سياسة الخصوصية الخاصة بتطبيق Streak Fit
تاريخ السريان: 27 أغسطس 2026
1. النطاق وجهة التحكم
توضح سياسة الخصوصية هذه كيفية جمع شركة ستريك فيت، الرقم الوطني الموحد 7052017741 («ستريك فيت» أو «نحن»)، للبيانات الشخصية واستخدامها والإفصاح عنها ونقلها والاحتفاظ بها وحمايتها عبر تطبيق Streak Fit ومواقعه وخدماته المرتبطة (ويشار إليها مجتمعةً بـ«المنصة»).
لأغراض نظام حماية البيانات الشخصية السعودي، تُعد شركة ستريك فيت جهة التحكم المسؤولة عن المعالجة الموضحة هنا. وتخص هذه السياسة مستخدمي المنصة وعملاءها، ولا تسري على بيانات الموظفين أو المتعاقدين أو المتقدمين للوظائف التي يغطيها إشعار مستقل.
2. البيانات التي تقدمها
بحسب الميزات التي تستخدمها، قد نجمع:
- بيانات التواصل والحساب: الاسم، والبريد الإلكتروني، ورقم الهاتف، ومعرّف المستخدم، وكلمة المرور أو رموز الدخول المؤقتة، وصورة الملف الشخصي، واللغة، وخيارات التواصل، وتاريخ إنشاء الحساب.
- بيانات الملف والتفضيلات: إجابات الاستبيانات، ومستوى اللياقة، والأهداف، والمدرب المختار، ومدة الراحة المخصصة، وتفضيلات البرنامج والإعدادات.
- بيانات التمرين والسجل: التمارين والمجموعات المكتملة، والتمارين المحفوظة، ووقت العمل والراحة، والوزن المستخدم، والشدة، والمدة، والتقدم، ووزن الجسم، والسعرات، ومعدل نبض القلب، والملاحظات التي تختار تدوينها.
- بيانات التغذية: الوجبات والأطعمة والتفضيلات الغذائية والحساسية والأهداف والعمر والجنس والنوع الاجتماعي أو الوزن عند اختيار استخدام ميزة ذات صلة.
- محتوى المستخدم: الصور وصور ما بعد التمرين والمقاطع الصوتية والمرئية والرسائل والتقييمات والشهادات والملفات أو المراسلات الأخرى التي تقدمها.
- بيانات المعاملات: العضوية والاشتراك والشراء وحالة الفوترة وبيانات الدفع المحدودة الواردة من جهة معالجة الدفع.
- بيانات الدعم والمشاركة: الاستفسارات والملاحظات والاستبيانات والعروض والفعاليات والمحادثات وتسجيلات المكالمات حيث يسمح النظام وبعد الإشعار.
سنوضح الحقول الإلزامية والاختيارية عند جمع البيانات. وإذا لم تقدم البيانات الإلزامية، فقد لا تتوفر الميزة المعنية.
3. البيانات الصحية والحساسة
نتعامل مع بيانات القياسات البدنية ومعدل نبض القلب والسجل التدريبي والوزن والبيانات التغذوية والحساسية وأي معلومات متعلقة بالإصابات على أنها بيانات صحية أو حساسة متى انطبق عليها وصف البيانات الحساسة في النظام السعودي، وذلك بحسب محتواها وسياقها.
- نقصر معالجة هذه البيانات الحساسة على تقديم الخدمات التدريبية المطلوبة، وتخصيص تجربة التمارين، ودعم السلامة البدنية أثناء استخدام المنصة.
- عندما تكون الموافقة هي المسوغ النظامي للمعالجة، نستند إلى موافقتك الصريحة والمسبقة والمستقلة والقابلة للإثبات، ونطلبها عبر إجراء منفصل وواضح عند إعداد الحساب أو قبل تفعيل الميزة ذات الصلة. ولا يُعد مجرد قبول شروط الخدمة موافقة مستقلة على معالجة البيانات الحساسة.
- يحق لك سحب هذه الموافقة في أي وقت عبر إعدادات التطبيق أو بالتواصل معنا، وبسهولة مماثلة لمنحها. وقد يترتب على السحب عدم قدرتنا على تقديم بعض الميزات المخصصة التي تحتاج إلى تلك البيانات، دون أن يؤثر السحب في مشروعية المعالجة التي تمت قبله أو في معالجة تستند إلى مسوغ نظامي آخر.
- لا نبيع أو نؤجر بياناتك الحساسة أو الصحية، ولا نستخدمها لأغراض التسويق أو الإعلانات الموجهة.
