Effective Date: 22 April 2026
Last Updated: 11 September 2026
This Privacy Policy explains how FitBond Inc Ltd ("FitBond", "we", "us", "our") collects, uses, shares, and protects personal data when you use the FitBond mobile application and related services (the "Service").
FitBond Inc Ltd is a company registered in England and Wales (company number 17020972), with its registered office at Flat 23, 112 Candlemakers Apartments, York Road, London SW11 3RS, United Kingdom, and is the data controller responsible for your personal data for the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — where applicable — the EU General Data Protection Regulation (EU GDPR) (together, "Data Protection Law").
If you have any questions about this Policy or wish to exercise your rights, contact us at:
Email: privacy@fitbond.co.uk
1. Summary
- We collect data you provide (account, profile, onboarding answers), data generated by your use of the Service (Bonds, activity, nutrition logs), and data from connected third parties (currently Fitbit, Strava, and Whoop; Garmin is planned but not yet live).
- Apple Health activity data used for Bond verification stays on your device; if you enable weight tracking, body-mass readings are uploaded to your account to provide weight history and trends.
- We use your data to operate the Service, personalise Bond Goals, process payments, prevent fraud, and improve the Service.
- We share data only with vetted processors (AWS, Stripe, RevenueCat), connected integrations you authorise, charities you select, and where required by law.
- You have strong rights under UK GDPR, including access, erasure, rectification, objection, and portability. See Section 10.
- You must be 18 or older to use the Service.
2. Data We Collect
2.1 Information You Provide Directly
Account registration — email address, chosen authentication provider (email/password via AWS Cognito, Apple Sign-In, or Google Sign-In), password (stored only by our identity provider in hashed form — FitBond never sees your password).
Profile information — first name, last name, date of birth, gender/biological sex, verified phone number, profile photograph.
Phone verification — during onboarding, you send a phone number to FitBond so Twilio Verify can deliver and check a one-time SMS code. While a code is pending, FitBond temporarily retains a protected phone hash and request timestamp to bind the verification to your account. After approval, FitBond stores the canonical E.164 phone number, a protected phone hash used to prevent duplicate accounts and match invitations, and the verification timestamp. The pending verification record is then deleted. We do not use the number for advertising or unrelated marketing.
Contact invitations — your address book is read on-device and is not uploaded as a list. When you explicitly select one contact for a Head-to-Head or Team invitation, that selected contact's display name and phone number are sent to FitBond for that invitation. The normalised phone number may be sent to Twilio when SMS delivery is enabled. For a Head-to-Head invitation, the selected contact details are not retained after the invitation attempt and the opponent place remains an open first-come-first-served place. For a Team invitation, FitBond removes the raw selected contact details before storing the Bond but retains a protected phone hash, the last four digits, invitation token and status, and the inviting account so the recipient can claim the correct reserved place and FitBond can prevent abuse.
Onboarding answers — responses to questions about your primary fitness goal, height, weight (current and target), activity level, exercise history, dietary preferences, behavioural preferences (used to assign you to a motivational "cohort"), health status, and related context. Where possible we minimise what we store — for example, we do not need to know specific medical diagnoses.
Bond inputs — the Goals, deposit amounts, durations, and Bond types you create or join; friend invitations; team membership.
Nutrition & food logs — foods you log (manually, via search, or via barcode scan), meal type, servings, notes, and nutritional macros associated with each entry.
Communications and waitlist — any message you send to us (support emails, chat messages, feedback) and, where you opt in on the website, your email address, consent timestamp, signup placement, and campaign attribution used for the pre-launch waitlist.
2.2 Information Collected Automatically
Device & technical data — device model, operating system and version, app version, language, locale, time zone, IP address, device identifiers (including APNs push token), crash logs, and diagnostic data.
Usage data — screens viewed, features used, Bond interactions, session timestamps, referral code usage.
Location data — only where required by a feature you are using (gym geofencing for Gym Bonds, geo check-in for Event Bonds, geo-located Marketplace offers). You control location access through your device settings.
