Privacy & Cookies Policy

MyFIT Quests understands that your privacy is important to you and that you care about how your Personal Data is used and shared online. We respect and value the privacy of everyone who visits this website, https://nicola.jozefwakeman.co.uk/ , the application portal at https://app.myfitquests.com/ (together, “Our Site”), and everyone who uses the MyFIT Quests mobile application available on the Apple App Store and Google Play Store (the “App”).pp Store and Google Play Store (the “App”). Together, Our Site and the App are referred to in this policy as “Our Services”. We will only collect and use Personal Data in ways that are described here, and in a manner that is consistent with Our obligations and your rights under the law.

Please read this Privacy & Cookies Policy carefully and ensure that you understand it. It explains how We handle your Personal Data.

1. Definition and Interpretation

In this Policy the following terms shall have the following meanings:

“App” means the MyFIT Quests mobile application available on the Apple App Store and Google Play Store, including all features and functionality provided through it. The App displays content from Our application portal at https://app.myfitquests.com/, which is also accessible via a standard web browser;

“Cookie” means a small text file placed on your computer or device by Our Site when you visit certain parts of Our Site and/or when you use certain features of Our Site. Details of the Cookies used by Our Site are set out in section 13, below;

“Cookie Law” means the relevant parts of the Privacy and Electronic Communications (EC Directive) Regulations 2003;

“Data Protection Legislation” means all applicable legislation in force from time to time in the United Kingdom applicable to data protection and privacy including, but not limited to, the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder); and the Privacy and Electronic Communications Regulations 2003 as amended;

“Health Data” means data relating to your physical activity and fitness, including step count, distance, active energy burned, heart rate, workout records and similar metrics, accessed from Apple HealthKit, Google Health Connect, Strava or similar fitness platforms with your explicit permission;

“Our Services” means Our Site and the App together;

“Personal Data” means any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means Personal Data that you give to Us via Our Services. This definition shall, where applicable, incorporate the definitions provided in the Data Protection Legislation; and

“We/Us/Our” means Ian Liggins t/a MyFIT Quests of Lodge Park House, Stretton Road, Lapley, Stafford, Staffordshire, ST19 9QQ.

2. Information About Us

Our Site at https://nicola.jozefwakeman.co.uk/ , the application portal at https://app.myfitquests.com/, and the MyFIT Quests App are all owned and/or operated by Us. This Privacy & Cookies Policy applies equally to your use of any of them, unless explicitly stated otherwise.

3. What Does This Policy Cover?

This Privacy Policy applies only to your use of Our Services. Our Services may contain links to other websites or third-party platforms (including Strava, Apple, Google, Stripe and SureCart). Please note that We have no control over how your data is collected, stored, or used by other websites or platforms and We advise you to check the privacy policies of any such third parties before providing any data to them.

4. Your Rights

a. As a data subject, you have the following rights under the Data Protection Legislation, which this Policy and Our use of Personal Data have been designed to uphold:

i. The right to be informed about Our collection and use of Personal Data; ii. The right of access to the Personal Data We hold about you (see section 12); iii. The right to rectification if any Personal Data We hold about you is inaccurate or incomplete (please contact Us using the details in section 14); iv. The right to be forgotten โ€“ i.e., the right to ask Us to delete any Personal Data We hold about you (We only hold your Personal Data for a limited time, as explained in section 6, but if you would like Us to delete it sooner, please contact Us using the details in section 14); v. The right to restrict (i.e., prevent) the processing of your Personal Data; vi. The right to data portability (obtaining a copy of your Personal Data to re-use with another service or organisation); vii. The right to object to Us using your Personal Data for particular purposes; and viii. Rights with respect to automated decision making and profiling.

b. If you have any cause for complaint about Our use of your Personal Data, please contact Us using the details provided in section 14 and We will do Our best to solve the problem for you. If We are unable to help, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office.

c. For further information about your rights, please contact the Information Commissioner’s Office or your local Citizens Advice Bureau.

5. What Data Do We Collect?

Depending upon your use of Our Services, We may collect some or all of the following personal and non-Personal Data (please also see section 13 on Our use of Cookies and similar technologies):

a. Name; b. Email address; c. Postal address; d. Account credentials (encrypted password); e. Profile content you choose to provide (avatar, journal entries, quest reflections); f. Quest progress and activity history within MyFIT Quests; and g. The categories of data described in section 5b below if you use the App.