4. البيانات التي تُجمع تلقائيًا
عند استخدام المنصة، قد نجمع نحن ومقدمو الخدمات المصرح لهم نوع الجهاز وصانعه وطرازه ونظام التشغيل وإصدار التطبيق أو المتصفح وعنوان IP ومزود الشبكة واللغة والمنطقة الزمنية ومعرّفات الجهاز أو التثبيت الفريدة وسجلات الأعطال والحوادث الأمنية والموقع التقريبي المستنتج من عنوان IP، والتفاعلات مثل الشاشات المعروضة والمقاطع المشغلة والروابط المختارة ومدة الجلسة واستخدام الميزات.
قد يتم الجمع باستخدام التخزين المحلي أو ملفات تعريف الارتباط في المواقع أو حزم تطوير تطبيقات الهاتف أو وحدات البكسل أو النصوص المضمنة أو السجلات أو تقنيات مشابهة. ونحصل على أي موافقة مطلوبة قبل استخدام تقنيات غير ضرورية. ولا نتعمد تسجيل كلمات المرور أو أرقام بطاقات الدفع أو نص السجل الصحي بواسطة أدوات تسجيل الجلسات.
5. البيانات من المصادر والتكاملات الأخرى
بحسب اختيارك أو عند إتاحة الميزة، قد نتلقى بيانات من:
- Apple أو Google أو مقدم تسجيل دخول موحد آخر، وعادةً على شكل رمز مصادقة وبيانات ملف مسموح بها بدلًا من كلمة مرور الخدمة الخارجية؛
- Apple Health أو Health Connect أو جهاز قابل للارتداء أو تكامل لياقة آخر، في حدود الفئات التي تصرح بها؛
- جهات معالجة الدفع ومتاجر التطبيقات بشأن حالة الشراء والاشتراك؛
- المدربين ودعم العملاء ومقدمي الاستبيانات وبرامج الإحالة والشبكات الاجتماعية وشركاء الأعمال؛
- مستخدمين آخرين يرسلون إحالة مشروعة أو يشاركون محتوى معك؛
- مصادر عامة أو أطراف معاملة في اندماج أو استحواذ أو إعادة هيكلة مشروعة.
إذا استخدمت المصادقة الحيوية في الجهاز، فإن جهازك يعالج بصمة الإصبع أو الوجه أو النموذج الحيوي الآخر. وعادةً لا نتلقى سوى تأكيد نجاح المصادقة، ولا نتلقى النموذج الحيوي أو نخزنه.
يمكنك إزالة التكامل أو تغيير أذوناته من إعدادات المنصة أو الجهاز أو مقدم الخدمة. ويوقف ذلك الجمع المستقبلي، لكنه لا يمحو تلقائيًا البيانات التي استلمناها بصورة مشروعة.
6. كيفية استخدام البيانات الشخصية
قد نستخدم البيانات الشخصية من أجل:
- تسجيل الحسابات والتحقق منها وتأمينها وإدارتها؛
- تقديم التمارين وخدمات المدربين والمؤقتات والسجل والتغذية والتقدم والعضوية والميزات المتكاملة؛
- تخصيص الخطط والإعدادات والمحتوى والتذكيرات والتوصيات؛
- معالجة المشتريات والتجديد والإلغاء والاسترداد والسجلات الضريبية أو المحاسبية؛
- تقديم الدعم والتواصل بشأن الأمن والمعاملات والتمارين وتغييرات الخدمة؛
- تشغيل المنصة واختبارها وتشخيصها وصيانتها وقياسها وتحسينها؛
- إنشاء رؤى مجمعة أو مجهولة الهوية وإجراء أبحاث المنتج؛
- منع الاحتيال وإساءة الاستخدام والاستخدام غير الآمن والانتهاكات والحوادث الأمنية؛
- إقامة المطالبات النظامية أو ممارستها أو الدفاع عنها وإنفاذ شروطنا؛
- الامتثال للمتطلبات النظامية والتنظيمية والمحاسبية وطلبات الجهات المشروعة؛
- حماية حياة شخص أو صحته أو سلامته؛
- إرسال التسويق أو الإعلانات المخصصة فقط عند وجود مسوغ نظامي صحيح وأي موافقة مطلوبة.
لا نستخدم البيانات الشخصية لغرض جديد غير متوافق بصورة جوهرية دون تقديم الإشعار المطلوب والحصول على الموافقة عند لزومها.
7. المسوغات النظامية
بحسب الغرض والبيانات، تستند المعالجة إلى الموافقة أو تنفيذ اتفاقنا معك أو الامتثال لالتزام نظامي أو حماية مصلحة حيوية أو مصلحة مشروعة يسمح بها نظام حماية البيانات الشخصية ولا تتغلب على حقوقك. ولا نعتمد على المصلحة المشروعة حيث يمنع النظام ذلك، بما في ذلك البيانات الحساسة. ويمكنك سحب الموافقة دون التأثير في مشروعية المعالجة التي تمت قبل السحب.
