Open the legally authoritative German version
Privacy Policy
for the StayFit24 Platform (app.stayfit24.de)
Version: September 2026 (2026-09)
This English version is provided for convenience only. In case of discrepancies, the German version shall prevail.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
StayFit24
Service provided by rauteweb (https://www.rauteweb.de)
Ansprechpartner: Sascha Knodel
Address: Telemannstr. 14, D-44869 Bochum
Email: info@stayfit24.de
This Privacy Policy applies exclusively to the use of the platform app.stayfit24.de (hereinafter referred to as the “Platform”).
A separate privacy policy applies to the publicly accessible website www.stayfit24.de.
2. Subject Matter of This Privacy Policy
This Privacy Policy provides information about the processing of personal data in connection with the use of the StayFit24 Platform by:
- Users / End Users (B2C)
- Operators (B2B)
- Visitors of the Platform without a user account
Depending on the respective role, different data protection responsibilities apply, in particular with regard to the roles of controller or processor, which are transparently explained below.
3. Definitions
- Users / End Users: Natural persons who book or manage services offered by Operators via the Platform
- Operators: Entrepreneurial users (e.g. sports clubs, fitness studios) who offer their own services via the Platform
- Platform: The cloud-based software solution StayFit24
- Controller: The entity that determines the purposes and means of the processing of personal data
- Processor: A service provider that processes personal data on behalf of a controller (Art. 28 GDPR)
4. Technical Provision of the Platform
4.1 Hosting
The Platform is operated using the following service providers:
- Hetzner Online GmbH (server operation, databases, application)
- Amazon Web Services EMEA SARL (storage of media files, e.g. images)
- Ploi B.V. (server and infrastructure management)
- Mailtrap.io (transactional email delivery)
Personal data is processed exclusively on servers located within the European Union / European Economic Area (EU/EEA).
Where service providers are based outside the EU/EEA, they are engaged exclusively in compliance with the requirements of Art. 44 et seq. GDPR, in particular by concluding EU Standard Contractual Clauses.
A transfer of personal data to third countries does not take place unless, in exceptional cases, a legally permissible transfer pursuant to Art. 44 et seq. GDPR is required.
4.2 Server Log Files
When using the Platform, the following data is processed automatically:
- IP address (shortened or stored only for a limited period)
- Date and time of access
- Accessed pages/functions
- Browser type and operating system
- Error messages and technical logs
Purposes of processing:
- Ensuring technical operation
- System security
- Error analysis
- Abuse prevention
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
Storage period: Up to 30 days; longer storage only in the event of security-relevant incidents.
4.3 Abuse and spam protection
We protect the platform and its forms against automated access, spam and misuse. Depending on the form, two different mechanisms are used.
4.3.1 Cloudflare Turnstile
To protect the platform against automated access, spam and misuse, we use Cloudflare Turnstile, a security service provided by:
Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA
Cloudflare Turnstile is used to verify whether a request originates from a human user. In this context, technical information is processed, in particular:
- IP address (shortened or risk-based),
- browser and device information,
- time and context of the request.
Processing is carried out solely for the purpose of ensuring the security and integrity of the platform.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in preventing abuse and attacks)
Cloudflare acts as a data processor. Data transfers to third countries (USA) cannot be ruled out and are carried out in accordance with the requirements of Articles 44 et seq. GDPR, in particular on the basis of EU Standard Contractual Clauses.
Further information on Cloudflare’s privacy practices: https://www.cloudflare.com/privacypolicy/
4.3.2 ALTCHA (contact and booking forms in the widgets)
In the contact and guest booking forms of our embeddable widgets we use ALTCHA, an open source alternative to conventional captchas (MIT licence). The user's browser solves a small computational task (“proof of work”) that makes sending forms in bulk economically unattractive for bots.
ALTCHA is operated entirely by us. The challenge is generated, signed and verified by our own servers and is solved entirely within the browser. No data is transmitted to altcha.org or any other third party. No cookies are set, no user profile is created and no device analysis takes place. The only data processed is the technically required challenge, its signature and its validity period. A solved challenge is valid once only and for a short period.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in preventing automated requests and in keeping the forms operational)
An overview of the open source components we use and their licences is available at https://www.stayfit24.de/open-source.
4.4 Maps (OpenStreetMap)
We use OpenStreetMap to display geographic information (e.g. locations and maps).
OpenStreetMap is an open-source project operated by the
OpenStreetMap Foundation,
St John’s Innovation Centre, Cowley Road, Cambridge, United Kingdom.
When accessing pages that include maps, map data ("tiles") are loaded from OpenStreetMap servers. In this process, the user's IP address is transmitted to these servers.
