Privacy Policy
Version 1.0 · Last updated: August 25, 2026 · Effective: September 1, 2026
In case of any discrepancy, the Spanish version (Aviso de Privacidad) prevails.
1. Who is responsible for your data
| Controller | Alejandro Sánchez Saucedo, sole proprietor (persona física con actividad empresarial), Mexico |
| Address | Prolongación Matamoros #100, Eulalio Gutiérrez, C.P. 25903, Ramos Arizpe, Coahuila, Mexico |
| Privacy contact | [email protected] |
| Brand | Zanza (trademark application pending before Mexico's IMPI; formerly "RoadToFit" / "Road") |
| Services | zanzahq.com, app.zanzahq.com (coach dashboard), api.zanzahq.com (API), and the Zanza mobile app for iOS and Android |
1.1 Who is responsible for what
Zanza is a two-sided platform. Depending on the case, there are two separate controllers over your data:
| Who | Decides | Examples |
|---|---|---|
| Zanza (us) | How the platform works: your account, security, retention, the coach directory, AI assistance features, and the infrastructure | Authentication, backups, encryption, retention periods |
| Your professional (coach, trainer, or nutritionist) | Their professional service: what they program for you, what they ask you, what measurements they take, and what they do with your results | The intake questionnaire, your plan, the measurements they record, the messages they send |
Your professional is an independent controller, not our employee or agent. They have their own privacy obligations and must give you their own privacy notice. If you use Zanza without a coach ("on my own" / self-coached mode), we are the only controller.
2. Who this policy covers
Athletes using the mobile app, professionals using the web dashboard, people who receive an email invitation, and visitors to our public websites.
3. What personal data we process
🔴 marks sensitive personal data, which receives reinforced protection (§5).
3.1 Account and identity
Email, username, password (stored only as a bcrypt hash, never in clear text), Google or Apple sign-in identifier, first and last name, nickname, mobile phone, date of birth 🔴 and sex 🔴, language, time zone, currency, role, and account status.
Sex and date of birth are not decorative: they determine which normative tables a test is read against, the anatomical illustrations of the pain map, and lab reference ranges. Given their direct link to health, we treat them to the same standard as sensitive data.
3.2 Access and security
IP address and user agent for each session, session creation/expiry/revocation timestamps, a SHA-256 hash of your session token (never the token itself), and hashed verification and password-reset codes.
We also keep proof of consent: which document you accepted, in which version, when, and from which IP and device. The law requires us to be able to demonstrate your consent for sensitive data, and that is only possible if we record it.
3.3 Health and training data 🔴
| Category | What it includes |
|---|---|
| Training log | Sets, reps, weight lifted, perceived effort (RPE/RIR), body side, machine variant, techniques used, duration, and date of each session |
| Pain and discomfort 🔴 | Discomfort level (1–10), body area marked on an anatomical map (front, side, or back view), and your free-text comments per exercise |
| Cardio and running | Duration, distance, pace, power (watts), cadence, elevation, and second-by-second heart-rate series; best efforts per distance |
| Daily health 🔴 | Resting heart rate and heart-rate variability (HRV), read from Apple Health or Health Connect if you authorize it |
| Workouts outside your plan | Every workout your watch or band recorded (type, duration, distance, calories, average and max heart rate), only if you turn on the specific toggle |
| Anthropometrics 🔴 | Weight, height, skinfolds, girths, bone diameters, segment lengths, bioimpedance (lean mass, body fat %, phase angle) |
| Vital signs 🔴 | Blood pressure, resting heart rate, oxygen saturation, respiratory rate, temperature |
| Lab results 🔴 | Biochemical results you or your coach enter: lipid panel, glucose, hormone panel, thyroid, liver, kidney, hematology, electrolytes, vitamins and minerals, inflammation and muscle-damage markers — including the sample type (serum, plasma, whole blood, urine, or saliva) |
| Assessments and records | Physical test results, personal records, goals, and training reference values |
| Questionnaires 🔴 | The intake questionnaire your coach defines (may include injury history, illnesses, medication, or surgeries) and the daily readiness questionnaire (sleep, stress, fatigue, pain) |
| Photos and videos 🔴 | Body progress photos and technique videos you choose to upload, with their date and pose |
3.4 Location data
When you start a workout recording in the app, we use your device's GPS to compute distance, pace, and elevation in real time, including with the screen off.
