YOUR PRIVACY MATTERS TO US. PLEASE READ THIS POLICY CAREFULLY TO UNDERSTAND HOW WE COLLECT, USE, AND PROTECT YOUR PERSONAL INFORMATION.
1. INTRODUCTION & SCOPE
1.1 About This Policy
This Privacy Policy ("Policy") describes how In-Shape Dates, LLC ("Company," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the In-Shape Dates mobile application and related services (collectively, the "Platform"). This Policy applies to all users of the Platform, including those who access via iOS, Android, or web interfaces.
1.2 Our Commitment
We are committed to protecting your privacy and handling your data responsibly. As a fitness accountability platform that integrates with health data services, we take extra care to ensure your sensitive health information is protected and used only for the purposes you authorize.
1.3 Agreement to This Policy
By creating an account or using the Platform, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use the Platform.
1.4 Company Information
In-Shape Dates, LLC is the data controller responsible for your personal information. For questions about this Policy or our data practices, contact us at:
- Email: privacy@inshapedates.com
- Support: support@inshapedates.com
- Location: Hillsborough County, Florida, USA
2. INFORMATION WE COLLECT
We collect several categories of information to provide and improve the Platform. The types of information we collect depend on how you use the Platform and which features you enable.
2.1 Account Information
When you create an account, we collect:
- Full name
- Email address
- Phone number (optional)
- Date of birth (to verify age eligibility)
- Password (stored in encrypted form)
- Profile photos
- Gender and gender preferences (optional)
2.2 Fitness & Wellness Information
To support your fitness accountability goals, we collect:
- Fitness goals and preferences
- Workout types and exercise preferences
- Activity logs and fitness progress
- Body measurements (if you choose to provide them)
- Diet and nutrition preferences
- Macro and calorie tracking inputs
2.3 Health Integration Data (Apple Health / Google Fit)
With your explicit consent, you may connect Apple Health, Google Fit, or similar services ("Health Integrations"). When connected, we may access:
- Step counts and daily activity data
- Workout and exercise data
- Active calories and energy expenditure
- Heart rate data (if shared)
- Sleep data (if shared)
- Other fitness metrics you choose to share
IMPORTANT HEALTH DATA NOTICE:
We do NOT store raw health records from Health Integrations on our servers. We only store Derived Metrics (non-medical data points such as completion flags, activity streaks, and Pepper Level scores) generated from Health Integration data to operate Platform features. Raw health data is accessed in real-time and is not retained after processing.
2.4 Communication Data
When you use Platform communication features, we collect:
- Direct messages between users
- Group session chat messages
- Voice session metadata (duration, participants)
- Voice session recordings (for safety and dispute resolution, with notice)
- Reports and feedback submitted
2.5 Trainer Interaction Data
If you use the Trainer Marketplace, we collect:
- Session bookings and history
- Communications with trainers
- Session ratings and reviews
- Payment transaction records (for in-app payments)
2.6 Location Data
With your consent, we may collect:
- Precise location (GPS) for finding nearby accountability partners and trainers
- General location (city/region) derived from IP address
- Location history for workout tracking features (if enabled)
Purpose Limitation for Precise Location: Precise location data is used only for features you explicitly enable (such as finding nearby trainers or accountability partners) and is not retained beyond what is necessary to provide those features. We do not build location history profiles or use precise location for advertising purposes.
2.7 Device & Technical Information
We automatically collect:
- Device type, model, and operating system
- Unique device identifiers
- IP address
- App version
- Browser type (for web access)
- Crash logs and performance data
- Push notification tokens
2.8 Usage Data
We collect information about how you use the Platform:
- Features accessed and frequency of use
- Session duration and engagement patterns
- Search queries within the Platform
- Interactions with other users (views, connections)
- Accountability session participation
2.9 Advertising Identifiers
On iOS, we collect the Identifier for Advertisers (IDFA) only after you provide consent through Apple's App Tracking Transparency (ATT) prompt. On Android, we may collect the Google Advertising ID with your consent. These identifiers are used for analytics and advertising attribution only. Health data is never used for advertising purposes.
