1. Introduction
HOUSE PULSE LIMITED ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the HoupulFit mobile application ("App").
2. Information we collect
2.1 Personal information you provide
- Account information: email address, username, password (stored as a hash).
- Profile information: name, age, fitness goals, preferences.
- Workout data: exercise routines, sets, reps, weights, workout history.
- Communication data: messages in community forums, support requests.
2.2 Automatically collected information
- Device information: device type, operating system, app version.
- Location data: GPS coordinates for the gym-finder feature (when permitted).
- Usage analytics: app interactions, feature usage, session duration.
- Technical data: IP address, crash reports, performance metrics.
2.3 Third-party data / sub-processors
- Google Maps / Google Places — location services for nearby-gym discovery.
- Supabase — database hosting, authentication, file storage.
- Stripe — subscription payment processing. Stripe collects your payment-card details directly; we never see or store your full card number.
3. How we use your information
3.1 Core app functionality
- Provide workout tracking and fitness program management.
- Authenticate accounts and maintain session security.
- Synchronise data across your devices.
- Locate nearby gyms and fitness facilities.
3.2 Service improvement
- Analyse app usage to improve user experience and develop new features.
- Troubleshoot technical issues and maintain app stability.
- Provide customer support and respond to inquiries.
3.3 Communications
- Send important app updates and security notifications.
- Provide subscription and billing information.
- Respond to support requests and feedback.
4. Data storage and security
4.1 Data storage
Your data is stored on Supabase infrastructure in secure, compliant facilities. All transmissions are encrypted using industry-standard protocols (HTTPS/TLS).
4.2 Security measures
- Password hashing (bcrypt).
- Secure HTTPS/TLS connections for all data transmission.
- Regular security audits and vulnerability assessments.
- Access controls limiting data access to authorised personnel only.
4.3 Data retention
- Account data: retained while your account is active.
- Workout data: retained for account lifetime or until deletion requested.
- Analytics data: retained indefinitely in aggregated form (no longer linked to you once your account is deleted).
- Support communications: retained for 3 years for quality assurance.
- Billing & payment records (managed by Stripe): retained by Stripe for at least 7 years to meet tax and financial-reporting obligations, even after you delete your HoupulFit account.
5. Data sharing and disclosure
5.1 We do not sell your data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
5.2 Limited sharing scenarios
- Service providers (sub-processors): Supabase (database, authentication, storage — US / AU regions), Google Maps Platform (gym discovery), Stripe (subscription payment processing).
- Legal requirements: when required by law, court orders, or to protect our legal rights.
- Safety protection: to prevent fraud, abuse, or harm to users or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets.
5.3 Community features
- Workout posts and comments you choose to share are visible to other users.
- You control what information appears in your public profile.
- Community interactions are governed by our Terms of Service.
6. Your privacy rights
6.1 Access and control
- Access: request a copy of your personal data.
- Correction: update or correct inaccurate information.
- Deletion: request deletion of your account and data.
- Portability: export your workout data in a standard format.
- Restriction: limit how we process your data.
6.2 Account management
- App Settings → Privacy Settings.
- Account Settings → Data Management.
- Email support@housepulse.org for assistance.
6.2.1 Account deletion (Google Play required disclosure)
You can permanently delete your HoupulFit account and all associated personal data at any time:
- In-app: Settings → Delete Account. Confirm both prompts to proceed. Your account, profile, workout history, social posts, and gamification data will be removed within 30 days.
- Without the app installed: email support@housepulse.org from your registered email with the subject line "Account Deletion". We will verify your identity and complete the deletion within 30 days.
- What is retained: Stripe billing records (legally required for tax and financial reporting), aggregated and anonymised analytics that no longer identify you, and any data we are legally required to retain.
For detailed step-by-step instructions see our Account Deletion page.
6.3 Marketing communications
You can opt out of promotional emails at any time. Essential service communications cannot be disabled. Push notification preferences can be managed in device settings.
7. Location data
7.1 Location services
Location access is optional and is used for two distinct purposes:
- Nearby-gym search. Only precise GPS coordinates for nearby-gym search are not stored — they are sent to Google Places at the moment of the search and discarded afterwards.
- Gym check-ins and local challenges. Check-ins to a specific gym are stored against your profile (gym ID, timestamp, optional caption) so the social feed, leaderboards, and local-challenge features can work.
You can enable/disable location services in your device settings at any time. Disabling location turns off nearby-gym search and check-in features but does not delete past check-ins; to remove those, edit or delete the relevant posts, or delete your account.
We do not derive your home address, work address, or movement history from check-ins.
7.2 Location data sharing
- Search-time GPS coordinates are sent to Google Maps Platform / Google Places to return relevant results.
- Stored gym check-ins are visible to other users via the social feed and leaderboards in accordance with your privacy settings.
- We do not sell location data and do not share it with advertisers.
8. Children's privacy
HoupulFit is not intended for children under 13 years of age (or under 16 in jurisdictions where the lawful age for digital consent is higher, including the European Economic Area and the United Kingdom unless your member-state law specifies otherwise). We do not knowingly collect personal information from children below the applicable minimum age. If we discover that we have collected such information, we will delete it immediately. Users between 13 and 18 should obtain parent or guardian consent before using HoupulFit.
9. International data transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with applicable data-protection laws.
10. Changes to this Privacy Policy
- We will notify you of significant changes through the app or email.
- The updated policy will be posted with a new effective date.
- At least 30 days notice will be given for material changes.
- Your rights under the previous policy will be honoured during transition periods.
11. California privacy rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act: the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale of personal information (we don't sell data), and the right to non-discrimination for exercising privacy rights.
12. European privacy rights (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, you have additional rights under the GDPR / UK GDPR:
- Lawful basis for processing: contract performance for core features, legitimate interest for analytics and security, consent for marketing and optional location features.
- Right to withdraw consent at any time.
- Right to data portability.
- Right to object to processing based on legitimate interests.
- Right to lodge a complaint with your local supervisory authority.
12A. New Zealand privacy rights (Privacy Act 2020)
HOUSE PULSE LIMITED is a New Zealand agency subject to the Privacy Act 2020 and the Information Privacy Principles (IPPs). You have the right to:
- Request access to the personal information we hold about you (IPP 6).
- Request correction of inaccurate information (IPP 7).
- Complain to the Office of the Privacy Commissioner (OPC) at privacy.org.nz if you believe we have not complied with the Privacy Act 2020.
If we become aware of a notifiable privacy breach (one likely to cause serious harm), we will notify affected individuals and the OPC in accordance with Part 6 of the Privacy Act 2020.
12B. Australian privacy rights (Privacy Act 1988)
If you are an Australian resident, the Australian Privacy Principles (APPs) apply. You may contact us to access or correct your personal information and may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Contact
For privacy-related questions or to exercise your rights:
- Email: support@housepulse.org
- Subject line: "Privacy Policy Inquiry" or "Data Protection Request"
- Response time: within 48 hours for privacy matters.
HOUSE PULSE LIMITED · Auckland, New Zealand · NZ Company 9304370 · NZBN 9429052554209
By using HoupulFit, you acknowledge that you have read, understood, and agree to this Privacy Policy. Your continued use of the app after policy updates constitutes acceptance of the revised terms.