Privacy Policy for Coaches
Version: 2026-08-24
Effective Date: August 24, 2026
The German version of this document is the authoritative version; this English translation is provided for convenience.
1. Introduction and scope
(1) Gain. Fitness GmbH, Kelchweg 3, 8048 Zurich, Switzerland ("Gain", "we", "us" or "our") operates the "Gain" coaching platform including the coach web application (the "Platform").
(2) This privacy policy is addressed to you as a coach (the "Coach"), that is, as a person who uses the Platform to support their clients (the "athletes").
(3) It explains two things:
- which personal data about you we process, for which purposes, on which legal basis, who receives it, how long it is stored and which rights you have (sections 4 to 16);
- in which data protection role you process your athletes' data on the Platform, and which obligations follow from that for you (sections 2, 3, 5 and 6).
(4) We comply in particular with:
- the EU General Data Protection Regulation (GDPR) — for coaches in the EU/EEA pursuant to Art. 3(2) GDPR;
- the Swiss Federal Act on Data Protection (revFADP);
- the California Consumer Privacy Act (CCPA/CPRA), where applicable (section 14).
(5) A separate privacy policy applies to athletes: https://gain-app.com/en/privacy/athlete. The full text of the joint controller agreement is available at https://gain-app.com/en/legal/joint-controller-agreement; the terms of use for coaches are available at https://gain-app.com/en/terms/coach.
2. Controllers — who is responsible for what?
There are three distinct spheres of responsibility on the Platform. This allocation has changed compared with earlier versions of this privacy policy: Gain is no longer the sole controller for all athlete data, and you are no longer merely an "authorised user" of the Platform.
2.1 Gain as sole controller
Gain. Fitness GmbH is the sole controller within the meaning of Art. 4(7) GDPR for:
- your account, registration and authentication data (section 4.1);
- technical and diagnostic data, including access logs (sections 4.4 and 4.6);
- billing and payment data in the relationship between you and Gain, and compliance with commercial and tax retention obligations (section 4.3);
- audience measurement and conversion tracking, in particular the conversion measurement at your registration (section 4.5);
- security, abuse and fraud prevention for the Platform;
- all data of users without a coach (solo use), including their health data.
Contact: privacy@gain-app.com.
2.2 Gain and you as joint controllers
As soon as an athlete account is linked to your coach account, Gain and you are joint controllers within the meaning of Art. 26 GDPR for that athlete's coaching data. These are the following eight categories of data:
| Category | Examples |
|---|---|
| Training data | Training plans, exercises, weights, repetitions, RIR, mesocycles and planning data |
| Nutrition data | Macronutrients (protein, carbohydrates, fat, fibre), nutrition targets, diet phases |
| Tracking data | Body weight, rate of weight change, step counts, sleep data, custom tracking fields |
| Check-in data | Athletes' check-in responses, your feedback and your notes |
| Anamnesis data | Information on pre-existing conditions, injuries, complaints, medication, food intolerances |
| Form check media | Photos and videos of movement execution as well as progress photos |
| Imported historical data | Training, nutrition, check-in and anamnesis history carried over from previous tools (section 6) |
| Messages | Messages between you and your athletes within the Platform, including any health information they contain |
This data is predominantly health data and therefore constitutes special categories of personal data under Art. 9(1) GDPR.
Joint controllership for an individual athlete begins when that athlete is linked to your coach account (accepted invitation); imported historical data is subject to it from the moment of import (section 6). It ends when that link is removed. The allocation of obligations between Gain and you is described in section 3.
2.3 You as sole controller
For everything you process outside the Platform, you alone are the controller. This includes in particular:
- your own notes, spreadsheets, previous tools and other records held outside the Platform;
- your communication with athletes outside the Platform (e.g. email, messenger, telephone, in-person conversations);
- contract initiation, invoicing and accounting towards your athletes;
- your marketing and advertising activities.
Gain is neither controller nor processor for that processing. This privacy policy does not apply to it. You comply with the applicable data protection obligations on your own responsibility in that respect and must inform your athletes about your own processing separately.
Where you carry data from your sole sphere of responsibility over into the Platform (data import, section 6), that data becomes subject to joint controllership under section 2.2 from the moment of import. The lawfulness of its collection and of your holding it before the import remains your sole responsibility.