2.10 Progress Ratings & Feedback
We collect:
- Ratings you give to other users
- Ratings you receive from other users
- Written feedback and comments
- Accountability session evaluations
2.11 Data Accuracy & User Responsibility
Some information on the Platform is provided directly by you or obtained from third-party integrations (such as Health Integrations). This information may be inaccurate, incomplete, or out of date. You are responsible for keeping your information accurate and up to date. We are not responsible for the accuracy of information provided by you or by third-party services. If you believe any information is incorrect, you can update it through your account settings or by contacting support@inshapedates.com.
3. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:
3.1 Providing Platform Services
- Creating and managing your account
- Displaying your profile to other users
- Facilitating accountability partnerships and group sessions
- Connecting you with trainers
- Processing payments for premium features and trainer services
- Enabling messaging and communication features
3.2 Fitness Accountability Features
- Tracking and displaying fitness progress
- Calculating Derived Metrics (Pepper Level, streaks, completion rates)
- Generating personalized fitness recommendations
- Providing Diet Corner macro and calorie suggestions
- Matching you with compatible accountability partners
3.3 Safety & Security
- Detecting and preventing fraud, abuse, and violations of our Terms
- Monitoring communications for safety (with notice)
- Investigating reported issues and disputes
- Protecting the security of the Platform and users
3.4 Communications
- Sending account notifications and updates
- Providing customer support
- Sending promotional messages (with your consent)
- Delivering push notifications (if enabled)
3.5 Analytics & Improvement
- Understanding how users interact with the Platform
- Improving features and user experience
- Developing new features
- Conducting research and analysis
3.6 Legal Compliance
- Complying with applicable laws and regulations
- Responding to legal requests and court orders
- Enforcing our Terms & Conditions
- Protecting our legal rights
4. LEGAL BASIS FOR PROCESSING (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions that require a legal basis for processing, we rely on the following:
4.1 Consent
We process the following based on your explicit consent:
- Health Integration data (Apple Health/Google Fit)
- Precise location data
- Advertising identifiers (IDFA/GAID)
- Marketing communications
- Voice session recordings
4.2 Contract Performance
We process the following to fulfill our contract with you:
- Account information (to create and maintain your account)
- Payment information (to process transactions)
- Communication data (to provide messaging features)
- Trainer booking data (to facilitate sessions)
4.3 Legitimate Interests
We process the following based on our legitimate business interests:
- Usage data (to improve the Platform)
- Device information (for security and troubleshooting)
- Analytics data (to understand user behavior)
- Fraud prevention data
4.4 Legal Obligation
We process certain data to comply with legal requirements:
- Tax and financial records
- Data required by law enforcement requests
- Records required for legal disputes
5. HEALTH DATA: SPECIAL PROTECTIONS
We recognize that health and fitness data requires special protection. This section explains our commitments regarding your health information.
5.1 Apple HealthKit Compliance
When you connect Apple Health (HealthKit), we comply with Apple's HealthKit guidelines:
- HealthKit data is never used for advertising or marketing purposes
- HealthKit data is never sold to third parties
- HealthKit data is never shared with third parties for their advertising or marketing purposes
- HealthKit data is never shared with data brokers
- HealthKit data is used only to provide health and fitness features you have enabled
- We do not store raw HealthKit data; only Derived Metrics are retained
5.2 Google Health Connect Compliance
When you connect Google Fit or Health Connect, we apply the same protections as HealthKit data. Health Connect data is never used for advertising, never sold, and never shared with data brokers.
5.3 No Sale of Health Data
We do NOT sell your health data under any circumstances. This applies to all health and fitness information, including data from Health Integrations, workout logs, nutrition data, and any Derived Metrics. This commitment applies regardless of whether a "sale" involves monetary compensation.
5.4 Purpose Limitation
Health data is used exclusively for:
- Displaying your fitness progress within the Platform
- Calculating accountability metrics (Pepper Level, streaks)
- Matching you with compatible accountability partners
- Providing personalized fitness recommendations
- Verifying fitness activity for accountability features
5.5 Data Minimization
We only access the specific health data categories necessary for features you enable. You can customize which data types are shared through your device's Health app permissions. We encourage you to share only the data necessary for your goals.
5.6 Consent & Revocation
Health Integration connections require your explicit consent. You may revoke this consent at any time through:
- Your device's Health app settings (Apple Health / Google Fit)
- The In-Shape Dates app settings
Revoking consent stops future data access immediately. Derived Metrics already generated may be retained but will no longer update.
