Barbells and Bows LLC. Effective September 3, 2026.

Barbells and Bows LLC is a personal training business in Scottsdale, Arizona, run by Paris Wright. This explains what we do with personal information collected through barbells-and-bows.com and the tools we use to run the business. We are a one-person business — when this says "we," it means Paris Wright.

Questions or requests: parisnoir@barbells-and-bows.com · (480) 463-4298 · Barbells and Bows LLC, 2012 N Scottsdale Rd, Scottsdale, AZ 85257

The short version

  • We collect what you give us on our forms, plus basic order details and basic website statistics.
  • We never see or store your full card number. Stripe handles that.
  • We do not sell your information. We do not share it for advertising.
  • Health information gets stricter handling than anything else. That has its own section.
  • You can ask for a copy of your information or ask us to delete it, and we will respond.

What we collect, and where it comes from

We only collect through the specific places listed here. If it is not on this list, we are not collecting it.

1. Contact form (Squarespace) — your name, email, and your message. So we can answer you.

2. Client intake form (Squarespace) — name and contact details, training goals, training history, injuries, and other health information you choose to share. So we can design a program that is safe for you. See the Health Information section.

3. Purchases of digital training guides (Squarespace Commerce, payments by Stripe) — name, email, billing address, what you bought, when, amount, and the last four digits and brand of your card. We never receive your full card number, expiry date or security code — those go directly into Stripe’s own payment fields. Stripe is a PCI DSS Level 1 certified service provider, audited annually. To take payment, deliver your download, keep tax records, and handle refunds.

4. Coaching and consultations (Trainerize, operated by ABC Fitness Solutions, LLC) — name and contact details, session bookings, programs and logged workouts, progress notes, body metrics you enter, messages between us, and any photos or videos you upload. If you connect a fitness tracker to Trainerize yourself, that data flows in too. To deliver coaching and communicate with you.

5. Email marketing (Squarespace Email Campaigns) — email address, name if given, sign-up date and source, and whether you opened or clicked. To send training tips and updates — only if you opted in. Every email has an unsubscribe link.

6. Website statistics and cookies (Squarespace Analytics) — IP address, browser and device type, pages visited, how you arrived, and cart activity. To understand what people read and what sells. Google Analytics is not currently running on this site. If we add it, we will update this policy and say so first.

7. Social media — if you follow, message, comment or tag us on Instagram, TikTok or Facebook, we see what those platforms show us. We do not control those platforms and this policy does not cover them.

Why we are allowed to use it

What we use it forWhy we are permitted to
Answering your messageYou asked us to
Fulfilling an order and delivering a downloadTo perform our contract with you
Designing your training programContract, and your consent for health details
Sending marketing emailsYour opt-in consent — withdrawable any time
Keeping tax, payment and dispute recordsLegal and accounting obligations
Basic website statistics and site securityOur legitimate interest in running the business

For health information, our basis is your explicit consent, and you can withdraw it.

Who we share it with

These providers handle information on our instructions and may not use it for their own marketing.

ProviderWhat they handle
SquarespaceWebsite hosting, contact and intake form submissions, store orders, email campaigns, site analytics
StripeCard payments, refunds, chargebacks, fraud checks. PCI DSS Level 1 certified
Trainerize / ABC Fitness SolutionsCoaching accounts, programs, bookings, messages, progress and body metrics
Our email and phone providersCorrespondence between us

We may also disclose information if the law requires it, to protect someone’s safety, or if the business is ever sold (we would tell you first).

We do not sell your personal information. We do not share it with advertisers or data brokers. We do not use it to train AI models.

Health information — read this part

This is the most sensitive information we hold and we treat it differently.

What it is. Injuries, surgeries, pain, medical conditions, medications, pregnancy, physical limitations, body metrics, and anything else health-related you tell us on the intake form, in Trainerize, or in conversation.

We are not a HIPAA-covered business — and here is what that actually means. HIPAA applies to health plans, clearinghouses, and health care providers who transmit health information electronically for standard insurance transactions. A personal trainer who does not bill health insurance is none of those. So HIPAA does not apply to us, and we are not anyone’s business associate.