8. التخصيص والاستنتاجات والميزات الآلية
قد نستنتج التفضيلات أو الاهتمامات المحتملة أو احتياجات التعافي أو المحتوى المقترح من المعلومات التي تقدمها ونشاط المنصة لتخصيص الخدمة. وقد تساعد الميزات الآلية أو المدعومة بالذكاء الاصطناعي في إنشاء تمارين أو محتوى تغذوي أو ملخصات للتقدم أو تذكيرات. ولا نستخدم معالجة آلية بحتة لاتخاذ قرار يترتب عليه أثر نظامي أو أثر مماثل مهم عليك، إلا بعد تقديم الإشعار المطلوب وتحديد المسوغ وتوفير الضمانات النظامية.
9. التحليلات والإعلانات والاتصالات
قد نستخدم التحليلات لفهم الزيارات وأداء الميزات والتحويلات والأخطاء التقنية. وإذا فُعلت ميزات الإعلان أو الإسناد، فقد نستخدم بيانات الجهاز أو ملف تعريف ارتباط أو معرّف إعلان أو معرّف حساب مشفر لقياس الإعلان أو تخصيصه، ولكن فقط عند وجود المسوغ والموافقة التي يطلبها النظام.
لا نفصح لشبكات الإعلان عن بيانات السجل الرياضي أو الصحة أو التغذية أو غيرها من البيانات الحساسة بغرض الإعلان الموجه، ولا نبيع البيانات الشخصية مقابل مبلغ مالي.
يمكنك إلغاء الرسائل الترويجية عبر رابط الإلغاء أو التعليمات المرفقة، وإدارة الإشعارات وأذونات التتبع من إعدادات المنصة أو الجهاز. وقد تستمر رسائل الحساب والأمن والمشتريات والخدمة الأساسية ما دام حسابك نشطًا.
10. حالات الإفصاح عن البيانات الشخصية
نفصح فقط عن القدر اللازم بصورة معقولة إلى:
- جهات المعالجة ومقدمي الخدمات: Firebase وغيرها من خدمات السحابة والمصادقة والاستضافة والتخزين والأمن والدعم والاتصالات والتحليلات والتسويق والاستبيانات والدفع، وفق ضوابط تعاقدية وسرية مناسبة.
- المدربين وموظفي الخدمة: المعلومات اللازمة لتقديم البرنامج والرد عليك ودعم السلامة، مع تقييد الوصول بحسب الدور والالتزام بالسرية.
- الخدمات المتكاملة: البيانات التي توجهنا لإرسالها إلى Apple Health أو Health Connect أو الأجهزة القابلة للارتداء أو الخدمات الاجتماعية أو المنتجات المتصلة الأخرى أو استقبالها منها.
- متاجر التطبيقات وأطراف المعاملة: بيانات الشراء والاشتراك والتنفيذ والإلغاء والاسترداد اللازمة لإتمام المعاملة.
- المستشارين والجهات المختصة: المعلومات اللازمة للمشورة النظامية أو المطالبات أو التدقيق أو منع الاحتيال أو تحصيل الديون أو الامتثال لطلب مشروع.
- المعاملات التجارية: البيانات اللازمة بصورة معقولة لتمويل أو اندماج أو استحواذ أو إعادة هيكلة أو إعسار أو نقل مشروع بصورة نظامية، مع مراعاة الإشعارات والضمانات المطلوبة.
- السلامة والحقوق: المعلومات اللازمة لحماية الحياة أو الصحة أو السلامة أو المنصة أو حقوق الشركة أو حقوق الغير.
- بناءً على توجيهك أو موافقتك: المعلومات التي تطلب منا مشاركتها، ومنها شهادة أو منشور عام.
لا يجوز لجهة المعالجة استخدام البيانات الشخصية إلا للخدمة المتعاقد عليها أو وفق تعليماتنا الموثقة أو لغرض آخر يسمح به النظام بصورة مستقلة.
11. ميزات المشاركة والحسابات الممولة
قد ينسخ المستلمون المحتوى الذي تنشره للعامة أو تشاركه عمدًا مع مستخدم آخر أو يعيدوا مشاركته. راجع الجمهور والمحتوى قبل النشر. ولا تكون بيانات السجل والصحة الخاصة متاحة للعامة بصورة افتراضية.
إذا موّل صاحب عمل أو فريق أو شركة تأمين أو جهة أخرى وصولك، فقد نشارك معها بيانات التسجيل والأهلية وإدارة الاشتراك ومعلومات عامة عن الاستخدام وفق ما نوضحه عند الانضمام. ولا نشارك بيانات التمرين التفصيلية أو السجل أو التغذية أو الصحة مع الجهة الممولة إلا إذا وجهتنا أو وافقت صراحةً أو وجد مسوغ نظامي آخر.
