Barbells and Bows LLC. Effective September 3, 2026.
Barbells and Bows LLC is a personal training business in Scottsdale, Arizona, run by Paris Wright. This explains what we do with personal information collected through barbells-and-bows.com and the tools we use to run the business. We are a one-person business — when this says "we," it means Paris Wright.
Questions or requests: parisnoir@barbells-and-bows.com · (480) 463-4298 · Barbells and Bows LLC, 2012 N Scottsdale Rd, Scottsdale, AZ 85257
The short version
- We collect what you give us on our forms, plus basic order details and basic website statistics.
- We never see or store your full card number. Stripe handles that.
- We do not sell your information. We do not share it for advertising.
- Health information gets stricter handling than anything else. That has its own section.
- You can ask for a copy of your information or ask us to delete it, and we will respond.
What we collect, and where it comes from
We only collect through the specific places listed here. If it is not on this list, we are not collecting it.
1. Contact form (Squarespace) — your name, email, and your message. So we can answer you.
2. Client intake form (Squarespace) — name and contact details, training goals, training history, injuries, and other health information you choose to share. So we can design a program that is safe for you. See the Health Information section.
3. Purchases of digital training guides (Squarespace Commerce, payments by Stripe) — name, email, billing address, what you bought, when, amount, and the last four digits and brand of your card. We never receive your full card number, expiry date or security code — those go directly into Stripe’s own payment fields. Stripe is a PCI DSS Level 1 certified service provider, audited annually. To take payment, deliver your download, keep tax records, and handle refunds.
4. Coaching and consultations (Trainerize, operated by ABC Fitness Solutions, LLC) — name and contact details, session bookings, programs and logged workouts, progress notes, body metrics you enter, messages between us, and any photos or videos you upload. If you connect a fitness tracker to Trainerize yourself, that data flows in too. To deliver coaching and communicate with you.
5. Email marketing (Squarespace Email Campaigns) — email address, name if given, sign-up date and source, and whether you opened or clicked. To send training tips and updates — only if you opted in. Every email has an unsubscribe link.
6. Website statistics and cookies (Squarespace Analytics) — IP address, browser and device type, pages visited, how you arrived, and cart activity. To understand what people read and what sells. Google Analytics is not currently running on this site. If we add it, we will update this policy and say so first.
7. Social media — if you follow, message, comment or tag us on Instagram, TikTok or Facebook, we see what those platforms show us. We do not control those platforms and this policy does not cover them.
Why we are allowed to use it
| What we use it for | Why we are permitted to |
|---|---|
| Answering your message | You asked us to |
| Fulfilling an order and delivering a download | To perform our contract with you |
| Designing your training program | Contract, and your consent for health details |
| Sending marketing emails | Your opt-in consent — withdrawable any time |
| Keeping tax, payment and dispute records | Legal and accounting obligations |
| Basic website statistics and site security | Our legitimate interest in running the business |
For health information, our basis is your explicit consent, and you can withdraw it.
Who we share it with
These providers handle information on our instructions and may not use it for their own marketing.
| Provider | What they handle |
|---|---|
| Squarespace | Website hosting, contact and intake form submissions, store orders, email campaigns, site analytics |
| Stripe | Card payments, refunds, chargebacks, fraud checks. PCI DSS Level 1 certified |
| Trainerize / ABC Fitness Solutions | Coaching accounts, programs, bookings, messages, progress and body metrics |
| Our email and phone providers | Correspondence between us |
We may also disclose information if the law requires it, to protect someone’s safety, or if the business is ever sold (we would tell you first).
We do not sell your personal information. We do not share it with advertisers or data brokers. We do not use it to train AI models.
Health information — read this part
This is the most sensitive information we hold and we treat it differently.
What it is. Injuries, surgeries, pain, medical conditions, medications, pregnancy, physical limitations, body metrics, and anything else health-related you tell us on the intake form, in Trainerize, or in conversation.
We are not a HIPAA-covered business — and here is what that actually means. HIPAA applies to health plans, clearinghouses, and health care providers who transmit health information electronically for standard insurance transactions. A personal trainer who does not bill health insurance is none of those. So HIPAA does not apply to us, and we are not anyone’s business associate.
We do not treat that as permission to be careless. We hold your health information to these standards voluntarily:
- We only ask for what we need to program safely. You can decline any question. If declining means we cannot train you safely, we will tell you rather than guess.
- We do not share it with anyone except Squarespace and Trainerize as the systems it lives in. It does not go to Stripe, into email marketing, into analytics, or to any other third party.