6. AUTOMATED DECISION-MAKING & AI RECOMMENDATIONS
6.1 Automated Processing
The Platform uses automated systems to:
- Generate Diet Corner macro and calorie recommendations
- Calculate Derived Metrics (Pepper Level, accountability scores)
- Suggest accountability partner matches
- Detect potential Terms violations
- Filter inappropriate content
6.2 Limitations of Automated Systems
Automated recommendations are generated by algorithms and Third-Party APIs that may contain errors, biases, or inaccuracies. You should not rely solely on automated recommendations for health or fitness decisions. Automated systems are tools to assist you, not replace professional advice or your own judgment.
6.3 Human Review
For significant decisions affecting your account (such as suspension or termination), we ensure human review is available. You may request human review of automated decisions by contacting support@inshapedates.com.
6.4 Right to Object (GDPR)
If you are in the EEA or UK, you have the right to object to decisions based solely on automated processing that significantly affect you. Contact us to exercise this right.
7. HOW WE SHARE YOUR INFORMATION
We share your information only as described in this Policy. We do not sell your personal information.
7.1 With Other Users
Depending on your settings, other users may see:
- Your profile information (name, photos, bio)
- Your fitness goals and activity level
- Your Pepper Level and accountability metrics
- Ratings and reviews you have received
- Your general location (if enabled)
- Messages you send to them
7.2 With Trainers
When you book sessions, trainers may access:
- Your profile and contact information
- Fitness goals and relevant health information you share
- Session history and notes
- Communications with the trainer
7.3 With Service Providers (Subprocessors)
We share data with third-party service providers who assist us:
- Cloud Hosting: Amazon Web Services (AWS) for data storage and processing
- Payment Processing: Stripe for payment transactions
- Analytics: Mixpanel, Firebase Analytics for usage analytics
- Communications: Twilio for SMS, SendGrid for email
- Push Notifications: Firebase Cloud Messaging, Apple Push Notification Service
- Nutrition APIs: Third-party services for macro/calorie calculations
- Customer Support: Zendesk for support ticket management
Service providers are contractually bound to use data only for providing services to us and must maintain appropriate security measures.
7.4 Subprocessor Changes
We may update our service providers (subprocessors) from time to time to improve our services or for operational reasons. Material changes to our subprocessors will be reflected in updates to this Privacy Policy and/or communicated to you via in-app notification or email. We ensure that any new subprocessors maintain equivalent data protection standards.
7.5 For Legal Reasons
We may disclose information:
- To comply with legal obligations, court orders, or government requests
- To protect our rights, property, or safety
- To protect the safety of users or the public
- In connection with legal proceedings
7.6 Business Transfers
If we are involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
7.7 With Your Consent
We may share information for other purposes with your explicit consent.
7.8 What We Do NOT Share
We do NOT:
- Sell personal information to third parties
- Share health data with advertisers
- Share health data with data brokers
- Use health data for advertising targeting
- Share your messages with third parties for marketing
8. ADVERTISING & TRACKING TECHNOLOGIES
8.1 Apple App Tracking Transparency (ATT)
On iOS devices, we request your permission through Apple's ATT framework before collecting the IDFA (Identifier for Advertisers). If you decline, we will not track you across other apps or websites for advertising purposes.
8.2 How We Use Advertising Identifiers
If you consent, advertising identifiers are used for:
- Measuring the effectiveness of our advertising campaigns
- Attribution (understanding which ads led to app installs)
- Analytics to improve marketing efforts
8.3 Health Data Exclusion
Health and fitness data is NEVER used for advertising purposes.
This includes data from Health Integrations, workout logs, nutrition data, and Derived Metrics. These data categories are completely excluded from all advertising systems.
8.4 Cookies & Similar Technologies
For web access, we use:
- Essential Cookies: Required for Platform functionality (authentication, security)
- Analytics Cookies: To understand usage patterns (with consent where required)
- Preference Cookies: To remember your settings
8.5 Do Not Track
Some browsers send "Do Not Track" (DNT) signals. There is no industry standard for responding to DNT signals. However, you can control tracking through your device settings and the choices described in this Policy.
