Privacy Policy

Effective date: 14 April 2025  ·  Last updated: 14 April 2025

This Privacy Policy explains how AppJuice di Carlo Di Giuseppe ("we", "us", "our") collects, uses, and protects your personal data when you use the WalkRace mobile application and related services. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR).

1 Data Controller

The data controller for your personal data is:

AppJuice di Carlo Di Giuseppe
Milan, Italy
Email: privacy@appjuice.it

For any privacy-related request, contact us at the address above.

2 Data We Collect

Category Examples Source
Account data Email address, username, display name, avatar, bio, city, country, gender Provided by you at registration or when editing your profile
Health & activity data Daily step count, estimated distance, estimated calories Apple HealthKit (only with your explicit permission)
Social data Posts, comments, messages, follow relationships, group memberships Generated by your activity in the app
Challenge & competition data Challenge participation, rankings, achievements, trophies Generated by your activity in the app
Technical data Device type, OS version, app version, IP address, session tokens Automatically collected during use
Communications Feedback submissions, support requests Provided by you voluntarily
Health data (HealthKit). WalkRace reads step data from Apple HealthKit solely to display your activity and participate in rankings. We never share raw health data with third parties, never use it for advertising, and never sell it. You can revoke HealthKit access at any time via iOS Settings → Privacy & Security → Health.

3 Legal Basis for Processing

Processing purpose Legal basis (GDPR)
Creating and managing your account Art. 6(1)(b) — performance of a contract
Providing leaderboards, challenges, social features Art. 6(1)(b) — performance of a contract
Processing health/step data Art. 9(2)(a) — explicit consent (HealthKit permission prompt)
Sending transactional emails (confirmations, GDPR requests) Art. 6(1)(b) — performance of a contract
Security, fraud prevention, debugging Art. 6(1)(f) — legitimate interests
Complying with legal obligations Art. 6(1)(c) — legal obligation

4 How We Use Your Data

We do not use your data to serve advertising, sell data to third parties, or build advertising profiles.

5 Data Sharing & Third Parties

We share your data only with the following trusted sub-processors, under appropriate data processing agreements:

Sub-processor Purpose Location
Supabase, Inc. Database, authentication, file storage, edge functions EU (AWS Frankfurt) / USA
Resend, Inc. Transactional email delivery USA
Apple Inc. HealthKit data source; App Store distribution; Apple Sign In USA
Google LLC Google Sign In (optional) USA

For transfers to the USA we rely on Standard Contractual Clauses (SCCs) or adequacy decisions where applicable. We will never sell your personal data.

We may also disclose data if required by applicable law, a court order, or to protect the rights, property, or safety of WalkRace, its users, or the public.

6 Data Retention

We keep your personal data for as long as your account is active or as needed to provide the service. Specifically:

When you delete your account, all personal data is permanently erased within 24 hours of the scheduled deletion date.

7 Your Rights under GDPR

As a data subject under the GDPR you have the following rights:

Art. 15
Right of Access

Obtain a copy of all personal data we hold about you.

Art. 16
Right to Rectification

Correct inaccurate or incomplete personal data.

Art. 17
Right to Erasure

Request permanent deletion of your account and all associated data.

Art. 18
Right to Restriction

Ask us to restrict processing of your data in certain circumstances.

Art. 20
Right to Portability

Receive your data in a structured, machine-readable format (JSON).

Art. 21
Right to Object

Object to processing based on legitimate interests.

Exercise your rights directly in the app. Go to Profile → Privacy & Data to request a data export or schedule account deletion. For all other requests, email privacy@appjuice.it. We will respond within 30 days.

You also have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it.

8 Apple HealthKit – Special Notice

WalkRace integrates with Apple HealthKit to read your step count. In compliance with Apple's requirements and the GDPR:

WalkRace is not a medical device and does not provide medical advice. Step counts and derived metrics (distance, calories) are estimates and may not be accurate.

9 Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:

No method of transmission over the internet or electronic storage is 100% secure. If you discover a security vulnerability, please report it responsibly to privacy@appjuice.it.

10 Children's Privacy

WalkRace is intended for users aged 16 or older. We do not knowingly collect personal data from children under 16. If we become aware that a user is under 16, we will delete their account and associated data promptly. If you believe a child has registered, contact us at privacy@appjuice.it.

11 Cookies & Tracking

The WalkRace mobile application does not use cookies. Session tokens are stored securely in the device's keychain and are used solely to authenticate your requests to our API. We do not use third-party advertising or analytics SDKs that track you across other apps or websites.

12 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-app notice at least 14 days before the new policy takes effect. The "Last updated" date at the top of this page always reflects the most recent version. Continued use of WalkRace after the effective date constitutes acceptance of the updated policy.

13 Contact Us

For any questions, requests, or complaints regarding this Privacy Policy or our data practices:

AppJuice di Carlo Di Giuseppe
Milan, Italy
Email: privacy@appjuice.it

We aim to respond to all enquiries within 30 days.