2.3 Fitness & Health Data
Apple Health (HealthKit) — if you grant permission, we read steps, distance, calories, workouts, body mass, and related metrics. Activity data used to calculate Bond progress is processed on-device; only the resulting Bond progress is sent to our servers. Body-mass readings are the explicit exception: when you use weight tracking, the app uploads the date, weight in kilograms, and scale timestamp to your FitBond account so it can maintain your weight history, trend, averages, and goal projection across devices. Manual and HealthKit weight entries are stored separately, and you can revoke Health access at any time to stop future syncing.
Fitbit, Strava, and Whoop — if you connect one of these accounts, we access and store on our servers the fitness data you authorise (activity, workouts, steps, distance, strain, recovery, and related metrics) to track progress on active Bonds. Data is synchronised periodically. We request only the scopes needed to verify your Bonds, and you can disconnect an account at any time to stop further syncing. Garmin is not live: no Garmin data is collected unless and until the integration is enabled and you expressly connect it.
Gym geofencing — your device detects gym visits via location services. Individual verification events may include a timestamp, coordinate, and accuracy so the server can validate that event against your selected gym. After validation, FitBond retains the gym identifier/location, event source, timestamp, and accuracy for the session audit, but does not retain your submitted event coordinate or build a location trail.
2.4 Payment & Financial Data
When you make a payment or receive a payout, we collect limited payment information necessary to process the transaction. Full card details are collected and held directly by Stripe, our payment processor. FitBond does not see or store your full card number. We retain only:
- Stripe customer identifier and payment intent identifiers;
- For bank withdrawals, country of residence, Stripe recipient and payout-method references, bank name and last four digits, quotes, currency amounts, payout identifiers and status;
- Last four digits of card, card brand, expiry;
- Wallet balance and transaction history (top-ups, Deposit payments, payouts, withdrawals, charity donations);
- Subscription status and identifiers (from the Apple App Store via RevenueCat).
For Coupon bank withdrawals, we send your account name, email and selected country to Stripe to establish the recipient. Stripe collects your bank details and any additional identity information directly in its hosted form. FitBond does not collect or store full bank account numbers or identity documents through this flow. We retain the limited recipient and transaction evidence needed to process withdrawals, investigate failures or returns and reconcile outstanding claims, including after account closure. Unused quote data and recipient contact snapshots are removed during closure; necessary payout evidence remains subject to the financial-record retention policy.
2.5 Third-Party Sign-In & Social Integrations
Apple Sign-In / Google Sign-In — when you sign in with Apple or Google we receive the profile attributes you choose to share (typically name and email, or a relay email).
Legacy social connections — Shame Bonds are no longer offered. If a pre-existing Bond or account still has an authorised Twitter/X, Facebook, Instagram, or TikTok connection, we may retain the access token and minimal identifier until it is disconnected or no longer needed. New sharing uses the platform share sheet and does not require FitBond to post to your social account.
2.6 Data From Referrals
If someone refers you, your account will be associated with their referral code. We record the referrer, the referred user, and the time of use.
2.7 Special Category Data
Some data we process — health and fitness data, and data revealing biological sex — is "special category data" under UK GDPR Article 9. We process this data only on the basis of your explicit consent and only where necessary to provide the Service you have requested.
3. How We Use Your Data & Lawful Basis
Under UK GDPR Article 6, every processing activity requires a lawful basis. Below we set out each purpose and the lawful basis we rely on.
