Privacy Policy

Just Hold Ltd — Effective 5 March 2026 — Last updated 11 September 2026

1. Who We Are

Just Hold Ltd (“we”, “us”, “our”) operates the Just Hold fitness-tracking application (“the App”). We are a company registered in England and Wales under company number 16976542.

Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom

Contact: privacy@justhold.app

For the purposes of UK and EU data protection law, Just Hold Ltd is the data controller.

2. What We Collect

We only collect the data necessary to provide the App. We do not use advertising cookies, behavioural advertising, or cross-site tracking. We use two cookie-free analytics systems: Vercel Web Analytics for aggregate page traffic, and our own product analytics, which records which features you use and is linked to your account for up to 90 days — see Section 5 for details and how to opt out.

CategoryDataWhy
AccountEmail address, display name, password (hashed), avatar imageTo create and secure your account
Date of birthThe date of birth you provided at signup or for each family profileTo verify you meet our age requirement (18+ for personal accounts; 13+ for family profiles). Never shared with other users; never used for marketing.
Fitness dataExercise type (plank, hang, wall squat), duration in seconds, date and time loggedTo track and display your progress
ProfilesProfile name, avatar image (linked to owner's account)To let you track multiple household members on one account
GroupsGroup name, group image, membership, activity feed messagesTo enable shared fitness tracking with friends and family
SubscriptionStripe customer ID, subscription ID, subscription status, plan typeTo manage billing and access
NotificationsIn-app messages between users (e.g., group invitations, activity updates)To keep you informed of group and account activity
SettingsEmail digest preferences, muted groupsTo respect your communication preferences
Feature requestsCategory, feedback textTo improve the App based on user input
Aggregate analyticsPage views, referrer, country (no city), browser, operating system, device class, and Web Vitals timingsTo understand aggregate use of the App so we can improve performance and usability. Cookie-free; not tied to your identity
Product analyticsEvents recording which features you use: account created (and the campaign or timer that led to it), workout logged (exercise and duration — except for family profiles of under-18s, where no duration is recorded), group created/joined, invite sent, upgrade prompt shown or clicked, checkout started, subscription started/cancelled/resumed. Each event carries your account ID, the time, and short category labels only — never your email, name, free text, or date of birthTo see where new users get stuck and whether the free tier and upgrade prompts work, so we can improve the App. Stored in our own database, never shared. Linked to your account for up to 90 days, then anonymised. You can opt out (Section 5)
Diagnostic logsYour user ID (UUID) when included in a server error message; stack traces; request pathsTo investigate and fix bugs that affect your account. We do not log your email, name, or workout content
Launch notificationsEmail addressTo notify you when Just Hold launches publicly; only collected via the pre-launch sign-up form; deleted within 30 days of launch or when you unsubscribe
Product updatesEmail address (already held for your account)To send updates about new App features and improvements; only used for this purpose if you opt in at sign-up

Data we do NOT collect

  • Your IP address or precise geolocation. We do not store your IP address. It is used for under a minute to limit abusive request rates (as a keyed hash, in our rate-limiting service — see Section 6), and Vercel determines your country from it at the network edge; neither is linked to your account
  • Persistent device fingerprints (Vercel Analytics records browser, operating system, and device class in aggregate only, with no link to your account)
  • Advertising cookies, behavioural advertising, or cross-site tracking
  • Cross-site or cross-device tracking. Our product analytics (Section 5) are linked to your account ID only while you are signed in, for at most 90 days, and are never combined with data from other websites or shared with anyone
  • Health or biometric data (hold durations are simple timers, not biometric measurements)
  • Data from third-party social media accounts (other than Google account email and name if you use Google sign-in)

