Français

Privacy Policy

Version 2.0 — effective 6 August 2026. Replaces the version dated 3 August 2026.

Related documents: Terms of Service · Assumption of Risk · Legal Notice

1. Who is responsible for your data

adré, an independent business operated from Switzerland — contact@adre.app. Contact details: see our Legal Notice.

We are not required to appoint a data protection officer. Any question relating to data is handled at the address above.

Processing is subject to the Swiss Federal Act on Data Protection (FADP) and, for people located in the European Union or the EEA, to the GDPR.

2. What data we process, for what purpose, on what legal basis

A. Account — e-mail address, first and last name, username, date of birth, profile photo, biography, language, identifiers provided by Google or Apple at sign-in. Purposes: creating and managing the account, age verification, security. Legal basis: performance of the contract (Art. 6(1)(b) GDPR; Art. 31(2)(a) FADP). Retention: lifetime of the account, then deletion within 30 days.

B. Content — photos, videos, stories, captions, comments, messages, reviews, challenges. Purposes: publication and sharing, operation of the social features. Legal basis: performance of the contract. Retention: until deleted by you or by us, then 30 days in technical backup.

C. Bookings and payments — history of sessions and transactions, amounts, coach concerned, cancellation policy applied. Purposes: booking, collection on behalf of the coach, refunds, accounting, disputes. Legal basis: performance of the contract; legal obligation for accounting retention (Art. 6(1)(c) GDPR; Art. 958f CO). Retention: 10 years for accounting records. Card details never pass through our systems and are processed by Stripe.

D. Health and activity data — steps, heart rate, calories, distance, workouts, read via Apple Health (iOS) or Health Connect (Android). Purposes: dashboard, session summaries, challenges. Legal basis: your explicit consent (Art. 9(2)(a) GDPR; Art. 6(7)(a) FADP — sensitive data). You may withdraw it at any time in your phone or App settings, without affecting the lawfulness of prior processing. This data is never sold and never used for advertising. Retention: lifetime of the account, or immediate deletion on withdrawal of consent.

E. Location — GPS position during a live session to trace your route; addresses entered to locate sessions. Purposes: route tracing, finding sessions nearby. Legal basis: your consent (withdrawable at any time in phone settings). Retention: lifetime of the account; routes can be deleted individually.

F. Coach data — identity documents, diplomas, certifications, any insurance certificates provided, declaration of self-employed status, bank details, KYC verification data processed by Stripe. Purposes: documentary check, payment of sums due, fraud prevention, compliance with our obligations. Legal basis: performance of the contract; legal obligation; legitimate interest in platform safety (Art. 6(1)(f) GDPR). Retention: duration of the relationship, then 10 years for supporting records.

G. Coach tax data — identity, address, date of birth, tax identification number, VAT number, financial account identifier, amounts paid and fees withheld per quarter — where a tax reporting obligation applies to the platform (in particular Directive (EU) 2021/514, “DAC7”, where applicable). Purposes: reporting to the competent tax authority. Legal basis: legal obligation (Art. 6(1)(c) GDPR). Recipient: the competent tax authority. Retention: as required by the applicable rules, at least 5 years.

H. Reports and moderation — reported content, grounds, decision, statement of reasons, appeal. Purposes: handling reports, compliance with Regulation (EU) 2022/2065, defence of our rights. Legal basis: legal obligation; legitimate interest. Retention: 6 months after the decision, or longer in case of dispute or authority request.

I. Technical data — device identifiers for push notifications (Firebase Cloud Messaging), performance and crash data, connection logs (IP address, timestamp, device type), pseudonymised usage statistics (Google Analytics for Firebase: screens viewed, usage events — without any advertising identifier). Purposes: notifications, service stability, security, fraud prevention, audience measurement and App improvement. Legal basis: performance of the contract; legitimate interest in security and service improvement (Art. 6(1)(f) GDPR). Push notifications rely on your operating-system consent. Retention: 12 months for connection logs; at most 14 months for audience measurement data.

3. Personalisation and automated decisions

The “For you” feed and coach and session suggestions are ranked automatically. The main parameters are: match with your search, geographical proximity, availability, average rating and number of reviews, the coach’s acceptance and cancellation rates, profile completeness, and your past interactions in the App. No position can be bought.

Every user can report content and block another user. Reports are reviewed by a human and acted upon within 24 hours. Any decision entailing suspension or closure of an account is subject to human review, a statement of reasons and a right of appeal (Section 10 of the Terms).

We take no decision producing legal effects concerning you based solely on automated processing within the meaning of Art. 22 GDPR and Art. 21 FADP.

4. Recipients and processors

These providers access data only to deliver their service, on written instructions and under a processing agreement compliant with Art. 28 GDPR and Art. 9 FADP.

Other recipients: coaches, for the data necessary to deliver the sessions they provide to you; other users, for your public content according to your privacy settings; tax authorities in the case described at 2.G; judicial or administrative authorities where the law compels us; a potential acquirer in the event of a business transfer.

We never sell your personal data and do not share it for advertising purposes.

5. Transfers outside Switzerland and the European Union

Some of the providers above process data in the United States (Google, Stripe, Mapbox, Apple, Resend) and in Ireland (Stripe Payments Europe, Google entities in the EU).

Transfers to the United States rely on: the Data Privacy Framework (the EU–US framework and its Swiss extension), where the provider is certified under it; and/or the European Commission’s standard contractual clauses, supplemented where appropriate by the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner, together with additional technical measures (encryption in transit and at rest, minimisation).

A copy of the applicable safeguards may be requested at contact@adre.app.

6. Security

We implement appropriate technical and organisational measures: encryption of communications (TLS) and of data at rest, named access control limited to what is strictly necessary, strong authentication for administrative access, logging, regular backups, environment separation, and periodic access reviews.

In the event of a personal data breach likely to result in a high risk to your rights, we will inform you and notify the competent authorities within the statutory deadlines (Arts. 33 and 34 GDPR; Art. 24 FADP).

For residents of the State of New York, clause 15.8 of the Terms sets out our obligations under the SHIELD Act.

7. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw your consent at any time for the processing that depends on it (health data, location, notifications).

To exercise them: contact@adre.app. We respond within one month. We may request information allowing us to verify your identity.

You can delete your account directly from the App settings.

Complaints. You have the right to lodge a complaint with a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch; in the European Union, the authority of your country of residence or place of work.

8. Cookies and web share pages

The mobile App uses no advertising cookies.

Share pages accessible from a browser use only cookies strictly necessary for their operation and security.

9. Minimum age

The App is restricted to people aged 18 or over. We do not knowingly collect data concerning minors. If we find that an account has been created by a minor, we close it and delete the associated data. Report any such case to contact@adre.app.

10. Changes

This policy may change; the date of the version in force appears at the top of the page. In the event of a substantial change, you will be informed in the App before it takes effect. Earlier versions are retained and available on request.

11. Contact

adré — contact@adre.app. Contact details: Legal Notice.