We do not store your route coordinates on our servers. What we store are derived metrics (distance, pace, speed, altitude per instant). If you share a session card with a map, that map is drawn on your phone using the route read from Apple Health at that moment, and it is never uploaded.
We do not track your location in the background outside a session you started, we never use it for advertising, and we never share it with advertisers.
3.5 Bluetooth sensors
If you connect a bike trainer or a heart-rate strap, we read its measurements (power, cadence, speed, heart rate) only while a workout is running. The app never scans for sensors in the background and never uses Bluetooth scanning to infer your location.
3.6 Your commercial relationship with your coach
If your coach uses the billing module, we record the agreed plan, its amount, billing cycle, payment dates, and payment method (cash, transfer, card, other).
We do not process payments and we never receive money from you. We never ask for, see, or store card numbers, CVV, or bank details. What exists is a manual ledger kept by your coach.
3.7 If you use the level calculator (visitors)
At zanzahq.com/nivel anyone can work out their strength level with no account and no sign-up. There are two distinct moments here, and it is worth being precise:
While you calculate, we collect nothing. The entire calculation runs in your browser: what you type — your sex, weight, height and lifts — is never sent to our servers. You can work out your level, read the full result and close the tab without leaving a trace anywhere. The page uses no cookies, no analytics and no trackers.
Only if you give us your email do we store, and only this:
| Data | Detail |
|---|---|
| Email address | The one you type into the form at the end. It is optional: the full result is shown before we ask for it |
| The level you scored | The band per lift ("intermediate on bench press"). We do not store your sex, your weight, your height or the loads you entered: those stay in your browser |
| Campaign source | The utm_source parameter in the URL, if you arrived from an ad or a link |
We use it to send you what you asked for and communications about Zanza (secondary purpose, §4.2). You can ask us to delete it at any time at [email protected], and you do not need an account to exercise that right.
3.8 Data stored on your device only
Session tokens (in the operating system's secure storage), local preferences, the draft of a
half-finished workout, a temporary response cache for poor connectivity, and — in the web
dashboard — localStorage for tokens and preferences. All of it is cleared when you sign out
or uninstall.
3.9 What we do NOT do
- ❌ No analytics, no trackers. There is no Google Analytics, Firebase, Meta SDK, Mixpanel, or any other SDK that tracks your behaviour inside the app or the dashboard: we do not measure which screens you view, how long you spend on them, or when you open the app.
- ✅ We do use error reporting (Sentry, see §7.2). We list it here for transparency even though it is not a tracker: something is sent only when the app, the dashboard, or the API fail. At that moment we send the exact point in the code that crashed, the device model and OS version, and the names of the screens you passed through just before. We do not send what you typed, your workouts, your photos, your name, your email, or your IP address. If nothing fails, nothing is sent.
- ❌ No advertising or third-party cookies (§11).
- ❌ We never sell or rent your personal data, under any circumstances.
- ❌ We never use your health data for advertising or marketing.
- ❌ We do not train AI models on your data, and we do not allow our providers to do so.
- ❌ No automated decisions with legal effects and no profiling of that scope.
- ❌ No server-side push notifications. Reminders are scheduled by your own phone; we hold no device push tokens.
4. Why we use your data
4.1 Primary purposes — required to provide the service
Creating and managing your account and authenticating you; linking you with your professional (or your athletes); showing your training plan and letting you log workouts; computing your progress (loads, volume, 1RM indices, records, adherence, fatigue, recovery); letting your professional review what you log; recording measurements, tests, and assessment results; storing your photos and videos and sharing them with your coach only when you mark each file; syncing the health data you authorize; sending transactional email (verification, password reset, invitations); maintaining security; keeping backups; and handling your rights requests and our legal obligations.
4.2 Secondary purposes — you can object without losing the service
Appearing in the public professional directory (professionals only, opt-in, off by default); product updates, surveys, and help material; aggregated, anonymized statistics to improve the product; and replying to anyone who leaves their email in the public level calculator (§3.7) — sending them their result in writing and communications about Zanza.
You may object at any time at [email protected]. Objecting is never a reason for us to deny you the service.
