Privacy Policy for Track28
Effective Date: Monday, August 10, 2026
Track28 ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our app and services.
1. Information We Collect
We collect the following types of personal data:
- Account Information: Your email address and a first name — which does not have to be your real name — plus an optional last name.
- Health Data: where this policy says "health data," it includes all of the following. These are the categories we may collect; the examples are illustrative, and which measurements we actually hold depends on the features you use and what you choose to sync.
- Cycle and hormonal information — such as period dates, cycle length, ovulation, contraception method and type (whichever method you use), cycle regularity, and your hormonal life stage, including perimenopause or menopause status and related information you enter (for example, hormone therapy);
- Details you enter about yourself — such as your year of birth, your body measurements, and the reference values your training is built on;
- Your workouts and activities;
- Body and physiological measurements — such as heart rate and heart-rate variability, VO₂ max, fitness age, sleep, and recovery indicators;
- Anything you choose to sync from a health platform such as Apple Health, or from any device or service you connect — including the GPS routes of your activities;
- Information we derive about you — such as cycle or hormonal predictions, phase estimates, and the training plan we adapt for you, generated from what you enter and sync.
- Files You Upload: Anything you choose to send us as a file — for example a photo or a document attached to a support-chat message. If what you send contains health information, we treat it as health data.
- App Usage Data: Interactions with the app, features used, and technical logs of how the app is used.
- Device Information: Information about the device used to access our app, including its IP address and a limited set of on-device identifiers.
- Cookies: Data collected through cookies for analytics and functionality.
2. How We Collect Your Information
We collect information in the following ways:
- User Input: Information provided directly by you when setting up your profile or using the app.
- Automatic Collection: Data gathered through your interactions with the app, including app usage patterns.
- Sign-in providers: If you create your account or sign in with a third-party sign-in service, we receive from it only an account identifier, your email address — or the private relay address you choose to share instead — and your name. Nothing else, and we never see your password for that service. The current sign-in providers are listed on our Service Providers page.
- Third-Party Integrations: Data obtained from the health platforms, devices and services you choose to connect, such as Apple's HealthKit.
3. Use of Collected Information
We use the collected information to:
- Personalize running plans tailored to your needs.
- Send notifications and updates.
- Improve and optimize app functionality.
- Analyze app usage for insights and troubleshooting.
Marketing emails: If you subscribe to our newsletter, we send it based on your consent and through our newsletter service (see Section 11). Every email includes an unsubscribe link, and you can withdraw your consent at any time. We do not need your consent to send essential service or transactional messages (for example, account or security notices).
Research & statistics: We may use de-identified information — stripped of your name, email, and account identifiers — for internal study, research, and statistics, to understand training patterns and improve our methodology. Identifiable health data is never used for this, the de-identified data never leaves our control, and anyone who works on it for us is bound by written confidentiality commitments.
4. Sharing of Information
We never sell your health data, and we never share it with advertisers or analytics providers. Apart from the disclosures the law can compel (below), the only third parties that ever hold it are the service providers who store and process it on our behalf, under written commitments (see Section 11).
We may share pseudonymized app usage data with:
- Analytics Providers: To help us understand and enhance app performance (see Section 11 below for details).
When the law compels disclosure. A court order, warrant, subpoena, or other binding legal demand can require us to disclose personal information, including health data. If we receive one, we verify that it is valid, disclose only what it actually requires, and tell you about it unless the law prohibits us from doing so.
5. Legal Basis, Consent & Compliance with Data Protection Laws
Track28 is operated by a Quebec company. Our primary framework is Quebec's Law 25 (Loi modernisant des dispositions législatives en matière de protection des renseignements personnels), and we apply its standard of protection to every user, wherever you live. Where the privacy laws of your place of residence give you additional rights — such as the GDPR if you live in the European Economic Area or the United Kingdom, or state laws such as the CCPA if you live in California — we honour those rights as those laws require.
Two categories, handled differently:
- Account & app-usage data (name, email, device data, in-app activity) is processed to provide and operate the Services. Where the GDPR applies, the legal basis is the performance of our contract with you (Art. 6(1)(b)) and our legitimate interest in operating and improving the app.
- Health data (as defined in Section 1) is sensitive personal information under Quebec's Law 25 and, where the GDPR applies, special-category data under Art. 9. We process it only with your express consent, and solely to build and adapt your training plan.
