Embrace the 8

Privacy Policy

Version 1.0 · Effective 15/06/2026
EnglishPortuguêsEspañol Terms & Conditions →

Privacy Policy for the “Zone 8 – Embrace the 8” Application

Version: 1.0 Effective date: 15/06/2026

Who we are and how to contact us

The “Zone 8 – Embrace the 8” application is operated by Guillaume Ribeiro, Carolina Santos and Carolina Verdasca, natural persons acting jointly as data controllers for the purposes described in this Policy. The joint controllers have entered into an arrangement pursuant to Article 26 of the GDPR, setting out their respective responsibilities for compliance with data protection obligations; the essential content of that arrangement, including each joint controller’s roles and responsibilities, is available upon request to the privacy contact indicated below. For any privacy and data protection queries, the single point of contact is zone8privacy@gmail.com. Should the nature or scale of the processing require the designation of a Data Protection Officer under Article 37 of the GDPR, this Policy will be updated with the relevant contact details.

We are established in the European Union, with our main establishment in Portugal. Our lead supervisory authority for GDPR purposes is the CNPD – Portugal, without prejudice to the user’s right to lodge a complaint with any competent EU/EEA authority.

What personal data we process

We process the data that the user provides to us when creating an account and when using the application, as described below. Most data is provided directly by the user; wearable and health platform data comes from Apple Health, Google Fit or compatible devices authorised by the user; social login data comes from the chosen provider (Google, Apple, Facebook, etc.).

We may collect the following categories of personal data:

Identification data (name) – required for registration and account creation;

Contact data (email) – required for operational communication;

Billing data (address, tax identification number) – required for premium subscriptions;

Physical profile data (age, gender, weight, height, calories, heart rate, VO2Max) – optional, used to personalise sports features;

Geolocation data (GPS coordinates) – optional, used to record routes, distances and activity maps;

Health and physical activity data from wearables (heart rate, steps, calories burned, sleep) – optional, through authorised integration with Apple Health, Google Fit or compatible devices;

Social login data (name, email, profile picture) – optional, received when the user chooses to register through third-party providers (Google, Apple, Facebook);

Marketing preferences – optional, recorded when the user chooses to receive promotional communications;

Race data (split times, total times, station results) – generated during participation in races and events tracked through the application;

Photos (avatar and race result images) – optional, uploaded by the user to personalise their profile or share race results;

Usage data (app interactions, crash reports, feature usage) – automatically collected to improve the application and diagnose technical issues.

Purposes of processing and legal bases

We use the data to create and manage the account, provide essential features, and ensure the operation, support and continuous improvement of the service. For these activities, the legal basis is the performance of the contract entered into with the user, as well as our legitimate interest in keeping the application secure and efficient, always with appropriate safeguards. We use gender, weight, height, calories, heart rate and other health and physical activity data (including wearable data) for personalisation of plans, metrics and recommendations. This information may reveal health-related aspects; therefore, where personalisation requires it, we will request your explicit consent through a clear and separate mechanism (for example, a specific checkbox for this purpose) before proceeding with the processing. You may withdraw that consent at any time in the application settings, without affecting the lawfulness of processing carried out prior to that date. The processing of geolocation data for activity tracking is based on the user’s consent, which is requested at the time of activation of the feature and may be withdrawn at any time in the application or device settings. Integration with Apple Health, Google Fit or other health services requires the user’s express authorisation on the respective platform; data is only accessed and processed with that consent, which may be revoked at any time in the device or platform settings. Login through third-party providers (Google, Apple, Facebook, etc.) is based on the user’s consent when authorising data sharing; the user may revoke this access in the respective platform settings. For electronic marketing communications, we use the email address only with the user’s consent, which may be withdrawn at any time through the account preferences or the mechanism indicated in each message. For fraud prevention and security, we process technical logs based on our legitimate interest and the need to protect the service and users.

Legal obligations (billing/accounting): we also process data for compliance with legal obligations regarding billing, accounting and taxation, including the issuance and retention of invoices/receipts, on the basis of compliance with an applicable legal obligation.

Right to object: where processing is based on our legitimate interest (for example, security and service improvement), the user may object at any time, on grounds relating to their particular situation, using the contacts indicated in Section 16.

Marketing and push notifications: electronic marketing is carried out only with prior and separate consent. Push notifications are controlled in the device settings and may be disabled at any time; non-essential notifications are only sent with your consent.

Non-essential Analytics/SDKs: for usage analytics and performance measurement that are not strictly necessary for the operation of the application, the legal basis is the user’s consent, which may be withdrawn at any time in the preference centre.

Payments and financial data

Premium subscriptions are processed by duly licensed payment service providers. We do not store complete payment card data on our systems. The data necessary for transaction processing is collected and tokenised by the payment providers and used exclusively for billing, renewal management and fraud prevention, under contracts that impose adequate security measures. We only retain payment identifiers (token) provided by the provider, the last 4 digits of the card and its expiry date for subscription management and fraud prevention purposes. Complete card data is processed only by the payment provider, in compliance with PSD2 and PCI DSS.

Optional nature

The basic features of the application require only the name and email address for account creation. The remaining data is optional; if the user chooses not to provide it, some advanced personalisation features may be limited. Where the processing of such information is based on explicit consent, refusal or withdrawal of consent does not affect access to the basic features.

Integration with Apple Health, Google Fit and wearable devices: Zone8 reads heart rate and calorie data from Apple Health (iOS) after your races. This includes data from Apple Watch, Garmin, Fitbit, and any other device that syncs to Apple Health. On Android, we read data from Google Fit and connected WearOS devices. This integration is entirely optional and requires express authorisation in the device or platform settings. The user may revoke access at any time, and already-synchronised data will be retained in accordance with the periods indicated in Section 6 and may be deleted upon request. This data is never shared with third parties and never used for advertising.

