← FitCard

FitCard — Privacy Policy

Effective date: 21 June 2026 Last updated: 16 August 2026 Information Officer: contactable at bilal@fitcard.co.za — named in FitCard's PAIA manual and registered with the Information Regulator


This Privacy Policy describes how FitCard handles your personal information when you use the FitCard mobile app on iOS and Android, the website at fitcard.co.za, and any related services (together, the "Service"). It is written in plain English so you can actually read it.

If anything here is unclear, email the Information Officer above and we'll explain.


1. Who runs FitCard

FitCard is operated by FitCard (Pty) Ltd (registration number 2026/470494/07), a South African private company incorporated on 15 June 2026. (During the earlier closed beta the service was operated by FitCard’s founder pending incorporation; your data is treated to the same standards under both.)


2. What we collect — and why

We collect the minimum personal information needed to render your trading card and let you contact us. Here is the complete list:

a) Strava activity data

When you connect Strava in the app, we receive:

Why: to render your fitness identity as a trading card. The "Six attributes" (Climb, Distance, Pace, Stamina, Recovery, Consistency), your rarity tier, and your sport position are all derived from this data.

b) Contact information

If you email us for support, we receive your email address and the content of your support message.

Why: to reply to your support request.

c) Your Strava athlete ID

A numeric identifier Strava assigns you (e.g. 12345678). We store this so we can re-associate your tokens with your account on re-login.

Why: session continuity.

d) Apple Health (HealthKit) — iOS, optional

If you connect Apple Health in the app, FitCard reads the following from HealthKit, on your device:

Why: the same reason as Strava — to compute the Six attributes and render your card. Recovery (REC) in particular is sharpened by heart-rate variability and resting heart rate.

FitCard never writes to Apple Health. The read is on-demand; in this version the data is aggregated and scored on your device rather than copied to our servers (see §2(f)). You can revoke access at any time in iOS Settings → Privacy & Security → Health → FitCard.

e) Health Connect — Android, optional

If you connect Health Connect on Android, FitCard requests read-only access to these eleven data types:

Why: identical to Apple Health — these feed the Six attributes (Climb, Distance, Pace, Stamina, Recovery, Consistency), your rarity tier and your position. Sleep and heart-rate variability feed Recovery only.

FitCard requests read permissions only — it never writes to Health Connect, and does not request background reads or extended history. Reads happen when you open the app. In this version the data is aggregated and scored on your device rather than copied to our servers (see §2(f)), and it is not shared with any third party. You can revoke access at any time in the Health Connect app → App permissions → FitCard.

Health Connect is an aggregator rather than a source: it only contains what other apps (Garmin Connect, Strava, Samsung Health and similar) have written to it.

f) How health data is aggregated

To be explicit, because this is the heart of what FitCard does: FitCard does collect health and activity data, and it aggregates it. Data from Strava, Apple Health and Health Connect is read, normalised into a single common format, de-duplicated where the same run or ride appears in more than one source, and combined into one continuous picture of your training. That aggregated picture is what produces the Six attributes, your Overall score, your rarity tier and your position — and it is what keeps your card current as you train.

Aggregating across sources is deliberate. One provider alone gives a partial view: a ride logged on a bike computer, a run captured by a watch, and sleep recorded by a phone are three fragments of the same athlete. FitCard joins them.

Where that processing happens today. As of this version, the aggregation runs on your device. Health data read from Apple Health and Health Connect is combined and scored locally, and is not uploaded to FitCard servers. Strava data is fetched from Strava on demand and is likewise not retained on our servers.

If that changes, this policy changes first. Server-side aggregation is on FitCard's roadmap — it is what would let your card update while the app is closed, and let history survive a lost phone. We will not move health data off your device without updating this policy, updating our Google Play Data safety declaration to match, and telling you in-app before it takes effect.


3. What we DO NOT collect

For transparency, here is what we explicitly do NOT collect:

If any of this changes in a future version, we'll update this policy and re-prompt you for the relevant permission.


4. How we use your data, and on what legal basis

We use your data only for these purposes, and only on the legal bases listed.

Purpose Legal basis under POPIA (South Africa) Legal basis under GDPR (EU/UK, if applicable)
Render your card from Strava data — the core app functionality POPIA §11(1)(b) — necessary for the conclusion or performance of a contract with you GDPR Art. 6(1)(b) — performance of a contract
Connect to Strava on your behalf — OAuth, token refresh POPIA §11(1)(a) — consent (you grant Strava OAuth) GDPR Art. 6(1)(a) — consent
Reply to your support requests POPIA §11(1)(d) — legitimate interest of FitCard in providing support GDPR Art. 6(1)(f) — legitimate interests
Improve the app via aggregated, de-identified analytics (from M5; see §2) POPIA §11(1)(d) — legitimate interest in product improvement GDPR Art. 6(1)(f) — legitimate interests

We do NOT: - Sell your data. - Share it with advertisers. - Use it to train AI models or feed it into any AI service. - Use it for any purpose not listed in this section.

You can withdraw consent for the Strava connection at any time — see §10 ("How to disconnect & delete"). Disconnecting Strava means your card cannot render and the app's primary functionality stops working.


