Document · client app

Ordo Gym Client Privacy Policy

Who is responsible for what in the client app: the trainer for the record, the publisher for the account. How we process training data and weight, usage statistics and crash reports, where the data is stored, what your rights are and how to delete your account.

Version 1.1 · effective 14 September 2026

1. Who this document is for and who is who

  1. This Policy describes how personal data of people using the Ordo Gym Client mobile app (the App) is processed - that is, clients of personal trainers who use the Ordo Gym app (the Trainer App).
  2. The publisher of the App and the service provider is POKO Adam Rokita, ul. Działkowa 127/11, 05-808 Parzniew, Poland, VAT ID 534-22-67-654 (the Publisher). Data protection contact: support@ordogym.com. General contact: app@ordogym.com.
  3. There are two distinct roles in the App, so we split the data into the two groups described in section 2. This split decides who to address your data requests to.

2. Two groups of data and two responsible parties

DataControllerPublisher's role
Account Data: account identifier, sign-in email address, display name and photo (if you sign in with Apple or Google), push notification tokens, notification settings, device language, the list of Trainers you are connected toPublisherdata controller
Training Data shared by your Trainer: first name, training goal, plan and history of workouts with exercises, sets and weights, training program, training package status, payment dates (amounts only if the Trainer enables them), weight history, the Trainer's contact detailsThe Trainer who keeps your record in the Trainer Appprocessor acting on the Trainer's instructions
Feedback you send to your Trainer: confirming or declining attendance, proposing another time, a short message, a weight entry, a workout logged as done on your ownThe Trainer (this information goes into your record kept by the Trainer)processor acting on the Trainer's instructions

The Trainer is the controller of the data in their record on the basis of the agreement they concluded with you as your trainer. The Publisher processes that data solely to display it in the App and to pass your Feedback to the Trainer, under the data processing agreement concluded with the Trainer in the terms of the Trainer App. You will find your Trainer's contact details in the "You" tab.

3. What data we process and where it comes from

  1. Account Data is provided by you when signing in (email address and password) or passed on by the sign-in provider (Apple, Google) to the extent you agree to with that provider. Passwords are not stored in plain text; they are handled by Firebase Authentication.
  2. Training Data comes from your Trainer. The App does not read the Trainer's record directly. It only reads a copy prepared specifically for you (a projection), which the Publisher's server creates once you enter an invitation code and refreshes after every change made by the Trainer. The projection does not include: the Trainer's notes about you, the Trainer's rate, other clients' data, or workouts scheduled beyond the visibility horizon set by the Trainer.
  3. Feedback is entered by you. The server moves it into the Trainer's record and deletes it from the intermediate inbox; entries the Trainer has not allowed in their settings are rejected.
  4. Technical data: the device identifier used for notifications (FCM token), the platform (iOS or Android) and the language.
  5. Usage statistics and crash reports are collected automatically. Firebase Analytics records that an event happened: connecting to a Trainer, confirming or declining attendance, asking for another time, adding a weight entry, marking a workout as done on your own, ending the collaboration, and opening one of the four tabs. We do not send the content of your messages to the Trainer, names or weight values - only the information that something happened. Firebase Crashlytics records a crash report: device model, operating system and App version, memory state and the stack trace from the point of failure. Both tools use a random installation identifier which we do not link to your Account or to Training Data; removing the App discards that identifier. The App contains no advertising tools, does not track you across other apps or websites, and does not profile users.
  6. Invitation code: a one-time code generated by your Trainer, together with information on when and by which account it was used.

4. Health-related data

  1. Body weight history, target weight, training goal and workout history with weights may constitute health data within the meaning of Article 9 GDPR.
  2. You enter your weight voluntarily. Making an entry constitutes explicit consent to process that information in order to show you your progress and pass it to your Trainer (Article 9(2)(a) GDPR). You may withdraw consent by asking the Trainer to delete the entries or by deleting your Account; withdrawal does not affect the lawfulness of earlier processing. The Trainer can switch off your ability to enter weight.
  3. Training Data entered by the Trainer is processed by the Trainer on the basis of their agreement with you and the consent you gave to the Trainer. In that scope the Publisher acts solely as a processor.

5. Purposes and legal bases (data for which the Publisher is the controller)

PurposeDataLegal basis
Creating and keeping the Account, signing in, connecting to a Trainer with an invitation code, displaying Training DataAccount Data, invitation code, list of connectionsArticle 6(1)(b) GDPR – performance of a contract (the App terms)
Push notifications about tomorrow's workout, a changed time, a Trainer's proposal and the training packagedevice token, notification settingsArticle 6(1)(a) GDPR – consent given in the operating system and in the App settings; it can be withdrawn at any time
Security of the Service: preventing abuse of invitation codes, server logsaccount identifier, timestamps, IP address in the provider's logsArticle 6(1)(f) GDPR – the Publisher's legitimate interest in ensuring security
Handling complaints and data-related requestsemail address, content of the requestArticle 6(1)(b) and (c) GDPR and (f) – defence against claims
Usage statistics and crash diagnostics: seeing which features are used and fixing errorsinstallation identifier, names of events and opened tabs, device model, operating system and App version, technical crash dataArticle 6(1)(f) GDPR – the Publisher's legitimate interest in maintaining and improving the quality of the App; you have the right to object (section 10)

Providing data is voluntary, but without an email address or an Apple or Google account you cannot create an Account, and without an invitation code the App will not show any Training Data.