We ask for each of these separately in the app, on a screen dedicated to your choices — each one its own Yes-or-No question, answered before we first collect any health data, and never bundled into accepting our Terms of Use. Nothing is pre-selected, and entering data is not how you agree — answering Yes is:
- Required — "I agree that Track28 can use my health data to build and adapt my training plan." — "health data" as defined in Section 1 (Law 25 — sensitive information; GDPR Art. 9(2)(a))
- Optional — "I agree that Track28 can use my activity in the app, linked to my account, to improve it. This never includes my health data." (GDPR Art. 6(1)(a))
How to withdraw each of these:
- Analytics consent — turn it off at any time in the app's settings. Nothing else changes.
- Session replay consent — an additional optional consent, only ever offered in the app's settings (never at signup): masked screen recordings that help us diagnose usability issues (see Section 11). Turn it off in the same place. It is also withdrawn automatically if you turn off analytics — turning analytics back on does not re-enable it.
- Health-data consent — the app cannot build a training plan without your cycle and health data, so there is no partial version of this: withdrawing means deleting your account, which you can do at any time in the app's settings. Deleting erases your health data along with the rest of your account (see Section 7).
Withdrawing your consent does not affect the lawfulness of processing done before the withdrawal.
Automated processing: Your training plans are generated automatically by our algorithms from the data you provide. Under Quebec's Law 25, we do not make decisions about you based exclusively on automated processing: your training plan is a recommendation you remain free to follow or not. We do not use automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Art. 22, and these plans are not a substitute for professional or medical advice — you should always apply your own judgment (see our Terms of Use, Section 4). If you would like to know what information was used to build a given plan, or to have a person review it, write to our Privacy Officer — we will explain the main factors, and a person will look at it.
U.S. residents (California and other states): We do not sell your personal information, and we do not share it for cross-context behavioral advertising; we never sell or share your health data under any definition. If you are a California resident, you may request access to, correction of, or deletion of your personal information, and you will not be discriminated against for exercising these rights. To exercise any right, contact us at privacy@track28app.com.
6. Data Security
We protect your information with measures proportionate to its sensitivity:
- In transit: traffic between the app or our website and our servers is encrypted with TLS/HTTPS.
- At rest: passwords are hashed, and access tokens for the services you connect are encrypted with a separate key. Our backups are encrypted before they leave our servers, and encrypted again by the storage provider that holds them.
- Access: only the minimum number of people can reach production data, each with their own credentials. Changes to accounts, training plans and connected devices are logged.
- No system is perfectly secure. We cannot guarantee that these measures will prevent every incident. If a confidentiality incident presents a risk of serious injury, we notify you and the Commission d'accès à l'information — see our Privacy Governance page.
7. Data Retention and Deletion
We keep your personal information only as long as necessary to provide the Services. This is our retention schedule:
| What we keep | How long we keep it |
|---|---|
| Account data, cycle and health data, workouts, connected-device data | As long as your account exists |
| Technical and security logs (including IP addresses) | 2 years |
| Your data after you delete your account | Removed from our live systems within 30 days |
| Backups | Purged within 90 days of deletion |
| Newsletter subscription (first name and email) | Until you unsubscribe, or when you delete your account |
| Records of privacy requests and complaints (including after account deletion) | 3 years from the day we close them |
| Our register of confidentiality incidents | 5 years from the day we become aware of the incident, as the law requires |
Your newsletter subscription is deleted with your account. If you subscribed to our newsletter, deleting your account also removes you from it. You can also unsubscribe at any time — without touching your account — using the link in any of our emails, or by writing to us.
One record outlives your account. For security, and to establish or defend legal claims, we keep a log of changes made to accounts, training plans and connected devices — what changed, when, and the IP address it came from, including, where the change was to the account itself, the account's email and name as they stood at the time — for up to 2 years, including after an account is deleted. This log never contains your cycle information, your contraception method, your physiological metrics or your location data.
We may retain limited information longer where required to meet a legal, tax, or accounting obligation, or to establish, exercise, or defend legal claims. Once personal information reaches the end of its retention period, we destroy or anonymize it.
You can request deletion at any time in the app, or by contacting our Privacy Officer at privacy@track28app.com.
8. Your Privacy Rights
Depending on your location, you have the following rights over your personal information:
- Access the personal data we hold about you.
- Correct inaccuracies in your data.
- Delete your data ("right to erasure").
- Portability — receive a copy of your data in a structured, commonly used, machine-readable format.
- Object to or restrict the processing of your data.
- Withdraw your consent at any time, including for health-data processing — see Section 5 for how each one is withdrawn (this does not affect processing carried out before withdrawal).