| Purpose | Lawful Basis |
|---|---|
| Create and manage your account; provide the Service you have requested | Contract (Art. 6(1)(b)) |
| Personalise Bond Goals, recommend Bond types, assign motivational cohort | Contract (Art. 6(1)(b)) + explicit consent (Art. 9(2)(a)) for health data |
| Track Bond progress using Fitbit / Strava / Whoop data | Contract + explicit consent for health data |
| Maintain weight history and trends from manual or Apple Health body-mass readings | Contract + explicit consent for health data |
| Process payments, captures, payouts, refunds, and chargebacks | Contract; Legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Manage subscriptions and trial periods | Contract |
| Verify phone ownership, prevent duplicate accounts, and match user-initiated invitations | Contract; Legitimate interests in fraud prevention |
| Deliver a user-initiated invitation to one selected contact and reserve the correct Bond place | Contract; Legitimate interests in service security and fraud prevention |
| Operate Marketplace Points, settlement Coupons, and the referral programme | Contract |
| Process charity donations | Contract (with user-directed instruction) |
| Detect and prevent fraud, abuse, data manipulation, and money laundering | Legitimate interests (Art. 6(1)(f)); Legal obligation |
| Send transactional emails and push notifications about your account and Bonds | Contract |
| Send marketing communications about new features and offers | Consent (Art. 6(1)(a)) — you can withdraw at any time |
| Manage the pre-launch website waitlist and send launch access | Consent (Art. 6(1)(a)) |
| Analyse usage to improve the Service (in aggregated / pseudonymised form where possible) | Legitimate interests |
| Respond to support enquiries | Contract; Legitimate interests |
| Enforce our Terms of Service and resolve disputes | Legitimate interests |
| Comply with legal obligations (regulatory, tax, law enforcement requests) | Legal obligation |
Our legitimate interests. Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interest (for example, preventing fraud) is not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests — see Section 10.
4. Who We Share Your Data With
We share your data only where necessary, and only with the following categories of recipients.
4.1 Service Providers (Processors)
These providers process data on our behalf under written data processing agreements that meet UK GDPR requirements:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Website and application hosting, secrets management, caching | United Kingdom (UK West / UK South) |
| Amazon Web Services (AWS) | Cloud hosting, database storage, authentication (AWS Cognito), file storage | UK / EU regions where available; otherwise USA (EU Standard Contractual Clauses) |
| Stripe Payments Europe, Ltd. | Payment processing, card storage, bank payout onboarding, identity checks and payouts | Ireland / USA (SCCs) |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Charity payout processing and payee identity verification | Luxembourg / USA (SCCs) |
| RevenueCat, Inc. | Apple App Store subscription entitlement management | USA (SCCs) |
| Twilio Ireland Limited | SMS delivery and phone-number verification | Ireland / USA (SCCs) |
| Loops | Consented waitlist and product email delivery | USA (SCCs / applicable transfer safeguards) |
| Functional Software, Inc. (Sentry) | Application error and performance monitoring; may incidentally process data contained in error reports | USA (SCCs) |
| Apple Push Notification service (APNs) | Push notification delivery | USA (SCCs) |
| Mongoose Atlas / MongoDB (if used) | Database hosting | UK / EU regions where available |
| ip-api.com (geolocation) | IP → country lookup for analytics and compliance | EU |
| Food and nutrition databases (e.g. USDA FoodData Central, Open Food Facts, FatSecret) | Food item lookup for nutrition logging | Varies |
| Email / SMS delivery providers (where used) | Transactional communications | USA / EU (SCCs) |
4.2 Integrations You Connect
When you connect a third-party account, data flows between FitBond and that service according to the permissions you grant:
- Fitbit (Google LLC) — activity data
- Strava, Inc. — workout data
- Whoop, Inc. — strain, recovery, activity
- Apple Sign-In / Google Sign-In — authentication
- Twitter / X, Meta (Facebook / Instagram), TikTok — legacy social connections only, where a User previously authorised one
These services are independent data controllers for the data they collect. Their privacy policies govern their use of your data.
4.3 Charities
When you use a Charity Bond or make a Friend Donate pledge, the applicable amount and approved direct-charity or intermediary route are recorded for reconciliation. A chosen public display name may be shown. Charity Bond forfeits are not eligible for Gift Aid, and Friend Donate pledges do not use Gift Aid during the pilot, so FitBond does not collect Gift Aid declarations for either source. FitBond does not receive full bank-card details from Stripe and does not provide them to charities.
