Trust, privacy and security

FitConnect Pro is a European platform for personal trainers and dietitians. We handle professional and client data with a privacy-by-design approach, EU data residency and GDPR compliance.

EU data residency

We host data on infrastructure located in the European Union. Our database, authentication and storage run on Supabase (EU region) and the app is served from Vercel. We do not sell personal data or use it for third-party advertising.

Providers and subprocessors

These providers are involved depending on the feature used. Some act as processors for NEXUSVIBE SL, while others, such as Stripe or Apple for payments, act as independent controllers under their own terms. We apply the relevant contractual and transfer safeguards.

ProviderPurposeLocation
SupabaseDatabase, authentication and file storageEU
VercelApplication hosting and delivery (hosting/CDN)EU / global edge
Vercel AnalyticsAggregated, cookieless usage analyticsEU / global edge
Google AnalyticsSite usage analytics, only if you accept analytics cookiesEU / US (standard contractual clauses)
Meta PlatformsFacebook and Instagram ad measurement through Pixel and Conversions API, only with marketing consentEU / US (standard contractual clauses)
StripeWeb subscriptions and trainer–client payments through Stripe ConnectEU / US (standard contractual clauses)
AppleOptional sign-in and subscriptions purchased in the iOS appEU / global (Apple's applicable safeguards)
AnthropicAI-assisted drafts and explanations using minimized, pseudonymized contextUS (applicable transfer safeguards)
ResendTransactional email delivery (notices and confirmations)EU / US (standard contractual clauses)
GoogleSign in with Google (OAuth), optionalEU / US (standard contractual clauses)

AI-assisted features apply deterministic rules first. Anthropic receives only structured, minimized, and pseudonymized context through our AI gateway; the trainer reviews the output before sharing it, and health data requires explicit consent.

Security practices

  • Per-user and per-role data isolation via Row Level Security (RLS) on every database table.
  • Encryption in transit (HTTPS/TLS) and at rest at the database level.
  • Least-privilege principle: service keys are never exposed to the client browser.
  • Audit logging of sensitive actions (who did what and when).
  • Authentication managed with Supabase Auth and optional Google or Apple sign-in, with role verification and versioned legal acceptance.
  • We never store full card numbers or Apple payment credentials: Stripe and Apple process their respective purchase channels.

Your rights (GDPR)

As a data subject, you can exercise the following rights over your personal data at any time:

  • Access to your personal data.
  • Rectification of inaccurate data.
  • Erasure ("right to be forgotten").
  • Portability of your data in a structured format.
  • Restriction of and objection to processing.
  • Withdraw consent at any time.

Payment security

Trainer web subscriptions and client-to-trainer payments are processed by Stripe; subscriptions purchased on iOS are processed through Apple In-App Purchase. We do not store full card details or Apple payment credentials. With Stripe Connect, the trainer is the seller of the coaching service and receives settlement; FitConnect Pro charges 10% of the net amount plus applicable VAT on that commission, and Stripe processing fees are separate. Web subscription requests go through FitConnect Pro support, Apple cancellation and refund requests through the Apple account and reportaproblem.apple.com, and coaching refunds follow the trainer-client agreement without limiting non-waivable rights.

Contact and Data Protection Officer

To exercise your rights or resolve any privacy question, email us at privacidad@fitconnect.pro. We respond within the time limits set by GDPR.

Legal information

Data controller: NEXUSVIBE SL (trading as FitConnect Pro), Tax ID (NIF) B70966650, registered office at Avenida del Cantábrico 249, 28939 Arroyomolinos, Madrid, Spain. Registered in the Commercial Registry of Madrid, Volume 46502, Folio 135, Section 1, Sheet M-816510. Contact: gestion@nexusvibe.net.

FitConnect Pro operates under European Union and Spanish law. See also our Legal Notice, Privacy Policy, Terms and Cookies Policy.

Frequently asked questions

Where is my data hosted?
Your data is hosted on infrastructure located in the European Union (Supabase in an EU region and Vercel). It is not transferred outside the EEA except to subprocessors with GDPR safeguards via standard contractual clauses.
Is FitConnect Pro GDPR compliant?
Yes. We apply privacy by design, data minimization and data processing agreements (DPAs) with our subprocessors, and we support the rights of access, rectification, erasure and portability.
Which providers process data?
Depending on the feature used, we work with Supabase, Vercel, Stripe, Apple, Anthropic, Resend, Google, Google Analytics, and Meta. The table above states each purpose and applicable safeguards.
Do you store my payment credentials?
No. Stripe processes cards and Apple processes iOS in-app purchases. FitConnect Pro does not see or store full card numbers or your Apple payment credentials.
How do I exercise my GDPR rights?
Email privacidad@fitconnect.pro with your request (access, rectification, erasure, portability or objection). We will verify your identity and respond within the legal time limits.