Back

Privacy Policy

Last updated: June 2026

1. Controller

The controller responsible for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR) is:

White Hammock
Sherief Rageb
Eggers Hoff 10, 25436 Moorrege, Germany
Email: info@white-hammock.de
Phone: +49 (0)5161 9424184

2. Scope

This policy applies to the website sheriffprotocol.com and the connected Sheriff Protocol web/PWA application (the "Service"). It explains which personal data we collect, how we use it, on what legal basis, and which rights you have.

3. Data we process

Account data: email, password (hashed), nickname, country, optional profile photo, time zone, unit preference.

Training data: training sessions, 1RM entries, bodyweight, cardio sessions, progress photos you upload, weekly scores, ranking position.

Social data: friend connections, messages you send through the app, privacy settings.

Billing data: subscription plan, Stripe customer ID, payment status. Card data is processed by Stripe — we never see or store it.

Technical data: IP address, browser type, device type, timestamps, error logs.

4. Purposes & legal basis

Contract performance (Art. 6 (1)(b) GDPR): account creation, training tracking, social features, billing.
Legal obligations (Art. 6 (1)(c) GDPR): tax & accounting records.
Legitimate interests (Art. 6 (1)(f) GDPR): service security, abuse prevention, error logging, basic analytics.
Consent (Art. 6 (1)(a) GDPR): non-essential cookies, marketing emails, push notifications. You can withdraw consent at any time.

5. Cookies & local storage

We use only strictly necessary cookies and local storage to keep you signed in and to remember your preferences (theme, unit, time zone). These are essential for the Service to function and do not require consent. We do not use advertising cookies or third-party tracking pixels.

6. Processors & third parties

We work with carefully selected processors under data processing agreements (Art. 28 GDPR):

  • Supabase / Lovable Cloud — database, authentication, file storage (EU region).
  • Cloudflare — hosting, CDN, DDoS protection.
  • Stripe Payments Europe, Ltd. — payment processing.
  • Resend — transactional email delivery.

Where data is transferred outside the EU/EEA we rely on EU Standard Contractual Clauses and equivalent safeguards.

7. Retention

We keep your data for as long as your account exists. When you delete your account we erase your personal data within 30 days, except where retention is required by law (e.g. invoices kept for 10 years under German tax law).

8. Your rights

Under the GDPR you have the right to:

  • access your personal data (Art. 15);
  • rectification (Art. 16) and erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time without affecting prior lawful processing;
  • lodge a complaint with a supervisory authority (in Germany: the data protection authority of your federal state).

To exercise any of these rights, contact us at info@white-hammock.de.

9. Security

We use TLS encryption, hashed passwords, row-level security on our database, and least-privilege access controls. Despite all efforts, no system is fully secure — please use a strong, unique password and keep your credentials private.

10. Changes

We may update this policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.