2. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve our platform and services.
- Process transactions and send related information such as invoices and payment confirmations.
- Send service-related communications including workout reminders, payment alerts, and system announcements.
- Personalise the platform experience — for example, surfacing relevant exercises or recommending nutrition targets.
- Monitor and analyse usage patterns to improve our features.
- Detect, investigate, and prevent fraudulent activity and security breaches.
- Comply with legal obligations.
4. Data Security
We implement industry-standard security measures to protect your data, including:
- TLS/HTTPS encryption for all data in transit.
- AES-256 encryption for sensitive configuration data at rest (Fernet encryption for API keys and secrets).
- Row-level security (RLS) in Supabase PostgreSQL to ensure gym data is strictly isolated between tenants.
- JWT-based authentication using ES256 (ECDSA) standards.
- Rate limiting and audit logging for all sensitive operations.
No method of transmission over the internet is 100% secure. We strive to protect your information but cannot guarantee absolute security.
5. Your Rights (GDPR / CCPA)
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to certain processing activities, including direct marketing.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at privacy@fitgly.com. We will respond within 30 days.
6. Cookies Policy
We use cookies and similar tracking technologies to:
- Essential cookies: Required for authentication sessions and core platform functionality.
- Analytics cookies: Help us understand how the platform is used so we can improve it (e.g. page view counts, feature usage).
- Preference cookies: Remember your settings such as language and theme preferences.
You can control cookie settings in your browser. Disabling essential cookies may impact platform functionality.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Specific retention periods:
- Account data: Retained until account deletion, plus up to 90 days for backup purposes.
- Financial records: Retained for 7 years to comply with tax and accounting regulations.
- Fitness & health data: Retained while your account is active. Deleted within 30 days of account deletion.
- Audit logs: Retained for 12 months for security and compliance purposes.