We do not treat that as permission to be careless. We hold your health information to these standards voluntarily:

  1. We only ask for what we need to program safely. You can decline any question. If declining means we cannot train you safely, we will tell you rather than guess.
  2. We do not share it with anyone except Squarespace and Trainerize as the systems it lives in. It does not go to Stripe, into email marketing, into analytics, or to any other third party.
  3. We never disclose it to family, employers or anyone else without your written permission, unless the law compels us.
  4. We do not post it. No case studies, progress photos, testimonials or social posts referencing your health, body or progress without your specific written consent for that specific use. Consent for one post is not consent for all posts, and you can withdraw it.
  5. We do not use it for marketing. Ever. Nothing you tell us about an injury will be used to target you with an offer.
  6. We keep it separate. Intake responses stay in the intake system and Trainerize. They are not copied into general contact lists or spreadsheets.
  7. You can withdraw consent at any time by emailing us. Withdrawing may mean we can no longer coach you safely.
  8. If your health information is ever exposed in a security incident, we will tell you — within 45 days of discovering it. Arizona’s breach notification law specifically counts medical and mental-health information as protected personal information.

One honest retention exception: if you have been a coaching client we keep your signed intake form and injury disclosures for 3 years after your last session, even if you ask for deletion. That is the record of what you told us before we programmed for you. We will delete everything else on request. We would rather tell you this than promise a clean deletion we will not perform.

We are not medical providers. Nothing we do is diagnosis or treatment.

How long we keep things

InformationHow long
Contact form messages12 months from your last message
Intake forms and health informationWhile you are a client, then 3 years after your last session
Trainerize account and coaching contentDeleted within 90 days of you closing it or asking us to
Order and payment records7 years, for tax and accounting
Email marketing listUntil you unsubscribe. Your address then goes on a permanent suppression list so we cannot accidentally email you again — that list is the only thing we keep forever, and it exists to protect you
Website analyticsSquarespace analytics cookies last up to 2 years

Your choices and rights

Whoever and wherever you are, you can ask us to send you a copy of what we hold, correct anything wrong, delete your information (subject to the exceptions above), stop marketing emails, withdraw consent for health information, or object to how we use it.

How to ask: email parisnoir@barbells-and-bows.com with "Privacy Request" in the subject, or call (480) 463-4298.

How fast: we acknowledge within 10 business days and complete within 45 calendar days. If something genuinely takes longer we will tell you why and give a new date. No charge, and we will never treat you worse for asking.

On California and other state laws. The CCPA applies to businesses with over $25 million in annual revenue, or that handle the data of 100,000+ California residents, or that make half their revenue selling personal information. We are far below all three, so it does not legally apply. Arizona has no comprehensive consumer privacy law — bills have been introduced, none enacted as of 2026. We offer the rights above to everyone anyway.

On GDPR. We are a US business serving clients in Arizona. We do not advertise into the EU, price in euros, or ship there, so we most likely fall outside GDPR’s reach — simply having a website an EU resident can reach is not enough to trigger it. But if you are in the UK or EU, tell us and we will handle your request to GDPR standards regardless.

Cookies

Our site uses cookies set by Squarespace.

Necessary — the site does not work without them: crumb (security), CART (remembers your cart, two weeks), SiteUserInfo (keeps you logged in, up to three years), _ssid (fraud prevention, up to four years).

Analytics — how many people visited and what they read: ss_cid, ss_cvr, ss_cpvisit (up to two years), ss_cvisit, ss_cvt (30 minutes).

We do not run advertising or retargeting cookies. You can block or delete cookies in your browser; blocking the necessary ones will break checkout and logins. If we ever add Google Analytics or advertising pixels we will update this section first.

Children

Our services and website are for adults 18 and over. We do not knowingly collect information from anyone under 18 and we do not accept clients under 18. If you believe a minor has given us information, email us and we will delete it promptly.

Security — what we actually do

We would rather be straight with you than impressive.

  • Card data never reaches us. Stripe collects it directly in its own PCI-certified fields.
  • The website, checkout, forms and Trainerize all run over HTTPS.
  • Squarespace, Stripe and Trainerize maintain their own security programs and encryption at rest. We rely on those defaults rather than running our own servers.
  • Paris is the only person with access to client records. Accounts use strong, unique passwords with two-factor authentication turned on wherever the provider offers it.
  • We do not keep client health information on paper, on unencrypted drives, or in shared cloud folders.

What we will not claim: no system is completely secure, and we are a small business, not a security company. If a breach affects your personal information we will notify you as Arizona law requires, within 45 days of discovery.

Changes

If we change this policy we update the date at the top and post the new version. For changes that meaningfully affect how we use your information — a new analytics tool, a new provider, a new purpose — we will email anyone on our list, and where the law requires consent, ask for it first.