9. DATA RETENTION
We retain your information for as long as necessary to provide services and fulfill the purposes described in this Policy. Specific retention periods include:
9.1 Retention Periods by Data Type
- Account Information: Retained while your account is active, plus 30 days after deletion request
- Health Integration Data: Raw data is not stored; Derived Metrics retained while account is active
- Messages: Retained for 2 years, or until you delete them
- Voice Recordings: Retained for 90 days for safety review, then deleted
- Workout/Activity Logs: Retained while account is active
- Payment Records: Retained for 7 years for tax and legal compliance
- Usage Analytics: Aggregated data retained indefinitely; identifiable data for 2 years
- Support Tickets: Retained for 3 years
- Reports/Safety Data: Retained for 5 years for legal protection
9.2 Post-Deletion Retention
After you delete your account, we may retain certain information as required by law, for fraud prevention, or to resolve disputes. Backup copies may persist for up to 90 days before complete deletion.
9.3 Post-Deletion Handling of Derived Metrics
Following account deletion, Derived Metrics (such as Pepper Level, streaks, and completion flags) are deleted or anonymized, except where retention is required for: (a) fraud prevention and abuse detection; (b) legal compliance; or (c) ongoing disputes or investigations. Anonymized data cannot be linked back to you and may be retained for aggregate analytics.
10. DATA SECURITY
10.1 Security Measures
We implement reasonable security measures including:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Secure password hashing
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
10.2 No Absolute Security
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.
10.3 Breach Notification
In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
10.4 Security Vulnerability Reporting
We value the security research community and encourage responsible disclosure of security vulnerabilities. If you discover a potential security issue with the Platform, please report it to support@inshapedates.com. We appreciate responsible disclosure and will work with researchers to address valid security concerns. Please do not publicly disclose vulnerabilities until we have had an opportunity to investigate and address them.
11. INTERNATIONAL DATA TRANSFERS
11.1 Data Location
Our servers and service providers are primarily located in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States.
11.2 EEA/UK Transfers
For users in the European Economic Area (EEA) or United Kingdom, we rely on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Service providers certified under recognized frameworks
- Your explicit consent where appropriate
11.3 Safeguards
We ensure that international transfers are protected by appropriate safeguards to maintain the level of protection required by applicable law.
12. YOUR PRIVACY RIGHTS
Depending on your location, you may have the following rights regarding your personal information:
12.1 Rights for All Users
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your account and personal information
- Data Portability: Receive your data in a portable format
- Withdraw Consent: Withdraw consent for optional data processing
- Opt-Out of Marketing: Unsubscribe from promotional communications
12.2 Additional Rights for EEA/UK Residents (GDPR)
- Restriction: Request restriction of processing in certain circumstances
- Object: Object to processing based on legitimate interests
- Automated Decisions: Not be subject to solely automated decisions with legal effects
- Complaint: Lodge a complaint with your local data protection authority
12.3 California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information collected, used, and shared
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt out of the sale or sharing of personal information
- Right to Limit: Limit use of sensitive personal information
- Non-Discrimination: Not be discriminated against for exercising privacy rights
12.4 Exercising Your Rights
To exercise your privacy rights:
- In-App: Use the Settings > Privacy section for most requests
- Email: Contact privacy@inshapedates.com
- Data Export: Request through Settings > Account > Export Data
We will respond to verified requests within the timeframes required by law (typically 30-45 days). We may need to verify your identity before processing requests.
12.5 Authorized Agents
You may designate an authorized agent to make requests on your behalf. We will require proof of authorization and may still verify your identity directly.
13. CALIFORNIA-SPECIFIC DISCLOSURES (CCPA/CPRA)
13.1 Categories of Personal Information
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (name, email, phone number, device IDs)
- Personal information under Cal. Civ. Code 1798.80 (name, address, phone)
- Characteristics of protected classifications (age, gender)
- Commercial information (purchase history, subscriptions)
- Biometric information (fitness metrics derived from Health Integrations)
- Internet/network activity (usage data, IP addresses)
- Geolocation data (with consent)
- Audio information (voice sessions, with notice)
- Inferences (fitness preferences, accountability patterns)
- Sensitive personal information (health data, precise location, with consent)
13.2 Sale and Sharing of Personal Information
We do NOT sell personal information as defined by the CCPA/CPRA. We do NOT share personal information for cross-context behavioral advertising. Health data is never sold or shared for advertising purposes.
