Gympulsed

Privacy Policy – GYMPULSED

Last updated: June 3, 2026

This Privacy Policy describes how we collect, use, and disclose your information when you use GYMPULSED (the "Service") and explains your privacy rights. By using the Service, you agree to this Privacy Policy and our Terms and Conditions.

1. Interpretation and definitions

Capitalized terms have the meanings below, whether singular or plural.

  • Account — your registered profile used to access the Service.
  • Application — the GYMPULSED Progressive Web App and, where available, the native mobile app.
  • Company / Provider — STIRBAT IT ENTERPRISES SRL, registered office at BLD. UNIRII NR.57 CAMERA 1 BL.A1 ET.5 AP.17, Focsani, Vrancea, Romania ("we", "us", "our").
  • Personal Data — information relating to an identified or identifiable individual.
  • Service — the Application and related websites, backend, and support channels we operate for GYMPULSED.
  • Service Provider — a third party that processes Personal Data on our behalf to help operate the Service.
  • Usage Data — data collected automatically through use of the Service (e.g. diagnostics, analytics events, IP address).
  • You — the individual using the Service.

2. Personal Data we collect

2.1 Account and profile data

We may collect, for example:

  • Email address and authentication identifiers (Firebase Auth)
  • Display name or profile fields you provide
  • Partner link status and partner-related metadata needed to operate challenges
  • Communication preferences (e.g. push notification opt-in)

2.2 Location and gym check-in data

To verify gym check-ins for challenges, we process location data when you initiate a check-in, including coordinates used to confirm you are within the geofence of the gym you selected. We may also store gym place identifiers, gym name, and address information you choose (including via Google Places search).

Important: we do not use location data for advertising or sell it to data brokers. Location is used to operate check-ins, challenge settlement, fraud prevention, and related Service features. You can control location permissions through your device or browser settings; without location permission you may be unable to check in.

GYMPULSED does not rely on Apple HealthKit or step-count data for challenge verification on our current product path. We use location-based check-in validation instead.

2.3 Payment and payout data

Challenge Deposits, settlement, and payout setup are processed by Stripe. We do not store full payment card numbers on our servers. Stripe collects and processes payment method details, Connect onboarding data (including bank account information for payouts), and identity verification where required. We receive and store references needed to operate the Service, such as Stripe customer IDs, connected account IDs, payment intent status, transaction amounts, and payout status metadata.

2.4 Challenge and transaction records

We store challenge configuration, check-in records, escrow/settlement status, and related financial metadata required to operate accountability challenges and comply with legal obligations.

2.5 Subscription data (platform access)

Pro subscription status may be processed via Stripe Billing on the web and/or Apple In-App Purchase and RevenueCat on iOS. We store entitlement fields on your user profile (e.g. subscription status, period end) as written by our backend; we do not use subscription data for challenge settlement logic beyond access control.

2.6 Push notification tokens

If you enable push notifications, we collect a device push token and your notification preferences to send transactional messages (e.g. challenge updates). Tokens are removed when you disable notifications or delete your account, subject to technical retention limits.

2.7 Usage Data and analytics

We use Google Analytics for Firebase (GA4) on supported clients to understand product usage (e.g. sign-up funnels, screen views, feature events). In v1 we do not send your Firebase Auth UID, email, payment identifiers, or precise check-in coordinates in analytics event parameters. Analytics may include coarse event names, device/browser diagnostics, and IP-derived region data processed by Google according to their policies.

On the web, analytics initializes when supported without a separate in-app consent gate (see Section 9). On iOS native builds, analytics follows our mobile configuration documented for App Store privacy labels.

2.8 Error monitoring (web)

In production web builds we may use Sentry for error reporting and limited session diagnostics to improve reliability. We configure Sentry to avoid sending unnecessary personally identifiable information by default.

2.9 Fraud prevention

We may process device signals, IP addresses, timestamps, and payment or account correlation metadata (including identifiers returned by Stripe) to detect abuse, duplicate accounts, location spoofing, and Terms violations. This data is used for security and enforcement, not for advertising.

2.10 Cookies and similar technologies (web)

Our web app uses technologies necessary for authentication, security, and basic functionality (including Firebase session mechanisms). We do not use third-party advertising cookies on the marketing site. Analytics on the PWA is implemented via Firebase as described above.

3. How we use Personal Data

We use Personal Data to:

  • Provide, maintain, and improve the Service
  • Create and manage your Account and partner linking
  • Operate challenges, check-ins, Deposits, Settlement, and payouts
  • Process subscriptions and platform access
  • Send transactional communications (email and push where enabled)
  • Prevent fraud, abuse, and violations of our Terms
  • Comply with legal, tax, and accounting obligations
  • Analyze aggregated usage to improve features (analytics)
  • Respond to support requests and disputes

We do not sell Personal Data. We do not use check-in location data or challenge outcomes for third-party advertising profiles.