12. نقل البيانات خارج المملكة
نظرًا لاستخدامنا خدمات استضافة سحابية وتقنيات عالمية، بما في ذلك Google Cloud وFirebase، فقد تُعالج بعض البيانات الشخصية أو تُخزن على خوادم أو بواسطة فرق دعم موجودة خارج المملكة العربية السعودية.
- نلتزم بأن يقتصر أي نقل أو وصول من خارج المملكة على الحد الأدنى اللازم، وأن يتم وفق المادة (29) من نظام حماية البيانات الشخصية ولائحة نقل البيانات الشخصية إلى خارج المملكة.
- بحسب وجهة النقل وطبيعته، نعتمد على وجود مستوى حماية مناسب أو نطبق ضمانًا مناسبًا يسمح به النظام. وقد يشمل ذلك البنود التعاقدية القياسية الصادرة عن الجهة المختصة، أو القواعد المشتركة الملزمة، أو شهادات الاعتماد والالتزامات القابلة للإنفاذ، مع الضوابط التعاقدية والتقنية اللازمة.
- نجري تقويمًا موثقًا لمخاطر النقل عندما توجبه الأنظمة، ونطبق تدابير أمنية مناسبة، ومنها التشفير أثناء النقل والتخزين حيثما تدعمه البنية المستخدمة وتتم تهيئته، وضوابط الوصول وتقليل البيانات.
يمكنك طلب معلومات عن الوجهات وفئات المستلمين والضمانات المطبقة على نقل بياناتك.
13. الاحتفاظ والإتلاف
نحتفظ بكل فئة للمدة اللازمة للغرض المحدد فقط. وتشمل معايير تحديد المدة مدة الحساب أو الاشتراك وحساسية البيانات وحجمها ومخاطرها الأمنية وتوقعات المستخدم ودورات النسخ الاحتياطي والمطالبات والالتزامات النظامية والضريبية والمحاسبية والتنظيمية السعودية.
عندما ينتفي مسوغ الاحتفاظ، نتلف البيانات بأمان أو نخفي هويتها بصورة لا يمكن عكسها، ونلزم جهات المعالجة بذلك عند انطباقه. وقد تُعزل البيانات الموجودة في نسخ احتياطية محمية عن المعالجة المعتادة حتى حذفها وفق دورة النسخ الاحتياطي. وقد يؤخر حجز نظامي موثق عملية الإتلاف حتى انتهاء المطالبة أو التحقيق أو المتطلب المعني.
14. المعلومات المجمعة ومجهولة الهوية
يجوز لنا إنشاء إحصاءات أو معلومات مجهولة الهوية لا يمكن بصورة معقولة ربطها بفرد. ويجوز استخدامها والإفصاح عنها لأغراض المنتج والبحث والسلامة والأعمال. ونحافظ عليها في صورة مجهولة، ولا نحاول إعادة تحديد الهوية إلا إذا أجاز النظام أو أوجب ذلك صراحةً لاختبار فاعلية إخفاء الهوية.
15. الأمن وحوادث تسرب البيانات
نطبق تدابير تنظيمية وإدارية وتقنية ومادية تتناسب مع طبيعة البيانات وحساسيتها لحمايتها من الوصول أو التغيير أو الإتلاف أو الإفصاح غير المصرح به. وتشمل هذه التدابير، بحسب طبيعة النظام والبيانات، التشفير أثناء النقل والتخزين، وضوابط الوصول والصلاحيات والمصادقة، والسجلات والنسخ الاحتياطية، وضوابط الموردين، والاستجابة للحوادث. ومع ذلك، لا يمكن لأي نظام ضمان الأمن المطلق.
إذا وقعت حادثة تسرب بيانات شخصية يُحتمل أن تسبب ضررًا للبيانات أو لصاحب البيانات أو تتعارض مع حقوقه أو مصالحه، فسنشعر الجهة المختصة، وهي الهيئة السعودية للبيانات والذكاء الاصطناعي («سدايا»)، خلال مدة لا تتجاوز (72) ساعة من وقت علمنا بالحادثة وفق اللائحة التنفيذية لنظام حماية البيانات الشخصية. وإذا لم تتوافر جميع المعلومات المطلوبة خلال تلك المدة، فسنقدمها في أقرب وقت ممكن مع بيان مبررات التأخير. وسنشعر المستخدمين المتأثرين دون تأخير غير مبرر عندما يتحقق المعيار النظامي لذلك، مع وصف الحادثة والمخاطر المحتملة والتدابير المتخذة والتوصيات المناسبة.
16. حقوقك بموجب النظام السعودي
بموجب نظام حماية البيانات الشخصية ولائحته التنفيذية، ومع مراعاة الاستثناءات والمتطلبات النظامية، تتمتع بالحقوق التالية:
1. حق العلم: معرفة المسوغ النظامي والغرض المحدد من جمع بياناتك الشخصية ومعالجتها.
