top of page

Privacy Policy

Criyo ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services (collectively, the "Service").

 

We take your privacy seriously and encourage you to read this Privacy Policy carefully. By accessing or using the Service, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy.

1. INFORMATION WE COLLECT

 

1.1 Personal Information You Provide

 

Identification Information: Your name, email address, mailing address, profile photo, username, and password. For creators and fitness professionals, we may also collect professional credentials and social security number for payment processing purposes.

 

Communication Information: Information you provide when you contact us with questions, respond to surveys, or participate in market research.

 

Content Information: Information contained in the content you create, upload, or make available through the Service, including workout plans, nutrition guides, coaching materials, and other digital products.

 

Social Media Information: When you connect your social media accounts to our Service or interact with our Social Media Pages (such as Instagram, Facebook, YouTube, and TikTok), we may collect information you make available through your settings with those platforms, such as profile details, friend lists, and engagement metrics.

1.2 Information We Collect Automatically

When you visit, use, or interact with our Service, we automatically collect certain information about your device and usage:

Log Information: Information that your browser automatically sends whenever you visit the Service, including your Internet Protocol (IP) address, browser type and settings, date and time of your request, and how you interacted with the Service.

Device Information: Information about the device you use to access the Service, including device name, operating system, browser type, and mobile network information.

Usage Information: Information about how you use our Service, such as the types of content you view or engage with, features you use, actions you take, and the time, frequency, and duration of your activities.

Location Information: We derive a rough estimate of your location from your IP address.

Analytics Information: We use PostHog, an analytics service, to collect information about how you interact with our Service. This helps us understand user behavior and improve our Service.

Email Open/Click Information: We use pixels in our email campaigns that allow us to collect your email and IP address as well as the date and time you open an email or click on any links in the email.

 

2. HOW WE USE YOUR INFORMATION

 

We use the information we collect for various purposes, including:

 

Providing, operating, maintaining, and improving the Service

Setting up and managing your account

Processing transactions and sending related information, including confirmations and receipts

Understanding how users interact with our Service through analytics

Personalizing your experience and delivering content relevant to your interests

Responding to your comments, questions, and requests

Sending you technical notices, updates, security alerts, and administrative messages

Communicating with you about products, services, offers, promotions, and events

Monitoring and analyzing trends, usage, and activities in connection with our Service

Detecting, preventing, and addressing technical issues, fraud, and illegal activities

Carrying out our obligations and enforcing our rights arising from any contracts between you and us

Complying with legal obligations

3. HOW WE SHARE YOUR INFORMATION

 

We may share your personal information in the following circumstances:

 

3.1 Service Providers

We share information with third-party service providers who perform services on our behalf, such as:

Analytics: We use PostHog to collect and analyze information about how users interact with our Service. To protect your privacy, we automatically anonymize sensitive personal information before it reaches PostHog, including but not limited to names, email addresses, phone numbers, physical addresses, and any other personally identifiable information. This ensures that our analytics data cannot be used to identify individual users while still allowing us to improve our service based on usage patterns.

 

Email Services: We use email service providers to send communications.

 

Cloud Hosting: We use cloud hosting providers to store data and host our Service.

 

Authentication: Supabase handles authentication and encryption to protect your core data such as name, email, phone number, and additional information. Supabase implements industry-standard security measures, including AES-256 encryption at rest and TLS encryption in transit. They are SOC2 Type 2 and HIPAA compliant, with comprehensive security features including role-based access control, multi-factor authentication, and regular security audits.

 

3.2 Platform Interactions

Creator-User Relationships: When you, as a user, book services, purchase products, communicate with a creator, or engage with a creator's content through our Service, that creator will receive certain information necessary to fulfill their services. This information may include, but is not limited to, your name, contact details, booking preferences, and any additional information you provide related to the service or product.

Creator Content: If you are a creator, information about your offerings, profile, and professional services will be visible to users of the Service. You control what information you make public through your storefront.

Creator Data Responsibilities: Creators who receive user data through our platform:

Must maintain appropriate confidentiality and security measures for user data

Are solely responsible for their use, storage, and handling of user data

May use user data only for the specific purposes for which it was collected

May send marketing or service-related communications to users who have engaged with their services

Must comply with all applicable privacy laws and regulations

User Acknowledgment: By engaging with a creator through our Service, you acknowledge that:

 

Your information will be shared with the creator as necessary for service fulfillment

The creator may have their own privacy practices and policies governing their use of your data

Criyo is not responsible for how creators use, store, or process your information once shared

You should review a creator's privacy practices before sharing sensitive information

Creator communications are governed by their own policies, not Criyo’s privacy policy

 

Data Minimization: We limit the personal information shared with creators to only what is necessary for service delivery, payment processing, and communication related to the services provided.