2.4 Overview
| Area of data | Controllership |
|---|---|
| Your account, registration and authentication data | Gain is sole controller |
| Technical data, diagnostic data and access logs | Gain is sole controller |
| Your billing and payment data towards Gain | Gain is sole controller |
| Conversion measurement at your registration, audience measurement | Gain is sole controller |
| Coaching data of your linked athletes under section 2.2 | Gain and you jointly (Art. 26 GDPR) |
| Messages inside the Platform (section 2.2) | Gain and you jointly (Art. 26 GDPR) |
| Data of users without a coach (solo use) | Gain is sole controller |
| Your processing outside the Platform | You are sole controller (outside this policy) |
3. Essence of the joint controller arrangement (Art. 26 GDPR)
(1) The basis of the joint controllership described in section 2.2 is the joint controller agreement under Art. 26 GDPR (the "Agreement"). You accept the Agreement expressly during onboarding (click-accept); the acceptance is logged with a version identifier and a timestamp. You can view the accepted version at any time in your coach account and download it as a PDF. The full text is publicly available at https://gain-app.com/en/legal/joint-controller-agreement.
(2) The Agreement is not a data processing agreement within the meaning of Art. 28 GDPR. Neither party processes the coaching data on the other party's behalf.
(3) The Agreement allocates the data protection obligations as follows:
| Obligation | Who performs it? |
|---|---|
| Informing data subjects (Art. 13, 14 GDPR), except where allocated to you below | Gain — via the privacy policy for athletes and in-app notices |
| Informing the data subject before historical data is imported (Art. 14 GDPR) | You (section 6) |
| Point of contact for data subjects (Art. 26(1) sentence 3 GDPR) | Gain, privacy@gain-app.com |
| Handling data subject rights (Art. 15 to 22 GDPR) | Gain, with your cooperation |
| Obtaining and documenting consent (Art. 7, Art. 9(2)(a) GDPR) | Gain — a separate, unbundled onboarding step (section 5) |
| Handling withdrawals of consent | Gain; you are notified (section 5) |
| Technical and organisational measures within the Platform (Art. 32 GDPR) | Gain (section 15) |
| Technical and organisational measures in your sphere (Art. 32 GDPR) | You (devices, credentials, working environment) |
| Notification of personal data breaches to the supervisory authority (Art. 33 GDPR) and communication to data subjects (Art. 34 GDPR) | Gain for Platform incidents |
| Records of processing activities (Art. 30 GDPR) | each party for itself |
| Data protection impact assessment (Art. 35 GDPR), where required | Gain, with your cooperation |
| Engagement and supervision of processors (Art. 28 GDPR) and international transfers (Chapter V GDPR) | Gain (sections 9 and 10) |
| Accuracy and currency of the data you enter | You |
| Lawfulness of imported historical data before the import | You (section 6) |
(4) Gain is the point of contact. Data subjects can reach us at privacy@gain-app.com. If you receive a request from a data subject concerning processing within the Platform, you forward it to privacy@gain-app.com without undue delay and in any event within three (3) business days and inform the data subject that it has been forwarded. You do not answer such requests yourself. You provide us with the information required to answer them within five (5) business days of our request, so that the time limit under Art. 12(3) GDPR can be met.
(5) Art. 26(3) GDPR. Irrespective of this allocation, a data subject may exercise their rights in respect of and against either party. Neither Gain nor you may turn a data subject away solely by reference to the Agreement.
(6) Liability. Under Art. 82(4) GDPR each joint controller is liable for the entire damage. Between themselves, Gain and you settle the damage according to the respective shares of responsibility (Art. 82(5) GDPR). The allocation of obligations in paragraph 3 is without prejudice to the statutory responsibility of both parties.
(7) Your principal obligations are set out in detail in § 10 of the Agreement, in particular: purpose limitation (processing athlete data solely for coaching purposes), strict confidentiality including after termination, credential hygiene and device security, no entry or import of health data before the athlete has completed onboarding including consent, no export or bulk extract beyond your own lawful sphere of responsibility, data quality, and cooperation under paragraphs 4 and 5 above.
4. Categories of data we process about you
4.1 Account and authentication data
When your coach account is set up via our authentication provider (Auth0) we process:
- name
- email address
- profile picture
- pseudonymous user identifier (Auth0 ID)
4.2 Content you create
The content you create in the Platform — in particular training and nutrition plans, check-in feedback, notes and custom tracking fields — is attributed to your coach account and displayed to your linked athletes. Insofar as that content contains personal data of your athletes, section 2.2 applies to it.