3. How We Use Your Data

  • Provide the service: create your account, record and display your workout history, enable group features and family profiles
  • Verify age eligibility: confirm that personal-account holders are 18 or over and that family-profile members are 13 or over
  • Process payments: manage subscriptions and billing via Stripe
  • Send transactional emails: account confirmation, password resets, email digests
  • Improve the App: review feature requests (aggregated, not tied to individual identity)
  • Improve performance and usability: aggregate analytics from Vercel Web Analytics highlight slow pages and broken flows, and our own product analytics show where new users get stuck and whether the free tier and upgrade prompts work; you can opt out of both at any time in Settings
  • Operate and debug the service: server-side error logs may include your user ID so we can investigate bugs you encounter. We do not log emails, names, or workout content
  • Send product update emails: notify account holders about new features and improvements, where you have opted in at sign-up; you can withdraw consent at any time by emailing privacy@justhold.app or using the unsubscribe link in any email we send

We do not use your data for advertising, profiling, or automated decision-making.

4. Lawful Basis for Processing (UK and EU GDPR)

BasisDataExplanation
Contract performance (Art. 6(1)(b))Account, fitness data, groups, profiles, subscription, notifications, settingsNecessary to provide the service you signed up for
Legal obligation (Art. 6(1)(c))Date of birth (account holder and family-profile members)We are required to take a risk-proportionate approach to verifying that users meet our minimum age requirements (18+ for personal accounts; 13+ for family profiles) under DPA 2018 s.9 and the ICO Age Appropriate Design Code. The date of birth is also held to evidence accountability under UK GDPR Art. 5(2)
Legitimate interests (Art. 6(1)(f))Feature requestsOur legitimate interest in improving the App; balanced against minimal privacy impact of voluntary feedback
Legitimate interests (Art. 6(1)(f))Aggregate analyticsOur legitimate interest in improving performance and usability; balanced against minimal privacy impact (cookie-free, no PII, no cross-site tracking) and a free opt-out in Settings
Legitimate interests (Art. 6(1)(f))Product analytics (feature-usage events)Our legitimate interest in understanding whether the App works for new users; balanced by data minimisation (category labels only, no free text, no durations for under-18 profiles), a 90-day limit on the link to your account, and a free opt-out in Settings that also anonymises what we already hold. Billing-lifecycle events (checkout, subscription started/cancelled/resumed) are instead kept as the record of your contract with us (Art. 6(1)(b)) and are not affected by the opt-out
Legitimate interests (Art. 6(1)(f))Server-side error logs and email send logsOur legitimate interest in operating, debugging, and securing the service; minimised to pseudonymous identifiers (user IDs) with short retention
Consent (Art. 6(1)(a))Google account data (email, name) via Google OAuthYou actively choose to sign in with Google; you can revoke access in your Google account settings at any time
Consent (Art. 6(1)(a))Launch notification emails; product update emails for account holdersYou actively opt in — via the pre-launch sign-up form or the checkbox at account creation; you can withdraw consent at any time by emailing privacy@justhold.app or using the unsubscribe link in any email we send

5. Cookies and Local Storage

The App uses no tracking cookies, no advertising cookies, and no cross-site analytics cookies.

Analytics

We use two analytics systems. Neither sets a cookie or writes to your device.

1. Vercel Web Analytics is a cookie-free analytics service to understand aggregate use of the App so we can improve performance and usability. Vercel Web Analytics records limited information — page views, referrer, country (no city), browser, operating system, device class, and Web Vitals timings — and identifies visitors only by a daily server-side hash that resets each day. It does not set cookies, does not write to your device's local storage, and does not track you across days, sessions, or other websites. Before each event leaves your browser, the App strips query strings and replaces dynamic identifiers in the URL (such as group IDs, family-profile IDs, invite codes, and unsubscribe tokens) with placeholders so they never reach Vercel.

2. Our own product analytics record a small set of in-app events (listed in Section 2 under “Product analytics”) in our own database when you are signed in. Each event carries your account ID so we can see, for example, how many people who created an account went on to log a hold or hit an upgrade prompt. The link to your account is removed automatically 90 days after each event; the anonymised rows are deleted after 24 months. Nothing is sent to a third party. Before you sign in, the only events recorded are anonymous: a public timer being used, the hold calculator on those pages being used (the exercise, the band of the chart your time fell in and, on the plank page, whether you chose men, women or rather not say, but never the time itself), the offer to save a time being shown, a time being saved to your own browser, the prompt to create an account being shown, and the signup page being opened. None of these is linked to you, to an account, or to any identifier that follows you around.