Creator Obligations: Creators agree to:

Use user data only for legitimate business purposes related to their services

Implement appropriate security measures to protect user data

Not sell or improperly disclose user data to third parties

Delete or anonymize user data when no longer needed

Promptly report any data incidents to Criyo

3.3 Data Usage Acknowledgment

By providing your personal information (name, email) to any creator through our Service, you acknowledge and agree that:

Creator Autonomy: The creator has independent control over how they use your data for their business purposes, subject to applicable laws and our Terms of Service

Direct Relationship: You are establishing a direct business relationship with the creator, who becomes a data controller for your information

Marketing Consent: You consent to receive both marketing and transactional communications from the creator through any communication channels you've provided

Creator Responsibility: The creator is solely responsible for their use of your data and compliance with applicable privacy and marketing laws

Platform Limitation: Criyo acts solely as a platform facilitating these connections and is not responsible for creators' independent use of your data

Content Restrictions: While creators have broad rights to communicate with you, all communications must comply with Criyo’s Content Moderation Policies as outlined in our Terms of Service

4. DATA SECURITY

 

We implement appropriate technical and organizational measures to protect the security of your personal information. Through our partnership with Supabase, we maintain a comprehensive security program that includes:

 

Encryption: All data is encrypted at rest using AES-256 encryption and in transit using TLS.

 

Access Controls: Implementation of role-based access control (RBAC) and strict permission management.

 

Authentication Security: Support for Multi-factor Authentication (MFA) to add an additional layer of security.

 

Regular Backups: Automated daily backups of all databases with point-in-time recovery capabilities.

 

DDoS Protection: Multiple layers of DDoS protection, including CDN-level protection via Cloudflare.

 

Vulnerability Management: Regular penetration testing and security scanning using industry-standard tools.

 

Compliance: Our infrastructure provider, Supabase, maintains SOC2 Type 2 and HIPAA compliance.

5. DATA RETENTION

 

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. We determine the appropriate retention period based on the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure, and applicable legal requirements.

6. DATA RETENTION

 

6.1 General Rights

 

You can:

 

Access, edit, or delete your account information through your profile settings.

Opt out of non-essential communications.

Delete your account; we will delete your personal data from active systems within a reasonable period.

Revoke email access at any time in your account settings.

 

6.2 Rights Under GDPR (EU/EEA Users)

If you are located in the European Union, you may have the following rights under the General Data Protection Regulation (GDPR):

 

Right to access the data we hold about you.

Right to request correction or deletion of your data.

Right to restrict or object to processing.

Right to data portability.

Right to withdraw consent for email integration.


 

6.3 Rights Under CCPA / CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

Right to know what categories of personal information we collect, the sources of that information, the purposes for which we use it, and the categories of third parties we share it with (all described in Sections 1 through 4 of this Policy).

Right to access a copy of the personal information we hold about you.

Right to request deletion of your personal information.

Right to correct inaccurate personal information.

Right to limit the use and disclosure of sensitive personal information.

Right to opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information and do not share it for cross-context behavioral advertising.

Right to non-discrimination for exercising any of these rights

7 CHILDREN'S PRIVACY

 

Our Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete such information as soon as possible.


 

8 HOW WE USE COOKIES AND SIMILAR TECHNOLOGIES

 

Cookies are small data files that are placed on your computer or mobile device when you visit a website. We use cookies to operate and administer our Service, gather usage data, and improve your experience.

 

Cookies can be stored on your computer for different periods of time:

Session Cookies: These expire after a certain amount of time or when you close your browser.

 

Persistent Cookies: These survive after your browser is closed until a defined expiration date and help recognize your computer when you open your browser and browse the Internet again.

PostHog, our analytics provider, stores some data in cookies to help us understand how users interact with our Service. These cookies collect information about your browsing habits to make advertising relevant to you and your interests.

9 CHANGES TO THIS PRIVACY POLICY

 

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last Updated" date at the top of this Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

 

Your continued use of our Service after any changes to this Privacy Policy constitutes your acceptance of the changes.

 

10 CONTACT US

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

 

Email: legal@criyo.co

bottom of page