- We never disclose it to family, employers or anyone else without your written permission, unless the law compels us.
- We do not post it. No case studies, progress photos, testimonials or social posts referencing your health, body or progress without your specific written consent for that specific use. Consent for one post is not consent for all posts, and you can withdraw it.
- We do not use it for marketing. Ever. Nothing you tell us about an injury will be used to target you with an offer.
- We keep it separate. Intake responses stay in the intake system and Trainerize. They are not copied into general contact lists or spreadsheets.
- You can withdraw consent at any time by emailing us. Withdrawing may mean we can no longer coach you safely.
- If your health information is ever exposed in a security incident, we will tell you — within 45 days of discovering it. Arizona’s breach notification law specifically counts medical and mental-health information as protected personal information.
One honest retention exception: if you have been a coaching client we keep your signed intake form and injury disclosures for 3 years after your last session, even if you ask for deletion. That is the record of what you told us before we programmed for you. We will delete everything else on request. We would rather tell you this than promise a clean deletion we will not perform.
We are not medical providers. Nothing we do is diagnosis or treatment.
How long we keep things
| Information | How long |
|---|---|
| Contact form messages | 12 months from your last message |
| Intake forms and health information | While you are a client, then 3 years after your last session |
| Trainerize account and coaching content | Deleted within 90 days of you closing it or asking us to |
| Order and payment records | 7 years, for tax and accounting |
| Email marketing list | Until you unsubscribe. Your address then goes on a permanent suppression list so we cannot accidentally email you again — that list is the only thing we keep forever, and it exists to protect you |
| Website analytics | Squarespace analytics cookies last up to 2 years |
Your choices and rights
Whoever and wherever you are, you can ask us to send you a copy of what we hold, correct anything wrong, delete your information (subject to the exceptions above), stop marketing emails, withdraw consent for health information, or object to how we use it.
How to ask: email parisnoir@barbells-and-bows.com with "Privacy Request" in the subject, or call (480) 463-4298.
How fast: we acknowledge within 10 business days and complete within 45 calendar days. If something genuinely takes longer we will tell you why and give a new date. No charge, and we will never treat you worse for asking.
On California and other state laws. The CCPA applies to businesses with over $25 million in annual revenue, or that handle the data of 100,000+ California residents, or that make half their revenue selling personal information. We are far below all three, so it does not legally apply. Arizona has no comprehensive consumer privacy law — bills have been introduced, none enacted as of 2026. We offer the rights above to everyone anyway.
On GDPR. We are a US business serving clients in Arizona. We do not advertise into the EU, price in euros, or ship there, so we most likely fall outside GDPR’s reach — simply having a website an EU resident can reach is not enough to trigger it. But if you are in the UK or EU, tell us and we will handle your request to GDPR standards regardless.
Cookies
Our site uses cookies set by Squarespace.
Necessary — the site does not work without them: crumb (security), CART (remembers your cart, two weeks), SiteUserInfo (keeps you logged in, up to three years), _ssid (fraud prevention, up to four years).
Analytics — how many people visited and what they read: ss_cid, ss_cvr, ss_cpvisit (up to two years), ss_cvisit, ss_cvt (30 minutes).
We do not run advertising or retargeting cookies. You can block or delete cookies in your browser; blocking the necessary ones will break checkout and logins. If we ever add Google Analytics or advertising pixels we will update this section first.
Children
Our services and website are for adults 18 and over. We do not knowingly collect information from anyone under 18 and we do not accept clients under 18. If you believe a minor has given us information, email us and we will delete it promptly.
Security — what we actually do
We would rather be straight with you than impressive.
- Card data never reaches us. Stripe collects it directly in its own PCI-certified fields.
- The website, checkout, forms and Trainerize all run over HTTPS.
- Squarespace, Stripe and Trainerize maintain their own security programs and encryption at rest. We rely on those defaults rather than running our own servers.
- Paris is the only person with access to client records. Accounts use strong, unique passwords with two-factor authentication turned on wherever the provider offers it.
- We do not keep client health information on paper, on unencrypted drives, or in shared cloud folders.
What we will not claim: no system is completely secure, and we are a small business, not a security company. If a breach affects your personal information we will notify you as Arizona law requires, within 45 days of discovery.
Changes
If we change this policy we update the date at the top and post the new version. For changes that meaningfully affect how we use your information — a new analytics tool, a new provider, a new purpose — we will email anyone on our list, and where the law requires consent, ask for it first.