5b. Mobile Application โ€” Additional Data Categories

When you use the MyFIT Quests App, with your explicit permission, We may also collect:

a. Apple Health Data. If you grant the App permission via the iOS Health permission dialog, We read Health Data from Apple HealthKit, including: step count, walking and running distance, active energy burned, heart rate, and workout records (activity type, duration, distance and calories). This data is transmitted securely (HTTPS) to Our servers and stored alongside your account as activity records contributing to your quest progress. Your Apple Health Data is never used for advertising, never sold or shared with third parties for marketing, and never combined with any data set unrelated to providing the App’s core fitness functionality. You may revoke this permission at any time via iOS Settings โ†’ Privacy & Security โ†’ Health โ†’ MyFIT Quests, after which We will stop receiving new Health Data; previously synced activity records remain in your account but you may request deletion under your rights set out in section 4. Step-by-step guidance is available on Our App Support page at https://nicola.jozefwakeman.co.uk/app-support.

b. Strava Activity Data. If you connect your Strava account, We read your activity history (workouts, distance, duration, route polyline) via Strava’s API to record quest progress. Strava data is governed by Strava’s own privacy policy in addition to this one. You may disconnect Strava at any time via the App’s settings, after which We will stop receiving new data.

c. Push Notification Token. If you grant notification permission, Apple (via the Apple Push Notification service) or Google (via Firebase Cloud Messaging) issues a unique device token We store against your account so We can send you quest progress notifications (for example: milestone unlocked, friend joined, weekly recap). The token does not personally identify you outside Our system and is invalidated automatically if you uninstall the App or revoke the permission in your device settings.

d. App Diagnostic Information. Apple and Google may collect anonymous crash and performance data from the App on Our behalf to help Us identify and fix issues. We do not receive any personally identifying data from Apple or Google about individual users in this context.

e. Google Health Connect Data. If you grant the App permission via the Android Health Connect permission dialog, We read Health Data from Google Health Connect, including: steps, distance, total calories burned, exercise sessions, heart rate, and sleep sessions. This data is transmitted securely (HTTPS) to Our servers and stored alongside your account as activity records contributing to your quest progress. Your Health Connect data is never used for advertising, never sold or shared with third parties for marketing, and never combined with any data set unrelated to providing the App’s core fitness functionality. You may revoke this permission at any time via the App’s Connected Apps page, or via Android Settings, then Apps, then Health Connect, then App permissions, then MyFIT Quests, after which We will stop receiving new data. Previously synced activity records remain in your account but you may request deletion under your rights set out in section 4. Step-by-step guidance is available on Our App Support page at https://nicola.jozefwakeman.co.uk/app-support.

6. How Do We Use Your Data?

a. All Personal Data is processed and stored securely, for no longer than is necessary in light of the reason(s) for which it was first collected. We will comply with Our obligations and safeguard your rights under the Data Protection Legislation at all times. For more details on security see section 7, below.

b. Our use of your Personal Data will always have a lawful basis, either because it is necessary for Our performance of a contract with you, because you have consented to Our use of your Personal Data (e.g. by subscribing to emails, or granting Health Data permissions in the App), or because it is in Our legitimate interests. Specifically, We may use your data for the following purposes:

i. Personalising and tailoring your experience on Our Services; ii. Supplying Our products and services to you (please note that We require your Personal Data in order to enter into a contract with you); iii. Recording your fitness activity against Our quests, calculating quest progress, milestones, badges and rewards; iv. Personalising and tailoring Our products and services for you; v. Replying to emails from you; vi. Sending you push notifications you have consented to receive; vii. Market research; viii. Analysing your use of Our Services to enable Us to continually improve Our Services and your user experience; and ix. Where you have separately consented for marketing purposes.

c. You have the right to withdraw your consent to Us using your Personal Data at any time, and to request that We delete it.

d. We do not keep your Personal Data for any longer than is necessary in light of the reason(s) for which it was first collected. Data will therefore be retained for the following periods (or its retention will be determined on the following bases):

i. We will retain your contact details for as long as we contract with you and for 24 months thereafter, with the exception of financial information as detailed in iv. below; ii. We will retain your contact details for 24 months if you have enquired about our services and not subsequently signed up; thereafter, they will be deleted; iii. If you sign up to Our mailing list, We will retain your personal data for as long as you consent to receive emails from us. You can unsubscribe at any time and We will remove you from Our mailing list and thereafter We will delete your details; iv. We will retain your financial information, which could include your name, address and email address, for as long as we contract with you and, thereafter, for the permitted period of time required by law; v. We will retain Health Data and activity records for as long as you have an active MyFIT Quests account, so that historical quest progress remains visible to you. Upon account deletion, all Health Data and activity records are removed within 30 days.

7. How and Where Do We Store Your Data?

a. We only keep your Personal Data for as long as We need to in order to use it as described above in section 6, and/or for as long as We have your permission to keep it.

b. We will store some of your Personal Data in the UK. This means that it will be fully protected under the UK’s Data Protection Legislation.

c. We will store some of your Personal Data within the European Economic Area (the “EEA”). The EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein. This means that your Personal Data will be fully protected under the EU GDPR and/or to equivalent standards by law. Transfers of Personal Data to the EEA from the UK are permitted without additional safeguards.

d. We may store some or all of your Personal Data in countries outside of the UK and EEA. These are known as “third countries”. We will take additional steps in order to ensure that your Personal Data is treated just as safely and securely as it would be within the UK and under the Data Protection Legislation. Data security is very important to Us, and to protect your data We have taken suitable measures to safeguard and secure data collected through Our Services.

