April 2026 edition
1. General Provisions
This Privacy Policy sets out how Sportstep collects, uses, stores, and otherwise processes personal data when individuals use the Sportstep website, mobile application, and other related services. The purpose of this Policy is to clearly, transparently, and understandably inform you about what personal data is processed, for what purposes, on what legal basis, to whom the data may be disclosed, how long it is retained, and what rights data subjects have.
This Policy applies to all persons who use the website www.sportstep.lt, the Sportstep mobile application, bookings, orders, community, communication, subscriptions, and other related Platform features. Hereinafter, the website, mobile application, and all related services are collectively referred to as the Platform.
2. Data Controller
Your personal data controller is Sportstep, MB, legal entity code 307605923, registered address Rimvydo g. 15-16, LT-50233 Kaunas, Lithuania.
You can contact Sportstep by email at [email protected]. For questions related to privacy, personal data processing, requests to exercise your rights, or complaints, you may also contact us at the same email address: [email protected].
3. Sportstep’s Role in Data Processing
Sportstep acts as a data controller in cases where it processes personal data for the purposes of its business operations, Platform administration, and service provision. This includes account creation and administration, login and security assurance, administration of bookings, orders, subscriptions, and payments, customer support, sending notifications, managing content and community features, improving the Platform, preventing security incidents and abuse, handling complaints, and complying with legal obligations.
In certain cases, coaches using the Platform may act as separate data controllers with respect to their clients’ data when they process such data for the purposes of their professional activities, for example, when providing individual consultations, creating training or nutrition plans, evaluating progress, or otherwise organizing their services. In such cases, Sportstep may act as a provider of the technical environment and infrastructure or process data only to the extent necessary to ensure the operation, security, and provision of the Platform’s services.
Where data related to physical condition, wellness, nutrition, sports goals, or progress is submitted or used on the Platform, such data is processed only to the extent necessary for providing the relevant feature or service and for complying with applicable laws.
4. What Personal Data We Process
Depending on how you use the Platform, Sportstep may process various categories of personal data. This may include your identity and contact data, such as your first name, last name, username, email address, phone number, date of birth, or other contact information you provide.
We may also process account and profile data, including login information and account settings, account statuses, selected language, time zone, profile picture, coach profile description, specializations, service descriptions, social media links, publicly displayed information, and other data related to your profile or account.
When using the Platform’s features, we may also process booking, order, subscription, payment, invoice, refund, and other data related to ordering and administering services. Sportstep does not store full payment card details. Payment information is processed via third-party payment service providers, and Sportstep may receive only limited information necessary to administer payments, subscriptions, and related processes.
Depending on the services used, the Platform may also process data related to wellness, physical condition, nutrition, and goals that you provide yourself or that is used in providing individualized services to you through the Platform.
We may also process communication and content data when you use community, messaging, comment, customer support, or other communication features, including content you create or upload and other information related to communication or content administration.
If you upload photos, videos, documents, certificates, or other files, data related to such files may also be processed, including their technical data, metadata, and information necessary for their storage, display, verification, or protection.
In addition, Sportstep may process technical, security, and Platform usage data, such as your IP address, device type, operating system, browser type, device or app identifiers, session information, login history, notification settings, and other information necessary for the operation, security, and improvement of the Platform.
Sportstep does not use precise device location tracking and does not request GPS permission. If addresses or location data are displayed on the Platform, they are provided based on information entered by users or coaches, rather than from the device’s precise location.
5. Where We Obtain Your Data
Sportstep receives most personal data directly from you when you register, complete your account, use the Platform, book services, make payments, purchase a subscription, publish content, upload files, or contact us.
Certain data may also be obtained from your actions on the Platform, from coaches where this is related to the provision of a service, and from payment service providers when administering payments or subscriptions.
If you provide another person’s data, for example when ordering a service on their behalf, you must have the right to do so and, where required by law, properly inform that person about the disclosure of their data.
6. Purposes and Legal Bases for Data Processing
Sportstep processes personal data only where it has a lawful basis to do so.
Personal data is primarily processed in order to enter into and perform a contract with the user and to provide the Platform’s services. On this basis, an account is created and administered, access to the Platform is provided, bookings and orders are organized, subscriptions and payments are administered, community, communication, and other Platform features are provided, and the core operation of the Platform is ensured.
Certain data is processed in order to comply with legal obligations, for example for accounting, tax, consumer protection, data protection, security, and other requirements under applicable law.
In some cases, data is processed on the basis of Sportstep’s legitimate interest. This includes ensuring the security of the Platform and accounts, preventing abuse and fraud, detecting and resolving technical incidents, administering content and community features, handling disputes and complaints, assessing service quality, improving the Platform’s functionality, and protecting Sportstep’s rights and interests.
Where you give your consent, your data may be processed for marketing purposes, for example for sending newsletters, offers, or other informational messages by email, within the app, or through other channels you choose.
