This Privacy Policy explains how Svitlana Ivanivna Rozdobudko, a private entrepreneur (ФОП) registered in Ukraine, tax number 3033512564 (“we”, “us”, “the Studio”), processes the personal data of users of the FitnessArt mobile app and the fitnessart.studio website.
We process data in accordance with the Law of Ukraine “On Personal Data Protection” and try to collect exactly as much as running the studio requires. We do not sell your data and do not use it for advertising profiling.
Who is responsible for your data
The data controller is Svitlana Ivanivna Rozdobudko, private entrepreneur. That means we decide what data is processed and why, and we are who you contact with questions or complaints.
- Contact for data protection matters: info@fitnessart.studio.
- We have not appointed a separate data protection officer — requests are handled by the Studio's owner personally.
- This Policy forms an integral part of the Terms of Service and supplements the personal data section of the Public Offer, which is published in Ukrainian only.
What this Policy covers
This Policy applies to:
- the FitnessArt mobile app for iOS;
- the fitnessart.studio website;
- the processing of visitors' data at the Studio itself, in connection with Bookings and attendance.
This Policy does not cover third-party sites and services you reach by following a link — they have their own policies. The providers we work with are listed under “Who we share data with”.
What data we process
The full list is below. If a category is not here, we do not collect it.
| Category | What exactly | Why | Legal basis | Retention |
|---|---|---|---|---|
| Account | Name, email address, phone number, profile photo (if you add one), internal identifier, sign-in method (email, phone, Apple, Google), date created | Creating and maintaining your Account, signing in, contacting you | Performance of a contract | For as long as the Account exists |
| Bookings and attendance | Class bookings, waitlist entries, attendance history, use of the free Drop-in | Reserving places, counting Credits, planning the timetable | Performance of a contract | 3 years after the last Membership ends |
| Membership | Plan name, validity period, number and balance of Credits, included class types and studios | Providing the services you paid for | Performance of a contract | 3 years after the Membership ends |
| Payments | Amount, currency, status, LiqPay transaction id, chosen plan, date. We never receive or store your full card number | Processing payment, issuing refunds, accounting and tax records | Performance of a contract; legal obligation | 3 years (tax records) |
| Device and notifications | Push notification token, device model, iOS and app version, interface language | Sending service notifications, technical support | Performance of a contract; legitimate interest | Until the Account is deleted or permission is withdrawn |
| Analytics and crashes | App usage events, the app's identifier for vendor (IDFV), device type, OS version, region, crash reports and app state at the moment of a crash | Understanding which features are used and fixing bugs | Legitimate interest | Up to 14 months (analytics), up to 90 days (crash reports) |
| Enquiries | Name, email, phone, the text of your message and any subsequent correspondence | Replying to you, handling complaints and refund requests | Performance of a contract; legitimate interest | 3 years |
| Apple Health | Workouts, heart rate, active energy | Showing you your own statistics in the app | Your separate consent (iOS permission) | Never stored by us — stays on your device |
We do not collect location data. The app never asks for location access; the coordinates it holds are the Studio's address on a map, not yours.
Apple Health data
This is the most sensitive category the app touches, so it gets its own section.
- The app reads three kinds of data from Apple Health (HealthKit): workouts, heart rate and active energy burned.
- Access is granted only with your separate iOS permission. Without it the app works fully, apart from the statistics screen.
- This data is processed entirely on your device. It is never sent to our servers, never written to Firestore, and never shared with anyone.
- We do not use Apple Health data for advertising, profiling or marketing, and do not disclose it to third parties — Apple's rules expressly prohibit this too.
- You can revoke the permission at any time: iOS Settings → Health → Data Access & Devices → FitnessArt. We never write anything back to Apple Health.
Payment data
- Membership payments are processed by LiqPay. You enter your card details on their side, or pass them through Apple Pay.
- We never receive or store your full card number, expiry date or CVV. All we keep is the amount, currency, payment status, the LiqPay transaction id, the chosen plan and the date.
- LiqPay processes payment data as an independent payment service provider, under its own rules and payment services legislation.
- We keep payment records for accounting and tax purposes and to handle refund requests under the Public Offer.
Analytics and crash reporting
To understand what works badly in the app we use Firebase Analytics and Firebase Crashlytics (Google services).
- Analytics collects de-identified usage events — which screens are opened, which features are used — along with device type, OS version, language and approximate region.
- Crashlytics collects crash reports: where in the code the error occurred, the app version, and the device state at that moment.
- It uses the app's identifier for vendor (IDFV). We do not use the advertising identifier (IDFA), show no advertising, and do not track you across other companies' apps or websites.
- We process this data on the basis of our legitimate interest in keeping the app working. We do not use it to make decisions about you and do not combine it with your booking history for profiling.
- You can object to this processing by writing to info@fitnessart.studio. We will consider your objection and tell you the outcome.
Push notifications
- To send notifications we store a device token issued by Firebase Cloud Messaging. On its own it contains neither your name nor your contact details.
- The notifications we send are service messages: booking confirmations, class reminders, waitlist promotions, class cancellations and payment status.
- You can withdraw notification permission in iOS Settings. The token then falls out of use and important messages go to your email address instead.
The website: cookies, local storage and the contact form
The fitnessart.studio website is static and deliberately simple.