2. حق الوصول: الاطلاع على بياناتك الشخصية المتوافرة لدينا.
3. حق الحصول على نسخة: طلب نسخة من بياناتك الشخصية بصيغة مقروءة وواضحة، وبصيغة إلكترونية شائعة الاستخدام متى كان ذلك ممكنًا.
4. حق التصحيح والتحديث: طلب تصحيح البيانات غير الصحيحة أو إكمال البيانات الناقصة أو تحديث البيانات القديمة.
5. حق الإتلاف: طلب حذف أو إتلاف بياناتك الشخصية في الحالات التي يقررها النظام، ومنها انتهاء الحاجة إليها، أو سحب الموافقة عندما تكون الموافقة هي المسوغ النظامي الوحيد للمعالجة، مع مراعاة متطلبات الاحتفاظ النظامية.
6. حق سحب الموافقة: سحب موافقتك على المعالجة في أي وقت، دون أن يؤثر ذلك في مشروعية المعالجة التي تمت قبل السحب أو المعالجة المستندة إلى مسوغ آخر.
7. حق حذف الحساب: يمكنك بدء حذف حسابك والبيانات المرتبطة به مباشرةً من داخل التطبيق عبر: الملف الشخصي > الإعدادات > حذف الحساب. ويشمل الحذف البيانات التي لا يلزمنا الاحتفاظ بها نظامًا، وفق البند (13) من هذه السياسة.
8. حق الشكوى: تقديم شكوى إلينا، ثم إلى الهيئة السعودية للبيانات والذكاء الاصطناعي («سدايا») إذا لم تُحل.
قد تؤثر ممارسة أحد الحقوق في ميزة تحتاج إلى البيانات المعنية. ولن نمنع حقًا إلزاميًا، لكن يجوز لنا رفض الطلب أو تقييده عندما يسمح النظام بذلك، وسنوضح السبب.
17. تقديم الطلبات والتحقق منها
قدم طلبك عبر بيانات التواصل أدناه وحدد الحق الذي تريد ممارسته. وقد نتحقق من الهوية عبر مصادقة الحساب أو مطابقة معلومات متوافرة لدينا، كما يجوز التحقق من صفة الولي الشرعي أو الممثل المفوض.
نستجيب في الأصل خلال 30 يومًا وفق اللائحة التنفيذية. ويجوز، حيث يسمح النظام، تمديدها مرة واحدة مدة لا تتجاوز 30 يومًا إضافية بعد إشعار مسبق يوضح السبب. ويجوز التعامل مع الطلبات المتكررة أو غير المعقولة بوضوح وفق ما يسمح به النظام.
18. المستخدمون القُصّر والأهلية
خدماتنا موجهة للاستخدام المستقل ممن بلغوا سن (18) عامًا أو كانوا كاملي الأهلية المعتبرة نظامًا. وإذا كان عمر المستخدم بين (13) و(17) عامًا، فلا نجمع بياناته أو نعالجها إلا بعد مراجعة وليه الشرعي لهذه السياسة والشروط ومنح الموافقة الصريحة المطلوبة نيابةً عنه، والتحقق من صفة الولي بالوسائل المناسبة، واستمرار إشرافه على الاستخدام. ولا نوجه خدماتنا لمن هم دون سن (13) عامًا ولا نجمع بياناتهم عن علم.
إذا علمنا بأن بيانات شخص دون السن المسموح به أو ناقص الأهلية جُمعت دون موافقة أو صلاحية معتبرة، فسنقيد معالجتها ونتخذ خطوات إتلافها دون تأخير غير مبرر، ما لم يلزم الاحتفاظ المؤقت بقدر محدود منها للامتثال لالتزام نظامي أو توثيق الواقعة، ثم نتلفها عند زوال سبب الاحتفاظ.
19. المواقع والخدمات الخارجية
قد تحتوي المنصة على روابط لخدمات لا نتحكم فيها. ولا تحكم هذه السياسة معالجة جهة خارجية مستقلة. راجع سياسة خصوصية تلك الجهة وأذوناتها قبل الربط أو تقديم البيانات.
20. التغييرات على السياسة
يجوز لنا تحديث هذه السياسة لأسباب نظامية أو تقنية أو أمنية أو متعلقة بالميزات أو التشغيل. وسننشر النسخة المحدثة بتاريخ سريان معدل، ونقدم إشعارًا بارزًا أو مباشرًا بالتغيير الجوهري متى كان ذلك مطلوبًا. وسنطلب موافقة جديدة قبل أي معالجة تستلزمها.
