Privacy Policy
Effective Date: December 24, 2024
STAYTRUE FITNESS LIMITED (hereinafter referred to as “we” or “our”) respects the right of every user to control their personal information to the fullest extent possible. We are committed to managing data related to user information strictly. When users access the PuroFit app (hereinafter referred to as “PuroFit”) or use our services, they need to agree to this policy regarding how PuroFit collects, uses, stores, and shares relevant user information. If users disagree with any part of this Privacy Policy, they should immediately stop using or accessing our products and services. For any questions about this policy, users may email us at service@staytruefitness.com.
Contents
- How We Collect and Use Your Information
- How We Use Cookies and Similar Technologies
- How We Share, Transfer, and Disclose Your Information
- How We Protect Your Information
- Your Rights
- How We Handle Minors' Information
- How Your Information is Stored and Transferred Globally
- Updates to This Policy
- How to Contact Us
1. How We Collect and Use Your Information
(1) Information Collected and Used When You Use Our Products or Services
We only collect and use your information as necessary for the functions described in this policy, primarily to provide you with products or services. You may choose not to provide this information; however, in most cases, we may not be able to provide you with the relevant services or respond to your queries.
When using our services, we may collect information provided directly by you or necessary for providing services, such as:
- Personal identification
- Device information
- Log information
- IP address
- Location data
Information You Provide
Personal information is collected when voluntarily provided by you via PuroFit. For example:
- When you email us, we collect your name, email address, and email content.
- When you respond to a customer satisfaction survey, we collect your name and email address.
- When you upload training records on PuroFit, we collect your relevant personal and fitness data.
Information Collected via Technology
Certain information may be passively collected when you browse or use PuroFit, including your IP address, browser type, domain name, access times, and operating system. We may also use cookies and URLs to collect information on visit dates and times, as well as search and browsing activities. This data helps us improve our products and services.
Information From Other Sources
We may receive your information from other sources, such as mail, phone, or fax, and combine it with information collected through the app to enhance the products and services we provide.
User Feedback
If you provide feedback (including suggestions, complaints, and reports) via PuroFit, we may use this feedback for any purpose without revealing personal information. We will collect any data within such communications and handle it per this policy.
Health Data We Collect and Use
To provide you with specific features, PuroFit may need access to and synchronization of the following types of health data. When requesting these permissions, we commit to the following:
-
Transparency: We will clearly explain the purpose and reasons for each permission request when accessing health data, ensuring full transparency.
-
Your Control: You can refuse or revoke authorization. Without your explicit consent, PuroFit cannot access your health data. Refusal or withdrawal of authorization may affect the functionality of certain features but will not hinder the use of other services.
-
Types of Health Data and Their Purpose:
-
Active Calories Burned: We access data on the active calories you burn during exercise to guide you in real-time adjustments to your training intensity, ensuring optimal results.
-
Total Calories Burned: We record your daily total calorie consumption to assist you in managing your health and weight.
-
Distance: We track the distance covered in each workout session to help you manage and adjust your training goals effectively.
-
Cycling Cadence: We monitor your cycling cadence to guide real-time adjustments in your training intensity for the best possible outcomes.
-
Workout Records: We log your exercise activities to create a workout history and help you review and optimize your fitness plan.
We use this information to provide identity verification, customer service, security measures, activity display, and training record functions. This information will be authorized for use throughout your period of service. If you discontinue push notifications, we will cease to use and delete the relevant information.
We guarantee that collected information will be anonymized where required by law. Information that cannot be used to identify individuals alone or in combination does not constitute personal information. If we combine non-personal data to identify you, we will treat it as personal information per this policy.
To improve our operations and services, if we need to use your information beyond the scope stated above or for additional purposes, we will notify you and obtain your consent within a reasonable period.
(2) Exceptions to Authorized Consent
According to relevant laws, we may collect and use your information without your consent under these circumstances:
- Directly related to national security or defense security.
- Directly related to public safety, public health, or significant public interest.
- Directly related to crime investigation, prosecution, trial, and enforcement.
- Necessary to protect significant lawful rights, such as life and property, when it is difficult to obtain your consent.
