WOD Manager

Privacy Policy

Last updated: June 5, 2026

At WOD Manager we take personal data protection seriously. This Privacy Policy describes what data we collect, why, for how long, who we share it with, and how you can exercise your rights. If anything is still unclear after reading it, write to us at hello@wod-manager.com.

1. Data controller

The controller of the data collected through this website (wod-manager.com), the admin dashboard (app.wod-manager.com) and the WOD Manager Android and iOS mobile apps is:

Legal name: Carles Corcoy Baleri

Tax ID (NIF): 40374276F

Address: Calle Provençal 34, A — 17130 L'Escala (Girona), Spain

Data protection contact email: hello@wod-manager.com

We are not required to appoint a Data Protection Officer (DPO) given our current volume, but the email above is the single point of contact for any data-related matter.

2. Dual role: controller and processor

WOD Manager acts in two distinct roles depending on the data:

  • Data controller with respect to the data of those who hire our service (the owners or managers of a CrossFit box), the navigation data of this public website and the data of those who contact us through our channels.
  • Data processor with respect to the personal data of the members of each box uploaded to the platform. In this case, the box itself is the controller, and our processing is limited to what is set out in the Data Processing Agreement (DPA) you accept when you sign up. You can read it at /legal/dpa.

3. Personal data we process

The categories of data we process vary depending on your relationship with us:

3.1 If you are a box owner or manager (customer)

  • Identification data: full name, tax ID (NIF/CIF/EIN depending on country).
  • Contact data: email, phone number.
  • Box tax data: legal name, fiscal address, tax regime, IBAN, invoice numbering prefix.
  • Billing data for your WOD Manager subscription (handled by Stripe; we only keep metadata: amount, date, status, transaction ID).
  • Platform usage data: access logs, IP address, browser, language, country inferred from IP geolocation.
  • Communications you send us (emails, contact forms, support).

3.2 If you are a member of a box using WOD Manager

  • Identification data: name, profile photo (optional), username (optional).
  • Contact data: email, phone number (optional).
  • Tax data for invoices: tax ID, address, where the box issues an invoice to you.
  • Athletic activity data: bookings, class attendance, completed WODs, personal records (PRs), saved payment methods (handled by Stripe), payment history.
  • Communications with your box staff inside the app.
  • Push notification token (with your consent).

Your box is the controller of these data. WOD Manager only processes them on the box's behalf to provide the contracted service, under the Data Processing Agreement.

3.3 If you visit this website (without being a customer)

  • Technical data: IP address, browser type, operating system, language, country.
  • Navigation data: pages visited, date and time.
  • Data you give us when filling forms (name, email, message).

We do not use advertising tracking cookies. If we activate analytics cookies, we will do so through a consent banner and you can reject them. Check our Cookies Policy for more information.

3.4 Sensitive data

Class attendance and sport result data are not formally considered "health data" (Art. 9 GDPR), but their processing could reveal information about your physical condition. As a precaution, we treat them with the same level of care as special categories and share them exclusively with you, your box and the processors strictly necessary. We do not transfer them to third parties for commercial purposes.

4. Purposes and legal bases

Each purpose relies on a different legal basis under Art. 6 GDPR. These are the main ones:

  • Providing the contracted Service (account signup, box management, mobile app, admin panel): performance of a contract (Art. 6.1.b).
  • Billing and tax obligations (issuing invoices, submission to AEAT/DIAN, bookkeeping): legal obligation (Art. 6.1.c).
  • Customer service and support: performance of a contract (Art. 6.1.b) and legitimate interest (Art. 6.1.f).
  • Sending service communications (failed payment notices, booking reminders, service changes): performance of a contract.
  • Sending commercial communications (newsletter, offers): consent (Art. 6.1.a), revocable at any time by clicking "unsubscribe" or writing to hello@wod-manager.com.
  • Product improvement and aggregated metrics: legitimate interest (Art. 6.1.f). Data is aggregated so that no specific individual is identifiable.
  • Compliance with legal obligations on anti-money laundering, tax and similar: legal obligation.
  • Defense against potential legal claims: legitimate interest during applicable prescription periods.

5. Retention period

We keep personal data only for as long as strictly necessary for each purpose, with the following indicative periods:

  • Account data: for as long as the contractual relationship lasts. After cancellation, for 30 days (grace period to reactivate). Then they are anonymized or deleted, unless retention is legally required.
  • Tax and billing data: 6 years (Art. 30 Spanish Commercial Code) or the equivalent legal period in your country. Spain's tax authority (AEAT) specifically requires retention of VERI*FACTU invoices for this period.
  • Contract data: 5 years after termination (Art. 1964 Spanish Civil Code).
  • Technical and security logs: 12 months max.
  • Marketing data (if you gave consent): until you revoke consent.
  • Cookies: as detailed in the Cookies Policy.