4.3 GDPR legal bases (EEA / UK)
| Purpose | Legal basis |
|---|---|
| Account, plan, logging, progress | Contract (art. 6.1.b) |
| Health data, measurements, photos, questionnaires | Explicit consent (art. 9.2.a) |
| Apple Health / Health Connect sync | Explicit consent (art. 9.2.a), revocable |
| Security, abuse prevention, backups | Legitimate interest (art. 6.1.f) |
| Transactional email | Contract |
| Product communications, public directory | Consent (art. 6.1.a) |
| Legal and tax obligations | Legal obligation (art. 6.1.c) |
5. Sensitive data: your express consent
Almost everything that makes Zanza useful is sensitive health data. Mexican law requires your express, written consent for it; the GDPR requires explicit consent.
Therefore: registration asks for a specific, separate acceptance for health data processing, not buried inside the Terms; Apple Health / Health Connect sync requires both the OS permission and a separate in-app toggle to share with your coach, both off by default; each photo and video has its own "share with my coach" switch, off by default; lab results only enter the platform if you or your coach type them in; and you may withdraw consent at any time (§9).
6. Where your data comes from
From you; from your professional (when they invite you, record measurements, or log a payment); from your device (GPS, Bluetooth, camera, photos, when you authorize them); from Apple Health or Health Connect if you authorize it — which may in turn contain data written there by Garmin, Whoop, Polar, Strava, or other apps you connected; and from Google or Apple if you use their sign-in (identifier and email only).
7. Who we share your data with
We never sell your data.
7.1 Your professional
That is the purpose of the service. Your coach sees your profile, logs, measurements, questionnaires, and progress. They see your photos and videos only if you marked that file as shared. When the relationship ends, your coach keeps the record of the period they trained you but stops receiving new data.
7.2 Processors acting on our behalf
Each one processes your data only on our instructions, under a data processing agreement (DPA) and Standard Contractual Clauses where applicable:
| Provider | Purpose | What it receives | Where |
|---|---|---|---|
| Railway | API servers and PostgreSQL database | All platform data | USA |
| Cloudflare | DNS, DDoS protection, Pages (hosting for the public zanzahq.com site), and R2 (photo and video storage) | Traffic, IP; media in a private bucket | Global / USA |
| Vercel | Hosting for the coach dashboard | Dashboard traffic and IP | USA |
| Sentry | Error reporting for the app, the dashboard, and the API, so we can fix them (§3.9) | The point in the code that failed, the device model, and its OS version. Never your name, email, IP address, or the contents of your workouts, photos, or answers | USA |
| Resend | Transactional email delivery | Your email address and the message content | USA |
| Anthropic (Claude) | Assisting the coach in drafting follow-up messages | Only your nickname and your weekly figures (sessions completed, discomfort level, comments). Never your full name, email, or phone | USA |
| Google (Drive) | Database backups | Full database copy | USA |
| Apple / Google | Sign-in and app distribution | Account identifier | USA |
About AI: the model drafts a message that your coach reads, edits, and decides whether to send. Nothing is ever sent automatically. Our provider does not use the content of these requests to train its models. The feature is optional at the platform level and can be disabled entirely.
7.3 Outside the platform: WhatsApp
If your coach messages you on WhatsApp, that message travels through WhatsApp (Meta) under their terms, not ours. We only keep, where applicable, a copy of the proposed and sent text for your coach's log.
7.4 Transfers allowed without your consent
To competent authorities upon a duly founded request; where necessary to address a medical emergency that puts you at risk; to our legal or accounting advisors under confidentiality; and in a merger, acquisition, or sale of the business, with prior notice and the same protections.
8. International transfers
Our servers and providers are outside Mexico (primarily the United States). If you are in the EEA, the UK, or Switzerland, your data is transferred to a country without an adequacy decision, safeguarded by Standard Contractual Clauses with each provider and by supplementary technical measures: encryption in transit (TLS) and at rest, a private bucket with short-lived signed URLs, and minimization of what each provider receives.
You can request a copy of these safeguards at [email protected].
9. Your rights
9.1 GDPR (EEA / UK)
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent at any time, and lodging a complaint with your national supervisory authority.
Zanza does not direct its service to the European Union — we do not advertise there, we do not price in euros, and we have no EU establishment — but we honour these requests wherever you live.
9.2 Mexico — ARCO rights
Access, Rectification, Cancellation, and Objection. Write to [email protected] with your name, a contact email, a copy of official ID, and a clear description of your request. We respond within 20 business days and, where applicable, act within the following 15 business days. Free of charge.
9.3 United States
Zanza is available in the United States. There is no general federal privacy law, so what applies to you depends on your state.
California (CCPA/CPRA). Right to know, delete, correct, limit the use of sensitive personal information, and not be discriminated against for exercising them. We do not sell or share personal information as defined by the CCPA, and we do not use it for cross-context behavioral advertising.