- Information you have voluntarily made public.
- Information collected from lawful, publicly disclosed sources, such as news reports and government disclosures.
- Necessary for signing or fulfilling a contract at your request.
- Necessary for maintaining software and service stability, such as detecting or resolving service issues.
- Collected by media organizations necessary for lawful news reporting.
- Necessary for statistical or academic research in the public interest when de-identified for external publication.
- Other circumstances stipulated by law.
2. How We Use Cookies and Similar Technologies
(1) Cookies
We store small data files called cookies on your device to ensure proper website or app operation. Cookies typically contain an identifier, site name, and numbers or characters and allow us to store your visit preferences.
We do not use cookies for any purpose outside those listed in this policy. You may manage or delete cookies per your preferences and adjust settings in your browser to prevent cookies. However, if you do so, you will need to reconfigure user settings with each visit.
(2) Web Beacons and Pixel Tags
Besides cookies, we may use other tracking technologies, such as web beacons and pixel tags, on our site or app. For example, emails sent to you may contain a URL link to our website. If you click the link, we track the click to understand your preferences and improve services. Web beacons are typically embedded images on websites or emails that help us know if the email was opened. If you do not want to be tracked in this way, you may unsubscribe from our mailing list.
(3) Do Not Track
Many browsers have a Do Not Track feature. Although no global standard exists yet for websites' responses to Do Not Track requests, all of our sites will respect this setting if enabled in your browser.
3. How We Share, Transfer, and Disclose Your Information
(1) Sharing
We do not share your information with other companies, organizations, or individuals, except in the following cases:
- With Explicit Consent: With your consent, we may share your information with third parties.
- As Required by Law: We may share your information externally as required by applicable laws, regulations, or mandatory requests from governmental authorities.
- With Affiliated Companies: Your information may be shared with our affiliated companies. We will only share the information necessary and will limit its use to the purposes stated in this Privacy Policy. If an affiliated company intends to change the purpose of processing your information, it will seek your consent again.
- With Authorized Partners: To achieve the purposes stated in this policy, certain services will be provided by authorized partners. We may share certain user information with these partners to provide better customer service and enhance user experience. We will only share user information for legitimate, justified, necessary, specific, and clear purposes and only the information essential for providing these services. For improved operation and development of technology and services, you agree that we and our authorized partners may use the collected information for additional services and purposes, in compliance with relevant laws and regulations.
Below is a list of specific authorized partners, along with links to their respective privacy policies. We recommend that you read these third-party privacy policies:
- Health Data Sharing Platform Services: The Health Connect functionality is provided by Google LLC. PuroFit accesses and uses the following health data via Health Connect, provided you have explicitly authorized it: activity and exercise data (e.g., workout sessions, duration, calories, distance, and class names).
Your health data will only be used to enable app features, such as generating personalized health reports, recording workouts, and managing health goals. We will not use your data for advertising or marketing purposes. Data accessed via Health Connect is stored directly on your device, and data transfers are encrypted to ensure security. Unless necessary, we will not store your health data on our servers.
You can manage or revoke our access to your health data at any time through the Health Connect settings in the Android system. Revoking access may impact the normal functionality of some features but will not affect the use of other services.
We will not sell your health data. We may only share your health data with third parties under the following circumstances:
- You explicitly authorize the synchronization of data with other health apps.
- Sharing is required by law (e.g., legal investigations or court orders).
All data sharing you authorize will adhere to the privacy policies of the relevant third parties, such as: Google Privacy Policy.
For companies, organizations, and individuals with whom we share user information, we will sign strict confidentiality agreements requiring them to handle the information according to our instructions, this Privacy Policy, and any other relevant confidentiality and security measures.
(2) Transfer
We will not transfer your information to any companies, organizations, or individuals, except in the following cases:
- With Explicit Consent: With your explicit consent, we may transfer your information to other parties.
- In the Event of Mergers, Acquisitions, or Bankruptcy: If a transfer of user information is involved in a merger, acquisition, or bankruptcy liquidation, we will require the new company or organization that holds your information to continue to be bound by this Privacy Policy. Otherwise, we will require that company or organization to seek your authorization and consent again.