The times you save stay in your browser. They are not sent to us unless you create an account.

You can opt out of both at any time in Settings → Your Data → Allow analytics. When you opt out, your browser stops sending Vercel Web Analytics events, our servers stop recording product-analytics events for your account, and the product-analytics events we already hold about you are anonymised immediately. Billing-lifecycle events (checkout started, subscription started, cancelled or resumed) are the record of your subscription contract and continue to be kept; they follow the same 90-day anonymisation. If you have deleted your browser data the setting still applies, because it is held on your account.

Local storage and session storage

We use browser local storage and session storage only for essential functionality:

ItemStorage typePurpose
Supabase auth session token (sb-*-auth-token)cookie (HTTP-only)Keeps you logged in between visits and authenticates your requests
Supabase PKCE code verifier (sb-*-auth-token-code-verifier)cookie (HTTP-only)Used during email-confirmation/OAuth sign-in to complete the secure exchange
auth_redirectcookie (during team signup only)Remembers where to send you after email confirmation. Deleted on the auth callback
pending_invite_codecookie (during signup or login, 1 hour)Remembers which group invited you while you create your account or log in, so you are added to the right group afterwards. Deleted once you have joined
justhold_current_profilelocalStorageRemembers your selected family profile
justhold:safety-ackedlocalStorageRecords that you have acknowledged the in-app safety warning so we do not re-prompt you on every workout
install_prompt_seenlocalStorageRecords that the “install as an app” prompt has been shown so we do not re-show it on every dashboard load
org_welcome_dismissed_<org slug>localStorageRecords that you have dismissed the team welcome card for a specific organisation, so it is not re-shown
justhold_local_holdslocalStorage (only present when set)Created only if you press “Save this time” on one of the free timer pages — it holds up to 20 of your own hold times (the exercise, the duration, and when you saved it) so you can see them again on your next visit. It stays in your browser and is not sent to us. If you create an account, those times are moved into it and this entry is removed. You can clear it at any time with “Clear saved times” on the page
analytics_opt_outlocalStorage (only present when set)Created only if you opt out of analytics in Settings — when present, it tells the App to drop analytics events client-side. Removed when you re-enable analytics

Google OAuth: If you sign in with Google, Google may set its own cookies during the authentication flow. These are governed by Google's Privacy Policy, not ours.

Because we use no non-essential cookies, we do not display a cookie consent banner. You can clear local storage at any time through your browser settings, though this will log you out.

6. Third-Party Processors

We share data with six service providers, all acting as data processors under written agreements:

Stripe (payment processing)

  • Data shared: email address, user ID (as metadata), payment card details (entered directly into Stripe's payment form — we never see or store card numbers)
  • Purpose: subscription billing and payment processing
  • Location: United States (certified under the EU-US Data Privacy Framework)
  • Their policy: stripe.com/privacy

Resend (transactional email)

  • Data shared: email address, display name, email content
  • Purpose: sending account confirmations, password resets, email digests
  • Location: United States
  • Their policy: resend.com/legal/privacy-policy

Vercel (hosting, server-side functions, runtime logs, analytics)

  • Data shared: all data the App processes server-side passes through Vercel's infrastructure during request handling. Server-side error logs may include your user ID. Vercel Web Analytics receives aggregate page views, referrer, country, browser, OS, device class, and Web Vitals — no cookies, no PII (see Section 5)
  • Purpose: hosting our application, running server-side functions, capturing diagnostic logs, providing aggregate usage analytics
  • Location: United States (multi-region)
  • Their policy: vercel.com/legal/privacy-policy

Upstash (rate limiting)

  • Data shared: a keyed hash of your IP address, held for 10–60 seconds to count requests and block abusive traffic (we never send the raw address, and Upstash cannot reverse the hash); Stripe event and subscription identifiers held for 7 days to prevent duplicate billing updates
  • Purpose: protecting the App against abuse; de-duplicating payment webhooks
  • Location: United States (Upstash, Inc.)
  • Their policy: upstash.com/trust/privacy.pdf