When data is no longer needed, it is deleted or anonymized. Effective deletion takes into account the technical timeframe for backups (up to 35 additional days).

6. Recipients and processors

To deliver the service we rely on technology providers acting as processors. With all of them we have an Art. 28 GDPR contract and, where applicable, Standard Contractual Clauses approved by the European Commission (Decision 2021/914).

ProcessorPurposeLocation
Google Ireland Ltd. (Firebase)Database hosting, authentication, file storage, Cloud Functions, push notificationsEU (europe-west1) with backups in the US
Stripe Payments Europe Ltd.Payment processing (Connect)Ireland + US
Resend, Inc.Transactional email deliveryUS (servers in Ireland)
Vercel Inc.Public website and admin panel hostingUS with global CDN
Cloudflare, Inc.DNS, DDoS protectionUS with global network
Anthropic PBCLanguage model for the AI Assistant (only when the optional feature is used)US

Additionally, pursuant to legal obligation, we may share data with:

  • Spanish Tax Agency (AEAT) for VERI*FACTU compliance.
  • Colombian Tax and Customs Office (DIAN) for electronic invoicing.
  • Courts, tribunals and law enforcement when legally required.

We do not transfer personal data to third parties for commercial purposes. We do not sell your data.

7. International transfers

Some of our processors are headquartered or have servers outside the European Economic Area (EEA), mainly in the United States. These transfers are made with the following safeguards:

  • Standard Contractual Clauses approved by the European Commission (Decision 2021/914) signed with each processor.
  • EU-US Data Privacy Framework: the main providers (Google, Stripe, Vercel) are certified, under the Adequacy Decision of July 10, 2023.
  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or higher).
  • Role-based access control with auditing and access logging at the infrastructure providers.

You can obtain a copy of the specific safeguards by writing to hello@wod-manager.com.

8. Your rights

Under Arts. 15 to 22 GDPR, you may exercise the following rights at any time:

  • Access: know what data we hold about you and obtain a copy.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): request deletion of your data when no longer necessary.
  • Restriction of processing: have us stop processing your data while a controversy about accuracy or lawfulness is resolved.
  • Objection: object to processing based on legitimate interest or to commercial communications.
  • Portability: receive your data in a structured, commonly used format (JSON) for transmission to another controller.
  • Automated decisions: not be subject to individual decisions based solely on automated processing. WOD Manager does not make such decisions about data subjects.
  • Withdraw consent at any time where consent is the basis for processing.

How to exercise them:

  • Directly from the app: Profile → Privacy has a button to download all your data and another to request account deletion.
  • Or by writing to hello@wod-manager.com from the email address associated with your account, indicating the right you wish to exercise. We will respond within one month, extendable to two months for complexity or volume, notifying you in advance.

If you believe your right has not been properly handled, you may file a complaint with the Spanish Data Protection Agency (AEPD), headquartered at C/ Jorge Juan 6, 28001 Madrid, or through their electronic office: sedeagpd.gob.es.

9. Data security

We apply appropriate technical and organizational measures to ensure the security of your data:

  • Encryption in transit (HTTPS / TLS) and at rest (AES-256).
  • Strong authentication via Firebase Authentication, role-based access control and Firestore security rules.
  • Automatic daily encrypted backups retained for 30 days.
  • Access logging and security event monitoring.
  • Servers in data centers certified ISO 27001 and SOC 2 Type II (Google Cloud Platform).
  • Documented procedure for security breach notification to the AEPD within 72 hours under Art. 33 GDPR, and to affected data subjects where the risk is high (Art. 34 GDPR).

No system is absolutely secure. If you spot a potential vulnerability, please disclose it responsibly to hello@wod-manager.com.

10. Minors

The Service is not directed at children under 14. If you are under that age, do not provide us your data. Where a box signs up a minor (for example, for kids' classes), it must do so with the express consent of the holder of parental authority or guardianship, under Art. 7 LOPDGDD. The box is responsible for collecting and retaining such consent.

11. Changes to this policy

We may update this Privacy Policy to reflect legal or service changes. Any significant change will be notified at least 30 days in advance via the email associated with your account and with a prominent in-app notice. The current version and its update date will always appear at the top of this document.

12. How to contact us

For any inquiry about this policy or the processing of your data:

Email: hello@wod-manager.com

General email: hello@wod-manager.com

Postal address: Calle Provençal 34, A — 17130 L'Escala (Girona), Spain