Skip to content

Account and more

Follow

FitFrek trust center

Privacy Policy

Last updated September 14, 2026

What we collect

FitFrek collects the account details you provide, including username, email, password handled by WordPress, age confirmation, and required policy acceptance. Registration does not enroll you in marketing. Your public username, profile details you choose to publish, approved review text, ratings, public product photos, and disclosed connections are public. Drafts, moderation records, reward status, payout details, contact messages, and private evidence are restricted.

Reviews, evidence, and rewards

Public product photos are intentionally public. Optional receipts or other purchase evidence are stored under randomized names outside the public web root and are available only to the submitting member and authorized moderators. Files may be JPEG, PNG, WebP, or PDF; metadata such as EXIF is not automatically removed. Payout destinations are encrypted at rest and a one-way risk fingerprint is retained to detect duplicates.

Health-related information

Free-text reviews can reveal identifiable information about side effects, conditions, medicines, sleep, mental health, bloodwork, or other health matters. Do not include medical records or unnecessary sensitive details. Anything placed in a published review or public photo becomes public; private evidence remains restricted as described above.

Analytics, journeys, and logs

Necessary cookies support sign-in, security, preferences, and form protection. Optional analytics remain off until you choose “Accept analytics,” and browser Global Privacy Control or Do Not Track signals keep them off. With consent, FitFrek may measure page and product views, product selections, Watch actions, retailer clicks, alert or newsletter links, return visits, and later on-site actions to understand journeys, funnels, retention, and data quality. Hosting, security, and mail systems may retain technical and delivery logs needed to operate and protect the service.

Identifiers and first-party event history

FitFrek may keep a first-party history of Watch, email, account, product, retailer-click, consent, and operational events. When signed-in analytics is enabled, a pseudonymous internal member identifier may connect authenticated activity across sessions. FitFrek does not use an email address, name, payout destination, review text, private proof, or another directly identifying value as the Google Analytics User-ID or as a custom analytics dimension. Email and alert links may contain a limited attribution token used to connect the message, landing page, and later action without placing the recipient’s email address in an analytics event.

Google Analytics and BigQuery

After opt-in, Google Analytics may process event-level page, product, Watch, email-attribution, member, and retailer journey data. FitFrek may export raw event and pseudonymous user-level Analytics data to a FitFrek-controlled Google BigQuery dataset for journey, funnel, retention, reconciliation, data-quality, and reporting analysis. BigQuery is a backend copy of consented Analytics data rather than a separate browser tracker. Access is limited through account and project permissions to authorized people and service providers with a business need.

Microsoft Clarity

FitFrek may enable Microsoft Clarity as optional analytics on designated public pages only. Clarity can reconstruct page sessions from page or DOM information and interactions such as clicks, scrolling, and mouse or touch activity, and can create recordings and heatmaps. It must remain behind the analytics-consent control, use strict masking so masked content is not uploaded, and be excluded from login, registration, account, private Watch, payout, private-proof, moderation, and administration pages. FitFrek does not intentionally send form entries, review drafts, email addresses, payout information, private evidence, or other sensitive account content to Clarity. Microsoft acts as an analytics service provider or processor for this use.

Who processes data

FitFrek uses WordPress and its installed account, review, anti-spam, security, hosting, email, analytics, cloud-data, and content-delivery services. Cloudflare may process network and security data. Akismet may process form or review data for spam screening. Google processes consented Analytics and BigQuery data; Microsoft processes Clarity data only when that optional service is enabled under the controls described above. Retailers receive data under their own policies after you follow an external link.

Sale, sharing, and advertising

FitFrek does not exchange account, review, private-proof, payout, or contact data for money and does not use the systems described here to sell advertising. Whether optional analytics or an affiliate interaction is legally classified as a “sale,” “sharing,” or targeted advertising depends on the applicable law. Choosing necessary-only analytics, withdrawing consent, or sending a supported browser privacy signal keeps Google Analytics and any optional Clarity collection off; leaving FitFrek for a retailer is governed by that retailer’s policy.

Retention, access, and choices

Raw Google Analytics and BigQuery journey data is retained for up to 14 months unless it is aggregated or de-identified sooner. First-party journey and operational-event records are retained for up to 24 months unless a shorter period meets the purpose or a longer period is required for security, fraud prevention, accounting, disputes, or legal obligations. If Clarity is enabled, Microsoft currently retains playback data for 30 days and click, heatmap, labeled, or favorited-session data for up to 9 months under its vendor terms. Access is limited to authorized FitFrek personnel and service providers who need it for the purposes described here.

Account and review records are kept while the account or content is needed to provide the service, meet security and accounting duties, resolve disputes, or preserve an accurate reward ledger. On native account deletion, unpaid payout requests are held for reconciliation, paid delivery secrets are erased, activity and revision payloads are minimized, and the private-proof cleanup is recorded as completed or pending administrator retry. Reward allocations, one-way risk fingerprints, and necessary financial audit records can remain. Infrastructure backups can persist for their normal recovery cycle. You may update profile data, change or withdraw analytics consent at any time on the Cookie Policy, or ask to access, correct, or delete applicable personal data through Contact. Withdrawal stops future optional collection but does not automatically erase lawfully collected records; deletion may be requested separately. Some public or financial records may need to be retained or de-identified.

International and sensitive information

FitFrek is available on the public internet and service providers may process data in other countries. Do not include health records, payment-card details, government identifiers, or another person’s information in a public review or evidence file. FitFrek accounts are for adults age 18 and older.