(3) Public Disclosure
We will only publicly disclose your information under the following circumstances:
- With Your Explicit Consent: We may publicly disclose your information with your explicit consent.
- Legal Disclosures: We may publicly disclose your information if required by law, legal proceedings, litigation, or mandatory requests from governmental authorities.
(4) Exceptions to Prior Consent for Sharing, Transferring, and Publicly Disclosing Information
Please understand that according to laws, regulations, and relevant national standards, we may share, transfer, or publicly disclose your information without obtaining your prior consent in the following circumstances:
- Directly related to national security or defense.
- Directly related to public safety, public health, or significant public interests.
- Directly related to criminal investigations, prosecutions, trials, or enforcement of judgments.
- Necessary to protect your or another individual’s significant legal rights, such as life and property, but it is difficult to obtain your consent.
- When you have voluntarily made the information public.
- When information is collected from legally disclosed public sources, such as legitimate news reports or government disclosures.
4. How We Protect Your Information
(1) Security Measures
We have implemented industry-standard security measures to protect the user information you provide, preventing unauthorized access, disclosure, use, modification, damage, or loss of data. We take all reasonable and feasible steps to safeguard your information. For example:
- Data exchanged between your browser and our services is protected by SSL encryption.
- We offer HTTPS secure browsing on our website.
- We use encryption to ensure data confidentiality.
- We deploy trusted protective mechanisms to prevent data from malicious attacks.
- We enforce access control to ensure only authorized personnel can access user information.
- We conduct security and privacy training to enhance employee awareness of the importance of protecting user information.
(2) Data Retention
We will take all reasonable and feasible steps to ensure that no irrelevant user information is collected. We will retain your information only for the time necessary to fulfill the purposes outlined in this policy, unless an extended retention period is required or permitted by law.
(3) Internet Security Risks
The internet is not an entirely secure environment, and email, instant messaging, and other communication methods with other users are not encrypted. We strongly recommend that you do not send personal information through these channels.
(4) Risks of Information Networks
The internet environment is not 100% secure, and while we strive to ensure the security of any information you send us, there may still be risks. Despite our best efforts and reasonable and necessary measures, unauthorized access, theft, alteration, or destruction of your information may occur, potentially harming your legal rights. Please understand and voluntarily assume these risks associated with information networks.
(5) Handling Security Incidents
In the unfortunate event of a security incident involving user information, we will inform you promptly as required by laws and regulations, providing details on the incident, possible impacts, measures we have taken or will take, advice on personal measures to mitigate risks, and available remedies. We will notify you by email, letter, phone, or push notification. If individual notifications are difficult, we will use reasonable and effective means to issue an announcement. We will also report the handling of user information security incidents to regulatory authorities as required.
5. Your Rights
In accordance with relevant laws, regulations, standards, and customary practices in other countries and regions, we ensure that you may exercise the following rights regarding your personal information:
Access to Your Information
You have the right to access your information, except in cases where laws and regulations provide otherwise. To exercise your right to data access, please email service@staytruefitness.com.
Correction of Your Information
If you find that we have processed incorrect information about you, you have the right to request correction. You may submit a correction request by contacting us via the email address provided above.
Deletion of Your Information
You may request the deletion of your information under the following circumstances:
- If our processing of your information violates laws or regulations.
- If we collect or use your information without obtaining your consent.
- If our processing of your information breaches our agreement with you.
- If you no longer use our products or services, or you have canceled your account.
- If we no longer provide products or services to you.
Change the Scope of Your Consent
Each business function requires some essential user information (as detailed in Part I of this policy). You may provide or withdraw consent for the collection and use of your information at any time. You may adjust consent by navigating to: My Profile > Settings > Personal Information.
Once consent is withdrawn, we will cease processing the relevant information. Please be aware that withdrawing consent may lead to certain consequences, such as the inability to continue providing certain services or features. However, your decision to withdraw consent will not affect the processing of your information previously authorized.
