CLIENTFITCLIENTFIT

Privacy Policy

Last updated: March 27, 2026

1

Data Controller

The data controller for personal data is ClientFit, managed by Jose Luis Calderon Ludena.

Contact email: ludenajluis@gmail.com

2

Types of Data Collected

Account Data

  • First and last name
  • Email address
  • Profile picture (if provided via Google authentication)

Client Data (entered by the PT)

  • Client name
  • Physical data (weight, height, body fat, BMI)
  • Notes and goals
  • Progress history

This data is entered and managed directly by the user (personal trainer).

Payment Data

  • Managed exclusively by Stripe
  • ClientFit does not store credit card data

Technical Data

  • IP address
  • Browser and device
  • Access logs (for security and abuse prevention)
3

Purpose of Processing

Data is used to:

  • Provide and manage the ClientFit service
  • Manage authentication and user access
  • Manage subscriptions and payments
  • Send transactional emails (login, invoices, notifications)
  • Ensure security and prevent unauthorized access
4

Legal Basis

Processing is based on:

  • Contract performance — use of the service
  • Consent — any marketing communications
  • Legitimate interest — security, fraud prevention
5

Data Retention

Data is retained:

  • For the duration of the active account
  • Until a deletion request is made by the user

You can delete your account at any time from the settings section.

6

Data Sharing

Data may be processed through trusted third-party services:

  • Stripe — payment management
  • Resend — email delivery
  • MongoDB Atlas — database
  • Vercel — hosting

Data is not sold to third parties.

7

Cookies

ClientFit uses exclusively:

  • Technical cookies (session, authentication)
  • Security cookies

It does not use profiling or advertising cookies.

8

User Rights (GDPR)

You have the right to:

  • Access your data
  • Modify or correct your data
  • Request deletion (right to be forgotten)
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time

To exercise these rights: ludenajluis@gmail.com

9

Data Security

We adopt appropriate technical and organizational measures:

  • HTTPS connections
  • Secure authentication (OAuth)
  • Rate limiting protection
  • Sensitive data hashing
  • Limited data access
10

User Responsibility

Users (personal trainers) are responsible for the data of their clients entered on the platform and must ensure they have the necessary consent.

11

Policy Changes

This Privacy Policy may be updated. Changes will be published on this page with a new date.