Privacy Policy
This draft explains the data flows built into the Fit Fit City website. It must be updated with the real operator identity, hosting region choices, retention periods and any analytics/marketing tools used at launch.
1. Controller
Before launch, insert the full legal identity and contact details of the data controller.
2. Data we collect
- Account data: name, email address, password hash, account status and account creation date.
- Membership data: payment-provider subscription identifiers and membership status. Full payment-card details are handled by the payment provider rather than stored in the Fit Fit City database.
- Optional progress data: weight, waist, chest, hips, arm and thigh measurements, date, unit system and notes you choose to enter.
- Security data: session identifiers and basic server/security information needed to operate and protect the service.
- Support data: information you provide if you contact us.
3. Why we use data
- to create and authenticate accounts;
- to confirm paid membership and enforce the member paywall;
- to provide the progress-tracking feature;
- to keep the service secure and prevent abuse;
- to comply with legal, accounting and consumer obligations;
- to respond to support requests.
4. Lawful bases
The final production policy should identify the lawful basis for each activity in the markets served. Likely bases may include performance of a contract for account/membership administration, legitimate interests for proportionate security and service operation, legal obligation for required records, and explicit consent for optional health-related progress data where special-category rules apply.
5. Progress data and explicit consent
The progress tracker is optional. The current sign-up screen allows a user to explicitly consent to storage of optional weight and measurement data. A user who does not consent should not be required to use the tracker. If consent is the lawful basis, users must be able to withdraw it as easily as it was given; deletion of progress entries or the account should be supported in the production product.
6. Payments
Payment details are processed by providers such as Stripe and PayPal. Those providers act under their own privacy policies for parts of the processing. Fit Fit City stores only the identifiers and membership status needed to determine access.
7. Hosting and processors
The supplied build is designed for Cloudflare Pages/Workers and Cloudflare D1. Before launch, document the specific Cloudflare services and data-location/transfer arrangements selected for the account. Add any email provider, analytics, customer-support, advertising or marketing platforms actually used.
8. International transfers
If personal data is transferred outside the UK/EEA or another protected jurisdiction, the operator must use a lawful transfer mechanism where required and explain it in the final policy.
9. Retention
Do not keep personal data longer than necessary. Before launch, define concrete retention periods for inactive accounts, audit/security logs, payment records and support correspondence. Progress data should be deleted when the account is deleted unless a legal requirement requires otherwise.
10. Security
The supplied build uses hashed passwords, secure HTTP-only session cookies and server-side membership checks. No internet service is completely secure. Production launch should also enable Cloudflare security controls, rate limiting/anti-bot controls where appropriate, access logging, secret management and tested backups.
11. Cookies
The core build uses a strictly necessary secure session cookie to keep members logged in. If analytics, advertising pixels or non-essential cookies are later added, the operator must implement any consent mechanism required by applicable law and update this policy.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent and complain to a data-protection authority. The final policy should provide a working contact route for exercising those rights.
13. Marketing
The supplied build does not include email marketing consent or marketing automation. If marketing is added, use a separate opt-in where required and do not bundle marketing consent into membership acceptance.
14. Children
The supplied membership is intended for adults aged 18 and over. The operator should not knowingly collect children's progress or health-related data through this version of the service.
15. Changes
This policy may be updated as the service changes. Material changes should be communicated where required.
16. Contact
For privacy questions, email [email protected]. Before public launch, add the operator’s legal postal address and the applicable supervisory-authority information where required.