Guavi Privacy Policy

Effective date: 14. 08. 2026
Last updated: 14. 08. 2026
Version: 1.0


1. Who we are

Guavi is operated by Sans Decorum d.o.o., a company registered in the Republic of Slovenia under registration number 8607222000, with its registered office at Topniška ulica 70, Suite 76, 1000 Ljubljana, Slovenia ("Guavi", "we", "us", "our").

We are the controller of the personal data described in this policy within the meaning of Article 4(7) of Regulation (EU) 2016/679 ("GDPR").

Guavi is available as a mobile application for iOS and Android and as a web application (together, the "App").

Contact for privacy matters: [email protected]
General contact: [email protected]

2. Summary

We collect the minimum data needed to verify that you visited a partner gym, award you points for that visit, and deliver the reward you redeem those points for.

The most important things to know:

  • We do not track your continuous location or build a route history. We detect only when your device enters and leaves the immediate area of a partner gym.
  • Background location is optional. You can use Guavi and earn points without it by checking in manually while the App is open.
  • We do not share your identity with partner brands. When you redeem points, the brand receives a code, not your name.
  • You can withdraw consent, export your data, or delete your account at any time from within the App.

This summary is for orientation only. The sections below govern.

3. What personal data we collect

3.1 Account data

Email address, password (stored only as a salted hash and never accessible to us in readable form), chosen username, and profile picture if you upload one.

Your username and profile picture are the only elements visible to other users. You can change both at any time in your profile settings.

3.2 Location data

We process location data in two distinct ways, on two distinct legal bases. See section 4.

Foreground check-in. When you open the App and start a check-in at a partner gym, we compare your device's position with the coordinates of that gym to confirm you are present.

Background arrival detection (optional). If you enable it, your device monitors a small number of circular geographic zones around partner gym locations. When your device crosses into or out of one of those zones, the operating system notifies the App. We record the entry timestamp and the exit timestamp and calculate the elapsed time to determine whether the minimum dwell requirement for a point award has been met.

What this means in practice:

  • The zones have a radius of approximately 120–150 metres and are centred only on partner gym locations.
  • We do not receive or store a continuous stream of your position.
  • We do not receive or store your location when you are not at or near a partner gym.
  • We do not build a movement history, route, or profile of the places you visit outside partner locations.
  • What is stored is a list of visit records: gym identifier, arrival time, departure time, points awarded.

3.3 Reward and redemption data

The rewards you redeem, the points balance and transaction history associated with your account, the discount or product codes issued to you, and the date they were issued.

Where a reward is a physical item requiring shipment, we collect your delivery name, address, and phone number solely to fulfil that shipment.

3.4 Device and technical data

Device model, operating system and version, App version, language and region settings, IP address, a device identifier, push notification token, and crash and diagnostic logs.

3.5 Usage data

Which screens you open, which features you use, session length and frequency, and how you arrived at the App.

3.6 Demographic data (optional)

Year of birth and gender, if you choose to provide them. This is optional and the App is fully functional without it.

3.7 Communications

Messages you send to our support, brand partnership, or privacy contacts, and our replies.

3.8 Data we do not collect

We do not collect payment card details. We do not collect health, medical, biometric, or body composition data. We do not ask for and do not want information about your medical conditions, and you should not send it to us.

4. Legal basis for each purpose

PurposeData usedLegal basis (GDPR Art. 6)
Creating and operating your accountAccount data6(1)(b) performance of a contract
Verifying a check-in you actively start in the AppForeground location6(1)(b) performance of a contract
Detecting arrival at a partner gym while the App is closedBackground location6(1)(a) consent — and Art. 9(2)(a) explicit consent, see 4.1
Awarding, calculating, and displaying pointsVisit records, reward data6(1)(b) performance of a contract
Issuing reward codes and shipping physical rewardsReward data, delivery address6(1)(b) performance of a contract
Security, fraud prevention, and detecting fraudulent check-insDevice data, visit records6(1)(f) legitimate interests
Diagnosing crashes and keeping the App stableDevice data, crash logs6(1)(f) legitimate interests
Understanding aggregate usage to improve the AppUsage data, demographic data6(1)(f) legitimate interests
Analytics and advertising cookies, pixels, and SDKsUsage data, device identifiers6(1)(a) consent
Marketing emails and push notificationsAccount data6(1)(a) consent
Responding to your support messagesCommunications6(1)(f) legitimate interests
Complying with accounting, tax, and consumer law obligationsReward and transaction data6(1)(c) legal obligation
Establishing, exercising, or defending legal claimsAs relevant6(1)(f) legitimate interests
Corporate transactionsAs set out in section 96(1)(f) legitimate interests

Where we rely on legitimate interests, we have carried out and documented a balancing assessment. You may request a summary of it at [email protected], and you may object at any time under Article 21 (see section 10).