- Ask us to stop disseminating your personal information, or to de-index a link to it, where the law provides.
- Lodge a complaint with your data-protection authority — in Quebec, the Commission d'accès à l'information du Québec (CAI); in the EEA, your national supervisory authority.
To exercise any of these rights, contact our Privacy Officer at privacy@track28app.com. We acknowledge your request within 10 business days and respond within 30 days, as the law requires.
9. Cookies & Trackers
On our website, non-essential analytics cookies are off by default — they load only after you accept them in our cookie banner. You can change or withdraw your choice at any time via the cookie-preferences link on our website. Essential cookies needed for the site to work do not require consent.
In the app, we use a limited set of on-device identifiers for analytics, described in Section 11. You can control these in the app's settings and through your device's privacy settings.
Location and profiling functions are off by default. Nothing in the Track28 app identifies, locates, or profiles you unless you turn it on: GPS routes reach us only if you connect a health platform, device or service and choose to sync activities, or if you record a run with the app, and analytics run only if you opt in. You can deactivate each of these at any time in the app's settings. On our website, our analytics provider's script loads in a cookieless mode that sets no identifier until you accept the banner.
See Section 11 for the categories of services we use and what each one collects.
10. Updates to this Policy
We may update this Privacy Policy from time to time. Changes are posted here with an updated "Effective Date." If a change materially affects how we handle your personal information — a new purpose, a new category of data, or a new type of recipient — we will notify you in the app or by email before it takes effect and, where the law requires it, ask for your consent.
11. Third-Party Services & Trackers
We use a small number of third-party service providers to run, measure, and support Track28, on our website and in the app. They fall into the following categories:
- Hosting, storage & email delivery — cloud infrastructure that runs our servers and database, stores our encrypted backups, and sends transactional email and our newsletter.
- App-usage & web analytics — help us understand how the app and website are used. In the app, analytics run only if you opt in; on the website, analytics cookies load only after you accept the cookie banner (see Section 9).
- Crash & performance diagnostics — necessary diagnostics that keep the app stable and responsive; they are not used for marketing and do not require consent.
- Session replay — optional, masked screen recordings used to diagnose usability issues. Off by default — it runs only if you turn it on in the app's Settings.
- Support chat — when you open the in-app support chat, it receives your messages and anything you attach to them, together with basic account and app details that let us recognize you and reproduce the problem — such as your email address, your name, and your app version. We never send it your health data.
- Device & health integrations — the health platforms, devices and services you choose to connect, such as Apple HealthKit (data stays on your device, under Apple's permission system).
The current list of providers — who they are, what each one does, and where it stores data — is published on our Service Providers page and kept up to date there. A change of provider within these categories does not change this policy or the commitments it makes.
What we never share: We do not send your health data, menstrual-cycle information, GPS routes, or personal health metrics to any analytics or advertising provider. This information is used only to build and adapt your training plan.
Cross-border processing: Some providers process personal information outside Quebec, including in the United States and Europe. Before communicating personal information outside Quebec, we carry out a privacy impact assessment to confirm it will receive adequate protection, and the providers that store or process your account and health information on our behalf are bound by written data-protection commitments — including, where applicable, the European Commission's Standard Contractual Clauses (SCCs) or a provider's certification under the EU–U.S. Data Privacy Framework. Which agreement covers which provider is set out on our Service Providers page.
12. Privacy Officer & Contact
Under Quebec's Law 25, we have designated a Privacy Officer (responsable de la protection des renseignements personnels) who oversees our compliance with privacy law and handles your requests.
Privacy Officer: privacy@track28app.com
To ask a question, raise a concern, or exercise your privacy rights — access, correction, deletion, portability, or withdrawal of consent — contact our Privacy Officer at the address above. We acknowledge your request within 10 business days and respond within 30 days, as the law requires. You can also download a copy of your data directly from the app at any time — it contains the information you gave us and what your devices synced; a full access request, covering everything we hold about you, goes through the Privacy Officer.
Complaints and how we govern your data: if you are unhappy with how we handled your information or your request, our Privacy Governance & Complaints page explains how we protect personal information internally and how to file a complaint — including your right to escalate to the Commission d'accès à l'information du Québec.
General contact: contact@track28app.com
Company: Solutions Track28 inc. — NEQ 1181834293
Mail: 1709 av. Egan, Montréal (Québec) H4E 2J6, Canada
This policy is drawn up in French. The French version prevails; this English version is provided for convenience.