e. We use the following third-party software and some of your data may be processed or stored on their servers:

i. FluentCRM (mailing list and customer relationship management); ii. Elasticmail (transactional and marketing email delivery); iii. Stripe (payment processing); iv. SureCart (subscription and checkout management); v. Strava (if you connect your Strava account; data is retrieved from Strava on Our behalf); vi. Apple HealthKit (Health Data is read locally on your device with your permission and transmitted by the App to Our servers under HTTPS โ€” Apple itself does not receive a copy of the Health Data We process); vii. Apple Push Notification service (delivery of push notifications to iOS devices); and viii. Firebase Cloud Messaging by Google (delivery of push notifications to Android devices, when applicable). vii. Google Health Connect (Health Data is read locally on your Android device with your permission and transmitted by the App to Our servers under HTTPS; Google itself does not receive a copy of the Health Data We process);

f. Steps We take to secure and protect your data include:

i. All devices and computers that we store your data on are password protected; ii. All devices and computers that we store your data on have anti-virus software and are constantly updated to the most recent operating system; iii. Data in transit between the App and Our servers is encrypted using HTTPS/TLS; and iv. We only store your data on computers and devices owned by Us or by Our trusted contractors. Any contractors with access to your data are bound by confidentiality and data protection obligations equivalent to those We are subject to under the law.

8. Do We Share Your Data?

a. We may sometimes contract with third parties to supply products and services to you on Our behalf. These may include payment processing, delivery of goods, search engine facilities, advertising, marketing and email or push notification delivery. In some cases, the third parties may require access to some or all of your data. Where any of your data is required for such a purpose, We will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, Our obligations, and the obligations of the third party under the law.

b. We do not sell, rent or trade your Personal Data, Health Data or activity records to third parties for advertising or marketing purposes under any circumstances.

c. We may compile statistics about the use of Our Services including data on traffic, usage patterns, user numbers, sales, and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may from time to time share such data with third parties such as prospective investors, affiliates, partners, and advertisers. Data will only be shared and used within the bounds of the law.

d. We may sometimes use third party data processors that are located outside of the United Kingdom and European Economic Area (“the EEA”) (the EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein). Where We transfer any Personal Data outside the EEA, We will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the UK under the Data Protection Legislation including:

i. Using Standard Contractual Clauses (“SCCs”) as a mechanism to safely process data outside of the UK and EEA to third countries which have not been granted adequacy; or ii. Where the country has been granted adequacy, which confirms its data protection legislation is adequate to safeguard data processing.

e. In certain circumstances, We may be legally required to share certain data held by Us, which may include your Personal Data, for example, where We are involved in legal proceedings, where We are complying with legal requirements, a court order, or a governmental authority.

f. Some parts of Our Services allow visitors to leave comments, such as Our blog page. If you do leave a comment and disclose your personal data within that comment, please be aware that any other visitors are able to see that information. You therefore do this at your own risk and we have no control of the personal data in that instance.

9. What Happens If Our Business Changes Hands?

a. We may, from time to time, expand or reduce Our business and this may involve the sale and/or the transfer of control of all or part of Our business. Any Personal Data that you have provided will, where it is relevant to any part of Our business that is being transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this Privacy & Cookies Policy, be permitted to use that data only for the same purposes for which it was originally collected by Us.

b. In the event that any of your data is to be transferred in such a manner, you will not be contacted in advance and informed of the changes.

10. How Can You Control Your Data?

In addition to your rights under the Data Protection Legislation set out in section 4, when you submit Personal Data via Our Services, you may be given options to restrict Our use of your data. In particular, We aim to give you strong controls over Our use of your data for direct marketing purposes (including the ability to opt out of marketing emails using the unsubscribe links in Our emails, and the ability to revoke any permission granted to the App via your device’s privacy settings).

11. Your Right to Withhold Information

a. You may access Our Site without providing any data at all.

b. You may use the App without granting permission for Apple Health, Google Health Connect, Strava connection, or push notifications, although certain features that depend on those permissions will be limited. For help managing App permissions, see Our App Support page at https://nicola.jozefwakeman.co.uk/app-support.

c. You may restrict Our use of Cookies. For more information, see section 13.

12. How Can You Access Your Data?

You have the right to ask for a copy of any of your Personal Data held by Us (where such data is held). Under the Data Protection Legislation, no fee is payable and We will provide any and all information in response to your reasonable request free of charge. Please contact Us for more details using the contact details in section 14.

13. Cookies

14. Contacting Us

If you have any questions about Our Services or this Privacy Policy, please contact Us:

Please ensure that your query is clear, particularly if it is a request for information about the data We hold about you (as under section 12, above).

15. Changes to Our Privacy Policy

We may change this Privacy Policy from time to time (for example, if the law changes). Any changes will be immediately posted on Our Services. This policy was last updated on 8th June 2026.