4.1 Location data and special categories

A record of your attendance at a gym may, over time, allow inferences about your physical activity. We do not treat this as health data and we do not use it to infer anything about your health, but because Article 9(1) GDPR and Recital 35 are drawn broadly, we take the cautious position and rely on your explicit consent under Article 9(2)(a) for background location monitoring.

We will ask for that consent separately and in clear terms. We will not bundle it with anything else.

4.2 Consent is genuinely optional

You can use Guavi, check in at partner gyms, earn points, and redeem rewards without granting background location access, by opening the App at the gym and checking in manually. Declining background location does not reduce the points you can earn, restrict which rewards you can claim, or otherwise degrade the service. It only means you have to open the App yourself.

We record, for each consent you give: what you consented to, the version of the notice shown to you, and the date and time.

4.3 Withdrawing consent

You can withdraw any consent at any time, and it is as easy to withdraw as it was to give:

  • Background location: turn it off in the App under Settings → Location, or in your device's operating system settings.
  • Analytics and advertising: Settings → Privacy → Tracking preferences.
  • Marketing communications: Settings → Notifications, or the unsubscribe link in any email.

Withdrawal takes effect immediately and stops future processing. It does not affect the lawfulness of processing carried out before withdrawal. Points you have already earned remain in your account. Visit records already created are retained under the schedule in section 8 unless you also ask us to delete them.

5. Automated decision-making

Points are awarded automatically when a verified visit meets the minimum dwell requirement. This is a simple rule applied consistently to everyone and is not a decision producing legal effects or similarly significant effects on you within the meaning of Article 22(1) GDPR.

We do not profile you to set different prices, different reward eligibility, or different terms from other users.

6. Who receives your data

We do not sell personal data. We share it only in the following categories:

Cloud infrastructure and database providers. Google LLC / Google Cloud EMEA Limited (Firebase, Cloud Firestore, Firebase Authentication, Cloud Functions) and Vercel Inc. These host the App and its database and act as our processors under Article 28 GDPR.

App distribution platforms. Apple Inc. and Google LLC, in connection with distribution, crash reporting, and push notification delivery.

Analytics and advertising providers. [LIST — e.g. Google Analytics, Meta Pixel], where you have consented. These providers receive online identifiers and usage events. Contrary to what is sometimes claimed, such identifiers are personal data under Article 4(1) GDPR, and we do not describe this data as anonymous.

Partner gyms. Partner gyms receive aggregate, non-identifying statistics about visit volumes. They do not receive your name, email, username, or individual visit history from us, and we do not cross-reference your Guavi account with their membership records.

Partner brands. When you redeem points for a reward, the brand receives an anonymous code and the fact that a code was issued. The brand does not receive your name, email, username, or gym attendance data from us. If you then use the code in the brand's own shop, that purchase is governed by the brand's own privacy policy and the brand is an independent controller for it. We are not responsible for their processing.

Logistics providers, where a physical reward has to be shipped to you.

Professional advisers — lawyers, accountants, and auditors — bound by professional confidentiality.

Public authorities, where we are legally required to disclose.

Acquirers and successors, as described in section 9.

Every processor acting on our behalf is bound by a written data processing agreement meeting the requirements of Article 28(3) GDPR.

7. International transfers

Our primary database and application infrastructure are hosted in the European Union ([CONFIRM REGION — e.g. europe-west3, Frankfurt]).

Some of our providers are established in, or may access data from, the United States. Where personal data is transferred outside the European Economic Area, we rely on one or more of the following safeguards under Chapter V GDPR:

  • the European Commission's adequacy decision of 10 July 2023 on the EU–US Data Privacy Framework, for providers certified under that framework (Article 45); or
  • Standard Contractual Clauses adopted by the European Commission (Article 46(2)(c)), supplemented where necessary by additional technical and organisational measures identified through a transfer impact assessment.

You may request a copy of the relevant safeguards at [email protected].

8. How long we keep your data

CategoryRetention period
Account dataFor the life of your account, then 30 days after deletion
Visit and check-in records (identified)24 months from the date of the visit
Visit records (aggregated)Indefinitely, in irreversibly anonymised form — see below
Points balance and transaction historyFor the life of your account, then as required by accounting law
Reward codes issued24 months, or the code's validity period plus 12 months, whichever is longer
Delivery addressesUntil delivery is complete, then as required by accounting and tax law
Invoicing and accounting records10 years, as required under Slovenian tax and accounting legislation
Device and crash data12 months
Usage and analytics data (identified)14 months
Support correspondence24 months from the last message
Consent recordsFor the duration of the consent plus 3 years
Data relevant to a legal claimUntil the claim is finally resolved

After the identified retention period expires, we may retain visit and usage data in irreversibly anonymised, aggregated form — for example, cohort-level retention curves and visit-frequency distributions that cannot be linked back to any individual, directly or indirectly, by us or anyone else. Anonymised data of this kind is outside the scope of GDPR under Recital 26 and we may retain and use it without time limit.