- We use Cloudflare Web Analytics, which sets no cookies and uses no fingerprinting. It records only aggregate page views and referring URLs, not individual identities. It does not build a profile of you and does not track you across other sites or apps. There is no cookie banner because there are no cookies.
- The site stores one entry in your browser's local storage — `fa-theme` — to remember whether you chose the light or dark theme. It is not an identifier and is never sent to us.
- The timetable and membership plans are loaded directly from the Google Firestore database by your browser. As a result your IP address becomes known to Google as the provider of that infrastructure. No account is needed to browse the site.
- The Contact page embeds a Google Maps frame. That is a third-party frame and may set its own cookies under Google's policy. If you do not open that page, the frame is never loaded.
- Through the contact form you send us your name, phone, email and message. We use this solely to reply to you and keep it for 3 years. We do not add these contacts to any mailing list without your consent.
We do not sell data and do not pass it on for anyone else's marketing. It reaches only the providers the service cannot run without, and only to the extent needed:
- Google (Firebase, Google Cloud) — authentication, database, file storage, backend hosting, push notifications, analytics and crash reporting;
- LiqPay — processing Membership payments;
- Apple — app distribution, Sign in with Apple, push notification delivery;
- our email delivery provider — sending service emails and replies to enquiries;
- our accountant and, where needed, a legal adviser — bookkeeping and defending our rights;
- public authorities — only in the cases and by the procedure the law expressly requires.
Studio instructors can see the names of people booked onto their own Session — they need this to run the class and mark attendance. They have no access to your payment data.
Transfers outside Ukraine
- Google's infrastructure (Firebase, Google Cloud) is located outside Ukraine, so your data is processed and stored on servers in other countries, including in the European Union and the United States.
- These transfers take place under contracts with our providers that include standard data protection clauses, and only to the extent needed to deliver the service.
- We choose providers that maintain an adequate level of protection and do not transfer data to countries where no such safeguards exist.
How long we keep data
We keep data no longer than the purpose it was collected for requires, and no longer than the law allows.
- Account — for as long as it exists. Once deleted, the profile and contact details are removed.
- Bookings, attendance and Memberships — 3 years after the last Membership ends, within the limitation period.
- Payment records — 3 years, as tax legislation requires. We cannot shorten this period at your request.
- Enquiries and correspondence — 3 years from the conclusion of the matter.
- Analytics and crash reports — up to 14 months and up to 90 days respectively, then deleted automatically by the provider.
How we protect your data
- Data travels over a secure connection (HTTPS/TLS) and is stored encrypted at rest on Google Cloud.
- Access is limited to those who need it to do their work: the Studio's owner and, for their own Session, the instructors.
- We never store passwords in plain text — authentication is handled by Firebase Authentication.
- Access to the database is constrained by security rules that define who may read and change what.
- No system is perfectly secure. If a breach occurs that may pose a risk to your rights, we will notify you and the competent authorities as the law requires.
Your rights
Under the Law of Ukraine “On Personal Data Protection” you have the right to:
- know who processes your data, what data that is, for what purpose, and who it is shared with;
- access your data and receive a copy in an intelligible form;
- correct inaccurate or incomplete data — some of it you can change directly in the app;
- erase your data where there is no lawful basis for keeping it;
- restrict processing, or object to it where we rely on legitimate interest;
- withdraw consent where processing rests on it — in particular the Apple Health and notification permissions. Withdrawal does not affect the lawfulness of processing before it;
- receive your data in a convenient format so you can pass it to another controller;
- lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights, or go to court.
To exercise any of these rights, write to info@fitnessart.studio. We reply without undue delay, normally within 30 calendar days. We may ask you to confirm your identity — solely so we do not hand your data to someone else.
Deleting your Account and data
You can ask us to delete your Account together with the data associated with it at any time.
- Send a request to info@fitnessart.studio from the email address or phone number registered to the Account, with the subject “Account deletion”.
- We confirm receipt and, if necessary, ask for details to satisfy ourselves that the request really came from you.
- We delete the Account and its associated data without undue delay, normally within 30 calendar days.
- Deleted: your profile, contact details, photo, notification tokens, booking and attendance history, and Membership data.
- Retained: payment and accounting records for 3 years as tax legislation requires, and any material needed to defend our rights in an ongoing dispute.
Deleting your Account is not a refund request for an unused Membership. To claim a refund, submit a separate request under the Public Offer — preferably before deleting your Account.
Children's data
- We do not create Accounts for children under 14 and do not knowingly collect their personal data.
- A person aged 14 to 18 uses the Service with the consent of a parent or other legal guardian.
- If you believe a child has given us data without such consent, write to info@fitnessart.studio and we will delete it.
Changes to this Policy
- We may update this Policy. A new version is published on this page, stating its number and the date it takes effect.
- We give notice of material changes — a new data category, a new purpose, a new recipient — through the app or by email, before they take effect.
- We keep previous versions and provide them on request.
Contact and complaints
For any question about your data, contact us — it is the fastest way to resolve it:
- Data controller
- Svitlana Ivanivna Rozdobudko, private entrepreneur (ФОП), tax number 3033512564
- Phone
- +380 97 413 95 95
- Postal address
- Apt. 199, 45-A Yevropeiskoho Soiuzu Ave, Kyiv, Ukraine
- Studio address
- 2 Novomostytska St, 2nd floor, Kyiv, Ukraine
If our answer does not satisfy you, you have the right to lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights — the authority supervising compliance with personal data protection legislation — or to go to court.