5. Who we share data with

We share data only with these service providers, and only the minimum each needs to do their job:

Provider What they receive Why
Strava OAuth requests + activity-fetch requests (you authorised this when you connected) Source of activity data
Vercel (Edge Function host) OAuth code/refresh tokens (in transit only — never stored server-side) Server-side OAuth exchange so the Strava Client Secret never sits on your device
Apple (App Store / TestFlight) App install + crash data (Apple-side; we receive aggregate reports only) App distribution
Google (Google Play) App install + crash data (Google-side; we receive aggregate reports only). No health data is sent to Google by FitCard — Health Connect is an on-device API, not a cloud service. App distribution on Android

We do NOT share your data with any other third party.


6. Where your data is stored, transferred, and how long for

6.1 Storage locations and transborder transfers

🔴 Transborder transfers. Some of your personal information leaves South Africa when processed by Vercel (US), Strava (US), and Google Workspace (US). The United States does NOT have a current adequacy decision from the South African Information Regulator or from the European Commission. Our safeguard is contractual: each of these processors operates under its own data-processing agreement, which (for Vercel and Google) includes Standard Contractual Clauses or equivalent. You can request copies of these via the Information Officer. Apple Health and Health Connect data is not part of any transborder transfer in this version — it is processed on your device (§2(f)).

6.2 Data retention schedule

Data Retention period Trigger to delete
Strava OAuth tokens (on-device) Until you disconnect Strava or uninstall the app Tap "Disconnect Strava" in-app, or uninstall, or call Strava's revoke endpoint
Strava athlete ID (on-device cache) Until you disconnect Strava or uninstall the app Same as above
Vercel server logs (IP + timestamp + status) Per Vercel's policy — typically 7-30 days Automatic; you can request earlier deletion via the Information Officer
Support email correspondence 90 days after the matter is resolved, or sooner on request Email the Information Officer to delete earlier
Strava activity data Never stored by FitCard; fetched on demand only n/a — controlled by your Strava account

7.1 EU/UK representative

🔴 If you reside in the EU/EEA or the UK, please note: FitCard's controller (FitCard (Pty) Ltd) is located in South Africa. Under GDPR Art. 27, a non-EU controller that directs services at EU users is generally required to designate an EU representative. FitCard is currently assessing whether the Art. 27 Small Enterprise exemption applies based on actual EU user counts and the occasional/non-large-scale nature of the processing. Until a representative is designated or the exemption analysis is documented and posted here, EU users may contact the Information Officer (§12) directly with any data-subject request, and we will respond within 30 days. This section will be updated before public App Store launch (Phase 9 per our internal Ship Runbook).

7. Your rights (POPIA & GDPR)

Under the Protection of Personal Information Act 2013 (South Africa) and, if you reside in the EU/EEA/UK, the General Data Protection Regulation, you have the right to:

To exercise any of these rights, email the Information Officer at bilal@fitcard.co.za. We'll respond within 30 days.


8. Children

FitCard is not intended for children under 13 (or 16 in some jurisdictions). We don't knowingly collect data from anyone in that age range. If you become aware that a child has signed up, email us and we'll delete their account.


9. Security

We take the following measures to protect your data:

No system is perfectly secure. If we ever experience a data breach that affects you, we will notify you in line with POPIA's 72-hour notification timeline.


10. How to disconnect & delete

You can disconnect Strava from FitCard at any time:

  1. In FitCard, open Card tab → tap your profile → "Disconnect Strava." This clears tokens from your device.
  2. On Strava (https://www.strava.com/settings/apps), find FitCard in the list and click "Revoke Access." This invalidates the OAuth grant on Strava's side.

To delete any data we hold off your device:


11. Algorithmic generation of your card ("The Six")

Your FitCard is generated algorithmically from your Strava activity history. Specifically:

This is a form of automated processing (under POPIA §71 and GDPR Art. 22, "profiling"). The output — your rarity tier, position, and card design — is displayed to you and used in the share image you may export. It does not produce a legal or similarly significant effect on you in our reading: the card is a creative artefact of your running activity, not a creditworthiness decision, employment screen, or service-eligibility determination.

You can: - See exactly which Strava activities contributed to each attribute by tapping any band on the card-back. - Disagree with the algorithm — email the Information Officer if you believe the card misrepresents you. We will investigate and, where the issue is a bug, fix it. - Stop using FitCard by disconnecting Strava (§10) at any time.

If you reside in the EU/UK and you believe this profiling does produce a significant effect on you, you have the right under GDPR Art. 22 to request human review of the output. Email the Information Officer.

12. Changes to this policy

If we change this policy materially, we'll:

Older versions are archived in the FitCard knowledge vault and available on request.


13. Contact

The Information Officer, FitCard (Pty) Ltd Email: bilal@fitcard.co.za Operating address: Available on request. FitCard (Pty) Ltd’s registered address is on the CIPC register and is provided on request to any data subject, regulator or counterparty.


FitCard (Pty) Ltd · Reg 2026/470494/07 · South Africa · fitcard.co.za