Privacy Policy
Last updated: [DATE]
This Privacy Policy explains what personal data SpotOn collects, how we use it, who we share it with, and what rights you have. It applies to the SpotOn website (justspoton.com) and the SpotOn app on iOS, Android, and the web.
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Data Controller: SpotOn (operating name — [registered legal entity TBD]) Address: [TBD] Contact: privacy@spoton.app Data Protection point of contact: privacy@spoton.app
You can contact our Data Protection point of contact about anything in this policy.
Quick summary
- We collect what we need to run a gym-buddy app: who you are, where you train, and what you're training for.
- We do not sell your data.
- We do not share it with advertisers.
- We do not track your real-time location.
- We do not read your messages unless you (or someone else) report a specific conversation.
- You can delete your account at any time, and within 30 days everything is permanently removed.
- You can export your data on request.
What we collect
Information you provide
| Category | Examples |
|---|---|
| Account | Email, phone number (if you sign up via SMS), first name |
| Profile | Age, gender, gym, city, training goal, training times, training frequency, experience level, bio, profile photo |
| Preferences | Who can discover you (everyone / women / men), filter selections |
| Activity | Connection requests + messages you send, profile photos and post photos you upload, posts you create |
| Reports | Reports you file against other users, including the report category, free-text details, and screenshots if attached |
Information collected automatically
| Category | Examples |
|---|---|
| Device | Device type, OS version, app version, browser type (web) |
| Diagnostic | Crash reports, performance metrics, error logs |
| Approximate location | The city you nominated when you signed up — not real-time GPS |
| Push tokens | Device tokens for sending push notifications, if you opt in |
| Cookies | Essential cookies for login session management. We do not use third-party advertising cookies. |
What we do not collect
- We do not collect real-time GPS or location data.
- We do not track which pages you visit elsewhere on the web.
- We do not scan or read your private messages unless you (or the recipient) submit a report referencing that specific thread.
- We do not record audio or video in the app.
How we use your information
We use your data for these purposes:
| Purpose | What it means | UK GDPR legal basis |
|---|---|---|
| Run the app | Show your profile to other users at your gym (per your visibility settings), deliver messages, manage your account | Contract |
| Match-making | Score and order Discover results so you see relevant buddies first | Legitimate interests — making the app useful |
| Communication | Send transactional emails / push notifications about connection requests, messages, follows | Contract |
| Safety + abuse handling | Investigate reports, suspend abusive accounts, cooperate with law enforcement where required | Legitimate interests — protecting users; Legal obligation |
| Product improvement | Fix bugs, improve features. Aggregated and anonymised wherever possible. | Legitimate interests |
| Marketing emails (optional) | If you opt in: occasional product updates. | Consent |
| Legal compliance | Respond to lawful information requests, comply with court orders, defend legal claims | Legal obligation |
We do not use your data for behavioural advertising, profiling for advertising purposes, or any "we noticed you looked at X" marketing.
Who sees your data
Other users
These profile fields are visible to other people at your gym (subject to your visibility settings):
- First name
- Age
- Gender
- Gym
- Training goal / time / frequency / experience
- Bio
- Profile photo
- Posts you create
These are never visible to other users:
- Email address
- Phone number
- Date you joined / signed in
- Reports you've made or had made about you
- Block list
- Messages (except with the other party to that conversation)
Service providers we share data with
We use third parties to deliver the service. Each is bound by data-processing terms.
| Provider | What they receive | Why |
|---|---|---|
| Database hosting ([TBD]) | All app data | Storing the database |
| Email delivery ([TBD]) | Email address, recipient name, message body | Transactional email |
| SMS delivery ([TBD]) | Phone number, message body | OTP codes |
| Image storage ([TBD]) | Uploaded profile + post photos | Hosting images |
| Push notifications (Apple APNs, Google FCM) | Device push token + notification title/body | Delivering pushes |
| Crash reporting ([TBD]) | Anonymised crash logs and device info | Fixing bugs |
| Analytics ([TBD]) | Anonymised app-usage events | Understanding usage |
We do not sell, rent, or trade personal data with anyone.
Law enforcement
We will disclose data to UK law enforcement and equivalent regulators when properly requested via a formal data-disclosure order (e.g. a Section 49 RIPA notice, a court order, or a similar instrument). We will challenge requests we believe are unlawfully broad. Where we can lawfully notify you of a request, we will.
Business transfer
If SpotOn is acquired or merged with another company, your data may transfer to the new entity. The new entity will be bound by this policy (or one no less protective) until they obtain your consent for any material change.
How long we keep your data
| Data | Retention |
|---|---|
| Live account data | While your account is active |
| Soft-deleted account (after you delete) | 30 days, then permanently removed |
| Paused account | Until you unpause or delete |
| Messages | Until the connection is deleted or your account is removed |
| Reports + moderation outcomes | 2 years after the report is closed — needed for repeat-offender detection |
| Block records | Until you unblock — block records survive account deletion of the blocked party so a returning user can't undo your block |
| Logs (server, crash, security) | 90 days |
| Backups | Up to 30 days |
Data needed to comply with a legal hold (e.g. an active police investigation) may be retained longer.
Your rights (UK GDPR)
You have these rights at any time. Email privacy@spoton.app to exercise them.
- Access — get a copy of your data.
- Rectification — correct anything that's wrong. You can update most fields directly in the app.
- Erasure ("right to be forgotten") — delete your account and personal data. Use the in-app delete flow or email us.
- Restriction — ask us to stop processing certain data while a dispute is resolved.
- Portability — get your data in a machine-readable format and ask us to send it to another service.
- Object — object to processing based on legitimate interests, or to direct marketing.
- Withdraw consent — where we process data based on consent (e.g. marketing emails), withdraw it anytime.
- Not be subject to automated decision-making with legal effect — we do not make any such decisions.
We respond to all rights requests within one month.
You also have the right to lodge a complaint with the UK Information Commissioner's Office:
- ICO: ico.org.uk — 0303 123 1113.
Children
SpotOn is for adults aged 18 and over. We do not knowingly collect data from anyone under 18.
If you are under 18, do not use SpotOn. If we discover an account belongs to someone under 18, we will delete it and ask for a parent/guardian to confirm if you reapply at 18+.
If you believe a child is using SpotOn, email safety@spoton.app.
Security
We protect your data with:
- HTTPS / TLS encryption for all traffic between your device and our servers.
- Encryption at rest for the database.
- Session-cookie protection (httpOnly, Secure, SameSite where applicable).
- Server-side authorisation checks on every API endpoint — your data is never returned to a session that shouldn't see it.
- Rate limits and abuse detection on sensitive endpoints (logins, reports, connection requests).
- Regular review of dependencies and security patches.
No system is 100% secure. If we discover a data breach affecting your personal data, we will notify you and the ICO within 72 hours as required by law.
International data transfers
We aim to keep your data in the UK or EEA. If a service provider stores data outside the UK / EEA, we ensure an appropriate safeguard is in place — typically the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs).
Cookies
We use only the cookies needed to run the service:
- Session cookies — keep you logged in.
- CSRF protection — defend against forged requests.
We do not use third-party advertising or tracking cookies. If we ever introduce non-essential cookies, we will ask for your consent first.
Changes to this policy
If we change this Privacy Policy, we will:
- Post the new version at justspoton.com/privacy and in the app.
- Update the "Last updated" date.
- Notify you via the app and/or email when changes are material (e.g. new categories of data, new sharing arrangements).
Continued use of SpotOn after a material change constitutes acceptance.
Contact
- Privacy questions / data rights: privacy@spoton.app
- Safety concerns: safety@spoton.app
- General support: hello@spoton.app