Geolocation: for sports activity tracking features (running, walking, cycling, etc.), the application may collect geolocation data through the device’s GPS. This collection is activated only when the user starts an activity that requires location and may be deactivated at any time in the application or device settings. Location data is used to record routes, calculate distances and speeds, and display activity maps. We do not share real-time location with third parties.

Social login (Google, Apple, Facebook, etc.): the application allows registration and login through third-party identity providers. When the user opts for this method, we receive only the basic profile data that the user authorises on the chosen platform (typically name, email and profile picture). We do not gain access to the password or other data from the provider’s account. The user may unlink social login in the application settings and, if desired, revoke access in the provider’s own settings.

Retention period

We retain data only for the period necessary for the purposes:

Account (name, email): while the account is active. When you delete your account, all personal data is permanently removed within 30 days.

Race results shared publicly may be anonymised rather than deleted where required for league integrity.

Weight/height: until withdrawal of consent or 12 months after the last update (whichever comes first), after which we delete or anonymise.

Technical logs: 90 days, unless a longer legal obligation applies.

Geolocation: up to 24 months after the activity record, allowing the user to view history; the user may delete individual activities at any time.

Health and wearable activity data: until withdrawal of consent or 24 months after the last synchronisation (whichever comes first).

Billing/receipts: 10 years (tax and accounting obligations).

Marketing preferences and records: until withdrawal of consent or 24 months of inactivity (we maintain a suppression list to ensure the objection is honoured).

Payment identifiers (token), last 4 digits and expiry date: while the subscription is active and up to 18 months after termination, for late charge/chargeback management and fraud prevention.

Recipients and processors

We disclose personal data to providers who support us in delivering the service, including cloud hosting, customer support, email delivery, application performance analytics, payment processing and fraud prevention. These providers act as processors and only process data in accordance with our instructions, under contracts that impose confidentiality, appropriate technical and organisational measures, assistance in fulfilling rights and deletion or return of data upon termination of the engagement. We may also disclose data to public authorities where required by law.

We never sell your data to third parties. We never use health data for advertising.

Key processors: (i) Supabase – database and authentication, hosted on EU servers; (ii) Firebase (Google) – push notifications; (iii) PostHog – anonymous usage analytics, EU servers; (iv) Sentry – crash reporting and error monitoring; (v) Apple / Google – payment processing for subscriptions. The list of processors may be updated periodically; whenever a change involves a new international transfer or a material change of purpose, we will communicate in advance via the app and/or by email.

Location of processing and international transfers

The main storage infrastructure is located in Ireland, in the European Economic Area. Where we engage providers located outside the EEA or involving international transfers, we ensure appropriate safeguards, including Standard Contractual Clauses adopted by the European Commission, transfer impact assessments (TIA) and, where necessary, supplementary measures (additional encryption, access restrictions and minimisation). Essential information about such transfers may be provided upon request to our privacy contact.

Information security

We implement appropriate technical and organisational measures to protect personal data against unauthorised destruction, loss, alteration, disclosure or access. Among others, we use encryption in transit and at rest, key management, least-privilege access controls, multi-factor authentication on internal systems, access logging and monitoring, periodic security testing, retention and deletion policies, and training for staff with access to personal data.

Incident management

We have an incident response procedure in place. In the event of a personal data breach that may pose a risk to data subjects, we will notify the supervisory authority and, where necessary, the affected users, in accordance with Articles 33 and 34 of the GDPR.

Cookies, SDKs and identifiers in the mobile environment

The application may incorporate SDKs and similar technologies for technical features, performance metrics, crash detection and, when authorised, usage analytics and marketing. Components that are not strictly necessary are activated only with the user’s consent. Preferences may be adjusted in the application’s privacy centre or in the device settings, without prejudice to the possibility that some features may be limited.

Minors

The application is not intended for persons under 16 years of age and we do not intentionally collect personal data from persons under 16 years of age. If we become aware that we have collected data from a person under 16 years of age without valid parental consent, we will proceed to delete such data.

Data subject rights

The user has the right to request access to their data, rectification of inaccuracies, erasure where applicable, restriction of processing, portability of data provided by the user (in machine-readable JSON format) and objection to processing based on legitimate interests. Where processing is based on consent, the user may withdraw it at any time through the account preferences or the contact indicated, without affecting the lawfulness of processing carried out prior thereto. Requests will be handled diligently and normally responded to within a maximum period of one month, unless complexity justifies a legal extension.

How to exercise: requests may be submitted directly in the application via Settings → Privacy & Data, where you can: (i) Export My Data – download all your data; (ii) Delete Account – erase your account and all associated data; (iii) Withdraw consent – manage your privacy preferences. You may also contact us by email at zone8privacy@gmail.com. In certain cases we may request additional information to confirm your identity. You may, at any time, object to direct marketing and withdraw consents in the account preferences or through the link included in each communication.

Supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) — Av. D. Carlos I, 134, 1.º, 1200‑651 Lisbon – www.cnpd.pt. The user may also contact the competent authority in their place of residence.

Automated decisions and profiling

We do not make solely automated decisions that produce legal effects or similarly significantly affect the user. The personalisation of content and recommendations is based on simple and transparent parameters and may be disabled through the application preferences when supported by consent.

Changes to this Policy

We may update this Policy to reflect legal, technical or operational changes. Where changes are material, we will communicate via the application or by email before they take effect. The effective date indicated at the beginning will be updated with each revision.

Contact

To exercise rights or clarify queries about this Policy, please use our single point of contact: zone8privacy@gmail.com. We will endeavour to respond promptly and, in any event, within the timeframes provided for under applicable legislation.