21. التواصل وحماية البيانات والشكاوى
تواصل معنا للاستفسار عن الخصوصية أو ممارسة حق أو سحب الموافقة أو تقديم شكوى. وإذا لم تُحل شكواك، فيمكنك تقديمها إلى سدايا عبر منصة حوكمة البيانات الوطنية. وإذا وجب على الشركة تعيين مسؤول لحماية البيانات الشخصية، فسننشر بيانات التواصل معه هنا.
شركة ستريك فيت
الرقم الوطني الموحد: 7052017741
البريد الإلكتروني: info@streakfit.sa
الموقع الإلكتروني: Streakfit.sa
العنوان المسجل: [العنوان المسجل]
مسؤول التواصل: المؤسس و الرئيس التنفيذي، بشائر الحربي
Privacy Policy for Streak Fit
Effective Date: August 27, 2026
1. Scope and Controller
This Privacy Policy explains how Streak Fit Company, Unified National Number 7052017741 ("Streak Fit," "we," "us," or "our"), collects, uses, discloses, transfers, retains, and protects Personal Data through the Streak Fit application, websites, and related services (collectively, the "Platform").
For purposes of the Saudi Personal Data Protection Law ("PDPL"), Streak Fit Company is the controller responsible for the processing described here. This Policy concerns Platform users and customers and does not govern employee, contractor, or job-applicant data covered by a separate notice.
2. Data You Provide
Depending on the features you use, we may collect:
- Contact and account data: name, email, phone number, user identifier, credentials or one-time codes, profile photo, language, communication choices, and account creation date.
- Profile and preference data: quiz answers, fitness level, goals, selected coach, custom rest time, program preferences, and settings.
- Workout and journal data: workouts and sets completed, exercises, saved workouts, work and rest time, weight used, intensity, duration, progress, body weight, calories, heart rate, and notes you choose to record.
- Nutrition data: meals, foods, dietary preferences, allergies, goals, age, sex, gender, or weight, when you choose to use a relevant feature.
- User content: images, workout selfies, audio, video, messages, reviews, testimonials, and other files or communications you submit.
- Transaction data: membership, subscription, purchase, billing status, and limited payment details received from a payment processor.
- Support and participation data: inquiries, feedback, surveys, promotions, events, chats, and call recordings where permitted and notified.
Required and optional fields will be identified when data is collected. If required data is not provided, the relevant feature may be unavailable.
3. Health and Sensitive Data
We treat body-measurement data, heart rate, workout history, weight, nutrition and allergy data, and information concerning injuries as Health Data or Sensitive Data whenever it falls within the applicable definitions under Saudi law, depending on its content and context.
- We limit the processing of this Sensitive Data to providing the requested training services, personalizing the workout experience, and supporting physical safety while using the Platform.
- Where consent is the legal basis for processing, we rely on your prior, separate, explicit, and provable consent, requested through a distinct and clear action during account setup or before the relevant feature is enabled. Merely accepting the Terms of Service does not constitute separate consent to process Sensitive Data.
- You may withdraw this consent at any time through the App settings or by contacting us, through a process as easy as giving consent. Withdrawal may prevent us from providing personalized features that require the data, but it does not affect the lawfulness of processing completed before withdrawal or processing based on another lawful basis.
- We do not sell or rent Sensitive Data or Health Data, or use it for marketing or targeted advertising.
4. Data Collected Automatically
When you use the Platform, we and authorized providers may automatically collect device type, manufacturer and model, operating system, App or browser version, IP address, network provider, language, time zone, unique device or installation identifiers, crash logs, security events, approximate location derived from IP, and interactions such as screens viewed, videos played, links selected, session duration, and feature usage.
Collection may use local storage, cookies on websites, mobile SDKs, pixels, embedded scripts, logs, or similar technologies. We obtain any consent required before using non-essential technologies. We do not intentionally record passwords, payment-card numbers, or health-journal text through session-recording tools.
5. Data from Other Sources and Integrations
Where you choose or the feature is offered, we may receive data from:
- Apple, Google, or another single-sign-on provider, normally as an authentication token and permitted profile details rather than your third-party password;
- Apple Health, Health Connect, a wearable, or another fitness integration, limited to categories you authorize;
- payment processors and App stores concerning purchase and subscription status;
- coaches, customer support, survey providers, referral programs, social networks, and business partners;
- other users who send a lawful referral or share content with you; and
- public sources or transaction counterparties in a lawful merger, acquisition, or restructuring.
If you use device biometric authentication, your device processes the fingerprint, face, or other biometric template. We normally receive only confirmation that authentication succeeded and do not receive or store the biometric template.
You can remove an integration or change its permissions through the Platform, device, or provider settings. Removal stops future collection but does not automatically erase data already lawfully received.
