Shredior markShredior
/Legal/Privacy Policy

Privacy Policy

Effective:
At public launch
Data controller:
Shredior, Inc.

Shredior, Inc. (“Shredior,” “we”) respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices you have. It applies to the Shredior website, mobile applications, and related services (the “Service”).

TL;DRWe collect the data we need to run a coaching platform — your account info, body metrics, progress photos, messages, and payment data via Stripe. We don’t sell your data. We don’t run advertising on Shredior. You can export or delete your data at any time.

What We Collect

Account & identity data

  • Name, email address, password (hashed and salted)
  • Date of birth (to verify 18+) and country of residence
  • Profile photo and bio (optional)
  • For coaches: certifications, business information, payout details

Coaching & health data

Because Shredior is a coaching platform, clients may provide sensitive health-related information. This data is treated with extra care, encrypted at rest, and accessible only to you and the coach you have explicitly authorized.

  • Body measurements (weight, body-fat %, circumferences)
  • Progress photos uploaded for weekly check-ins
  • Workout logs, nutrition logs, habit tracking
  • Health disclosures provided during intake (injuries, medications, dietary needs)
  • Coach–client messages and check-in responses

Payment data

All card and bank-account data is collected and processed directly by Stripe. Shredior never sees, stores, or transmits your full card number. We store only a token, the last four digits, the card brand, and the expiry date so we can display “Visa ···· 4242” in your billing settings.

Usage & device data

  • IP address, browser type, operating system, device model
  • Pages viewed, features used, time spent, error logs
  • Referring URL and approximate location (city / country, derived from IP)

Why We Collect It

  • To provide the Service — host your account, match clients with coaches, deliver programs, run check-ins, process payments.
  • To improve the Service — aggregate, anonymized analytics on feature usage, performance, and bugs.
  • To communicate — service emails (billing receipts, renewal reminders, security alerts), and product updates you can unsubscribe from.
  • For safety & compliance — preventing fraud, abuse, money-laundering, and complying with legal obligations such as tax and accounting law.

Our legal bases under GDPR are: performance of a contract (delivering the Service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where you have explicitly opted in, e.g. marketing email), and legal obligation (tax records, court orders).

Where we process health-related data — body measurements, progress photos, and health disclosures provided during intake — this is a special category of data under GDPR Article 9. We process it on the basis of your explicit consent, which you can withdraw at any time by contacting privacy@shredior.com or by deleting the data from your account.

Cookies & Similar Technologies

We use a small number of cookies, all categorized below. On your first visit you can accept or reject non-essential categories via our cookie banner; you can change your choice at any time from Settings → Privacy.

  • Strictly necessary — session cookies that keep you logged in. Cannot be disabled.
  • Functional — remember your theme, language, and similar preferences.
  • Analytics — first-party (PostHog, self-hosted) usage measurement, IP-anonymized.

We do not use third-party advertising cookies, retargeting pixels, or behavioural-ad networks.

Sharing & Third-Party Processors

We share data only with vetted sub-processors who help us run the Service, under a written Data Processing Agreement. Current sub-processors:

  • Stripe, Inc. — payment processing (USA)
  • Amazon Web Services (AWS)— application hosting and file storage, S3 (US-East & EU-Frankfurt)
  • Postmark — transactional email delivery (USA)
  • PostHog — self-hosted product analytics (EU-Frankfurt)
  • Cloudflare— DDoS protection & CDN
  • Sentry — error monitoring (USA)

We also share data with coaches you are working with (for the duration of that coaching relationship) and with law-enforcement when we are legally required to do so. We never sell personal data and never share it with advertisers.

International Transfers

Shredior is operated from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. and other countries where our sub-processors operate. For transfers from the European Economic Area, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.

Retention

  • Active accounts — for as long as your account is open.
  • Closed accounts — most personal data is deleted within 30 days of account closure.
  • Financial records — invoices and tax-relevant records are kept for 7 years per U.S. tax law.
  • Backups — encrypted backups roll off within 90 days.

Your Rights

Regardless of where you live, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your account and associated personal data
  • Export your data in a portable, machine-readable format (JSON / CSV)
  • Object to processing based on legitimate interest
  • Withdraw consent for processing where consent is the legal basis

To exercise any of these rights, email privacy@shredior.com or use the self-service tools at Settings → Privacy. We respond within 30 days. EEA / UK residents may also lodge a complaint with their local supervisory authority.

Your California privacy rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the CCPA/CPRA. Over the past 12 months we have collected the categories of personal information described in Section 01 above — identifiers, account & profile data, health-related information, payment tokens, and usage / device data. We do not sell or share your personal information, and we do not use sensitive personal information for purposes other than providing the Service.

You have the right to know what we collect, delete it, correct it, and limit the use of sensitive personal information. To exercise these rights, email privacy@shredior.com; we will not discriminate against you for exercising them.

Children

Shredior is for users 18 years of age and older. We do not knowingly collect personal data from anyone under 18. If you become aware that a minor has provided us with personal data, please contact us and we will delete it.

Security

We protect your data with industry-standard safeguards: TLS 1.3 in transit, AES-256 at rest, hashed passwords, role-based access control, MFA for staff, encrypted backups, and continuous security monitoring. No system is perfectly secure; we will notify affected users without undue delay in the event of a data breach affecting their personal data, as required by law.

Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email and in-product at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.

Contact Us

Shredior, Inc. — Data Controller
1209 W 6th St, Suite 200
Austin, TX 78703, USA
Email: privacy@shredior.com
Support: support@shredior.com

EU Representative (GDPR Art. 27): to be appointed before EU/UK launch
UK Representative (UK GDPR Art. 27): to be appointed before EU/UK launch