The processing is carried out solely for the purpose of providing map functionality.
Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in providing a user-friendly map display)
Further information:
https://wiki.osmfoundation.org/wiki/Privacy_Polic
4.5 Maps (MapTiler)
We use MapTiler to provide map functionality.
The provider is
MapTiler AG,
Höhenstrasse 2, 8200 Schaffhausen, Switzerland.
When accessing pages with maps, map data is loaded from MapTiler servers. In this process, personal data, in particular the user's IP address, may be transmitted to MapTiler.
The processing is carried out for the purpose of providing a reliable and high-performance map display.
Legal basis:
Art. 6(1)(f) GDPR (legitimate interest)
Further information:
https://www.maptiler.com/privacy-policy/
5. No Marketing Cookies; Internal Analytics
The Platform uses:
- no tracking cookies
- no marketing or analytics cookies
- no external analytics tools
Only technically necessary mechanisms for authentication, security and session management are used.
Consent pursuant to Section 25(2) No. 2 TDDDG is therefore not required.
Within the Platform, however, usage, booking, contractual, communication and interaction data is evaluated to provide Operators with commissioned reports, lead processes and automations and to improve operations, security and product quality. Rules and segments may be created, for example based on membership status, bookings, interests or communication events. No solely automated decision with legal or similarly significant effects within the meaning of Art. 22 GDPR is made. Processing determined by an Operator is additionally described in that Operator's privacy information.
5.1 Personalised Course Recommendations
In the member area, future course appointments may be displayed and recommended to Users on a personalised basis. For this purpose, the Platform evaluates in particular previous course bookings, frequently booked courses and trainers, preferred booking times and locations, and attributes of previously booked courses. Bookings from the previous 30 days are generally considered; where no bookings exist for that period, the ten most recent course bookings may be used instead. Future bookings made by confirmed friends are considered only where those friends have chosen to make their bookings visible to friends.
The selection, weighting and sorting follow fixed rules defined by humans. Neither a self-learning model nor generative artificial intelligence is used for these recommendations. The recommendations do not decide booking eligibility, prices, available booking options or contract formation. Users decide for themselves whether to view or book a recommended appointment.
The purpose of this processing is to provide a user-friendly course display aligned with previous interests. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in improving course selection and the usability of the member area.
TEIL A – DATENVERARBEITUNG FÜR NUTZER (B2C)
6. User Account and Platform Use
6.1 Processed Data
When registering for and using a user account, the following data is processed in particular:
- First and last name
- Email address
- Telephone number (if provided)
- Date of birth (if provided)
- Login information (e.g. password hash, 2FA status)
- Profile information
- Booking and membership data
- Communication data with Operators
Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
6.2 Minimum Age and Age Confirmation
Personal User and Operator accounts may be created only by persons aged 18 or over. An explicit age confirmation is therefore collected during registration and documented together with the accepted version of the applicable Terms.
Providing a date of birth is generally voluntary, but an Operator may make it a required profile field. Where provided, the Platform checks only whether the age threshold of 18 has been reached. No identity verification using identity documents, biometric data or external information services takes place.
The purposes of processing are to verify eligibility to use the Platform and to document contract formation. The legal bases are Art. 6(1)(b) GDPR and, for evidentiary purposes, Art. 6(1)(f) GDPR. The age confirmation is retained in accordance with Section 14(c), and a provided date of birth is retained as profile information in accordance with Section 15.
6.3 Profiles, Network and Visibility
Users may use profile, friendship, status, interest, booking and achievement features. Visibility is controlled through separate settings. Birthday and status activities are disabled by default and may be enabled separately for friends; the birthday activity displays only on the relevant day and does not disclose the full date of birth. Depending on the feature, processing is based on Art. 6(1)(b) or (f) GDPR.
Friendships are created only through an express request and confirmation between two Users. The participating user accounts, request and confirmation status, and required timestamps are processed for this purpose. A friendship belongs to the platform-wide user account and may therefore continue after a membership or other relationship with an individual Operator ends. Operator-specific discoverability, community content and new Operator-related messages are no longer provided from that point; existing chat messages may remain readable for the retention period stated in Section 15.
Either User may remove a friendship at any time. Shared profile, status, birthday, interest, booking or achievement information is visible only in accordance with the visibility settings enabled for the relevant feature. A continuing friendship does not cause membership or contract data to be shared between different Operators. The legal basis for managing the expressly selected friendship is Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR additionally applies to abuse prevention and secure provision of the network feature.