6. How We Use Personal Data
We may use Personal Data to:
- register, authenticate, secure, and administer accounts;
- deliver workouts, coach services, timers, journal, nutrition, progress, membership, and integrated features;
- personalize plans, settings, content, reminders, and recommendations;
- process purchases, renewals, cancellations, refunds, and tax or accounting records;
- provide support and communicate about security, transactions, workouts, and service changes;
- operate, test, diagnose, maintain, measure, and improve the Platform;
- create aggregated or anonymized insights and conduct product research;
- prevent fraud, abuse, unsafe use, infringement, and security incidents;
- establish, exercise, or defend legal claims and enforce our Terms;
- comply with legal, regulatory, accounting, and lawful authority requirements;
- protect a person's life, health, or safety; and
- send marketing or personalized advertising only where we have a valid legal basis and any required consent.
We do not use Personal Data for a materially incompatible new purpose without providing required notice and obtaining consent where required.
7. Legal Bases
Depending on the purpose and data involved, processing is based on consent, performance of our agreement with you, compliance with a legal obligation, protection of a vital interest, or a legitimate interest allowed by the PDPL that does not override your rights. We do not rely on legitimate interest where the PDPL prohibits it, including for sensitive data. You may withdraw consent without affecting lawful processing completed before withdrawal.
8. Personalization, Inferences, and Automated Features
We may infer preferences, likely interests, recovery needs, or recommended content from information you provide and Platform activity to personalize the service. Automated or AI-assisted features may help create workout, nutrition, progress, or reminder outputs. We do not use solely automated processing to make a decision that produces a legal or similarly significant effect on you unless we give the required notice, identify the lawful basis, and provide the safeguards required by law.
9. Analytics, Advertising, and Communications
We may use analytics to understand traffic, feature performance, conversions, and technical errors. If advertising or attribution features are enabled, we may use device data, a cookie or advertising identifier, or a hashed account identifier to measure or personalize advertising only with the legal basis and consent required by law.
We do not disclose workout-journal, health, nutrition, or other sensitive data to advertising networks for targeted advertising. We do not sell Personal Data for monetary consideration.
You may unsubscribe from promotional email or SMS using the supplied link or instructions and may manage push notifications and tracking permissions in Platform or device settings. Essential account, security, purchase, and service messages may continue while your account is active.
10. When We Disclose Personal Data
We disclose only what is reasonably necessary to:
- Processors and service providers: Firebase and other cloud, authentication, hosting, storage, security, support, communications, analytics, marketing, survey, and payment providers acting under appropriate contractual and confidentiality controls.
- Coaches and service personnel: information needed to deliver the program, respond to you, and support safety, subject to role-based access and confidentiality.
- Integrated services: data you direct us to send to or receive from Apple Health, Health Connect, wearables, social services, or other connected products.
- App stores and transaction parties: purchase, subscription, delivery, cancellation, and refund data needed to complete a transaction.
- Professional advisers and authorities: information needed for legal advice, claims, audits, fraud prevention, debt collection, or compliance with a lawful request.
- Business transactions: data reasonably necessary for a lawful financing, merger, acquisition, restructuring, insolvency, or transfer, subject to required notices and safeguards.
- Safety and rights: information necessary to protect life, health, safety, the Platform, Company rights, or the rights of others.
- Your direction or consent: information you ask us to share, including a testimonial or public post.
Processors may use Personal Data only for the contracted service, our documented instructions, or another purpose independently authorized by law.
11. Sharing Features and Sponsored Accounts
Content you intentionally post publicly or share with another user may be copied or reshared by its recipients. Review the audience and content before publishing. Private journal and health information is not made public by default.
If an employer, team, insurer, or other organization sponsors your access, we may share enrollment, eligibility, subscription administration, and high-level usage information with that sponsor as disclosed when you join. We will not share detailed workout, journal, nutrition, or health data with the sponsor unless you explicitly direct or consent to it or another lawful basis applies.
12. International Transfers
Because we use global cloud-hosting services and technologies, including Google Cloud and Firebase, some Personal Data may be processed or stored on servers, or by support teams, located outside the Kingdom of Saudi Arabia.
- We limit transfers and access from outside the Kingdom to the minimum necessary and conduct them in accordance with Article 29 of the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom.
- Depending on the destination and nature of the transfer, we rely on an adequate level of protection or apply an appropriate safeguard permitted by law. Safeguards may include Standard Contractual Clauses issued by the competent authority, Binding Common Rules, or approved certifications and enforceable commitments, together with appropriate contractual and technical controls.
- We conduct a documented transfer risk assessment when required by law and apply appropriate security measures, including encryption in transit and at rest where supported and configured by the infrastructure used, access controls, and data minimization.
You may request information about the destinations, recipient categories, and safeguards applicable to transfers of your Personal Data.
13. Retention and Destruction
We retain each category only for the period necessary for the stated purpose. Relevant criteria include account or subscription duration, sensitivity, volume, security risk, user expectations, backup cycles, legal claims, and Saudi legal, tax, accounting, and regulatory requirements.
