Privacy Policy
Introduction
HyCoach is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data.
Data Collected
We may collect the following information:
- Identification information (name, email) when creating an account
- Sports performance data that you voluntarily enter
- Technical data (IP address, browser type) to improve the service
- Cookies for site operation and audience analysis
Use of Data
Your data is used to:
- Provide and improve our services
- Personalize your user experience
- Communicate with you regarding your account
- Analyze site usage in aggregate
Data Sharing
We never sell your personal data. We may share your data only in the following cases:
- With your explicit consent
- To comply with legal obligations
- With technical service providers essential to service operation
Sign-in with Google (Google Sign-In)
HyCoach offers sign-in with your Google account ("Google Sign-In"). When you use this option:
Purposes
- Identify the user in order to create or retrieve your HyCoach account and let you sign back in without a password.
- Claim your HYROX athlete profile: associate HYROX race results that belong to you with your personal account so that you can view, analyze, and appear as a verified athlete.
Data retrieved from Google
Your email address, your last name, your first name, your profile picture, and your unique Google identifier (sub). This data is obtained via the OAuth permissions openid, email, and profile.
Use
This information is used solely for the purposes described above. It is not used for advertising, resale, or training of artificial intelligence models.
Storage
This information is stored in our database on our servers. No other Google data (Gmail, Drive, Contacts, Calendar, etc.) is requested or accessible.
Sharing
We never share this data with third parties outside of the technical service providers necessary for the operation of the service.
Revocation
You can revoke HyCoach's access to your Google account at any time from the Your third-party Google apps page. You can also delete your HyCoach account from your settings, which erases all associated data.
HyCoach complies with the Google API Services User Data Policy, including the Limited Use requirements.
Data Security
We implement technical and organizational security measures to protect your data against unauthorized access, modification, or destruction.
Your Rights
In accordance with GDPR, you have the following rights:
- Right to access your personal data
- Right to rectify inaccurate data
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to object to processing
To exercise these rights, contact us via our contact form.
Cookies and trackers
This section lists every cookie and tracker actively dropped by HyCoach, in accordance with the French CNIL guidelines (article 82 of the Data Protection Act) and the GDPR. You can accept, refuse, or change your choice at any time via the cookie banner or the "Manage cookies" link in the footer.
Manage your preferences
To change your consent, use the "Manage cookies" link at the bottom of every page. Your choice is retained for a maximum of 13 months (CNIL recommendation).
Detailed tracker inventory
The table below lists all cookies and trackers actively dropped on hycoach.ai. Each entry specifies the operator, the CNIL purpose category, the retention period, the GDPR legal basis, and the hosting country.
hycoach-gdpr-consent
- Operator
- HyCoach — FORTUNE FORGE / BLOCK-OPS SAS (France)
- Purpose (CNIL category)
- Essential — stores the proof of your decision (acceptance or refusal of tracker deposit).
- Retention period
- 13 months (395 days), per the CNIL "Cookies & trackers" recommendation.
- Legal basis
- Legal obligation — GDPR art. 6.1.c, French Data Protection Act art. 82. Exempt from prior consent.
- Hosting
- OVH — France, Germany, and Canada (see processing register NES-23 v1.1).
Sentry (session cookies + Session Replay)
- Operator
- Sentry — instance self-hosted by HyCoach in the European Union.
- Purpose (CNIL category)
- Technical measurement and diagnostics — JavaScript error tracking, response-time measurement, and Session Replay (anonymized screen recording limited to sessions affected by an error). Sensitive inputs (passwords, emails, form fields) are automatically masked before transmission.
- Retention period
- 90 days maximum.
- Legal basis
- Consent — GDPR art. 6.1.a.
- Hosting
- European Union (internal instance).
Google Analytics 4 (_ga, _ga_*, _gid)
- Operator
- Google LLC — 1600 Amphitheatre Parkway, Mountain View, CA 94043 (United States).
- Purpose (CNIL category)
- Audience measurement — analysis of page views, user journeys, time spent, and traffic sources. IP addresses are anonymized before processing. No advertising features (Google Signals, remarketing, audiences) are enabled.
- Retention period
- 14 months (GA4 default setting).
- Legal basis
- Consent — GDPR art. 6.1.a. HyCoach does not currently claim the CNIL "audience measurement" exemption: the current configuration involves a non-EU data transfer that does not meet all the exemption criteria.
- Hosting
- United States. Transfer covered by Google's adherence to the EU-US Data Privacy Framework (DPF), approved by the European Commission on 10 July 2023.
Ahrefs Analytics
- Operator
- Ahrefs Pte Ltd — 16 Raffles Quay #33-03, Hong Leong Building, Singapore 048581.
- Purpose (CNIL category)
- SEO audit — aggregated visit counts used to measure SEO coverage and site visibility in search engines (Google, Bing, etc.).
- Retention period
- 13 months.
- Legal basis
- Consent — GDPR art. 6.1.a. An "audience measurement" exemption request is under review as part of ticket NES-21.
- Hosting
- Singapore. Transfer covered by the Standard Contractual Clauses (SCCs) approved by the European Commission (decision 2021/914).
Other third-party processors (no measurement cookies dropped)
Stripe (payments), OVH (hosting), and Google Sign-In (optional authentication) operate on the site but do not drop measurement or advertising cookies. Stripe may drop its own technical cookies during a transaction, strictly necessary for payment processing. The full list of sub-processors is available in our processing register (GDPR art. 30).
HyCoach does not run any targeted advertising and does not drop any advertising cookies (no Google Ads, Meta Pixel, TikTok Pixel, LinkedIn Insight, or equivalent).
Data Retention
Your data is retained for the duration necessary for the purposes for which it was collected, or in accordance with applicable legal obligations.
Contact
For any questions regarding this privacy policy, please contact us via our contact form.
Last updated: 6/14/2026