4.3 Billing and payment data
After the trial period ends, continued use of the Platform requires a paid subscription directly with Gain (§ 12 of the coach terms of use). To perform that subscription we process the required contract, billing and payment data (e.g. subscription status, invoice details, payment status, the number of active clients billed). Payments are handled by Stripe (section 9.1); we do not receive full card details. Gain is the sole controller for this data; it is subject to statutory commercial and tax retention periods (section 11).
If you invoice your athletes directly for your coaching services, you alone are responsible for that (section 2.3).
4.4 Technical and diagnostic data
We collect limited technical data via Sentry:
- exception class names
- stack traces
- performance traces
- allowlisted breadcrumb messages
- browser type and version
- operating system version
- pseudonymous user identifier (Auth0 ID)
No name, email address or IP address is intentionally stored in diagnostic logs. For the IP address processed during transmission of the conversion event to Meta, see section 4.5.
Crash logs are retained for a maximum of 90 days unless required for security investigations.
4.5 Conversion measurement at your registration
(1) When you complete coach registration, we may transmit a one-time conversion event (a Lead event via the Meta Conversions API) to Meta Platforms, Inc. ("Meta") in order to measure the effectiveness of our advertising campaigns.
(2) The event is transmitted only where attribution data is available. At least one of the following signals must be present:
- the Meta Pixel cookie
_fbp, set by Meta'sfbevents.jsscript in your browser (this happens only if you have accepted analytics/measurement cookies via the cookie banner), or - the Meta Pixel cookie
_fbc, set byfbevents.js, or - a
metaFbclidentry in yoursessionStoragecontaining the Meta click identifier from thefbclidURL parameter captured when you opened the application (section 16.1).
If none of these signals is available — for example because you declined the cookie banner and did not arrive via a Meta ad — no conversion event is transmitted.
(3) Where the event is transmitted, the following data is shared:
- a SHA-256 hash of your email address (the raw address never leaves our servers)
- your IP address (observed by our server; not stored on our side beyond the request)
- the browser user agent
- the URL of the page on which registration was completed
- a randomly generated event ID (used solely to deduplicate against any browser-side Pixel event)
- the Meta browser identifier (
_fbp) and/or click identifier (_fbc), where available
(4) This data is used solely to attribute your registration to the corresponding advertising campaign and to measure conversion rates. It is not used for personalised advertising, profiling, retargeting or automated decision-making.
(5) Meta acts as an independent controller for the data it receives and processes it under its own Data Policy and Business Tools Terms.
(6) We rely on legitimate interests (Art. 6(1)(f) GDPR) for this measurement, supported by a documented legitimate interest assessment. The notice on the registration screen informs you at the moment of transmission. You have the right to object at any time (Art. 21 GDPR) on grounds relating to your particular situation, by email to privacy@gain-app.com; see section 13.
4.6 Access logs
Access to athlete data is logged for security and compliance purposes. These logs are also attributed to your coach account and therefore constitute personal data about you. Gain is the sole controller for them; the legal basis is Art. 6(1)(f) GDPR (Platform security, accountability and audit capability).
5. Your athletes' consent to the processing of health data (Art. 9(2)(a) GDPR)
(1) Gain obtains the consent — not you. Gain obtains from every athlete, during onboarding, an explicit consent to the processing of their health data under Art. 9(2)(a) GDPR. This is done as a separate, unbundled step, separate from acceptance of the terms of use. The wording of the consent declaration, in the version currently in force, is published at https://gain-app.com/en/legal/art9-consent. Gain documents the consent in a demonstrable manner (wording of the consent text, version identifier, timestamp; Art. 7(1) GDPR). You do not obtain consent on Gain's behalf.
(2) Scope of the consent. It covers the processing of the health data listed in section 2.2 for coaching purposes, conditionally the access by the coach linked to the athlete to that data, and historical data that you provide, including data imported from previous tools (section 6).
(3) Consent status in the Platform. You can view the consent status for each athlete in the Platform. You may rely on the consent obtained by Gain. Where no consent exists for an athlete, that athlete's health data is not available to you in the Platform.
(4) No pre-emptive entry. You may enter or import an athlete's health data into the Platform only once that athlete has completed onboarding including the consent.