9. Corporate transactions and change of controller

If Guavi is involved in a merger, acquisition, investment, financing, corporate reorganisation, insolvency, or a sale of all or part of its business or assets, personal data may be:

  • disclosed under confidentiality to the counterparty and its professional advisers as part of due diligence, in the minimum scope necessary and, wherever possible, in pseudonymised or aggregated form; and
  • transferred to the acquiring entity as part of the transferred business.

Our legal basis for this disclosure is our legitimate interest in the continuity and transferability of our business under Article 6(1)(f) GDPR.

Where a transaction results in a change of the controller of your data:

  • we will inform you before the change takes effect, by email and by in-App notice, giving you at least 30 days' notice;
  • you may delete your account and your data before the transfer takes effect, or object under Article 21 GDPR;
  • the acquiring entity will be bound by this Privacy Policy, or by a successor policy that is no less protective, until you are given notice of and an opportunity to consider any change; and
  • where processing is based on your consent, that consent does not automatically carry over. We will ask you to give consent again to the new controller, and processing on that basis will stop if you do not.

10. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • Access — obtain confirmation of whether we process your data and a copy of it (Article 15).
  • Rectification — have inaccurate data corrected and incomplete data completed (Article 16).
  • Erasure — have your data deleted, subject to the exceptions in Article 17(3), such as data we must keep for accounting purposes (Article 17).
  • Restriction — have processing restricted in the circumstances listed in Article 18.
  • Portability — receive the data you provided to us, and the data we observed about your activity, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Article 20). You can export your account and visit history directly from the App under Settings → Privacy → Export my data.
  • Object — object at any time to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21(1)). Where you object to processing for direct marketing purposes, we will stop, without exception and without any balancing (Article 21(2)).
  • Withdraw consent at any time (Article 7(3)), as described in section 4.3.

To exercise any right, contact [email protected]. We will respond within one month of receiving your request, extendable by a further two months where the request is complex, in which case we will tell you within the first month (Article 12(3)). Exercising your rights is free of charge unless a request is manifestly unfounded or excessive (Article 12(5)).

Right to complain. If you believe we have processed your data unlawfully, you may lodge a complaint with the Slovenian supervisory authority:

Informacijski pooblaščenec Republike Slovenije
Dunajska cesta 22, 1000 Ljubljana, Slovenia
[email protected]  |  +386 1 230 97 30  |  www.ip-rs.si

You may also complain to the supervisory authority in your country of residence or place of work, and you have the right to an effective judicial remedy under Article 79 GDPR.

11. Children

Guavi is not intended for children under 15. You must be at least 15 years old to create an account, in line with the age of consent for information society services set under Slovenian law implementing Article 8(1) GDPR.

If you are under 15, do not create an account. If we learn that we hold data relating to a person under 15 without the required authorisation of a holder of parental responsibility, we will delete it without undue delay.

If you are a parent or guardian and believe your child has created an account, contact [email protected] and we will act on it.

12. Security

We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR, including:

  • encryption of data in transit (TLS) and at rest;
  • passwords stored only as salted hashes;
  • role-based access control, with access to production data limited to personnel who need it;
  • multi-factor authentication on administrative and infrastructure accounts;
  • logging and monitoring of access to personal data;
  • separation of production and development environments, with no live personal data used in testing;
  • regular review of our processors' security posture; and
  • a documented incident response procedure.

No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Informacijski pooblaščenec within 72 hours as required by Article 33, and we will inform you directly without undue delay where the breach is likely to result in a high risk to you, as required by Article 34.

13. Changes to this policy

We may update this policy. Where a change is material — for example, a new purpose, a new category of recipient, a change of controller, or a change to how location data is used — we will:

  • notify you by email and by in-App notice before the change takes effect;
  • give you a reasonable period to review it; and
  • where the change concerns processing based on your consent, ask for your consent again rather than assume it.

Non-material changes, such as corrections and clarifications, will be published here with an updated version number and date. We keep previous versions and will provide them on request.

14. Contact

Privacy and data protection: [email protected]
Postal: Sans Decorum d.o.o., Topniška ulica 70, Suite 76, 1000 Ljubljana, Slovenia

Get rewarded for going to the gym.

Brands & partnerships

[email protected]
Topniška ulica 70, Suite 76, Ljubljana, 1000, Slovenia Copyright Guavi © 2026. Website created by Stelios.