PT/Class/Gym with whom you message will be able to see your message to them, as well as your name and profile photo (if you have uploaded one).

Our site administrators are able to view messages sent to and from PT/Classes/Gyms for security purposes.


You are only able to leave reviews or comments if you create an account on our website. This is for security purposes and to limit the amount of spam messages sent/received. By using Stumble, you agree to cookies being stored on your device.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish a review, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

CookiEmbedded content from other websiteses

Articles and resources on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.


When someone visits , we use a third party service called Google Analytics. This amazing bit of software allows us to collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to various parts of our site. This information is only processed in a way in which it does not identify anyone. We do not make, nor do we allow Google to make, any attempt to find out the identities of those visiting our site.

Billing Information

You are able to pay for subscriptions and promotions on our site using a payment card. In order for our payment processor (Stripe) to process your payment, we are required to collect the following information:

  • First and Last Name
  • Address
  • Payment Card Details

This information is sent in an encrypted form directly to Stripe who will process the transaction. Your payment information is not stored by us.

You can view the privacy policy of Stripe by visiting:

You do have the option to “store” credit cards on our site via a secure method called tokenisation. Tokenised payment methods can be used for convenience in future purchases. Credit card tokens include the last four digits of a card, the card brand/type, and its expiration date, mostly so the customer can identify which token is for which card.

Tokenisation is extremely secure. With tokenisation, customers’ actual credit card information is stored on the servers of our payment processor (Stripe) and not by us.

The only data saved on our site is in the form of a string of characters called a token. These tokens are designed to be useless outside the precise context they’re created for. Imagine if, when you exchanged your money for chips at a casino or ride tickets at a fair, those chips or tickets not only couldn’t be spent on anything outside the casino or fair but couldn’t be spent by anyone but you.

Tokens are super-specific — specific to you, the customer, specific to our website, specific to the payment gateway’s payment processor (Stripe), and specific to our merchant account with our processor, Stripe. If any of those factors aren’t precise, the token won’t work as a placeholder for a customer’s payment information.

Payment gateways that allow tokenisation require websites to meet higher security standards set by the payment processors, which we adhere to.

Stumble Points are awarded for when you refer someone to our site who then subsequently creates an account and becomes a paying member. We store your total number of points on your account, and keep a log of spending / acquiring to ensure we can help you with any queries.

Account Information

When creating an account with Stumble, irrespective of whether you are a customer, personal trainer (PT), exercise class and or gym we require the following information:

  • Full Name
  • Email Address
  • Account Password

The above details are stored securely. No one, not even the site administrators can view your password. Should you need help resetting your password, then the site administrators can help, but there is no way for them to see your existing password.

We require your name in order to personalise your account and to make the messaging system between customers and PTs/Classes/Gyms more effective.

Your email address is required so that we can verify your account, can message you any essential emails (such as password resets), and notify you if you have any messages on our system.

PT/Class/Gym Listing

Should you wish to publish your profile on Stumble, we require the following information.

  • Your Name (or Business/Trading Name)*
  • Your Biography*
  • Your relevant Qualifications
  • Your specialities*
  • Your Gender*
  • Your Contact number
  • Instagram URL
  • Relevant image(s)
  • Your location*
  • Your hourly price*

All fields marked with an asterisk (*) are mandatory. We require these fields at the minimum to ensure that customers who visit the site are given enough information to make an informed decision.

Fields without an asterisk (*) are not mandatory, however we recommend competing them nonetheless in order to help customers search the site.

You are not required to fill in your gender if you choose not to. Stumble loves inclusivity and diversity. If you do not see your prefered gender listed, do let us know and we will get it added.

Whilst you are able to input your full address into our website/app to pinpoint it on the map, we do not list your address on our website/app. On your profile however is a marker on a map. We encourage you to place the marker where you are based, but this is optional. You are, for example, also able to place it at the end of your road or in the middle of where you are happy to commute to.

Who we share your data with

If you request a password reset, your IP address will be included in the reset email.

If you message another user on this site, we will share your message, profile photo (if you have one) and your name with the other user.

Your payment information is sent in an encrypted form to our payment processor, Stripe. You can view the privacy policy of Stripe here:

By design, we do not store credit/debit card numbers or security codes on our website. The payment gateway gives this sensitive information directly to the payment processor (Stripe) to process.


Pending orders, and Failed Orders, are unpaid and may have been abandoned by a customer. Cancelled orders are unpaid and may have been cancelled by a customer, or us. As you need an account to place any orders on our website/app, we will keep record of all interactions unless you request for your data to be deleted. Our payment process, Stripe, requires us to store unique tokens, including Stripe Customer ID and Source ID. These will be deleted after 2 weeks.

How long we retain your data

If you leave a comment, review or message, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website, we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

For any questions or queries surround your personal data, please email us at

Our Contact Information

Data Protection Officer: James Ward


Additional information

How we protect your data

Your data security is of the utmost importance to us. Not only do we not store your payment information, but our servers are based within the EU and are thus compliant of strict EU security laws. For more information on our servers, please visit our supplier:

Our website’s connection to our server is secure (HTTPS with an SSL certificate – look for the padlock in the URL) with all information sent encrypted. Passwords are stored securely and in an encrypted form.

Moreover, if you decide to create an account with us, your details are stored in an encrypted database and only accessible by you or site administrators.

What data breach procedures we have in place

In the event of a data breach, our data protection officer and/or site administrators will be in touch with you immediately. Upon doing so, we will reset the passwords of affected user(s).