Google Workspace (email for support and privacy requests)

  • Data shared: the contents of any email you send to us (for example to privacy@justhold.app) and our replies — including whatever personal data you choose to include
  • Purpose: receiving and answering support queries, privacy questions, and data-rights requests
  • Location: United States (Google LLC), under Google's Cloud Data Processing Addendum
  • Their policy: workspace.google.com/terms/dpa_terms.html

Supabase (database, authentication, file storage)

  • Data shared: all App data listed in Section 2
  • Purpose: database hosting, user authentication, avatar and group image storage
  • Location: EU (London/Frankfurt)
  • Their policy: supabase.com/privacy

We do not share data with any other third parties. We do not sell, rent, or trade personal data.

7. Data Visibility Within the App

  • Group members can see your display name, avatar, exercise type, hold duration, and the date/time you logged a workout — for all groups you share
  • Profiles: all profiles under a single account share the same login. The account owner can view and manage all profiles and their workout history

Your email address is never displayed to other users.

8. Data Retention

DataRetention period
NotificationsAutomatically deleted after 90 days
Expired group invitationsDeleted daily by automated cleanup
Orphaned activity feed entriesDeleted weekly by automated cleanup
Workouts, account data, groupsRetained while your account is active; deleted within 30 days of an account deletion request
Subscription and payment records6 years after the end of the subscription (UK tax and accounting obligations)
Product analytics events (Section 5)Linked to your account for 90 days, then anonymised (immediately if you opt out or delete your account); anonymised events deleted after 24 months
Rate-limiting records (hashed IP)10–60 seconds
Support and privacy correspondence (email)Deleted 24 months after your query is resolved; emails exercising your data rights may be kept longer as evidence of how the request was handled
Supabase auth tokensExpire according to session configuration; cleared on logout

9. Your Rights Under UK and EU GDPR

If you are in the UK or European Economic Area, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (“right to be forgotten”) (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability — receive your data in a structured, machine-readable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time where processing is based on consent (Art. 7(3)) — this does not affect the lawfulness of processing before withdrawal

To exercise any of these rights, email privacy@justhold.app. We will respond within one month (extendable by two further months for complex requests, with notice).

Right to complain: You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):

10. Your Rights Under California Law (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:

  • Right to know: You can request the categories and specific pieces of personal information we have collected about you
  • Right to delete: You can request deletion of your personal information
  • Right to correct: You can request correction of inaccurate personal information
  • Right to opt out of sale or sharing: We do not sell or share your personal information for cross-context behavioural advertising. There is nothing to opt out of
  • Right to non-discrimination: We will not treat you differently for exercising your privacy rights

Categories of personal information collected (per CCPA)

CCPA CategoryExamples from our App
IdentifiersEmail address, display name, Stripe customer ID
Commercial informationSubscription plan type, subscription status
Internet or electronic network activityAggregate page views (not linked to you) and the in-app feature-usage events described in Section 5, linked to your account for up to 90 days. We do not collect browsing history from other sites or search history
Audio, electronic, visual, or similar informationAvatar images and group images you upload
InferencesNone — we do not create profiles or draw inferences

We have not sold personal information in the preceding 12 months. We have not shared personal information for cross-context behavioural advertising.

To exercise your California privacy rights, email privacy@justhold.app. We will verify your identity and respond within 45 days.

11. Account Deletion and Data Export

You can request account deletion or a copy of your data by emailing privacy@justhold.app.

  • Deletion: We will delete your account and all associated personal data within 30 days of a verified request. Data we are legally required to retain (e.g., financial records for tax purposes) will be kept for the required period and then deleted
  • Data export: We will provide your data in a common machine-readable format (JSON or CSV)
  • Family profiles: Deleting an account also deletes all family profiles associated with it
  • Group data: Your workout entries will be removed from all groups. Group activity feed messages you authored may be retained in anonymised form

12. Children's Privacy

The App is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13.