6. Where the data is stored

  1. The App uses Google Firebase services (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging) provided by Google Ireland Limited and Google LLC. The database is kept in the europe-central2 region (Warsaw) and server functions in the europe-west1 region (Belgium).
  2. Backups are made by the provider as part of the service, within the European region.
  3. Account Data and a copy of Training Data are also stored on your device in the App's cache so that it works without an internet connection. Deleting the App from the device removes that cache.

7. Recipients and sub-processors

EntityRoleScope
Google Ireland Ltd / Google LLC (Firebase)sub-processor for hosting, authentication, server functions, push notifications, and statistics and crash reports (Firebase Analytics, Crashlytics)Account Data, the projection of Training Data, Feedback, device tokens, statistical events and crash reports with a random installation identifier
Apple Inc.distribution of the App (App Store), "Sign in with Apple", delivery of notifications (APNs)Apple account data under Apple's rules; the Publisher receives an identifier and, if you agree, an email address or an Apple relay address
Google LLCdistribution of the App (Google Play), signing in with a Google accountGoogle account data under Google's rules; the Publisher receives an identifier, email address, name and profile photo
Your Trainercontroller of the recordFeedback and the information that you use the App and when you connected

Google LLC and Apple Inc. are based in the United States. Data is transferred on the basis of the European Commission's adequacy decision (Data Privacy Framework) and standard contractual clauses. The Publisher does not sell data and does not share it with other entities unless required by law.

8. Notifications

  1. The App may send push notifications: about tomorrow's workout (when you have not confirmed attendance), about a new or moved workout, about a time proposed by your Trainer, and about a training package that is running out.
  2. Notifications require consent in the operating system. Each type of notification can be switched off separately in the "You" tab → "Notifications". The content of notifications is generated on the Publisher's server and delivered through Firebase Cloud Messaging and Apple and Google services.

9. Retention period

  • Account Data: until you delete your Account. Deletion takes effect immediately and erases sign-in data, tokens, settings and all projections.
  • The projection of Training Data from a given Trainer: until you or the Trainer end the collaboration, or until the Account is deleted; it is erased then. The record kept by the Trainer stays with the Trainer and is subject to their policy and to the terms of the Trainer App.
  • Feedback: in the intermediate inbox only until it is moved into the Trainer's record (usually seconds); after that as part of the Trainer's record.
  • Invitation codes: valid for 7 days, and after being used or expiring kept for up to 30 more days for security purposes, then deleted.
  • Server logs (Cloud Functions, Firestore): up to 30 days at the provider.
  • Usage statistics (Firebase Analytics): events tied to the installation identifier for up to 14 months at the provider; after that only aggregate data remains, from which a single installation cannot be singled out.
  • Crash reports (Firebase Crashlytics): up to 90 days from the report.
  • Complaint correspondence and correspondence concerning personal data: up to 3 years from the end of the matter, due to limitation periods for claims.

10. Your rights

  1. You have the right to access your data, to rectify it, to erase it, to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent at any time. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl).
  2. For matters concerning Training Data and Feedback, the Trainer is the competent controller. The Publisher, acting on their instructions, will pass your request on and help to fulfil it.
  3. For matters concerning Account Data write to support@ordogym.com. We respond without undue delay, within one month at the latest.
  4. You can exercise most of your rights yourself in the App: ending the collaboration with a Trainer ("You" tab), switching off notifications, deleting your Account ("You" → "Delete account").

11. Security

  1. Data is transmitted over an encrypted connection (TLS) and stored in Google Cloud infrastructure with encryption at rest.
  2. Only the signed-in Account the projection was created for has access to it; access rules are enforced on the server side. Invitations and projections are created and modified solely by the Publisher's server, not by the App on the device.
  3. Invitation codes are one-time, short-lived and do not reveal who is whose client. We recommend securing your device with a screen lock and using an Apple or Google account to sign in.

12. Children

The App is intended for people aged 16 and over. A younger person may use the App only with the consent of a parent or legal guardian, which the Trainer should obtain before handing over an invitation code. If we learn that an Account was created by a younger person without such consent, we will delete it.

13. Changes to the Policy

We announce material changes to this Policy in the App at least 14 days in advance. The current version is always available at https://ordogym.com/client-privacy-policy, and its version number and effective date are given at the beginning of the document.