Account Deactivation
You may deactivate your previously registered account at any time by navigating to My Profile > Settings > Account Deactivation > Enter Password > Complete Deactivation. After deactivation, we will stop providing products or services to you and, at your request, delete or anonymize your information, except as otherwise required by law. Deactivation may also result in the loss of access to data in your account, so please proceed with caution.
Restriction on Automated Decision-Making Systems
In certain business functions, we may make decisions based solely on non-human automated processes, such as information systems and algorithms. If these decisions significantly impact your legal rights, you have the right to request an explanation, and we will provide appropriate remedial measures.
Responding to Your Requests
To ensure security, you may need to provide a written request or other proof of identity. We may ask you to verify your identity before processing your request. We will respond within 30 days.
For reasonable requests, we do not charge fees in principle; however, for repeated requests or those that exceed reasonable limits, we may charge a cost-based fee. We may refuse requests that are unduly repetitive, require excessive technical resources (e.g., developing new systems or fundamentally changing existing practices), compromise the legitimate rights of others, or are otherwise impractical.
Please understand that, for security purposes, due to legal or regulatory requirements, or due to technical limitations, we may not be able to respond to certain requests, such as the following:
- Requests related to the obligations of the data controller under laws and regulations.
- Requests directly related to national security or defense.
- Requests directly related to public safety, public health, or significant public interests.
- Requests directly related to criminal investigations, prosecutions, trials, or enforcement of judgments.
- Requests where there is sufficient evidence to indicate that the data subject is acting in bad faith or abusing rights.
- Requests made to protect the life, property, and other significant legal rights of the data subject or other individuals but where obtaining consent is challenging.
- Requests that, if fulfilled, could severely harm the legitimate rights of the data subject or other individuals or organizations.
- Requests involving trade secrets.
6. How We Handle Children's Personal Information
We take the protection of children's personal information very seriously. Our products, websites, and services are primarily intended for adults. Children should not create their own user accounts without the consent of a parent or guardian. Although local laws and customs may define "children" differently, we regard anyone under the age of 13 as a minor.
For cases where children’s information is collected with parental or guardian consent, we will only store, use, or disclose this information as legally permitted, with explicit consent from the parent or guardian, or as necessary to protect the child. Otherwise, we will strive to promptly delete the relevant data.
Due to limitations in current technology and business practices, we may find it challenging to proactively identify children’s personal information. If you discover that we have unknowingly collected children’s personal information without verified consent from a guardian, please contact us, and we will work to delete the information promptly upon discovery. If we discover such information ourselves, we will also delete it promptly unless otherwise required by law.
7. How Your Information Is Stored and Transferred Globally
In principle, user information that we collect and generate within the United States will be stored within the United States. We will retain your information only for the period necessary to achieve the purposes outlined in this policy and as required by applicable laws. After the retention period, we will delete or anonymize your information in accordance with legal requirements.
Since we provide products and services through globally distributed resources and servers, your information may be transferred to jurisdictions outside of your country or region where the products or services are used, subject to your authorization and consent. Such jurisdictions may have different data protection laws or no relevant laws at all. In such cases, we will ensure that your information is adequately protected in a manner equivalent to U.S. standards. For example, we may request your consent for cross-border data transfers or implement security measures like data de-identification before transferring data.
8. How This Policy Is Updated
Our Privacy Policy may change. We will not reduce your rights under this Privacy Policy without your explicit consent. Any changes to this policy will be posted on this page.
For significant changes, we will provide a more prominent notice. Significant changes to this policy include, but are not limited to:
- Major changes to our service model, such as the purpose of processing user information, the type of information processed, or how information is used.
- Major changes in ownership structure or organizational structure, such as changes in ownership due to business adjustments, mergers, or acquisitions.
- Changes to the main entities with whom information is shared, transferred, or publicly disclosed.
- Significant changes to your rights regarding information processing and how you can exercise those rights.
- Changes to the department responsible for user information security, as well as contact information and complaint channels.
- When an information security impact assessment indicates a high risk.
9. How to Contact Us
If you have any questions, comments, or suggestions regarding this Privacy Policy, please contact us via email at service@staytruefitness.com. In general, we will respond within 30 days.