This Privacy Policy explains how VaPlan collects, uses, and protects personal data in compliance with GDPR (Regulation (EU) 2016/679) and applicable French law. Please read it alongside our Terms of Use.
This Privacy Policy describes how VaPlan collects, uses, and protects user data in line with GDPR and the French Data Protection Act.
Data controller: VaPlan, legal address: 60, rue François 1er – 75008 Paris, contact email: theo.bouedo@vaplan.app.
Access can use email magic-link (confirmation email) or Google OAuth 2.0. For email sign-in, we store your email and temporary one-time connection tokens (hashed server-side). For Google sign-in, with user consent we receive verified email, display name, optional profile photo, and unique Google ID (sub). We never access Google passwords or Gmail/Drive/Contacts/private data. Docs: Google OAuth 2.0.
Training sessions, notes and comments, sport settings, intensity zones, goals.
IP address, connection logs, browser/device type, technical cookies.
Examples: Strava, Garmin, Intervals.icu. Possible data: distance, duration, pace, HR, power; GPS, elevation, segments, laps; public profile info; activity history.
Email/Google sign-in, account management, user data display.
Session creation/management, stats analysis, charts/tables/performance, training planning.
UI optimization, bug fixing, new feature development.
Abuse prevention, detection of unauthorized access, OAuth session controls.
Contract performance (account, access); consent (OAuth sign-in, analytics cookies, third-party APIs); legitimate interest (security, service improvement). For potentially sensitive sports data (e.g., heart rate), processing also relies on explicit user consent (GDPR Art. 9.2.a).
Session management, authentication, security.
Used only with user consent (CNIL). Examples: Google Analytics, Matomo.
No sensitive data transmitted; no access to emails or private data. Revoke at: https://myaccount.google.com/permissions
Only OAuth-authorized data are imported; used solely for sports features; access can be revoked from the third-party service; deletion of imported data can be requested.
Potential vendors: Hosting and servers: Scaleway SAS, 8, rue de la Ville-l’Évêque, 75008 Paris, France; Analytics: Coming soon™. All vendors are GDPR-compliant or provide equivalent safeguards.
User account and sports data: while the account remains active. Product-usage and AI audit events: at most 12 months. Authentication and presence records: at most 30 days once no longer operationally required. Minimized webhook audit metadata: at most 7 days. Raw IP addresses are not retained in product analytics. Analytics cookies: according to the user’s choice.
Rights: access, rectification, deletion, portability, objection, restriction, withdrawal of consent. Contact: theo.bouedo@vaplan.app. CNIL complaints: https://www.cnil.fr/fr/plaintes
Measures: secure authentication (one-time email links and OAuth), HTTPS, encrypted token storage, protected databases, restricted internal access, anomaly monitoring.
Some services (Google, Strava, etc.) are outside the EU. Transfers rely on Standard Contractual Clauses (SCCs) or equivalent safeguards.
The account-reset action in the user menu deletes the associated VaPlan training and imported sports data while keeping sign-in access. To request complete account deletion, contact theo.bouedo@vaplan.app; the account and associated data will be removed unless a legal obligation requires limited retention.
This policy may be updated. The current version is the one displayed on this page.