13.3 "Do Not Sell or Share" Control
California residents may use the "Do Not Sell or Share My Personal Information" control located in Settings > Privacy within the app. While we do not sell or share personal information for cross-context behavioral advertising, we provide this control to honor your preferences and comply with CPRA requirements. You may also submit requests via email to privacy@inshapedates.com.
13.4 Sensitive Personal Information
We collect sensitive personal information (health data, precise location) only with your explicit consent and use it only for providing Platform features. We do not use sensitive personal information for purposes beyond what is necessary to provide the services you request.
13.5 Retention
We retain personal information as described in Section 9 (Data Retention) of this Policy.
13.6 Financial Incentives
We do not offer financial incentives for the collection, sale, or deletion of personal information.
14. LIVE FEATURES & COMMUNICATIONS PRIVACY
14.1 Voice Sessions
When you participate in live voice sessions within Accountability Sessions, you acknowledge that:
- Voice communications are transmitted in real-time to other participants
- Sessions may be recorded for safety review and dispute resolution
- Recordings are retained for 90 days and then deleted
- We may review recordings when investigating reported violations
- We do not use voice recordings for advertising or marketing
14.2 Voice Recording Notice
We provide in-app notice when recording is enabled. You will see a clear visual indicator within the session interface when a voice session is being recorded. This indicator will identify when recording is active, ensuring transparency about when your voice communications may be captured. You may choose not to participate in recorded sessions.
14.3 Messaging
Messages sent through the Platform are stored on our servers to enable delivery and history features. Messages may be scanned by automated systems to detect prohibited content and protect user safety. Message content is not shared with third parties except as described in this Policy.
14.4 Group Sessions
When participating in group Accountability Sessions, other participants can see:
- Your profile name and photo
- Your fitness metrics shared during the session
- Your voice communications (in voice sessions)
- Your chat messages within the session
- Your accountability ratings (if you choose to share them)
15. TRAINER MARKETPLACE DATA
15.1 Data Shared with Trainers
When you book sessions with trainers, they may access:
- Your name and profile photo
- Contact information for session coordination
- Fitness goals and relevant health information you provide
- Session history and progress notes
- Your ratings and reviews of other trainers
15.2 Trainer Obligations
Trainers agree to our Trainer Terms which require them to protect your information and use it only for providing training services. We are not responsible for how trainers handle information shared during off-platform interactions.
15.3 Reviews & Ratings
Reviews and ratings you provide for trainers are visible to other users and to the trainer. Your profile name and photo may appear with your reviews.
16. CHILDREN'S PRIVACY
16.1 Age Restriction
The Platform is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will promptly delete it.
16.2 Reporting Suspected Minors
If you believe a child under 18 has provided us with personal information or is using the Platform, please report the account immediately using the in-app reporting feature or by contacting us at privacy@inshapedates.com. We take these reports seriously and will investigate promptly.
16.3 Enforcement Pathway
Upon receiving a report of a suspected minor, we will: (a) investigate the account; (b) suspend the account pending investigation if warranted; (c) request age verification if appropriate; and (d) permanently terminate the account and delete associated data if we determine the user is under 18. We cooperate with law enforcement when required and report suspected child exploitation to the National Center for Missing & Exploited Children (NCMEC) as required by law.
17. CHANGES TO THIS POLICY
17.1 Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
17.2 Notification
We will notify you of material changes through:
- In-app notifications
- Email to your registered address
- A prominent notice on the Platform
17.3 Effective Date
The "Last Updated" date at the top of this Policy indicates when changes were made. Material changes will take effect 30 days after notice, unless we indicate otherwise. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
18. CONTACT US
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
In-Shape Dates, LLC
- Privacy Inquiries: privacy@inshapedates.com
- General Support: support@inshapedates.com
- Security Vulnerabilities: support@inshapedates.com
- Location: Hillsborough County, Florida, USA
For EEA/UK residents, you also have the right to lodge a complaint with your local data protection supervisory authority.
BY USING IN-SHAPE DATES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.