4.4 Other Users
Certain information is visible to other users of the Service based on your settings and participation — for example, your display name and profile photograph on shared Bonds, team memberships, and leaderboards. You control what is shown in your profile settings.
4.5 Friend Pledgers
If a friend opens your website pledge link, they will see limited information about the Bond (including Goal, duration, charity and your display name). To pay, the Pledger signs in with FitBond ID and enters payment details in Stripe's hosted checkout. FitBond records their account identity, amount, optional message and anonymity choice, consent version, timestamp, IP address, Stripe identifiers, and payment status for payment, fraud, reconciliation and legal-record purposes.
4.6 Law Enforcement and Legal Obligations
We may disclose personal data where required by law, a court order, or a binding regulatory request, or where we believe disclosure is necessary to protect the rights, property, or safety of FitBond, our users, or the public, or to investigate fraud or other unlawful activity.
4.7 Business Transfers
If FitBond is involved in a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred as part of that transaction. We will provide notice in advance and ensure any recipient is bound by obligations no less protective than this Policy.
4.8 We Do Not Sell Your Data
We do not sell your personal data to third parties, and we do not share it for third-party targeted advertising.
5. International Transfers
Your personal data is primarily stored in the United Kingdom or the European Economic Area (EEA). Where data is transferred outside the UK/EEA (for example, to AWS or Stripe servers in the United States), we rely on one or more of the following safeguards approved under UK GDPR:
- UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses (SCCs);
- EU Standard Contractual Clauses where transfers originate from the EEA;
- Adequacy decisions (where in force).
Copies of these safeguards are available on request.
6. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal, accounting, and reporting obligations.
| Data category | Retention period |
|---|---|
| Account profile data | For as long as your account exists; deleted within 30 days of account deletion (subject to legal holds) |
| Verified phone number, phone hash, and verification timestamp | For as long as your account exists; deleted within 30 days of account deletion (subject to legal holds) |
| Bond records, Deposits, payouts, and Wallet transactions | 7 years after the transaction, to comply with UK tax and financial record-keeping obligations |
| Payment records, invoices, subscription history | 7 years (UK HMRC requirements) |
| Charity donation records | 7 years |
| Fitness data from Fitbit / Strava / Whoop | While needed to operate and audit active/recently settled Bonds; otherwise until account deletion plus up to 30 days, subject to legal holds |
| Nutrition and food log data | Duration of account plus 30 days after deletion |
| Gym visit records | 24 months |
| Support communications | 24 months after the communication |
| Security logs, audit logs | 12 months |
| Waitlist contact and marketing consent records | Until consent is withdrawn or the waitlist purpose ends, plus 3 years to evidence consent and withdrawal |
| Friend Pledge legal consents (ToS version + IP) | 7 years |
| Anonymised / aggregated analytics | Indefinite |
Account deletion removes your app identity and unrelated profile/activity data. Where necessary to resolve balances, refunds, disputes or legal claims, we retain limited financial records, including a protected matching value derived from your email so support can locate a closed-account claim. We remove saved payment-method details and noncash loyalty data from the closed Wallet. Financial records may need to be retained longer while an unresolved claim or legal retention requirement applies; they are restricted to the relevant financial and legal purposes.
After the relevant retention period, we either permanently delete the data or irreversibly anonymise it.
7. Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS 1.2+) and at rest for databases and backups;
- Access controls on internal systems, principle of least privilege;
- Secure authentication via AWS Cognito (password hashing, rate limiting);
- Payment card data handled exclusively by PCI-DSS-compliant provider (Stripe);
- Logging, monitoring, and intrusion detection;
- Regular backups and disaster recovery procedures;
- Vendor due diligence for data processors.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office (ICO) within 72 hours and, where required, notify you without undue delay.