Consumer health data (Washington and Nevada). Washington's My Health My Data Act and Nevada's equivalent protect health data with no company-size threshold: they apply from the first user. If you live in those states, we collect your health data only with your consent, we do not sell it, and sharing it with anyone other than your professional would require your specific authorization. You can withdraw consent and request deletion at [email protected].
HIPAA does not apply to us. We are not a health plan, a health care provider, or a clearinghouse, and neither is your professional when training you. HIPAA not applying does not mean your data is unprotected: it is protected by this policy, Mexican law, and the state laws above.
9.4 Self-service
Edit your profile in the app or dashboard; turn off a photo or video's "share with my coach" switch; turn off health sync in Settings and/or revoke the permission in Apple Health or Health Connect; sign out of your devices.
Delete your account: write to [email protected] from your account email and we will delete it within 30 calendar days. What is deleted and what is kept is detailed at https://zanzahq.com/eliminar-cuenta.
9.5 If you need this policy in another format
If a disability makes this policy hard to read as published, write to [email protected] and we will send it in a format you can use — plain text that works with a screen reader, large print, or audio. It is free, and you do not have to tell us why you are asking.
The same applies to the Terms of Service and to exercising any of the rights above: if email does not work for you as a channel, tell us what does and we will use it. A right you can only exercise through a channel you cannot use is not a right.
10. How long we keep your data
| Data | Retention |
|---|---|
| Account and profile | While your account is active |
| Training logs, measurements, tests, records | While your account is active — this is your history, and its value is the multi-year comparison |
| Technique videos | Automatically deleted ~90 days after upload (bucket lifecycle rule). Not a permanent archive |
| Progress photos | While your account is active, or until you delete them |
| Sessions (IP, user agent) | Up to 30 days after expiry or revocation |
| Verification and reset codes | 30 minutes (reset) or until used |
| Unaccepted invitations | 7 days |
| Coach message drafts | For the duration of the coaching relationship |
| Accounting and tax records | As required by applicable law (in Mexico, up to 5 years) |
| Backups | The 14 most recent copies (about two weeks). Deleted data leaves the live database immediately and the backups within that window |
When you delete your account, we erase or anonymize your data except what we must keep by legal obligation or to demonstrate compliance.
11. Cookies and similar technologies
We use no advertising, analytics, or third-party cookies. Only strictly necessary
storage: localStorage in the coach dashboard (session and preferences), the OS secure
storage in the mobile app (session tokens), and local preferences and cache so the app works
on a bad connection. Clear it by signing out, clearing browser data, or uninstalling.
12. How we protect your data
Passwords hashed with bcrypt (12 salt rounds); HTTPS/TLS everywhere; session tokens stored
as SHA-256 hashes with rotation and revocation, and held in the OS secure storage on the
phone; photos and videos in a private bucket served through signed URLs that expire in
about an hour, with the object path chosen by the server rather than the client; verified
access control (every route touching an athlete's data checks for an active coach↔athlete
relationship — audited 2026-08-25 with no findings); rate limiting on login, registration,
and password reset; generic password-reset responses so nobody can enumerate accounts;
Cloudflare in front of the API; security headers on the dashboard; and verified, rotated
backups.
No system is infallible. If a breach materially affects your rights, we will notify you and the competent authority within the legal deadlines (72 hours under the GDPR).
13. Minors
Zanza is for people aged 18 and over. The Terms of Service (§3.1) require it as a condition of use, and in the app the athlete also declares it by ticking a specific box when creating their account. We store that acceptance with its date. We do not verify age with documents — we do not ask for ID to register — and we do not knowingly collect data from minors. Professionals must not create accounts for minors or enter their data. If we detect an account belonging to someone under 18 we will suspend it and delete the data. Contact [email protected] if you believe a minor has given us data.
14. Changes to this policy
The current version will always be at https://zanzahq.com/privacy with its version number and date. For material changes — a new purpose, a new category of data, or a new provider with access to health data — we will notify you by email or in the app before it takes effect, and we will ask for renewed consent where the law requires it.
15. Contact
| Privacy and data rights | [email protected] |
| General | [email protected] |
| Address | Prolongación Matamoros #100, Eulalio Gutiérrez, C.P. 25903, Ramos Arizpe, Coahuila, Mexico |
Drafted from the actual state of the product on August 25, 2026.
