Trust & Privacy
This page is maintained by ZoneFitly to answer common security and privacy questions about the app. It describes current practices and is not an independent certification or audit.
Accounts & authentication
Sign-in uses Google OAuth. We do not store your Google password. Sessions are managed by our auth provider and you can sign out at any time from Settings.
Admin actions are gated server-side by role checks; client-side role flags alone never grant access.
What we store
Profile (display name, optional bio, optional avatar), the matches you host or join, optional availability windows, and any cosmetics or subscriptions you purchase.
Payment processing is handled by Stripe. We never receive or store your card details โ only a reference to the subscription/checkout.
Access controls
Database access is restricted by row-level security. You can read and modify your own data; other users see only public profile fields and public match listings.
Sensitive fields (moderation status, payment session IDs) are hidden from regular clients and accessible only to administrators through audited server functions.
Hosting & infrastructure
The app runs on Lovable Cloud with Supabase as the managed backend. Data is encrypted in transit (HTTPS/TLS) and at rest by the underlying provider.
This is shared responsibility: platform-level controls are provided by Lovable Cloud and Supabase; app-level controls (RLS, input validation, role checks) are maintained by ZoneFitly.
Email & communications
We send transactional emails (e.g., match updates, account notices). You can unsubscribe from non-essential mail via the link in any message. Suppression is honored across the app.
Data requests & deletion
You may request export or deletion of your account data by contacting us. Account deletion removes your profile, hosted matches, availability, and personal records; aggregate analytics may remain in anonymized form.
Contact: support@zonefitly.com