8. Cookies & Similar Technologies
The Service is a mobile application and does not use cookies in the traditional web sense. We use:
- Device identifiers (such as Apple IDFV) for crash reporting and fraud prevention;
- Push notification tokens (APNs) to send notifications you have permitted;
- Local storage on your device to remember login state, preferences, and cached Bond data.
The FitBond website uses essential storage and server logs needed to operate forms, security, and sign-in. It currently sets no advertising or analytics cookies. When you dismiss the cookie notice, fb_cookie_notice remembers that acknowledgement for 180 days; it contains no account identifier and does not consent to tracking. You can reopen the notice using “Cookies” in the website footer. Waitlist forms may record source and UTM campaign values supplied in the page URL. FitBond does not use those values to infer health information. If non-essential analytics or advertising cookies are added, the website will provide the consent controls required by law before they are set.
9. Automated Decision-Making & Profiling
We use automated processes to:
- Assign an onboarding motivational cohort (Investor, Team Player, Competitor, Altruist, Self-Believer, or Balanced) based on your onboarding answers;
- Suggest personalised Bond Goals and recommended Bond types;
- Flag suspicious activity (possible data manipulation, multiple accounts, fraud indicators).
These processes do not produce legal or similarly significant effects on you without human review, except that automated fraud-detection flags may result in a temporary account hold pending human investigation. You have the right to request human review of any such decision — contact privacy@fitbond.co.uk.
10. Your Rights
Under UK GDPR, you have the following rights in respect of your personal data:
(a) Right of access — to obtain a copy of the personal data we hold about you.
(b) Right to rectification — to have inaccurate or incomplete data corrected.
(c) Right to erasure ("right to be forgotten") — to have your data deleted in certain circumstances. Note that we may retain data where required by law (for example, financial records for 7 years).
(d) Right to restriction of processing — to limit how we use your data in certain circumstances.
(e) Right to data portability — to receive your data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller.
(f) Right to object — to processing based on legitimate interests, and to direct marketing at any time.
(g) Right to withdraw consent — where we rely on consent (including for health data and marketing), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
(h) Rights in relation to automated decision-making — see Section 9.
To exercise any of these rights, email privacy@fitbond.co.uk. We will respond within one month (extendable by a further two months for complex requests, in which case we will notify you). We do not charge a fee, except where requests are manifestly unfounded or excessive.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
We encourage you to contact us first so we can try to resolve any concerns.
11. Children
The Service is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided data to us, please contact privacy@fitbond.co.uk and we will delete it.
12. Sensitive Contexts
12.1 Health Data
Fitness, activity, and body composition data (including weight, height, calories, macros, menstrual cycle data if logged, and tracker-derived strain and recovery) may reveal information about your physical health. We treat this as special category data and process it only with your explicit consent and for the specific purposes set out in Section 3.
12.2 Nutrition & Disordered Eating
Calorie and macronutrient logging can be harmful for people with a history of disordered eating. If this is a risk for you, please use nutrition features cautiously, speak to a qualified healthcare professional, or contact Beat on 0808 801 0677 (UK).
12.3 Biological Sex & Gender
We collect biological sex because it affects the accuracy of fitness calculations (such as calorie estimates). Gender identity is stored only where you choose to provide it and is used to personalise your experience. You can update or remove these fields at any time.
13. Third-Party Links
The Service may contain links to third-party websites, apps, or services (including merchants on the Marketplace and charities). This Policy does not apply to those third parties. Please review their own privacy policies before providing them with personal data.
14. Changes to This Policy
We may update this Policy from time to time. For material changes, we will notify you by email and/or via an in-app notice at least 30 days before the changes take effect. The date at the top of this Policy indicates when it was last updated. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
15. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:
FitBond Inc Ltd Registered in England and Wales, company number 17020972 Registered office: Flat 23, 112 Candlemakers Apartments, York Road, London SW11 3RS, United Kingdom Email: privacy@fitbond.co.uk Support: support@fitbond.co.uk
This Privacy Policy was last updated on 11 September 2026.