6.4 Newsletters, Operator Communications and Automations
Newsletters are sent only where the relevant setting is enabled and, where required, double opt-in has been confirmed. Important non-promotional information may be sent based on the contract or a legitimate interest. Operators may configure rule-based automations and audiences for members and leads. Recipients, delivery status, unsubscribe events and required evidence are recorded. StayFit24 does not use personal open tracking in newsletter emails. Unsubscribe links and communication settings remain available.
6.5 Leads, Product Interests and Surveys
For contact, trial, product or membership enquiries, the contact details entered, source, processing status and communications are processed for the relevant Operator. Survey responses are processed confidentially and pseudonymously where configured accordingly by the Operator. They are not technically anonymous because a link may remain for duplicate prevention, authorisation or reporting.
6.6 Public Profiles, Appointment Pages and Widgets
Operator-published profile, offer, appointment and workshop pages and embedded widgets process the data required for display, enquiries, bookings, abuse prevention and, where applicable, online payment. The Operator is responsible for its content and offer information; StayFit24 generally processes End User data on the Operator's behalf.
6.7 Notices, Complaints and Misuse Review
Users, recipients and guests may use profile, newsletter, review or other reporting functions to submit notices concerning content or activity they consider unlawful, incorrect or abusive. The following data may be processed:
- name and contact details of the reporting person
- category, subject, description and voluntarily submitted evidence
- the affected Operator, content, newsletter, review or other matter
- processing status, decision, reasoning and internal event records
- technical security data, in particular the IP address and abuse-prevention evidence
The purposes are to receive and review notices, communicate with involved parties, prevent misuse, comply with statutory duties and establish, exercise or defend legal claims. The legal bases are Art. 6(1)(c) GDPR where a statutory obligation applies and otherwise Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and lawful operation of the Platform and the proper resolution of complaints.
Where necessary for the review or a response, the content of the notice and necessary surrounding circumstances may be disclosed to the affected Operator or other involved parties. The reporting person's contact details are disclosed only where necessary or legally required. A notice is not automatically treated as an established case of fraud or a legal violation. Decisions to remove or suspend a profile are not made solely by automated means.
7. Bookings and Operator Services
When bookings are made via the Platform, personal data is transmitted to the respective Operator to the extent necessary to perform the booking.
Responsibility:
- The Operator is the controller for data processing in connection with its services
- The Provider processes this data exclusively as a technical service provider
The Provider does not determine the purposes or means of processing in connection with the performance of Operator services.
For guest bookings, the express confirmation that the booking person is at least 18 years old is also processed. The confirmation, timestamp, policy version and, for internal entry, the confirming staff member may be stored. Bookings for minors are not currently offered.
8. Payment Processing (Users)
If Operators offer online payments, payment processing is carried out via external payment service providers (e.g. Stripe, PayPal).
The Provider does not act as a payment service provider and does not store complete payment data.
Legal basis: Art. 6(1)(b) GDPR
Payment service providers act as independent controllers under data protection law. Their respective privacy policies apply.
9. Health-Related Information & Notes Functions
The Platform may provide functions that allow Users to voluntarily enter additional information (e.g. notes on physical limitations).
Principles:
- Information is provided voluntarily
- There is no obligation to provide such information
- No automatic disclosure to other Operators
Legal basis: Art. 9(2)(a) GDPR (explicit consent)
Users may withdraw their consent at any time with effect for the future.
10. Deletion of the User Account
Users may delete their account at any time.
Personal data will be deleted or anonymised provided that:
- no statutory retention obligations apply, and
- no overriding legitimate interests exist
Booking or billing data may be retained for legal reasons and will be restricted from further processing for other purposes.
Upon deletion, a reduced archive record containing the name, email address and a summary of roles and memberships is created. It serves to attribute the booking and evidentiary data that remains with the respective Operator and is anonymised after two years.
10a. Deletion of Unused User Accounts
The Provider deletes user accounts that have not been used for an extended period. The legal basis is the principle of storage limitation under Art. 5(1)(e) GDPR in conjunction with the contractual provision in the Terms and Conditions.
The following periods apply:
- user accounts without any activity: 24 months
- operator accounts without an active sports club: 12 months
- sports club setups that were never completed (drafts): 6 months
- registrations whose email address was never confirmed: 90 days
Activity means the last sign-in, the last use of the application, the last booking and the last change to a club connection. Signing in alone is not decisive, because participation can also take place without signing in, through check-in by the Operator's staff.
Before deletion the user is notified twice by email, 30 and 7 days before the scheduled deletion date. Each notification states the exact date and offers a way to keep the account without signing in. Confirming extends retention by at least twelve months; signing in again has the same effect.
Deletion does not take place while an active or paused membership, a future booking, a future appointment assignment as a trainer, an own sports club that has not been closed, or an outstanding membership fee exists. Registrations that were never confirmed are deleted without prior notice, as no confirmed means of contact exists for them.
