FITHR CLUB · POLICIES
Privacy Policy
Effective September 29, 2026
Who this policy covers
This policy explains how FITHR Club handles personal information when you use our website, create an account, complete onboarding, or use enabled payment and connected-account features. FITHR Club is operated by FITHR LLC. Contact: christian@neilcreative.com.
Information we collect
Account information: Google account identifier, name, email address, email verification status and profile information supplied through sign-in. Onboarding information: first and last name, date of birth, mobile phone number, SMS acknowledgement and its time and wording, selected fitness goal and biggest challenge. Please do not submit medical records, diagnoses or other information that is unnecessary for training preferences.
Payments and technical information
When payments are enabled, we store purchase and subscription identifiers, selected plans, prices, payment status, billing periods, session allowances, and refund or dispute status. Stripe collects payment details through its secure embedded forms. FITHR does not store complete payment card numbers or card security codes. We may display limited details such as card brand, last four digits and expiry. Hosting and authentication services process information such as IP address, browser/device information, request logs and security events to operate and protect the service.
Connected Google and Zoom accounts
Google sign-in is separate from an optional calendar connection. Authorizing a calendar connection provides identity information and grants permission to check availability and manage events on calendars you own. Where the scheduling feature is enabled, calendar data is used for busy-time checks, booking updates and Google Meet links. Optional Zoom authorization supplies account identity and permission to manage meetings for scheduled sessions. We store provider account identifiers, connection status and encrypted authorization tokens. Some scheduling and meeting features are still being prepared; connecting an account does not mean every feature is available. FITHR does not request access to Gmail messages or Zoom recordings in the current integration.
How information is used
We use information to authenticate users, maintain accounts and preferences, deliver enabled coaching and scheduling features, process and reconcile purchases, manage renewals and cancellations, answer support requests, prevent abuse, and comply with applicable obligations. We do not sell personal information or use connected Google account data for advertising or training general-purpose AI models.
Google data use
Data received from Google APIs is used only for the account and connected-calendar features described here. Transfers are limited to providing those features with your consent, security purposes, legal requirements, or other transfers permitted by Google’s user-data rules. Human access to connected Google data is limited to your affirmative permission, security investigations, applicable legal requirements, or permitted aggregated internal operations. Our use of Google API data is subject to the Google API Services User Data Policy, including its Limited Use requirements.
Who receives information
Supabase provides authentication and database services; Vercel hosts the app and its backend; Stripe processes enabled payments. Google provides sign-in and, if authorized, calendar/meeting services; Zoom provides an optional meeting integration. FITHR operates as one administrative team. Authorized administrators may access the same client, plan, payment, booking and connected-service records as needed to operate FITHR and provide the services a client selects. Client records are not shared with other clients through this administrative access. Meeting and event details may be shared with the participants involved. Google Fonts receives network information when the site loads its fonts. We may disclose information where needed to address fraud or security incidents, respond to lawful requests, or protect legal rights. Providers also process information under their own privacy notices. PayPal and email delivery services will be disclosed and configured before those features are enabled.
Browser storage and private calendar links
FITHR uses browser storage to maintain sign-in, selected-plan/onboarding flow and appearance preferences, and a temporary secure cookie to protect account-connection requests. Clearing storage can sign you out or reset preferences. Private iCal feed links act like access keys: anyone with a valid link may read its calendar feed. Share them only with trusted calendar apps; use the connection controls to rotate or disable a link.
Retention and security
We retain information as needed to provide the service, maintain required financial and security records, resolve disputes and meet applicable retention obligations. Different records may be retained for different periods. We use access controls and encryption for stored provider tokens, but no service can guarantee absolute security. Removing a connection stops future authorized use through that connection; it does not automatically delete all existing booking or legally required transaction records.
Your choices and requests
You can sign out, disconnect supported accounts in Connections, and revoke Google or Zoom access from the provider’s account settings. You may request access, correction, a copy of your information, account deletion or assistance with a connection by emailing christian@neilcreative.com. We may verify your identity before fulfilling a request and explain any records we must retain. Where local law gives additional privacy rights, those rights remain available. Cancel any active subscription separately before requesting account deletion so the billing outcome can be confirmed.
Processing locations, age and updates
Our service providers may process information outside your country. If you believe a child has provided personal information without appropriate authorization, contact us so we can review and address it. We will update this policy when practices change and provide additional notice or seek consent where required. New uses of connected-account data will not be silently added under this policy.