Privacy policy
Last updated: 2026/09/17
1 Introduction
Fitnesskar ("we", the "Company") is committed to protecting the privacy of its users. This privacy policy explains how we collect, use, store and protect your personal information.
By using the Fitnesskar application, the website and the related services (the "Services"), you agree to the practices described in this policy.
This policy has been prepared in line with Iran's data protection laws, the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2 Information we collect
2.1 Information you provide:
- Account information: name, email address, phone number, password
- Profile information: profile picture, age, gender, height, weight
- Fitness goals: training goals, experience level, training preferences
- Training data: workout routines, records, progress
- Payment information: transaction details (card details are processed by the payment gateway)
2.2 Information collected automatically:
- Device information: device type, operating system, unique device identifier
- Usage information: features used, time spent, interactions
- Location information: approximate location based on IP address (not GPS)
- Log data: IP address, browser type, pages visited, access times
2.3 Information from other sources:
- Information from signing in with Google, Apple or Facebook (if you use them)
- Information from the App Store and Google Play for processing payments
3 How we use your information
We use your information for the following purposes:
3.1 Providing and improving the Services:
- Creating and managing your account
- Personalising workout routines and suggestions
- Tracking progress and providing statistics and reports
- Processing payments and managing subscriptions
- Providing customer support
3.2 Communication:
- Sending important notices about your account and the Services
- Sending workout reminders and motivational messages (with your consent)
- Informing you about new features and updates
- Sending special offers (with your consent)
3.3 Analysis and research:
- Analysing usage patterns to improve the Services
- Carrying out statistical research (anonymised data)
- Developing new features
3.4 Security and legal:
- Protecting the security of the Services and their users
- Detecting and preventing fraud
- Meeting legal requirements
4 Legal basis for processing (GDPR)
For users in the European Union, data is processed on the following bases:
- Performance of a contract: to provide the services you have requested
- Consent: to send marketing messages and optional notifications
- Legitimate interests: to improve the Services and maintain security
- Legal obligation: to comply with applicable laws
5 Sharing of information
We do not sell your personal information. Information is shared only in the following cases:
5.1 Service providers:
- Hosting and cloud infrastructure services
- Payment processors (with no access to card details)
- Email and notification delivery services
- Analytics tools (anonymised data)
5.2 Legal requirements:
- In response to a lawful order of a court or judicial authority
- To protect our rights, property or safety, or those of others
- To detect and prevent fraud
5.3 Business transfers:
In the event of a merger, acquisition or sale of assets, user information may be transferred. You will be informed if this happens.
5.4 With your consent:
In all other cases, we will obtain your explicit consent before sharing information.
6 Data retention
We keep your information for as long as your account is active or as long as it is needed to provide the Services:
- Account information: until you delete your account
- Training data: until the account is deleted
- Payment records: 7 years (as required by law)
- System logs: 90 days
- Anonymised analytics data: indefinitely
After you delete your account, your personal data is deleted within 30 days, unless we are legally required to keep it.
7 Data security
We use technical and organisational security measures to protect your information:
Technical measures:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Password hashing with secure algorithms
- Firewalls and intrusion detection systems
- Regular software updates and security patches
Organisational measures:
- Restricted staff access to user data
- Security training for staff
- Access control policies
- Periodic security assessments
Please note: No system is 100% secure. We do everything we can to protect your data, but we cannot guarantee absolute security.
8 Your rights
You have the following rights in relation to your personal information:
8.1 Right to rectification:
You can correct information about you that is inaccurate or incomplete.
8.2 Right to erasure (right to be forgotten):
You can ask for your personal information to be deleted. This can be done through the account deletion page.
8.3 Right to withdraw consent:
You can withdraw your consent to data processing at any time.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
9 Cookies and tracking technologies
We use the following technologies to improve the user experience:
9.1 Essential cookies:
Required for the basic operation of the website and the application.
9.2 Analytics cookies:
Help us understand how users use our Services (can be disabled).
9.3 Functional cookies:
Remember your preferences.
Managing cookies:
You can manage or disable cookies through your browser settings. Please note that disabling some cookies may affect how the Services work.
10 Third-party services
We use the following third-party services:
- Google Analytics: to analyse use of the Services
- Firebase: for notifications and app analytics
- Apple/Google Sign-In: for authentication
- Payment gateways: to process transactions
Each of these services has its own privacy policy, which we recommend you read.
11 Children's privacy
Our Services are not designed for anyone under 13. We do not knowingly collect personal information from children under 13.
If you become aware that a child under 13 has given us personal information, please contact us so that we can take the necessary action.
For users aged 13 to 18, the consent of a parent or legal guardian is required.
12 International data transfers
Your data may be stored and processed on servers outside your country. We make sure that:
- Data is transferred in line with security standards
- Data protection agreements are in place with service providers
- An appropriate level of protection is provided for your data
13 Rights of California residents (CCPA)
If you are a California resident, you have the following additional rights:
- Right to know: to know what information is collected and how it is used
- Right to delete: to ask for personal information to be deleted
- Right to opt out of sale: we do not sell personal information
- Right to non-discrimination: to receive the same service regardless of exercising your privacy rights
14 Changes to this policy
We may update this policy. Important changes will be announced through:
- A notice in the application
- An email to your registered address
- An update to the "Last updated" date at the top of this page
so that you are informed. Continued use of the Services after a change has been announced means you accept the new policy.
15 Contact us
For questions, concerns or requests about privacy, contact us:
- Email: [email protected]
- Website: fitnesskar.com
- Response time: within 30 working days at most