Privacy Policy
- Effective:
- At public launch
- Data controller:
- Shredior, Inc.
- Contact:
- privacy@shredior.com
Shredior, Inc. (“Shredior,” “we”) respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices you have. It applies to the Shredior website, mobile applications, and related services (the “Service”).
What We Collect
Account & identity data
- Name, email address, password (hashed and salted)
- Date of birth (to verify 18+) and country of residence
- Profile photo and bio (optional)
- For coaches: certifications, business information, payout details
Coaching & health data
Because Shredior is a coaching platform, clients may provide sensitive health-related information. This data is treated with extra care, encrypted at rest, and accessible only to you and the coach you have explicitly authorized.
- Body measurements (weight, body-fat %, circumferences)
- Progress photos uploaded for weekly check-ins
- Workout logs, nutrition logs, habit tracking
- Health disclosures provided during intake (injuries, medications, dietary needs)
- Coach–client messages and check-in responses
Payment data
All card and bank-account data is collected and processed directly by Stripe. Shredior never sees, stores, or transmits your full card number. We store only a token, the last four digits, the card brand, and the expiry date so we can display “Visa ···· 4242” in your billing settings.
Usage & device data
- IP address, browser type, operating system, device model
- Pages viewed, features used, time spent, error logs
- Referring URL and approximate location (city / country, derived from IP)
Why We Collect It
- To provide the Service — host your account, match clients with coaches, deliver programs, run check-ins, process payments.
- To improve the Service — aggregate, anonymized analytics on feature usage, performance, and bugs.
- To communicate — service emails (billing receipts, renewal reminders, security alerts), and product updates you can unsubscribe from.
- For safety & compliance — preventing fraud, abuse, money-laundering, and complying with legal obligations such as tax and accounting law.
Our legal bases under GDPR are: performance of a contract (delivering the Service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where you have explicitly opted in, e.g. marketing email), and legal obligation (tax records, court orders).
Where we process health-related data — body measurements, progress photos, and health disclosures provided during intake — this is a special category of data under GDPR Article 9. We process it on the basis of your explicit consent, which you can withdraw at any time by contacting privacy@shredior.com or by deleting the data from your account.
Cookies & Similar Technologies
We use a small number of cookies, all categorized below. On your first visit you can accept or reject non-essential categories via our cookie banner; you can change your choice at any time from Settings → Privacy.
- Strictly necessary — session cookies that keep you logged in. Cannot be disabled.
- Functional — remember your theme, language, and similar preferences.
- Analytics — first-party (PostHog, self-hosted) usage measurement, IP-anonymized.
We do not use third-party advertising cookies, retargeting pixels, or behavioural-ad networks.
Sharing & Third-Party Processors
We share data only with vetted sub-processors who help us run the Service, under a written Data Processing Agreement. Current sub-processors:
- Stripe, Inc. — payment processing (USA)
- Amazon Web Services (AWS)— application hosting and file storage, S3 (US-East & EU-Frankfurt)
- Postmark — transactional email delivery (USA)
- PostHog — self-hosted product analytics (EU-Frankfurt)
- Cloudflare— DDoS protection & CDN
- Sentry — error monitoring (USA)
We also share data with coaches you are working with (for the duration of that coaching relationship) and with law-enforcement when we are legally required to do so. We never sell personal data and never share it with advertisers.
International Transfers
Shredior is operated from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. and other countries where our sub-processors operate. For transfers from the European Economic Area, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
Retention
- Active accounts — for as long as your account is open.
- Closed accounts — most personal data is deleted within 30 days of account closure.
- Financial records — invoices and tax-relevant records are kept for 7 years per U.S. tax law.
- Backups — encrypted backups roll off within 90 days.
Your Rights
Regardless of where you live, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated personal data
- Export your data in a portable, machine-readable format (JSON / CSV)
- Object to processing based on legitimate interest
- Withdraw consent for processing where consent is the legal basis
To exercise any of these rights, email privacy@shredior.com or use the self-service tools at Settings → Privacy. We respond within 30 days. EEA / UK residents may also lodge a complaint with their local supervisory authority.
Your California privacy rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the CCPA/CPRA. Over the past 12 months we have collected the categories of personal information described in Section 01 above — identifiers, account & profile data, health-related information, payment tokens, and usage / device data. We do not sell or share your personal information, and we do not use sensitive personal information for purposes other than providing the Service.
You have the right to know what we collect, delete it, correct it, and limit the use of sensitive personal information. To exercise these rights, email privacy@shredior.com; we will not discriminate against you for exercising them.
Children
Shredior is for users 18 years of age and older. We do not knowingly collect personal data from anyone under 18. If you become aware that a minor has provided us with personal data, please contact us and we will delete it.
Security
We protect your data with industry-standard safeguards: TLS 1.3 in transit, AES-256 at rest, hashed passwords, role-based access control, MFA for staff, encrypted backups, and continuous security monitoring. No system is perfectly secure; we will notify affected users without undue delay in the event of a data breach affecting their personal data, as required by law.
Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email and in-product at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.
Contact Us
Shredior, Inc. — Data Controller
1209 W 6th St, Suite 200
Austin, TX 78703, USA
Email: privacy@shredior.com
Support: support@shredior.com
EU Representative (GDPR Art. 27): to be appointed before EU/UK launch
UK Representative (UK GDPR Art. 27): to be appointed before EU/UK launch