When retention is no longer justified, we securely destroy or irreversibly anonymize the data and require processors to do the same where applicable. Data in protected backups may be isolated from ordinary processing until deletion under the backup cycle. A documented legal hold may delay destruction until the relevant claim, investigation, or requirement ends.
14. Aggregated and Anonymized Information
We may create statistics or anonymized information that cannot reasonably identify an individual. We may use and disclose it for product, research, safety, and business purposes. We maintain it in anonymized form and do not attempt re-identification except where expressly permitted or required by law to test the effectiveness of anonymization.
15. Security and Personal Data Breaches
We maintain organizational, administrative, technical, and physical measures appropriate to the nature and sensitivity of the data to protect it against unauthorized access, alteration, destruction, or disclosure. Depending on the system and data involved, these measures include encryption in transit and at rest, access and authorization controls, authentication, logging, backups, vendor controls, and incident response. No system can guarantee absolute security.
If a Personal Data Breach may cause harm to Personal Data or a Data Subject, or conflict with the Data Subject's rights or interests, we will notify the competent authority, the Saudi Data & AI Authority ("SDAIA"), within no more than seventy-two (72) hours after becoming aware of the incident, as required by the PDPL Implementing Regulations. If all required information is unavailable within that period, we will provide it as soon as possible and explain the delay. We will notify affected users without undue delay where the statutory threshold is met, describing the incident, potential risks, measures taken, and appropriate recommendations.
16. Your Rights Under the Saudi PDPL
Under the PDPL and its Implementing Regulations, and subject to applicable statutory requirements and exceptions, you have the following rights:
1. Right to be informed: Know the legal basis and specific purpose for collecting and processing your Personal Data.
2. Right of access: Access the Personal Data available to us.
3. Right to obtain a copy: Request a readable and clear copy of your Personal Data in a commonly used electronic format where feasible.
4. Right to correction and updating: Request correction of inaccurate data, completion of incomplete data, or updating of outdated data.
5. Right to destruction: Request deletion or destruction in the circumstances established by law, including where the data is no longer necessary or consent is withdrawn and consent was the sole legal basis, subject to applicable retention requirements.
6. Right to withdraw consent: Withdraw consent at any time, without affecting processing lawfully completed before withdrawal or processing based on another lawful basis.
7. Right to delete your account: You may initiate deletion of your account and associated data directly in the App through Profile > Settings > Delete Account. Deletion covers data that we are not legally required to retain, in accordance with Section 13 of this Policy.
8. Right to complain: Submit a complaint to us and then to the Saudi Data & AI Authority ("SDAIA") if the issue is not resolved.
The exercise of a right may affect a feature that requires the relevant data. We will not deny a mandatory right, but we may decline or limit a request where the PDPL permits and will explain the reason.
17. Submitting and Verifying Requests
Submit a request through the contact details below and identify the right you wish to exercise. We may verify identity through account authentication or by matching information already held, and may verify a legal guardian or authorized representative's authority.
We generally respond within 30 days as required by the PDPL Implementing Regulations. Where permitted, this may be extended once for up to 30 additional days after prior notice explaining the reason. Repetitive or manifestly unreasonable requests may be handled as allowed by law.
18. Minors and Legal Capacity
Our services are intended for independent use by persons who are at least 18 years old or otherwise have full legal capacity recognized by applicable law. If a user is between 13 and 17 years old, we collect and process their Personal Data only after their legal guardian has reviewed this Policy and the Terms, given the required express consent on the user's behalf, had their guardianship verified through appropriate means, and continues to supervise use. We do not direct our services to anyone under 13 or knowingly collect their Personal Data.
If we learn that Personal Data from a person below the permitted age or lacking legal capacity was collected without valid consent or authority, we will restrict processing and take steps to destroy it without undue delay, except where limited temporary retention is required to comply with a legal obligation or document the incident, after which the data will be destroyed when the retention reason ends.
19. Third-Party Sites and Services
The Platform may link to services we do not control. This Policy does not govern an independent third party's processing. Review that party's privacy notice and permissions before connecting or providing data.
20. Changes to This Policy
We may update this Policy for legal, technical, security, feature, or operational changes. We will publish the updated version with a revised effective date and provide prominent or direct notice of a material change where required. We will request new consent before processing that requires it.
21. Contact, Data Protection, and Complaints
Contact us to ask a privacy question, exercise a right, withdraw consent, or submit a complaint. If your complaint is not resolved, you may complain to SDAIA through the National Data Governance Platform. If the Company is required to appoint a Data Protection Officer, the officer's contact details will be published here.
Streak Fit Company
Unified National Number: 7052017741
Email: info@streakfit.sa
Website: Streakfit.sa
Registered Address: [Registered Address]
Authorized Contact: Founder&CEO Bashayer Alharbi