Privacy Policy

Last updated: June 2026

1. Data Controller

The data controller is the developer of the MoveCare application, reachable at: movecare.mc@gmail.com.

As controller, they are responsible for all personal data processing operations described in this policy.

2. Data Collected

The app collects and processes the following categories of data:

  • Account data: email address, display name, user ID
  • Fitness and training data: workout programs, exercise logs, performance metrics
  • Nutrition data: meal logs and dietary information (if used)
  • Coach–client relationship data: assigned plans, coach messages, shared content
  • Payment data: subscription status processed via Stripe (no card details stored by us)
  • Technical data: device type, operating system, app version, crash logs

3. Legal Basis and Purposes

Processing is based on:

  • Contract performance (Art. 6(1)(b) GDPR): to provide the core service (account management, training plans, coach–client features)
  • Legitimate interest (Art. 6(1)(f) GDPR): to improve app stability, prevent abuse, and send service-related notifications
  • Legal obligation (Art. 6(1)(c) GDPR): to retain billing records as required by law

Fitness and health-related data (e.g. body metrics, health conditions) may constitute special category data under Art. 9 GDPR and is processed only with your explicit consent.

4. Retention Periods

  • Account and fitness data: retained for the duration of your account, then deleted within 90 days of account deletion
  • Billing and payment records: retained for 10 years as required by Italian and EU tax law
  • Crash logs and technical diagnostics: retained for up to 12 months

You may request deletion at any time by contacting us at movecare.mc@gmail.com.

5. Third-Party Processors

Your data is processed by the following sub-processors under data processing agreements:

  • Google LLC / Firebase (USA): authentication, cloud database, file storage, crash analytics. Firebase is certified under EU Standard Contractual Clauses.
  • Stripe Inc. (USA): payment processing and subscription management. Stripe is certified under EU Standard Contractual Clauses.

No data is sold or shared with third parties for marketing purposes.

6. International Data Transfers

Firebase and Stripe servers are located in the United States. Data transfers to the US are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of protection for your personal data.

For more information:

https://firebase.google.com/support/privacy

7. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (right to be forgotten) (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time, without affecting prior processing
  • Lodge a complaint with your national data protection authority (in Italy: Garante per la protezione dei dati personali – www.garanteprivacy.it)

To exercise your rights, contact: movecare.mc@gmail.com

8. Contact

For any privacy-related request or question, contact the data controller:

movecare.mc@gmail.com