(5) Withdrawal and your obligation thereafter. Athletes may withdraw their consent at any time with effect for the future. In that case:
- Gain freezes and hides the health data concerned; it is no longer processed for coaching purposes;
- your access to that data is revoked;
- Gain notifies you without undue delay of the withdrawal;
- upon receipt of that notification you must cease any further processing of the health data concerned without undue delay. This also covers copies and extracts held outside the Platform; these must be deleted or blocked unless you have your own continuing legal basis for them or are subject to a statutory retention obligation;
- permanent erasure follows the standard account deletion route (https://gain-app.com/en/account-deletion) or the retention periods stated in the privacy policy for athletes.
(6) The lawfulness of processing carried out before the withdrawal remains unaffected.
6. Data import from previous tools (Google Sheets)
(1) Where you carry an athlete's historical data over from a previous tool (e.g. a Google Sheets spreadsheet) into the Platform, Annex 2 to the Agreement (https://gain-app.com/en/legal/joint-controller-agreement) and the terms of use for coaches (https://gain-app.com/en/terms/coach) apply in addition.
(2) Prerequisite: completed onboarding and consent. An import is permitted only once the athlete concerned has accepted the invitation, completed onboarding and given the consent pursuant to Art. 9(2)(a) GDPR (section 5). No historical data is transferred to the Platform before the consent has been given; importing "in advance" is not permitted.
(3) One athlete per spreadsheet. Each spreadsheet submitted for import may contain the data of exactly one athlete and no personal data of third parties.
(4) Your warranties. By submitting the spreadsheet you warrant that you collected and hold the data contained in it lawfully, that you informed the athlete concerned about the transfer before the import, that the data is accurate, and that it contains no third-party data.
(5) Information before the import (Art. 14 GDPR). Informing the data subject before the import is your obligation (section 3(3)). Gain provides a template notice for this purpose: https://gain-app.com/en/legal/migration-notice. Its use is recommended.
(6) Deletion of the source file. Gain deletes the source file submitted for import once the import is complete. You remain solely responsible for any copies remaining in your own sphere of responsibility (section 2.3).
(7) Controllership from the import onwards. From the moment of import, the data carried over is subject to joint controllership under section 2.2.
7. Legal bases for processing
| Legal basis | Data | Purpose | Controllership |
|---|---|---|---|
| Art. 6(1)(b) GDPR — contract | Your account and authentication data | Provision and operation of your coach access | Gain alone |
| Art. 6(1)(b) GDPR — contract | Your athletes' coaching data | Provision of the coaching features of the Platform | Gain and you jointly (section 2.2) |
| Art. 6(1)(b) in conjunction with Art. 9(2)(a) GDPR — contract and explicit consent | Your athletes' health data | Processing of special categories of personal data within the coaching service | Gain and you jointly (section 2.2) |
| Art. 6(1)(f) GDPR — legitimate interests | Technical data, diagnostic data, access logs | Stability, security and abuse/fraud prevention of the Platform | Gain alone |
| Art. 6(1)(f) GDPR — legitimate interests | Conversion measurement data (section 4.5) | Measuring the effectiveness of our advertising campaigns; right to object under Art. 21 | Gain alone |
| Art. 6(1)(a) GDPR — consent | Analytics/measurement cookies (_fbp, _fbc; section 16.2) | Audience and campaign measurement | Gain alone |
| Art. 6(1)(b) GDPR — contract | Billing and payment data | Performance of the paid contractual relationship with Gain (section 4.3) | Gain alone |
| Art. 6(1)(c) GDPR — legal obligation | Billing and payment data | Compliance with commercial and tax retention obligations | Gain alone |
Health-related data is a special category of personal data. Art. 6(1)(b) GDPR is not sufficient on its own for processing it; an exception under Art. 9(2) GDPR must apply in addition. As that exception we rely exclusively on the athlete's explicit consent under Art. 9(2)(a) GDPR (section 5).
Any consent given may be withdrawn at any time with effect for the future; the lawfulness of processing carried out up to that point remains unaffected.
8. Purposes of processing
We process data in order to:
- provide and operate the Platform and the coach features;
- enable you to support your athletes and to collaborate with them;
- authenticate you;
- maintain system security and prevent unauthorised access;
- detect and fix technical issues;
- measure the effectiveness of our own advertising campaigns (section 4.5);
- comply with legal obligations (e.g. retention obligations).
We do not:
- sell personal data;
- use personal data for personalised advertising, ad targeting or retargeting;
- engage in profiling;
- conduct automated decision-making with legal or similarly significant effects.