In all other respects, deletion follows section 10.
PART B – DATA PROCESSING FOR OPERATORS (B2B)
11. Operator Account and Organisational Data
When Operators use the Platform, the following data is processed in particular:
- Company name
- Contact persons
- Contact details
- Payment and billing data
- Organisational and employee data
- End User data processed on behalf of the Operator
Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
12. Processing on Behalf (Data Processing Agreement – DPA)
Where Operators process personal data of End Users via the Platform, such processing is carried out as processing on behalf pursuant to Art. 28 GDPR.
The corresponding data processing agreement (DPA) is deemed concluded upon acceptance of the Platform usage or may be confirmed separately in electronic form.
13. Payment Processing (Operators)
Payments between the Operator and the Provider are processed via external payment service providers (e.g. Stripe, PayPal).
The Provider processes billing data exclusively for the purpose of contract performance and compliance with statutory tax obligations.
Payment service providers act as independent controllers under data protection law. Their respective privacy policies apply.
PART C – COMMON PROVISIONS
14. Recipients of Personal Data
a) Personal data is disclosed only to: Hosting providers
- Payment service providers
- Support and security service providers
- Public authorities where there is a statutory obligation
b) Support and maintenance access In the context of support, maintenance or troubleshooting services, the Provider may access personal data insofar as this is necessary for the performance of the contractual services. Such access is granted solely on the basis of the Data Processing Agreement, is limited in time and purpose, and is subject to appropriate technical and organisational safeguards.
c) Consent to legal documents and contract formation For the purpose of documenting and evidencing consent to legal documents (e.g. Terms and Conditions, Privacy Policy, Data Processing Agreement), the Provider processes the time of consent, the respective document version and technical metadata (e.g. IP address and user agent).
Processing is based on Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest in evidencing lawful contract formation).
These data are stored for the duration of the contractual relationship and beyond in accordance with statutory limitation and retention periods.
15. Storage Period
Personal data is stored only for as long as this is necessary for the respective purposes or as long as statutory retention obligations apply.
The following standard periods apply to the most important categories of data:
| Category | Period |
|---|---|
| User account without any activity | 24 months, with prior notification (section 10a) |
| Archive record after an account deletion | 2 years, anonymised afterwards |
| Guest data without a new booking | Operator setting between 3 and 24 months; 24 months where the Operator set none |
| Enquiry data without new activity | Operator setting between 3 and 24 months; 24 months where the Operator set none |
| Newsletter delivery logs | 24 months from sending |
| Data copy provided for an access request | 7 days from provision |
| Unconfirmed guest bookings | cancelled after 60 minutes |
| Chat messages | 12 months |
| Friendship link | until removed by either User or deletion of a user account |
| Images attached to closed support requests | 1 month after closure |
| Raw sign-in events for internal analytics | 30 days, aggregated totals afterwards |
| Raw send events for email statistics | until the end of the month, aggregated totals afterwards |
| IP address attached to a profile report | 30 days |
| Export archive after a sports club closure | 3 months from closure |
For the data of a sports club's members and guests, the respective Operator is the controller. The periods above are therefore the Provider's default settings as a processor; the Operator may set shorter periods and remains responsible for stating its own retention periods in its own privacy policy.
Excluded from automatic deletion are invoices and payment records due to the retention obligations under § 147 AO and § 257 HGB, evidence of the acceptance of legal documents, and logs of support access.
After a sports club is closed, a time-limited final export may be made available to the responsible Operator. The export archive is deleted when the displayed export period expires. Operational data is then deleted or anonymised unless it is required for statutory retention duties, processing of payments, refunds, payouts, or disputes already initiated, or the establishment, exercise, or defence of legal claims. In those cases processing is restricted to the relevant purpose.
For profile reports, an IP address stored directly with the notice is removed after no more than 30 days. The remaining case data is generally retained after closure for the applicable statutory limitation periods and is then erased or anonymised. Retention for other notices and review cases depends on the type and outcome of the matter, required suppression or evidentiary obligations and potential legal claims.
16. Rights of Data Subjects
Access and data portability are available as self-service in the user account under "Export my data". The data copy created there contains the data stored for the account in machine-readable form plus a plain-text overview. It contains no data of other people and no security-relevant material such as passwords, two-factor secrets or access tokens. Data created without a user account is matched through the confirmed email address and listed separately; for that data the respective Operator is the controller.
Also available in the user account, under "My consents", is an overview of the legal documents accepted, with version, time and a link to the respective wording.
Data subjects have the right at any time to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
17. Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
18. Amendments
The Provider reserves the right to amend this Privacy Policy. The current version is available at any time within the Platform.