Where more sensitive data related to wellness, physical condition, nutrition, or similar matters is processed on the Platform, such data is processed only to the extent permitted by applicable law and only as necessary to provide the relevant service or feature. Where required by law, such data is processed only upon obtaining the relevant consent or on another lawful basis provided for by law.
7. Whether You Must Provide Data
Certain data is necessary in order for Sportstep to provide services. If you do not provide such data, you will not be able to create an account and use the Platform.
If specific data is not necessary, providing it is considered voluntary. In such a case, failure to provide it will generally not prevent you from using Sportstep’s core services, but it may limit certain additional features or personalization options.
8. Publicly Shared Content
Certain parts of the Platform may be visible to other users, such as coach profiles, community posts, comments, reactions, success stories, publicly shared materials, or other information published by users.
If you publicly post information about yourself or another person, whether publicly or within the community, such information may become visible to other Platform users depending on the nature and settings of the specific feature. For this reason, it is recommended that you publicly share only as much information as is actually necessary.
Sportstep may also process information related to the administration and security of community content, such as reports of potential violations, moderation actions, or other information necessary to ensure a safe and orderly community environment.
9. To Whom We May Disclose Your Data
Your personal data is not sold.
Where necessary for the provision of services, data may be disclosed to coaches. If you order a coach’s service or use features offered by a coach, the coach receives the contact and service-related data that is necessary for them to properly provide the service. The coach may see the contact details that you have provided in your account.
For the administration of payments and subscriptions, Sportstep uses the third-party payment service provider Stripe. Where required by law or where necessary to protect Sportstep’s rights and interests, data may be disclosed to lawyers, auditors, accounting service providers, supervisory authorities, law enforcement authorities, courts, or other authorized entities.
If Sportstep’s business is reorganized, transferred, or sold in the future, personal data may be transferred to the entity taking over the business to the extent permitted by law.
10. Data Transfers Outside the European Economic Area
In some cases, personal data may be transferred outside the European Economic Area, for example where this relates to international technology or payment service providers.
In such cases, Sportstep seeks to ensure that appropriate safeguards are applied, such as data transfer mechanisms approved by the European Commission, standard contractual clauses, or other safeguards provided for under applicable law.
11. How Long We Retain Your Data
Personal data is not retained longer than necessary for the purposes for which it was collected, except where a longer retention period is required by law or necessary for the establishment, exercise, or defense of legal claims.
Account data is generally retained for the duration of the account and for a reasonable period after its closure. Order, subscription, and payment data may be retained for longer where necessary to comply with accounting, tax, or other statutory obligations. Customer support, complaint, and dispute data is retained for as long as necessary to resolve the relevant matter and, where necessary, for potential legal actions.
When data is no longer needed, it is deleted or anonymized.
12. Cookies and Similar Technologies
The Sportstep website currently uses only essential cookies and technical measures that are necessary for the operation of the website, session maintenance, login functionality, and security.
At present, no analytics or marketing cookies requiring separate user consent are used. If such technologies are introduced in the future, this Privacy Policy will be updated accordingly.
| Name | Provider | Purpose | Category | Duration | Essential |
|---|---|---|---|---|---|
| sportstep_locale | Sportstep | Stores the selected website language | Functional | Session | Yes |
13. Marketing Communications and Opt-Out
If you have given your consent, Sportstep may send you marketing communications by email or push notifications. Such communications may include news about the Platform, offers, new features, or other information related to Sportstep’s activities.
You may opt out of marketing emails at any time by clicking the unsubscribe link in the email you receive. You may opt out of push notifications in your device or app settings. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
14. Automated Decision-Making
Sportstep does not currently carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
15. Your Rights
Under the General Data Protection Regulation (GDPR), you have the right to receive information about the processing of your data, access your data, request the rectification of inaccurate data, request the deletion of data where applicable, request the restriction of data processing, object to processing where it is based on legitimate interest, request data portability where this right applies, and withdraw consent where data is processed on the basis of consent. These rights are an essential part of the GDPR information framework.
If you wish to exercise your rights, you may contact us by email at [email protected]. In certain cases, Sportstep may request additional information in order to verify your identity.
16. Data Security
Sportstep implements technical and organizational security measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Such measures include access control, system protection, secure data storage, backups, security monitoring, and incident management processes.
17. Complaints and Questions
If you have questions about this Privacy Policy, the processing of your personal data, submitting a complaint, or would like your data to be removed, please first contact Sportstep administration by email at [email protected]. Sportstep aims to review all requests and complaints as promptly and efficiently as possible.
18. Changes to the Privacy Policy
Sportstep may periodically update this Privacy Policy to reflect changes in law, services, or data processing practices. The most recent version of this Policy will always be published on the Platform. If the changes are significant, Platform users may also be informed through the Platform or by another appropriate means.