We do, however, transmit a limited, one-time conversion event to Meta when you complete registration and attribution data is available (section 4.5). This serves solely to measure advertising effectiveness, not to target ads to you.
9. Recipients
9.1 Processors (Art. 28 GDPR)
We use carefully selected processors under data processing agreements (Art. 28 GDPR):
| Service | Purpose | Data shared |
|---|---|---|
| Auth0 LLC / Okta, Inc. | Authentication and user management | Name, email address, profile picture, Auth0 ID |
| Amazon Web Services (Amazon.com, Inc.) | Hosting, storage, media storage | All data stored within the Platform |
| Amazon Simple Email Service (SES) | Transactional email delivery | Name, email address, content of the respective message |
| Functional Software, Inc. (Sentry) | Crash reporting and performance monitoring | Error metadata, browser and system info, pseudonymous user ID |
| Stripe Payments Europe, Ltd. (Ireland) | Handling of the subscription and payments (section 4.3) | Name, email address, invoice details, subscription and payment status, number of active clients |
Note on Stripe. Stripe also processes some of the payment data as its own controller — in particular to meet its own regulatory obligations (anti-money-laundering, fraud prevention, payment services law). Stripe's own privacy notice applies in that respect. Payments are handled by Stripe Payments Europe, Ltd. (Ireland), which may engage Stripe, Inc. (USA) as a sub-processor (section 10).
Save for the controller role of Stripe described above, the processors listed act solely on our behalf and under contractual safeguards. The selection, engagement and supervision of processors is Gain's responsibility (section 3(3)).
9.2 Independent controllers
| Recipient | Purpose | Data shared |
|---|---|---|
| Meta Platforms, Inc. | Conversion measurement for our own advertising campaigns | See section 4.5 |
| Stripe Payments Europe, Ltd. | Meeting its own regulatory obligations (anti-money-laundering, fraud prevention, payment services law) | See section 9.1 |
Meta and Stripe are independent controllers for the data they receive in that respect and process it under their own privacy notices. Stripe additionally acts in the processor role set out in section 9.1.
9.3 Other recipients
We disclose data to authorities, courts or legal advisers only where we are legally obliged to do so or where this is necessary to establish, exercise or defend legal claims.
10. International data transfers
(1) Data is stored on servers in the United States. Personal data is therefore transferred from the EEA and Switzerland to a third country.
(2) Primary safeguard: Data Privacy Framework. The US processors we use — Amazon Web Services (Amazon.com, Inc.) including Amazon SES, Auth0 LLC / Okta, Inc. and Functional Software, Inc. (Sentry) — are active participants in the EU–U.S. Data Privacy Framework (DPF) and in the Swiss–U.S. Data Privacy Framework. The transfer therefore takes place on the basis of the European Commission's adequacy decision (Art. 45 GDPR) and the recognition by the Swiss Federal Council respectively.
(3) Fallback safeguard: Standard Contractual Clauses. Should the relevant Data Privacy Framework cease to apply, be suspended or be inapplicable to a transfer, the transfer takes place on the basis of the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) — for transfers from Switzerland in the version recognised by the FDPIC — together with supplementary technical and organisational measures (section 15).
(4) Transfer to Meta Platforms, Inc. The same structure applies to the transfer to Meta as an independent controller (section 4.5): the primary safeguard is the active participation of Meta Platforms, Inc. in the EU–U.S. Data Privacy Framework (DPF) and in the Swiss–U.S. Data Privacy Framework; the transfer therefore takes place on the basis of the European Commission's adequacy decision (Art. 45 GDPR) and the recognition by the Swiss Federal Council respectively. The fallback safeguard, should the relevant Framework cease to apply, be suspended or be inapplicable, is the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) — for transfers from Switzerland in the version recognised by the FDPIC.
(4a) Transfer to Stripe. Payments are handled by Stripe Payments Europe, Ltd., established in Ireland; a transfer to the USA takes place only insofar as Stripe engages Stripe, Inc. as a sub-processor. Stripe, Inc. is an active participant in the EU–U.S. Data Privacy Framework and in the Swiss–U.S. Data Privacy Framework; the fallback safeguard, should the Framework cease to apply, be suspended or be inapplicable, is the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) — for transfers from Switzerland in the version recognised by the FDPIC.
(5) You may obtain a copy of the applicable safeguards on request at privacy@gain-app.com.
11. Retention periods
| Data | Retention period |
|---|---|
| Active coach accounts | for as long as the account is active |
| Following an erasure request | data permanently deleted upon receipt of the erasure request |
| Backup systems | overwritten within 30 days |
| Technical logs and crash reports | deleted after 90 days |
| Inactive accounts | may be deleted after 24 months of inactivity |
| Conversion events (section 4.5) | the randomly generated event ID is retained for up to 90 days for deduplication; the hashed email address, IP address and user agent are transmitted to Meta only and are not stored by us |
| Health data after withdrawal of consent | frozen from withdrawal; erased via account deletion or the periods in this table |
| Records of acceptance of the Agreement and the terms of use | for the duration of the account and thereafter for the statutory limitation periods |
| Billing and payment data | in accordance with statutory commercial and tax retention periods |
Data stored in your browser is handled as described in section 16.1.
12. Termination of the coach account and deletion
(1) Upon termination of your coach account, your access to all athlete data is revoked without undue delay. The joint controller agreement ends automatically; the obligations regarding confidentiality, cooperation on matters arising before termination, and liability continue to apply.
(2) Termination does not affect the athletes' rights in their data or their relationship with Gain.
(3) You may request deletion of your account and the associated data at any time. The procedure is described at https://gain-app.com/en/account-deletion; alternatively, a message to privacy@gain-app.com is sufficient. Data subject to a statutory retention obligation (in particular billing data), or required to establish, exercise or defend legal claims, is excluded from deletion; it is blocked and erased once the relevant period expires.
13. Your rights
(1) In respect of the personal data we process about you, you have the following rights under the GDPR and the revFADP:
- access (Art. 15 GDPR);
- rectification of inaccurate data (Art. 16 GDPR);
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- objection to processing based on legitimate interests (Art. 21 GDPR), including the conversion measurement described in section 4.5. We will stop the processing concerned unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms;
- withdrawal of consent with effect for the future (Art. 7(3) GDPR), for example the cookie consent (section 16.2).
(2) Contact: privacy@gain-app.com. We answer your request within the one-month time limit under Art. 12(3) GDPR; for complex requests the period may be extended by up to two further months, of which we will inform you.
(3) Delimitation. These rights concern your own data. Your athletes' rights in respect of the coaching data are handled in accordance with section 3; you forward requests from athletes to privacy@gain-app.com (section 3(4)).
(4) Right to lodge a complaint (Art. 77 GDPR). You have the right to lodge a complaint with a data protection supervisory authority — in the EU/EEA with the authority of your place of residence, place of work or the place of the alleged infringement; in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
14. California privacy rights (CCPA/CPRA)
If you are a California resident, you may have the following rights, subject to verification and applicable exceptions:
- Right to know what personal information we collect, use and disclose;
- Right to delete personal information, subject to legal exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of sale or sharing — we do not sell personal information. We may transmit a limited, one-time conversion event to Meta at registration (section 4.5), which under California law may qualify as "sharing" for cross-context behavioural advertising purposes. You can prevent this transmission by not completing registration after seeing the notice on the registration screen, or by declining the cookie banner and not arriving at the application via a Meta ad click. Already-registered coaches may contact us at privacy@gain-app.com to request deletion of any conversion event records we still retain (event ID and request metadata are retained for up to 90 days; section 11). We respond to verifiable requests within 15 business days;
- Right to non-discrimination for exercising these rights.
To exercise your rights, contact us at privacy@gain-app.com.
15. Data security
(1) We implement the technical and organisational measures required under Art. 32 GDPR, in particular:
- encryption in transit (TLS 1.2 or higher) and HTTPS enforcement;
- encryption at rest (server-side AES-256 at AWS);
- strict role-based access controls — coaches see only the data of the athletes linked to them;
- time-limited, presigned upload and access URLs for media (form check photos and videos);
- Content Security Policy headers, X-Frame-Options (clickjacking protection) and a strict referrer policy (
strict-origin-when-cross-origin); - logging of access to athlete data for security and compliance purposes (section 4.6);
- tenant separation at the application logic level;
- confidentiality undertakings and regular data protection training for the personnel involved;
- regular backups and recovery procedures.
A detailed overview is set out in Annex 1 to the Agreement (https://gain-app.com/en/legal/joint-controller-agreement).
