Privacy Policy
Last updated: 24 July 2026
This policy explains what personal data fitness.com.cy ("we") collects, why, and what your rights are. The short, honest version: we collect what the Platform needs to work, nothing more, and we never sell your data.
What we collect
Account data: your email address and a password (stored in hashed form by our authentication provider), or your Google account email if you sign in with Google. Profile data you add: for clients, your name and optional photo and location; for providers, the business information you publish (name, description, photos, prices, location, staff, contact details). Messages: conversations between clients and providers through the Platform's messaging. Call-back form: your name and phone number when you ask us to call you (emails you send us stay in email). Technical data: functional cookies (see below) and, for security, pseudonymous identifiers derived from your IP address (we store a salted hash, never the address itself) used for rate limiting and abuse prevention.
How we use it
To run the Platform: show provider profiles, power search by location, deliver messages and notifications. To moderate: review provider listings and handle abuse reports. To respond: answer your emails and call-back requests. To protect: prevent spam, bots and abuse. We do not use your data for advertising and we do not sell it to anyone.
Cookies
We use only functional cookies: your session (so you stay signed in), your language and your theme preference. There are no advertising cookies and no third-party analytics cookies.
Who processes data for us
Like every modern website, we rely on a few infrastructure providers that process data on our behalf: Supabase (database, authentication and file storage), Vercel (website hosting), Mapbox (maps and address search), Cloudflare Turnstile (bot protection on forms) and Google (only if you choose to sign in with Google). Each processes only what its role requires.
What is public and what is shared
Provider profiles are public by design: everything a provider publishes on their profile is visible to anyone. Client accounts are not public. We share personal data only with the processors above, or when the law requires it. We never sell personal data.
How long we keep data
Account and profile data: until you delete your account; deletion permanently erases your profile, messages and images. Contact-form requests: deleted within 90 days after they are handled. In-app notifications: deleted after 30 days. Limited records may be kept longer where the law requires it or to prevent abuse (for example, the ban list that stops a banned account from re-registering).
Your rights
Under the GDPR you can ask for access to, correction of, or deletion of your personal data, ask us to restrict or object to processing, and request a copy in a portable format. Most of this is self-service: you can edit your data and delete your account from your account settings. For anything else, email us and we will respond within a month. You also have the right to complain to the Commissioner for Personal Data Protection of the Republic of Cyprus.
Security
All traffic to the Platform is encrypted (HTTPS). Access to personal data is restricted by row-level security rules in our database, and administrative actions are logged. No system is perfectly secure, but we design for least access by default.
Children
The Platform is not directed at children under 16, and you must be at least 16 to create an account. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If we change what we collect or how we use it, we will update this page and its date. Significant changes will be made visible on the Platform.
Contact
For any privacy question or request, email us at info@fitness.com.cy.