Privacy • Security • Readiness

Trust Center

Fitpocket is built with privacy-first controls to help protect sensitive wellness information.

Fitpocket is a consumer wellness platform that helps users manage wellness-related information. We take a security- and privacy-conscious approach to how data is collected, stored, accessed, and governed.

Compliance posture

Fitpocket uses cautious, transparent language about readiness, privacy principles, and current product boundaries.

SOC 2

Readiness in progress

We are implementing security controls aligned with SOC 2 principles, including access control, change management, incident response, vendor governance, and monitoring. We do not currently claim SOC 2 certification unless and until an independent audit has been completed.

GDPR

Privacy principles supported

Fitpocket is designed to support GDPR and POPIA privacy principles, including privacy rights such as access, correction, deletion, and data portability where applicable. We aim to collect only the data needed to provide and improve the product.

POPIA

South Africa privacy safeguards

Fitpocket is designed to support GDPR and POPIA privacy principles with safeguards for personal information, including reasonable technical and organisational controls, data subject request handling, and vendor governance.

HIPAA

Consumer wellness boundary

Fitpocket is a consumer wellness platform. HIPAA-regulated workflows require a separate Business Associate Agreement. Fitpocket is not intended to be used by covered entities or business associates to create, receive, maintain, or transmit HIPAA-regulated protected health information unless a separate Business Associate Agreement has been executed by Fitpocket.

Security controls

We use layered technical and organisational safeguards to reduce risk and protect user information.

Encryption in transit

Network connections are protected with transport-layer encryption where supported.

Encryption at rest where supported by infrastructure

Stored data uses infrastructure-supported encryption controls where available.

Role-based access control

Administrative capabilities are limited according to role and responsibility.

Least-privilege permissions

Access is scoped to the minimum level needed for operational work.

Multi-factor authentication for administrative access

Administrative accounts use stronger authentication controls where supported.

Environment separation for production, staging, and development

Separate environments help reduce accidental production impact.

Audit logging for sensitive administrative activity

Sensitive administrative actions are logged where the platform supports it.

Secure secrets management

Secrets are managed outside source code and scoped to operational need.

Dependency and vulnerability monitoring

Dependencies are reviewed and monitored to reduce known vulnerability exposure.

Code review and controlled release processes

Changes are reviewed and released through controlled development workflows.

Backup and recovery processes

Backup and recovery practices are maintained to support continuity.

Incident response procedures

Response procedures guide investigation, containment, communication, and follow-up.

Privacy controls

Privacy is handled as a product and operational responsibility, not just a legal document.

Data minimisation

We aim to collect the information needed to provide, secure, and improve Fitpocket.

User rights

Where applicable, users can request access, correction, export, or deletion of their personal information.

Retention

We aim to retain personal information only for as long as needed for legitimate product, legal, security, and operational purposes.

Vendor governance

We review vendors and subprocessors that may process personal information on Fitpocket’s behalf.

Sensitive wellness data

Wellness-related information is treated as sensitive and is protected with additional care in product and operational workflows.

How we handle data

Data use is tied to product delivery, account security, support, and operational improvement.

Account data

Used to create, secure, and manage user accounts.

Wellness inputs

Used to provide the Fitpocket product experience.

Usage and device data

Used to maintain security, debug issues, and improve product performance.

Support communications

Used to respond to user questions and resolve issues.

Payment data

Payments may be processed through Apple App Store or Google Play depending on the platform used. Fitpocket may receive limited payment or subscription status information needed to manage paid access and does not intentionally collect or store raw card details for mobile app-store purchases.

Responsible disclosure

If you believe you have found a security issue, contact us through the security contact below or email our support inbox with the subject ‘Security issue’ so we can investigate.

Security issues can be sent to our support inbox with the subject ‘Security issue’.

Report a security issue

This page is provided for transparency and general informational purposes. It does not create contractual commitments, legal representations, or compliance certifications. Specific obligations may be governed by written agreements between Fitpocket and its customers or partners.

Subscription required

Subscribe in the FitPocket mobile app to unlock this feature on both mobile and web.

Sign in required

You need to be signed in to use this feature.