Last updated: 1 May 2026
Flow State Ltd is the data controller for all personal information collected through our website and membership services. We are registered with the Information Commissioner’s Office.
If you have any questions about how we handle your data, contact us at concierge@joinflowstate.club.
Website visits: IP address, browser type, pages visited, and referral source, collected via cookies and analytics tools.
Membership applications: Name, email address, phone number, date of birth, address, occupation, employer, and the content of your application.
Active members: Payment information (processed securely by Stripe — we do not store card numbers), direct debit mandates, emergency contacts, and communication preferences.
Service usage: Health and medical information you provide to trainers or recovery providers (such as injuries, conditions, allergies, and medications), training session details, attendance records, facility access logs, and concierge communication history.
Events: Photographs and video recordings taken at Flow State events.
Communications: The content of emails, messages, and calls with the concierge team.
Contract: We process data where necessary to deliver your membership, including arranging gym access, booking sessions, coordinating recovery services, and managing your account.
Legitimate interest: We process data to improve our services based on usage patterns, send relevant updates about your membership, maintain internal records, and prevent fraud.
Consent: We require your consent before processing health data, using your image in marketing materials, or communicating with you outside the scope of your existing membership.
Legal obligation: We process data where required for tax, accounting, and regulatory compliance.
We share your information only where necessary to deliver your membership or where required by law.
Partner facilities: Name and membership status for access purposes. Health information is shared with facility partners only with your consent, and only where necessary for your safety.
Service providers: Name, contact details, and relevant health data shared with personal trainers and recovery practitioners for the purpose of delivering your sessions.
Payment processors: Stripe processes all payment data under its own privacy terms. We do not store full card details.
Professional advisers: Our accountants, lawyers, and insurers may receive data as required for business and legal purposes.
Law enforcement: We disclose data where required by law or to protect the safety of any person.
We do not sell your data to anyone. We do not share your data with third parties for their marketing purposes.
Your data is primarily stored in the United Kingdom. Where we arrange access to international partner facilities, we may share limited data (name and membership status) with overseas providers. We ensure appropriate safeguards are in place, including UK International Data Transfer Agreements or adequacy decisions where applicable.
Stripe may process payment data internationally in accordance with its standard contractual clauses.
Active members: We retain your data for the duration of your membership and for 6 years following termination.
Health data: Retained for the duration of membership plus 3 years, then securely deleted. Records relating to specific incidents may be retained for up to 6 years from the date of the incident.
Payment records: Retained for 6 years after the transaction for tax compliance purposes.
Non-member applicants: Application data is deleted 12 months after our decision, or sooner upon request.
Website analytics: Anonymised data is retained indefinitely. Personally identifiable data is deleted after 26 months.
Marketing consent records: Retained for as long as necessary to demonstrate compliance with consent requirements.
We may photograph or film at Flow State events and use those images on our website, social media, and in other marketing materials. If you would prefer not to be photographed or filmed, or if you would like existing images removed, please email concierge@joinflowstate.club. We will remove identifiable images within 30 days where this is practicable.
We will never use your image in a way that implies endorsement of a specific product or service without your separate written consent.
Under UK GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, email concierge@joinflowstate.club. We will respond within 30 days. Complex or high-volume requests may take up to 60 days, in which case we will notify you. Most requests are free of charge. Clearly unfounded or excessive requests may incur a reasonable fee, which we will explain in advance.
Strictly necessary cookies: Required for the website to function. These cannot be disabled.
Analytics cookies: We use Google Analytics with IP anonymisation enabled to understand how our website is used. You can opt out through your browser settings or using the Google Analytics opt-out browser add-on.
Marketing cookies: These are only deployed with your consent, to measure the effectiveness of our advertising. You can manage your cookie preferences through the settings on our website.
We implement reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. These include encryption of data in transit, secure access controls, and regular review of our security practices.
In the event of a data breach that affects your personal rights and freedoms, we will notify the ICO within 72 hours and contact you directly where the risk is high.
Our services are intended for adults only. We do not knowingly collect personal data from children under the age of 18. If we become aware that we have inadvertently collected such data, we will delete it promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on our website. The date at the top of this page reflects when it was last revised.
If you have a concern about how we handle your data, please contact us first at concierge@joinflowstate.club. If we are unable to resolve your concern, you have the right to escalate to the Information Commissioner’s Office: