VolleyFit VolleyFit
  • Home
  • Features
  • Support
  • Pricing
Get the app
VolleyFit VolleyFit
  • Home
  • Features
  • Support
  • Pricing
Get the app
VolleyFit Privacy

Privacy

Information on the processing of personal data

Website Mobile App
Contents
01 Controller Part A – Website 02 Hosting 03 Contact Form 04 Cookies & Storage 05 Fonts & Resources 06 App Statistics Part B – Mobile App 07 General 08 Data Collected 09 Services 10 Minors 11 Your Rights 12 Data Security 13 Third Countries 14 Retention Periods 15 Account Deletion 16 Changes

01 Controller

The controller within the meaning of the GDPR for the website and the app is:

Alexander Beitz
Hartengrube 58
23552 Lübeck
Germany
Email: alex@beitz.me

Who is responsible for what?

VolleyFit is used by individuals as well as by clubs and teams. Depending on the matter at hand, responsibility under data protection law lies with different parties — this is important for you to know if you wish to request information about your data or object to a processing operation.

  • Your user account and your own data – registration, profile, your own workouts, training diary, workload analysis, subscription and support: the controller named above is responsible for these. Please direct any requests in this regard to him directly.
  • Data within a club or team – member lists, attendance, roles and permissions, and the question of which coaches may view your health data: these decisions are made by the respective club or by the person managing the group. Requests in this regard are best directed there first. We will of course support you if you do not get anywhere.

Regardless of the above, you can contact us with any concern — we will forward it if another party is responsible.

Part A · volleyfit.app

Website

02 Hosting

The website is hosted by:

Hostinger International Ltd.
61 Lordou Vyronos, 6023 Larnaca, Cyprus
Hostinger Privacy Policy

When you visit the website, the server automatically records the following data in so-called server logs:

  • IP address of the requesting device
  • Date and time of access
  • Requested URL, volume of data transferred
  • Browser type and operating system
  • Referrer URL (previously visited page)

This data is processed solely to ensure technical operation and to defend against attacks. It is not attributed to individual persons. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Retention period: max. 30 days.

03 Contact Form

You can send us a message via the contact form at /support. The following data is collected in the process:

  • Name (required)
  • Email address (required)
  • Category of your request (required)
  • Message text (required, 1,000 characters maximum)
  • Platform (iOS, Android or Web) – requested for bug reports and submitted with every enquiry
  • For subscription and payment enquiries, additionally and always optional: club name, selected plan (group or club) and billing period (monthly or yearly)

The data is transmitted exclusively by email to support@volleyfit.app and is not stored in a database. It is used solely to process your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR.

3.1 Automatic confirmation email

We automatically send a confirmation of receipt to the email address you provide. It contains the category, the platform and a reference number — but, for security reasons, not the text of your message. Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR.

3.2 Protection against misuse

To prevent the form from being abused as a spam relay, a maximum of three messages per hour and IP address is permitted. Your IP address is not stored in plain text for this: the server only writes a SHA-256 hash of the IP address together with the timestamps of your submissions to its temporary directory. The hash is not intended to allow the IP address to be recovered; the entries become meaningless after one hour, are discarded on the next access and are deleted at the latest when the server's temporary directory is cleaned up. No tracking or profiling takes place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing misuse, Art. 32 GDPR).

3.3 Retention

After your request has been handled, your message remains in the support mailbox so that we can follow up on further questions. We retain support correspondence for as long as it is required to handle follow-up questions and to document how we dealt with your request; there is currently no automatic deletion. You may request deletion of your support correspondence at any time — we will then delete it, unless statutory retention obligations apply (see section 11 – Your Rights).

04 Cookies & Local Storage

The website only uses storage that is technically necessary. There is no tracking, no analytics and no profiling, and no data is passed on to third parties.

4.1 Cookie

NamePurpose, content and lifetime
vf-lang Stores the language you selected (German or English) so the site appears in that language on every visit. It is only set if you actively switch the language. Lifetime: 12 months. Its content is exclusively de or en. The cookie is read by the server only (HttpOnly, Secure, SameSite=Lax).

As a strictly necessary cookie it is exempt from consent under Section 25(2)(2) TDDDG — no cookie banner is required for it. Legal basis: Art. 6(1)(f) GDPR.

4.2 localStorage

KeyPurpose, content and lifetime
vf-theme Remembers whether you want to view the site in the light or dark design. Content: light or dark. Kept until you clear your browser storage.
volleyfit_stats Cache for the public app statistics (number of users, workouts, etc.) to save loading operations. Contains no personal data whatsoever and expires automatically after 24 hours.

Both entries remain on your device only and are never transmitted to us. You can delete them at any time via your browser settings. Legal basis: Art. 6(1)(f) GDPR.

05 Google Fonts & External Resources

Fonts (Barlow Condensed, DM Sans), icons (Lucide) and the GSAP animation library (incl. ScrollTrigger) are delivered exclusively from our own server and are an integral part of this website. There is no integration of external services such as Google Fonts (fonts.googleapis.com, fonts.gstatic.com), CDN providers (e.g. cdnjs / Cloudflare) or unpkg.com; accordingly, no IP address is transmitted to third parties when these resources are loaded. No cookies are set for this purpose.

06 Public App Statistics

On the home page we display aggregated, non-personal figures about app usage (number of users, workouts, etc.). These figures are retrieved by our own server and delivered from a cache. Your IP address is not transmitted to Google in the process — when you visit the home page, your device does not connect to Google servers. Legal basis: Art. 6(1)(f) GDPR.

Part B · iOS & Android

Mobile App

07 General Information on Data Processing

7.1 Scope of Processing

As a matter of principle, we process personal data of our users only to the extent necessary to provide a functional app and our content and services. Processing regularly takes place only with the user's consent.

7.2 Legal Bases

Depending on the processing operation, we rely on the following legal bases:

  • Art. 6(1)(a) GDPR – Consent
  • Art. 6(1)(b) GDPR – Performance of a contract
  • Art. 6(1)(c) GDPR – Legal obligation
  • Art. 6(1)(f) GDPR – Legitimate interest
  • Art. 9(2)(a) GDPR – Explicit consent for health data

7.3 Data Erasure and Retention

Personal data is erased or blocked as soon as the purpose of its storage no longer applies, unless statutory retention obligations require otherwise.

08 Data Collected and Purposes of Processing

8.1 Registration and Profile Data

The following data is collected upon registration:

  • First name, last name
  • Email address
  • Password (encrypted; only for email registration)
  • Date of birth
  • Gender, phone number, home address, profile picture, club name (all optional)
  • Timestamps of registration, last login and last activity

Your contact details (email address, phone number, home address, date of birth) are accessible only to you and to the coaches you have authorized, and are not displayed to all users.

Your name and profile picture are also visible to other signed-in users within the app wherever you appear — for instance as the author of posts, comments or public workout templates, in participant lists and chats; this also applies to content from groups you have since left. They can only be retrieved for one specific person at a time, not as a searchable directory. When you delete your account, your name and profile picture are removed and your contributions are anonymized (Section 15). All other profile data is accessible only to the extent described in this policy.

Your date of birth is required as soon as you wish to record health or training data: below the age of 16, the additional consent of a parent or legal guardian is required (Art. 8 GDPR), and without an age on file this threshold cannot be verified. Without a date of birth, the health features remain locked; you can use all other features of the app without restriction.

Legal basis: Art. 6(1)(b) GDPR; for optional data Art. 6(1)(a) GDPR.

8.2 Health and Training Data Special category under Art. 9 GDPR

The following data constitutes health data within the meaning of Art. 4(15) GDPR. It is processed exclusively on the basis of your explicit consent.

8.2.1 Daily Check

Daily well-being score (scale 1–10). This information is visible only to you and to the coaches of your group whom you have authorized or your personal coach – not to other users.

8.2.2 Pain Reports

Affected body areas, pain intensity and optional notes. This information is visible only to you and – unless you have disabled this – to the coaches of your group whom you have authorized or your personal coach; it cannot be viewed by other users.

8.2.3 Body Measurements

Optional: body weight (kg) and height (cm). BMI is calculated but not stored.

8.2.4 ACWR – Training Load Index

The app can calculate the Acute:Chronic Workload Ratio (ACWR) for injury prevention. Training duration, RPE values and acute and chronic load (7/28 days) are processed; the calculation runs automatically every day at 03:00 (Europe/Berlin). This analysis takes place only if you have consented to the processing of your health and training data. Without this consent, no ACWR calculation is performed.

Legal basis: Art. 9(2)(a) GDPR.

8.2.5 Measurements and Athletic Tests

Test values relating to your physical performance (e.g. jump height, speed, strength) recorded by you or by authorized coaches, optionally linked to a group. These values can be viewed only by you and by the coaches of your group whom you have authorized or your personal coach.

Legal basis: Art. 9(2)(a) GDPR.

8.2.6 Training Diary

Optional personal entries on training, load and well-being (training diary). This information is visible only to you and to the coaches of your group whom you have authorized or your personal coach.

Legal basis: Art. 9(2)(a) GDPR.

8.2.7 Weekly Plan

Weekly training and load planning. Visible only to you and to the coaches you have authorized or your personal coach.

Legal basis: Art. 9(2)(a) GDPR or Art. 6(1)(b) GDPR.

8.3 Workout and Training Data

Workout templates, completed workouts (sets, reps, weights, duration), exercise history, personal records, RPE ratings and workouts assigned by coaches.

Legal basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR for RPE data.

8.4 Event and Schedule Management

Event details, participation status, reasons for declining, waiting lists, absences and geographic coordinates of event locations (Google Places API).

Legal basis: Art. 6(1)(b) GDPR.

8.5 Chat and Communication Data

Text messages, images, voice messages, file attachments, time sent, read status, typing indicators, reactions and reply information.

Legal basis: Art. 6(1)(b) GDPR.

8.6 Group and Club Data

Membership in teams and clubs, roles, join requests, invitations, subgroup membership and custom fields.

Legal basis: Art. 6(1)(b) GDPR.

8.7 Posts, Polls and Comments

Posts, polls including votes cast, comments, reactions and @mentions.

Legal basis: Art. 6(1)(a) GDPR.

8.8 Guardian–Ward Relationship (Guardianship)

Link between guardian and ward accounts, status of the guardianship and actions performed by the guardian on the ward's behalf.

Legal basis: Art. 6(1)(a) GDPR; Art. 8 GDPR for minors.

8.9 Push Notifications

With your consent, FCM tokens (incl. device ID and platform) are stored. Notifications are triggered for chat, comments, events, workouts, Daily Check, pain reports, absences and group requests. FCM tokens are deleted automatically after 30 days of inactivity. Consent can be withdrawn at any time in the system settings.

Notifications are deliberately worded with restraint and contain no health content — in the case of a pain report, for example, only the notice that one has been recorded, not its content. In addition, you can specify in the notification settings that no names appear on the lock screen either.

Legal basis: Art. 6(1)(a) GDPR.

8.10 Location Data

The device location can optionally be used to search for event locations. The location is not stored permanently and is transmitted to the Google Places API only for the duration of the search query.

Legal basis: Art. 6(1)(a) GDPR.

8.11 iOS-Specific Features

Live Activities and the Home Widget process data exclusively locally on the device. Calendar synchronization processes events locally and requires your permission.

Legal basis: Art. 6(1)(a) GDPR.

8.12 Patient and Personal Coach Area (1:1 Coaching)

VolleyFit enables individual 1:1 coaching between a personal coach or physiotherapist and a coached person. After redeeming a personal invitation link, a coaching relationship is established between the two accounts. As long as this relationship is active, the authorized coach can view the health and training data expressly shared by the coached person – in particular the Daily Check, pain reports and the workouts assigned to them. The coached person can end the relationship at any time; the coach's access then ceases.

Legal basis: Art. 6(1)(b) GDPR (provision of the coaching) and Art. 9(2)(a) GDPR (explicit consent to the processing of health data).

8.13 Payment Processing for Paid Subscriptions (App Store / Google Play)

Paid premium subscriptions (group and club premium) are concluded exclusively as in-app purchases via the Apple App Store or Google Play. The contracting party for the purchase and the payment processor is the respective store operator (Apple or Google) as an independent controller. You enter your actual payment details (e.g. credit card or bank account details) exclusively with Apple or Google; we never receive or store this payment data.

To manage and verify subscriptions we use the RevenueCat service (see Section 9.6). Our system processes only: a pseudonymous user identifier, the purchased subscription tier and product identifier, billing interval, subscription status, expiry date, store origin (App Store / Google Play) and the assignment of the subscription to your groups or clubs ("slots"). Purchase and transaction receipts remain with Apple or Google.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

8.14 Leaderboards, XP and Ranks

For motivation, the app displays leaderboards within your groups and clubs. Your name and activity and performance values (e.g. experience points "XP", rank, number of completed workouts) are visible to other members of your group. You can object to appearing in leaderboards at any time (opt-out in the leaderboard settings); you will then no longer be listed there.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in motivation and team cohesion); your objection (Art. 21 GDPR) is honoured through the opt-out.

8.15 Minigames

The app contains optional minigames. Your game results and scores are stored and may appear in group-internal rankings.

Legal basis: Art. 6(1)(b) or (f) GDPR.

8.16 In-App Feedback and Support

If you send us feedback or a support request from within the app, we process your message, optional screenshots or attachments, and your user and contact data in order to process and answer your request.

Legal basis: Art. 6(1)(b) or (f) GDPR.

09 Services Used and Processors

9.1 Google Firebase (Google Ireland Limited)

  • Firebase Authentication – authentication. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
  • Cloud Firestore – database in europe-west10 (Berlin, Germany). No third-country transfer.
  • Firebase Cloud Functions – server-side logic in europe-west3 (Frankfurt).
  • Firebase Cloud Messaging (FCM) – push notifications. Transfer on the basis of SCCs (Art. 46 GDPR).
  • Firebase Storage – media files in europe-west10 (Berlin, Germany). No third-country transfer.
  • Firebase Remote Config – checks on app launch whether an update is required (for instance after a security-relevant bug). A device- or installation-related identifier (Firebase Installation ID) is transmitted to Google in the process. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an up-to-date, secure app version).
  • Firebase Installations – issues the aforementioned identifier; a technical prerequisite for Remote Config and push notifications. Any transfers to the USA are safeguarded by standard contractual clauses.
  • Firebase App Check – confirms to our servers that a request originates from a genuine, unmodified installation of our app, thereby protecting your data against automated access by third parties. Only a device integrity attestation from Apple or Google and the app version are processed, no usage data. Legal basis: Art. 6(1)(f) GDPR (security of processing, Art. 32 GDPR).

Google Privacy Policy  ·  Firebase Data Processing Terms

9.2 Google Sign-In

When you sign in with Google, your name, email and profile picture are transmitted. Provider: Google LLC, USA. Third-country transfer on the basis of SCCs (Art. 46(2)(c) GDPR).

9.3 Apple Sign-In

When you sign in with your Apple ID, your name and email are transmitted if you choose to share them. Provider: Apple Inc., Cupertino, CA 95014, USA. Third-country transfer on the basis of SCCs and the EU-US Data Privacy Framework.

Apple Privacy Policy

9.4 Google Maps / Places API

Search queries and optionally the device location are transmitted to Google LLC (USA) for the event location search. Third-country transfer on the basis of SCCs.

9.5 Apple App Store & Google Play (In-App Purchases)

Paid subscriptions are concluded and billed via the in-app purchase systems of the store operators. In doing so, the store operators process your payment and billing data as independent controllers under their own privacy policies:

  • Apple: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (or Apple Inc., USA). Apple Privacy Policy
  • Google: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (or Google LLC, USA). Google Privacy Policy

We do not receive any payment data from the store operators, only pseudonymous transaction and subscription information (e.g. product identifier, time of purchase/renewal, status). Any third-country transfers by Apple or Google are safeguarded by standard contractual clauses (Art. 46(2)(c) GDPR) or the EU-US Data Privacy Framework.

9.6 RevenueCat (Subscription Management)

To manage, assign and verify in-app subscriptions server-side, we use RevenueCat as a processor (Art. 28 GDPR). Provider: RevenueCat, Inc., San Francisco, California, USA. On our behalf, RevenueCat processes: a pseudonymous user identifier (app user ID), store receipt data and transaction identifiers, product identifier, purchase and renewal times, subscription status and technical information (platform, app version). Your name, email address and payment data are not transmitted to RevenueCat. A data processing agreement is in place with RevenueCat; the transfer to the USA is safeguarded by standard contractual clauses (Art. 46(2)(c) GDPR). When you delete your account, your RevenueCat profile is deleted as well.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract). RevenueCat Privacy Policy

10 Special Provisions for Minors

  • In Germany, the minimum age for consent under data protection law is 16. Users under 16 may only participate with the consent of a parent or legal guardian (Art. 8 GDPR). This consent is documented with its time and version.
  • The registration of minors requires the consent of a parent or legal guardian (Art. 8 GDPR).
  • Guardians can create and manage an account and perform actions on the ward's behalf. These are marked as such in the app.
  • Health data of minors requires the explicit consent of the parent or legal guardian.
  • Account deletion can be initiated by the parent or legal guardian at any time.

If you have questions about the processing of your child's data: alex@beitz.me

11 Your Rights as a Data Subject

Access Art. 15 GDPR

Right to obtain information about the data stored about you. You can obtain a complete copy at any time via the data export in the app (see Data Portability).

Rectification Art. 16 GDPR

Right to rectification of inaccurate or incomplete data.

Erasure Art. 17 GDPR

Right to erasure of your data. In the app: Settings → Account → Delete Account.

Restriction Art. 18 GDPR

Right to restriction of processing.

Data Portability Art. 20 GDPR

Right to receive your data in a machine-readable format. You can export your data directly in the app ("Export my data") or request it by email to alex@beitz.me.

Objection Art. 21 GDPR

Right to object to processing based on legitimate interests.

Withdrawal Art. 7(3) GDPR

Withdraw push notifications in your device settings. You can withdraw your consent to the processing of your health data at any time directly in the app ("Withdraw health consent"); your stored health data will be deleted in the process. Alternatively by email to alex@beitz.me.

Complaint Art. 77 GDPR

ULD Schleswig-Holstein
Holstenstr. 98, 24103 Kiel, Germany
mail@datenschutzzentrum.de
datenschutzzentrum.de

12 Data Security

Transmission between device and server is encrypted via HTTPS/TLS. On iOS, FCM tokens are stored encrypted using the Keychain. Passwords are managed exclusively in hashed form by Firebase Authentication.

13 Data Transfers to Third Countries

Some service providers process data in the USA. The transfer is safeguarded by standard contractual clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and the EU-US Data Privacy Framework. The app's core data is stored exclusively in German data centres (Frankfurt and Berlin).

14 Retention Periods

Data categoryRetention period
Account dataUntil account deletion
Training data, workout logsUntil account deletion
Health data (Daily Check, pain reports, body measurements, ACWR, training diary, weekly plan)Until account deletion or withdrawal of consent
Chat messages (private 1:1 chats)Until user or account deletion – complete erasure
Chat messages (group chats)Upon account deletion your messages are anonymized, not deleted – see Section 15
FCM tokens30 days of inactivity, then deleted automatically
Subscription data (store transaction identifiers, subscription status/term, slot assignments)Until account deletion; anonymized thereafter where applicable
Purchase and billing receiptsRemain with Apple or Google (independent controllers)
Leaderboard/XP, minigame and feedback dataUntil account deletion
Logs (Cloud Functions)Up to 30 days

15 Account Deletion

Delete your account in the app: Settings → Account → "Delete Account". In doing so, all data associated with your account – including health, training, chat, measurement and relationship data (e.g. coaching relationships) as well as subscription data including your RevenueCat profile – is irrevocably deleted or anonymized, unless statutory retention obligations require otherwise. You must additionally cancel any ongoing subscription yourself in your Apple or Google account, as the purchase contract exists with the store operator; purchase and billing receipts remain with Apple or Google in accordance with their own policies. Alternatively, you can request deletion in writing at alex@beitz.me.

15.1 What Is Anonymized Instead of Deleted

In shared areas, complete deletion would destroy the context for the other participants — a conversation history with gaps or a poll with a retroactively altered result. Your contributions in group chats, posts, comments, polls and in the event and carpool history are therefore anonymized: your name and identifier are replaced by a neutral placeholder, after which no link to your person can be established. Private 1:1 chats are deleted completely. Anonymous polls remain counted anonymously.

15.2 Backups and Finality of Deletion

To protect against technical failures and data loss, we create a daily backup of the database. These copies are retained for seven days and then deleted automatically. They are stored in the same data centre in Germany (europe-west10, Berlin) and serve exclusively for recovery in the event of a failure; they are not analysed for other purposes and are not restored into live operation.

In practical terms this means: when you delete your account, your data is removed from live operation immediately. It may persist in the backups for up to seven days before these are overwritten as well. In addition, our database provider retains earlier version states for a maximum of one hour for technical reasons.

15.3 Verification

After every account deletion, we automatically check whether any data related to your account remains, and we record the result as evidence.

16 Currency and Changes

Version: 13 August 2026. In the event of significant changes, you will be informed via in-app notification or push notification. The current version is available at any time in the app under Settings → Privacy.

16.1 Language Versions

This privacy policy is provided in German and English. Both versions are intended to have the same meaning. In the event of a discrepancy, the German version prevails to the extent mandatory local law does not provide otherwise.

VolleyFit VolleyFit
  • Privacy
  • Terms of Use
  • Imprint
  • Support
© 2026 VolleyFit. All rights reserved.