Privacy Policy

Last updated 19 August 2026

This policy explains what CoreFix collects about you, why we hold it, who else can see it, and how to get it back or get rid of it. It is written to be read, not to be survived.

Who we are

CoreFix is an online fitness coaching service operated by CoreFix, based in New Zealand. For any question about this policy, or to exercise any right described below, email corefix2801@gmail.com.

We handle personal information under the New Zealand Privacy Act 2020. If you are in the UK or the European Economic Area, the UK GDPR and EU GDPR also apply to you, and the rights section below sets out what that adds.

What we collect

Account details. Your name, email address, and an optional phone number. Your password is stored only as a bcrypt hash — we never hold the password itself, and cannot recover it for you. If you sign in with Google or Apple, we store the account identifier they give us instead of a password.

Health and fitness information. Body weight, height, age, gender, fitness goal and experience level, plus the weight logs, workout completions and progress history you record as you train. This is the information a coach needs to write a plan for you, and some of it is sensitive, so it is treated accordingly.

Payment records. What you bought, how much, in which currency, when, and the reference our payment provider returns. We never see or store your card number — card details are entered on Stripe’s or PayPal’s own systems and never reach our servers.

Payment screenshots. If you pay by bank transfer and upload proof, that image is stored privately, is never publicly accessible, and is visible only to the coach reviewing your upgrade.

Messages. Anything you send the coach through in-app chat, including attachments.

Technical information. Server logs recording requests, and your IP address where it is needed to apply rate limits and detect abuse. We record the IP address against administrative actions in an audit log.

Cookies and tracking

We do not use analytics, advertising, or tracking cookies, and there are no third-party trackers on this site. We set one cookie: an HTTP-only session cookie that keeps you logged in. It is strictly necessary for the site to work, cannot be read by JavaScript, and is deleted when you log out.

Because we set no non-essential cookies, there is no consent banner to click through. If that ever changes, we will ask first.

Why we hold it

To create and secure your account; to let the coach write and deliver plans built for your body; to take payment and give you access to what you paid for; to send you service email such as address verification, password resets and membership expiry notices; to keep the service working and protect it from abuse; and to meet our legal obligations, particularly tax record-keeping.

Under the GDPR our lawful bases are: performing our contract with you (your account, plans and payments), our legitimate interests (security, abuse prevention, keeping records), and legal obligation (financial records). Where we handle health-related information, we do so on the basis of your explicit consent, given when you enter it — and you can withdraw that by deleting the information or your account.

Who else sees it

We do not sell your personal information, and we do not share it for advertising. We use a small number of service providers who process data on our behalf:

  • Neon — database hosting. Your data is stored in the AWS Asia Pacific (Sydney) region.
  • Stripe and PayPal — payment processing. They receive what they need to take the payment and apply their own privacy policies.
  • Google (Gmail) — carries our transactional email, such as verification and password-reset messages. Your address and the contents of those messages pass through Google’s mail servers.
  • Cloudinary — image and video storage, where configured.
  • Google and Apple — only if you choose to sign in with them.

We will also disclose information where the law requires it. Because these providers operate internationally, your information may be stored or processed outside New Zealand; we choose providers that offer protections comparable to the Privacy Act.

How long we keep it

Payment screenshots are deleted automatically 30 days after the related upgrade is decided.

Payment and subscription records are kept for seven years after the transaction, because tax law requires businesses to retain financial records. When you delete your account these records stay, but your name, email and contact details are stripped from them, leaving an amount and a date not linked to you.

Everything else — your profile, plans, progress history, weight logs and messages — is deleted when you delete your account, or when your account has been inactive long enough that we no longer have a reason to hold it.

Your rights

You can, at any time:

  • See what we hold. Most of it is visible in your profile; email us for the rest.
  • Correct it. Edit your profile directly, or ask us.
  • Delete it. Go to Profile → Security → Delete your account. This erases your personal data immediately and is not reversible. The retention section above explains the one category we must keep.
  • Get a copy. Ask us and we will send you your data in a portable format.
  • Object or restrict. Ask us to stop a particular use of your information.

If you are unhappy with how we have handled your information, you can complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz. In the EEA or UK, you can complain to your local supervisory authority.

How we protect it

Passwords are hashed with bcrypt and never stored in readable form. Traffic is encrypted in transit, and the database connection requires TLS. Payment screenshots are held in private storage reachable only through short-lived signed links issued to the reviewing coach. Two-factor authentication is available on your account, and we recommend turning it on.

No system is perfectly secure. If a breach affects you, we will notify you and the Privacy Commissioner as the Privacy Act requires.

Children

CoreFix is not intended for under-16s, and we do not knowingly collect their information. If you believe a child has given us personal information, email us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top, and for material changes we will tell you by email or in the app before they take effect.