Privacy Policy
Last updated: 9/3/2026
This policy explains what GymnasTrack (a Carrefield product, in beta) collects, why, and how you can export or delete it. We do not sell your personal data.
GymnasTrack is operated by Carrefield. Product surfaces: gymnastrack.com, app.gymnastrack.com, studio.gymnastrack.com, api.gymnastrack.com, and the native athlete apps.
Privacy requests: use the Contact page on gymnastrack.com.
We collect the minimum needed to run an account-based training product.
- Account: email, username, display name, password hash (if you set a password), Apple/Google subject ids when you use those providers, verification status.
- Profile you choose to add: bio, optional height/weight/age/gender, language, privacy (public vs private account).
- Training: programs, sessions, sets, PRs, class watch/complete and optional logged sets from class chapters.
- Social: follows and requests, activity cards you explicitly share, kudos, comments, chat messages, blocks, and reports you submit.
- Coaching: roster relationships, invites, trainer profile (including displayed 1:1 monthly price), class metadata you publish.
- Billing metadata: Stripe customer / Connect / subscription / purchase ids and status. We do not store full card numbers.
- Technical: IP and device data as needed for security, rate limits, and (on native) push tokens if you allow notifications.
- Contact and demo form submissions on the marketing site if you write to us. Those submissions are stored in our database and emailed to our inbox.
Training logs and optional body metrics can be sensitive. We treat them as confidential product data. We do not run medical analytics, diagnosis, or insurance scoring. Do not enter clinical records the product does not need.
- Provide the product you signed up for (train, coach, classes, social, notifications).
- Send email: transactional messages (verification, password reset, coach or group invites), and promotional or product-update email if you opt in. You can unsubscribe from promotional email at any time.
- Process trainer SaaS payments and class checkout (Stripe).
- Host class video (our video provider) and send signed playback.
- Prevent abuse, debug, and keep the service secure.
- Comply with law when required.
If you use Apple or Google, those companies authenticate you and send us an identity token we verify on the server. We receive the email they assert (Apple may provide a relay address) and a stable subject id. We do not put OAuth client secrets in the app bundle.
We share data with vendors only to operate GymnasTrack, under their own terms:
- Hosting: API and database (currently Railway), websites (Vercel or similar).
- Email: Resend (or SMTP in development).
- Marketing contact/demo forms: stored in our database (same host as the product API) and emailed to our inbox.
- Payments: Stripe (including Connect for class payouts).
- Identity: Apple, Google.
- Video: Mux or an HTTPS playback URL you paste if Mux is unset.
- Error monitoring: Sentry, only if we configure a DSN.
- We do not currently use Google Analytics or advertising pixels on the product.
We do not sell personal information. We do not use invasive advertising analytics in this launch. If we add privacy-respecting product analytics later (for example Plausible or Umami), we will update this policy.
You can download a copy of your account data and delete (anonymize) your account from Profile / Settings in the athlete app, athlete web, and Studio.
After deletion we replace email and username, revoke refresh tokens, cancel Stripe customer subscriptions when a customer id exists, and set the account inactive. Some training or health rows may remain attached to the anonymized user id so historical logs stay internally consistent. Chat and social content you posted may remain visible to others in limited form or be orphaned; we do not promise a full cascade delete of every message.
Backups are retained for a limited operational period, then expire.
Depending on where you live (including GDPR/UK GDPR and similar laws), you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority.
Use in-app export/delete first. For other requests, use the Contact page and identify the email on the account. We may need to verify it is you.
You can opt out of promotional email at any time via the unsubscribe link in those messages or by contacting us.
GymnasTrack is 18+ only. We do not knowingly collect data from minors.
Servers and vendors may be in the United States or other countries. If you use the product from elsewhere, you understand your data may be processed in those locations.
We will update this page when the product’s data practices change. The date at the top is the latest version.