Account owners may create profiles for household members, including children aged 13 and over. The account owner is responsible for any data entered under family profiles and must have appropriate authority (such as parental responsibility) to manage profiles on behalf of minors.

If we learn that we have collected personal data from a child under 13 without verified parental consent, we will delete that data promptly. If you believe a child under 13 has provided us with personal data, please contact privacy@justhold.app.

If you are between 13 and 17 and using a family profile. You can contact us directly at privacy@justhold.app about anything to do with your information — even if you didn't set up the account. You can ask to see what we hold about you, ask us to correct it, or ask us to delete it. The person who runs the account does not need to be involved.

13. International Data Transfers

Our database is hosted by Supabase in the EU (London/Frankfurt). Most of your data stays within the EU.

Data may be transferred to the United States by:

  • Stripe: for payment processing. Stripe is certified under the EU-US Data Privacy Framework and uses Standard Contractual Clauses (SCCs) as an additional safeguard
  • Resend: for transactional email delivery. Transfers are protected by Standard Contractual Clauses (SCCs)
  • Vercel: for hosting, server-side function execution, diagnostic logs, and aggregate analytics. Transfers are protected by Standard Contractual Clauses (SCCs)
  • Upstash: for rate limiting (hashed IP addresses only) and payment-webhook de-duplication. Upstash is certified under the EU-US Data Privacy Framework and its UK Extension, with Standard Contractual Clauses and the UK Addendum as the fallback safeguard
  • Google (Workspace): for hosting our support and privacy mailbox. Google is certified under the EU-US Data Privacy Framework and its UK Extension, with Standard Contractual Clauses incorporated via its Cloud Data Processing Addendum

We only transfer data to third parties that provide appropriate safeguards as required by UK GDPR (Chapter V) and EU GDPR (Chapter V).

14. Security

  • All data in transit is encrypted via HTTPS/TLS
  • Data at rest is encrypted by our database provider (Supabase)
  • Passwords are hashed — we cannot see or recover your password
  • Row-level security (RLS) policies ensure users can only access their own data and data shared with their groups
  • Stripe handles all payment card data and is PCI-DSS Level 1 certified — card details never touch our servers
  • Access to production systems is restricted to authorised personnel

No system is 100% secure. If you discover a security vulnerability, please report it to privacy@justhold.app.

15. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and notify you via the App or by email for significant changes.

Your continued use of the App after changes take effect constitutes acceptance of the updated policy.

16. Organisation (Team) Accounts

Just Hold offers team subscriptions for organisations. When a company signs up for Just Hold Teams, the following applies to employees or members who join via an organisation invite.

Who sees what

  • Organisation administrators can see participation and engagement signals for members of groups they manage: whether a member has logged a workout, how often, and weekly activity trends.
  • Administrators cannot see individual workout durations, personal bests, or the specific exercises you perform. That data stays with the individual account holder.
  • Other members of your organisation's groups see the same data that members of any group see: your display name, avatar, workout activity, and positions on group leaderboards.

Data controller and processor roles

Where an organisation subscribes to Just Hold Teams and invites its employees or members to join the app, the organisation is the data controller for the decision to enrol those people in the programme and for the engagement data it receives about them. Just Hold Ltd acts as a data processor for that engagement data and as an independent controller for the personal account data each individual creates (display name, password, workout durations, group memberships).

When someone leaves an organisation

If your organisation cancels its subscription, or you are removed from your organisation's groups, you lose access to those team groups but your personal account and workout history are preserved. You can continue using Just Hold on your own account (free, or with Just Hold Plus) or export your data at any time (see section 11).

Billing data

Organisation billing is processed via Stripe in the same way as individual billing (see section 6). The organisation's billing contact details (email address, company name, address for invoicing) are held by Just Hold Ltd for the purpose of providing the Teams service and by Stripe for the purpose of processing payments.

17. Contact Us

If you have questions about this Privacy Policy or how we handle your data:

Email: privacy@justhold.app

Post: Just Hold Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom

For UK data protection complaints, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk or by phone at 0303 123 1113.