Privacy policy
What data miaforo handles on this website, why, and how to exercise your rights.
Last updated: 3 October 2026
If you belong to a gym
Your gym is the controller of your data. Its policy is at the same address where you book. miaforo only handles that data on the gym’s behalf. It does not sell it or use it for its own purposes.
Who answers for this website
- Contact email: chema@miaforo.com
What data we handle here
If you only browse, we do not ask for your name or email. No outside service measures your visit unless you accept the visit count below.
If a screen fails, we keep the type of error, without anything you typed. miaforo team accounts keep a name, an email, a hashed password and sign-in data. The legal bases are providing the service and our legitimate interest in keeping it secure.
If you accept the visit count
On miaforo’s own pages we ask whether Cronitor may count your visit. It never runs on a gym’s pages or inside the app. Only if you press Accept does your browser load Cronitor’s script and send Cronitor, for each page you open, your IP address, the page address, the site you came from and technical details of your browser and device. The cookie policy has the full list. Cronitor receives no name, email or account data. We use it to know how many people visit these pages and where they come from.
Cronitor is a company in the United States. It is not certified under the EU-US Data Privacy Framework, so no adequacy decision covers it, and it offers no other appropriate safeguard such as standard contractual clauses. US authorities could therefore access the data, and you may not have the same rights and remedies there as in the European Union. The legal basis is your explicit consent, given after being told these risks: Article 6(1)(a) GDPR for the count and Article 49(1)(a) GDPR for the transfer.
You can withdraw your consent at any time on the cookie policy page, as easily as you gave it. The count stops from that moment. Withdrawing does not affect what was sent before.
If you play the video
The front page has a video about miaforo. Nothing loads from YouTube until you press its play button. Then your browser loads the player from youtube-nocookie.com, and YouTube, which belongs to Google, receives your IP address, the page address and technical details of your browser, and may store data in your browser to play the video. Google is a company in the United States. It receives no name, email or account data. The legal basis is your consent, which you give by pressing play: Article 6(1)(a) GDPR. If you do not press it, YouTube handles nothing about you.
If you open your gym from here
The signup form asks for your gym’s name, the web address you want, your name and your email. Before we create anything, we send a six-digit code to that email. You type it back in the same tab, so only whoever reads that inbox can open the account.
While the code can be used, we keep the email and an irreversible fingerprint of the code, never the code itself. The code expires after ten minutes if you do not type it. What it proves lasts one more hour. After that, both are deleted with the next signup or by the nightly clean-up, so by the next day at the latest.
We count how many codes go out from one connection and to one email in an hour. That stops anyone opening gyms in bulk or filling somebody’s inbox with codes. For that count we store neither your IP nor your email. We store irreversible codes derived from them with a key that only exists on our server. They cannot be turned back into either, and cannot recognise you anywhere else. They are deleted once the hour they count has passed, and by the next day at the latest. The legal basis is our legitimate interest in keeping the service running, article 6(1)(f) GDPR.
A gym nobody ever opens closes itself after fourteen days, and its web address becomes free again.
If you ask us for a demo
The form on the front page asks for your gym’s name, your name, your email and how many people train with you. A phone number and a message are optional. We use them to write back and show you miaforo, and for nothing else. They are not used for advertising or passed on to anyone.
The request arrives as an email at chema@miaforo.com and is not stored in the app. The legal basis is taking the steps you asked for before a contract, Article 6.1.b of the GDPR. We keep the email while the conversation lasts, and for at most a year after the last message. Ask us to delete it sooner and we will.
If your gym pays miaforo
A gym can pay its miaforo subscription automatically. It gives a payment method once, and Stripe collects each period on its own page. miaforo is the seller and issues the invoices. To set up that collection, we send Stripe what your gym wrote on its billing form:
- the registered name;
- the contact email or, if there is none, the email of the person who pressed the button;
- the address, with its postcode, city and country;
- the language you read the app in;
- an internal reference for the gym;
- the intra-community VAT number, if your gym holds one.
Stripe checks that VAT number against VIES. The answer decides whether the invoice carries VAT, and we ask again before every renewal. The tax number does not go to Stripe. Stripe then opens the collection for the plan and period you chose, and emails you each invoice at that address.
You give your card or bank account to Stripe on its page, not to us. No card number and no IBAN ever reaches miaforo, at payment or afterwards. Changing the card, reading the invoices and cancelling also happen on a Stripe page. In return, we keep:
- the identifier Stripe knows your gym by;
- the subscription’s identifier and its status;
- for each payment, the invoice number, the amounts, the period it covers and whether it carried VAT, so we hold our own copy of what we charged you;
- for each notice Stripe sends us, its identifier, its type and its dates, never its content.
A refund, or a charge your bank takes back, is recorded as a negative amount beside the payment, with its own corrective invoice. The legal basis is the contract between your gym and miaforo, Article 6.1.b of the GDPR. It is also the invoicing and VAT obligations that contract places on us, Article 6.1.c. Nothing about a gym reaches Stripe until it starts subscribing to a paid plan.
Stripe handles this data partly on our behalf, to collect the payments, and partly as a controller of its own, for its own purposes such as preventing fraud and meeting its legal obligations. Its privacy policy says which. Stripe may transfer data outside the European Economic Area, including to the United States, relying on the EU-US Data Privacy Framework and standard contractual clauses.
If your gym closes, 30 days after the closure we delete what it wrote about itself: its name, web address, public page, address, phone, registered name, tax number, VAT number, contact emails and pictures. We keep the identifier Stripe knows it by, so money Stripe still reports reaches the right records. Each invoice keeps the name, tax number, address and email it was issued to for 8 years from the end of the year it was issued in, which is how long German tax law requires us to keep our invoices (§ 147 AO and § 14b UStG), or longer while a tax assessment they matter for is still open. The legal basis for that is Article 6.1.c of the GDPR. We also keep the PDF of each invoice exactly as Stripe issued it, encrypted in the Hetzner Storage Box named below, for the same years. After them, the nightly job deletes our copy and the monthly job deletes the PDF. The copy Stripe issued stays in our Stripe account, because Stripe does not let an issued invoice be deleted.
When your gym takes its free month, we also keep, so it is given once per gym: a one-way hash of the owner’s email, never the address, and the fingerprint Stripe computes for the card or bank account, which is not the number and cannot be turned back into it. We keep both for 3 years from that day, even if the gym closes, and then delete them. The legal basis is our legitimate interest in giving the offer once, Article 6.1.f of the GDPR.
Where it is hosted
- IONOS SE hosts the app, the database and the service email in Berlin, Germany.
- Every night an encrypted copy of the database and the photos goes to a Hetzner Storage Box in Falkenstein, also in Germany. The server encrypts it before sending, so Hetzner only ever holds bytes it cannot read. Once a month the invoices we issue to gyms go there too, encrypted the same way, for the years above.
Gym files, bookings and payments are handled in Germany and do not leave the European Union. What reaches Stripe is separate. It is what your gym gives us to pay miaforo, set out in the section above. It is also the little that leaves when a gym charges its members online, set out in that gym’s own policy. If you accept the visit count, what it sends goes to Cronitor in the United States, as set out above. If you play the video, what it sends goes to Google in the United States. Browser details are in the cookie policy.
Your rights
You can ask for access, rectification, erasure, restriction, portability and objection. Write to chema@miaforo.com. If your request is about your gym, we pass it on, because the gym is responsible for answering.
If you think your data has not been handled properly, you can complain to the Spanish Data Protection Agency, the AEPD, www.aepd.es. It is free and you do not need a lawyer.