4. Retention

We retain Personal Data only as long as needed for the purposes above and to comply with law. Indicatively:

  • Account and challenge data: while your Account is active and for a limited period afterward for disputes, fraud prevention, and legal compliance
  • Check-in and location records: for the challenge lifecycle and a reasonable period thereafter for settlement disputes and anti-abuse investigations
  • Financial and transaction records: as required by applicable tax, accounting, and payment regulations (often several years)
  • Analytics: according to Google Analytics / Firebase retention settings configured in our Google accounts
  • Push tokens: while notifications are enabled or until Account deletion

You may request deletion (Section 8), but we may retain certain records where we have a legal obligation or legitimate need (e.g. financial records, fraud logs).

5. Sharing with Service Providers

We share Personal Data with vendors that help us operate the Service, including:

  • Stripe — Deposits, captures, Connect onboarding, payouts, and billing (see Stripe's privacy policy)
  • Google / Firebase — authentication, database, cloud functions, analytics (Firestore, Auth, Cloud Functions, Analytics)
  • Google Places — gym search and place details when you use location search features
  • Apple — push notification delivery (APNs) and In-App Purchase on iOS
  • RevenueCat — subscription entitlement sync on iOS (where used)
  • Vercel — hosting and delivery of the web application
  • Sentry — error monitoring on production web (where enabled)

These providers process data under our instructions and their own terms, only to the extent needed to provide their services to us.

6. Other disclosures

We may disclose Personal Data if required to:

  • Comply with law, regulation, or valid legal process
  • Protect the rights, property, or safety of users, the public, or us
  • Investigate fraud, security issues, or Terms violations
  • Complete a merger, acquisition, or asset sale (with notice where required)

7. International transfers

Personal Data may be processed in the European Union (including Firebase resources we configure in EU regions) and in other countries where our Service Providers operate (e.g. United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by vendors.

8. Your choices and deletion

You can update certain profile information in the app. You may request access, correction, or deletion by contacting gympulsed@stirbatitenterprises.com with "Privacy Request" in the subject line.

Account deletion may be available in-app (where implemented). Deletion may be delayed while active challenges settle or payouts complete. We may retain data as described in Section 4.

You can withdraw location or notification permissions in device settings; this may limit check-ins or push delivery.

9. Security

We use industry-standard measures such as encryption in transit (TLS), access controls, and vendor security practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

10. Legal bases (EEA / UK users)

If you are in the EEA or UK, we process Personal Data based on:

  • Contract — to provide the Service, challenges, payments, and support
  • Legal obligation — tax, accounting, and regulatory requirements
  • Legitimate interests — fraud prevention, security, and product improvement, balanced against your rights
  • Consent — where required (e.g. optional marketing, push notifications where consent applies, location permissions via your device)

Product analytics on supported clients is described in Section 2.7; confirm lawful basis wording with counsel for Italy/EU launch.

11. Your privacy rights

Depending on your location, you may have rights to access, rectify, erase, restrict, object, or port your Personal Data, and to withdraw consent where processing is consent-based. To exercise rights, email gympulsed@stirbatitenterprises.com. You may lodge a complaint with your local supervisory authority.

California residents (CCPA/CPRA): we do not sell Personal Data. You may have rights to know, delete, and non-discrimination; contact us with "CCPA Request" in the subject line.

12. Data breach notification

If a breach affecting your Personal Data occurs, we will notify you and regulators as required by applicable law, including within 72 hours where GDPR requires notification to authorities.

13. Children

The Service is not directed to anyone under 18. We do not knowingly collect Personal Data from minors. If you believe a minor provided data, contact us and we will take steps to delete it.

14. Third-party links

The Service may link to third-party sites (e.g. Stripe onboarding). We are not responsible for their privacy practices. Review their policies before providing data.

15. Changes

We may update this Privacy Policy. We will post the new version on this page and update the "Last updated" date. Material changes may also be communicated by email or in-app notice where appropriate.

16. Contact

Privacy and data protection inquiries: gympulsed@stirbatitenterprises.com (subject: "Privacy Request")

Data controller: STIRBAT IT ENTERPRISES SRL — BLD. UNIRII NR.57 CAMERA 1 BL.A1 ET.5 AP.17, Focsani, Vrancea, Romania

© 2026 STIRBAT IT ENTERPRISES SRL. All rights reserved.

← Back to homeTerms and Conditions