Legal

Privacy Notice

Last updated: 5/22/2026

Who we are

Benjamin Nilsson (sole trader, trading as FitTok) operates the FitTok service ("we", "us", "our"). We act as the data controller of personal data collected through the Service.

If you have any privacy-related questions, you can reach us through the Service.

What we collect and why

  • Account data (name, email, login credentials) — to create and secure your account. Legal basis: contract performance.
  • Subscription and order data (plan, status, order IDs) — to provide the paid features you purchased. Legal basis: contract performance.
  • Support messages — to respond to your inquiries. Legal basis: legitimate interest.
  • Usage data and device identifiers (pages viewed, IP address, browser type) — to operate, secure, and improve the Service. Legal basis: legitimate interest.
  • Marketing communications (only if you opt in) — to send product updates. Legal basis: consent.

Payment card details are collected and processed directly by Paddle and never reach our servers.

Who we share data with

  • Paddle.com Market Limited — our Merchant of Record for sale of the product, subscription management, payments, tax compliance, and invoicing.
  • Hosting & infrastructure providers — to operate the Service (database, file storage, analytics).
  • Professional advisers (legal, accounting) where necessary.
  • Authorities where required by law.

International transfers

Some of our providers operate outside the UK/EEA. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

Retention

We keep personal data only as long as needed for the purposes above. Account data is kept while your account is active and for up to 24 months after closure for legal and accounting reasons, after which it is deleted or anonymized.

Your rights

Subject to applicable law (including the GDPR for UK/EEA residents), you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data, and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority. We respond to requests within one month.

Security

We use appropriate technical and organisational measures — including encryption in transit, access controls, and regular security reviews — to protect your data.

Cookies

We use strictly necessary cookies to keep you logged in and to operate the Service. We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings.

Contact

To exercise your rights or ask questions about this Privacy Notice, contact us through the Service.