(2) Your contribution. In your own sphere, you are responsible for appropriate technical and organisational measures (section 3(3)): keeping credentials secret, no account sharing, a strong and unique password, enabling multi-factor authentication where available, and protecting your devices with a screen lock and current security updates. You are also bound to strict confidentiality regarding all athlete data accessible through the Platform; that obligation continues to apply after termination of the coach account.
(3) Incidents. You must report to us the loss or compromise of credentials or devices, unauthorised access to your coach account, and any unauthorised outflow of athlete data from your sphere without undue delay and in any event within 24 hours of becoming aware of it, at privacy@gain-app.com, so that the 72-hour notification deadline under Art. 33(1) GDPR can be met.
16. Browser storage and cookies
16.1 Browser storage
The Platform stores the following data locally in your browser:
- localStorage: authentication tokens (via Auth0), UI preferences (theme, language, sidebar state), view settings and your cookie banner choice. UI preferences and your cookie banner choice persist across browser sessions.
- sessionStorage: temporary authentication redirect paths, onboarding data and — if you arrive at the application via a Meta advertising link — a
metaFbclidentry containing the Meta click identifier from thefbclidURL parameter and the time of the click. This entry is used at registration time only, to attribute your signup to the corresponding ad (section 4.5), and is automatically cleared when the browser tab is closed.
Authentication tokens and session-scoped entries are cleared upon logout. UI preferences and your cookie banner choice are preserved so that your settings are remembered on next sign-in.
16.2 Cookies
The Platform uses the following cookies:
Strictly necessary (set without consent):
- Auth0 authentication cookies
Analytics / measurement (set only after you accept the cookie banner):
_fbp— Meta Pixel browser identifier. Set by Meta'sfbevents.jsscript when the Meta Pixel is initialised in your browser, which only happens after you have accepted analytics/measurement cookies via the cookie banner (and only on production deployments). Used together with the Conversions API event (section 4.5) to deduplicate the registration event between browser and server. Lifetime: 90-day rolling (resets on each visit where the Pixel is active). You can decline this by rejecting the cookie banner; you can withdraw consent at any time by clearing your browser storage._fbc— Meta click identifier. Set byfbevents.jswhen you arrive via a link containing thefbclidURL parameter (and likewise only after analytics/measurement cookie consent). Used to attribute your registration to the originating ad click. Lifetime: 90-day rolling.
If you decline the cookie banner, neither _fbp nor _fbc is set. The conversion event described in section 4.5 may still be transmitted at registration on the basis described there, but without these cookie values.
This section describes the Platform's cookies. On our marketing website (gain-app.com) we additionally set Google Analytics 4 and Google Ads cookies (including _ga, _ga_*, _gcl_au) after you consent via the website's cookie banner. These are fully described in the Cookie Policy: https://gain-app.com/en/cookies.
17. Children's privacy
The Platform is not intended for individuals under 16. We do not knowingly collect data from children under 16. If we become aware that data of a person under 16 is being processed without the required basis, we will delete it without undue delay.
18. No automated decision-making
We do not carry out automated decision-making, including profiling, with legal or similarly significant effects within the meaning of Art. 22 GDPR.
19. Changes to this privacy policy
We may update this privacy policy, for example when the Platform or the legal situation changes. We will inform you of material changes via the Platform or by email. The version in force is available at https://gain-app.com/en/privacy/coach; the version identifier is shown in the header of this document and in the changelog.
Changes to the joint controller agreement are notified to you separately with reasonable advance notice and take effect only once you have accepted them anew.
20. Contact
Gain. Fitness GmbH
Kelchweg 3
8048 Zurich
Switzerland
EU representative (Art. 27 GDPR): We have appointed Prighter EU Rep GmbH, Schellinggasse 3, 1010 Vienna, Austria, as our representative in the European Union pursuant to Art. 27 GDPR. Data subjects and supervisory authorities in the EU may contact our representative regarding any matter related to the processing of personal data: https://prighter.com/q/14301940924 (or by post to the address above, marked "attn: Gain. Fitness GmbH").
Related documents: Joint Controller Agreement (Art. 26 GDPR) · Template data migration notice · Terms of Use for Coaches · Privacy Policy for Athletes · Cookie Policy · Account deletion
Changelog
| Version | Change |
|---|---|
| 2026-08-24 | Added Stripe as payment service provider in sections 9.1, 9.2 (dual role) and 10; aligned section 4.3 with the paid subscription under § 12 of the coach terms |
| 2026-08-23 | Initial version |