Last updated: June 2026
The controller responsible for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR) is:
White Hammock
Sherief Rageb
Eggers Hoff 10, 25436 Moorrege, Germany
Email: info@white-hammock.de
Phone: +49 (0)5161 9424184
This policy applies to the website sheriffprotocol.com and the connected Sheriff Protocol web/PWA application (the "Service"). It explains which personal data we collect, how we use it, on what legal basis, and which rights you have.
Account data: email, password (hashed), nickname, country, optional profile photo, time zone, unit preference.
Training data: training sessions, 1RM entries, bodyweight, cardio sessions, progress photos you upload, weekly scores, ranking position.
Social data: friend connections, messages you send through the app, privacy settings.
Billing data: subscription plan, Stripe customer ID, payment status. Card data is processed by Stripe — we never see or store it.
Technical data: IP address, browser type, device type, timestamps, error logs.
Contract performance (Art. 6 (1)(b) GDPR): account creation, training tracking, social features, billing.
Legal obligations (Art. 6 (1)(c) GDPR): tax & accounting records.
Legitimate interests (Art. 6 (1)(f) GDPR): service security, abuse prevention, error logging, basic analytics.
Consent (Art. 6 (1)(a) GDPR): non-essential cookies, marketing emails, push notifications. You can withdraw consent at any time.
We use only strictly necessary cookies and local storage to keep you signed in and to remember your preferences (theme, unit, time zone). These are essential for the Service to function and do not require consent. We do not use advertising cookies or third-party tracking pixels.
We work with carefully selected processors under data processing agreements (Art. 28 GDPR):
Where data is transferred outside the EU/EEA we rely on EU Standard Contractual Clauses and equivalent safeguards.
We keep your data for as long as your account exists. When you delete your account we erase your personal data within 30 days, except where retention is required by law (e.g. invoices kept for 10 years under German tax law).
Under the GDPR you have the right to:
To exercise any of these rights, contact us at info@white-hammock.de.
We use TLS encryption, hashed passwords, row-level security on our database, and least-privilege access controls. Despite all efforts, no system is fully secure — please use a strong, unique password and keep your credentials private.
We may update this policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.