B42 Logo
  • For Players
  • For Coaches & Clubs
  • For Academies
DEEN
  • For Players
  • For Coaches & Clubs
  • For Academies
DEEN

B42 Nutrition for Footballers Privacy Policy

Last updated on September 9, 2026

This privacy policy applies to the “B42 Nutrition for Footballers” app (iOS and Android). The separate B42 App Privacy Policy applies to the B42 training app. The B42 Websites Privacy Policy applies to our websites.

1. Data Protection at a Glance

General information

The following information provides a simple overview of what happens to your personal data when you use our app. Personal data means any data that can identify you personally. Detailed information is provided in the full privacy policy below.

Who is responsible for data collection in this app?

Data is processed by the app operator. Contact details are provided in section 2.2.

How do we collect your data?

Some data is collected when you provide it to us, for example during registration or use of the app (body measurements, dietary preferences). Other data is collected automatically by our IT systems when the app operates (e.g. device information and the time the app starts).

Analytics tools and third-party tools

Your usage behavior may be statistically evaluated while the app operates. This happens only after your express consent when you first launch the app.

2. General Information and Mandatory Disclosures

2.1. Data protection

The operators of this app take protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy. Communication between the app and our servers is exclusively encrypted using SSL/TLS.

2.2. Controller

The controller responsible for data processing in this app is:

SFY GmbH
Industriestraße 15
84149 Velden
Germany
Phone: +49 160 97978139
Email: info@b-42.com

Represented by Managing Director Andreas Gschaider.

2.3. Withdrawal of your consent to data processing

Many processing operations are possible only with your express consent. You can withdraw consent at any time, directly in the app settings or by emailing info@b-42.com. The lawfulness of processing carried out before withdrawal remains unaffected.

2.4. Right to lodge a complaint with the competent supervisory authority

In the event of data protection violations, you have the right to lodge a complaint with the competent supervisory authority. A list of authorities is available at: www.bfdi.bund.de.

2.5. Right to data portability

You have the right to receive, or have a third party receive, data that we process automatically based on your consent or in performance of a contract, in a commonly used, machine-readable format.

2.6. Access, rectification, and erasure

You have the right at any time to obtain free information about your stored personal data, its source and recipients, and the purpose of processing, and, where applicable, a right to rectification or erasure. Contact info@b-42.com at any time for this purpose.

2.7. Transfers to third countries

Some services used in this app are based in the USA. Where we transfer data to the USA, we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (DPF) of July 10, 2023, provided the relevant provider is DPF-certified. Otherwise, we rely on standard contractual clauses under Article 46(2)(c) GDPR.

3. Data Collection in the App

3.1. Categories of data collected

We process the following categories of personal data:

Identity data

First and last name, date of birth, email address, and information forwarded to us through your Meta, Google, or Apple account. We use this data to verify your identity and provide your account. Retention period: for the duration of the contractual relationship and 3 years after it ends.

Body measurements

Height and body weight. We use this data to better tailor calorie requirement calculations and recipe recommendations to your individual needs. Retention period: for the duration of the contractual relationship. You can update or delete this data at any time in the app settings. The legal basis is Article 6(1)(b) GDPR (performance of a contract).

Nutrition and recipe data

Recipes you view, save, or rate, and dietary preferences you provide. We use this data to generate personalized recipe suggestions. Retention period: for the duration of the contractual relationship, until account deletion. The legal basis is Article 6(1)(b) GDPR (performance of a contract).

Purchase information

Payment provider, subscription duration, price, currency, VAT, and the payment number assigned by the payment provider (Apple, Google). We do not store credit card information ourselves. Payment data is subject to statutory retention requirements and is stored for 10 years (sections 146 and 147 of the German Fiscal Code, AO).

Behavioral and profile information

Your usage behavior in the app (e.g. recipes viewed and frequency of use). We use this data to improve our app and provide suitable content. Retention period: 12 months, after which it is anonymized. The legal basis is Article 6(1)(a) GDPR (consent).

Device information

IP address, date and time of app use, device identifiers, device type, operating system, and version. This data is needed for network security and error diagnosis. Retention period: 30 days.

3.2. Account and profile data

Full use of the app requires an account, which can be created through registration or login with Meta, Google, or Apple. The required email address is stored on our server and used exclusively for login functionality and sending important transactional emails. The legal basis is Article 6(1)(b) GDPR.

3.3. Marketing communications

Marketing emails and in-app communications are directed exclusively to users aged 16 and over. The legal basis is Article 6(1)(a) GDPR (consent). You can withdraw consent at any time in the app settings or by emailing info@b-42.com.

4. Analytics Tools

4.1. PostHog

This app uses PostHog, a product and analytics tool provided by PostHog Inc. We use the EU cloud version; all data is processed and stored exclusively on servers within the European Union (Frankfurt, Germany). No personal data is transferred to third countries.

PostHog enables us to analyze how users use the app (e.g. screens viewed, click paths, and session duration) and also supports error analysis to identify problems in user flows. Data is processed in pseudonymized form.

We also use PostHog Workflows to trigger automated, contextual in-app messages based on usage behavior. No automated decision-making within the meaning of Article 22 GDPR takes place.

PostHog is used only after your express consent when you first launch the app. The legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time in the app settings. Collected usage data is automatically deleted after 12 months.

We have concluded a data processing agreement with PostHog. Further information: posthog.com/privacy.

5. Stability and Troubleshooting

5.1. Firebase / Google Crashlytics

To detect and resolve app errors and crashes, we use Firebase Crashlytics, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

When an error occurs, the following data is transmitted automatically: anonymized user ID, device type, operating system and app version, time of error, error log and stack trace, and geographic location (country only).

The legal basis is Article 6(1)(f) GDPR (legitimate interest in stable app operation). Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified. Crash data is automatically deleted after 90 days.

We have concluded a data processing agreement with Google. Further information: firebase.google.com/support/privacy.

5.2. Sentry

We also use Sentry for error tracking and performance monitoring. The provider is Sentry, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.

When errors occur, Sentry collects: anonymized user ID, device type, operating system and app version, time and type of error, error log, stack trace, and performance metrics.

The legal basis is Article 6(1)(f) GDPR. We use Sentry in the EU region; all data is processed exclusively on servers within the EU. No transfers to third countries take place. Error data is deleted after 90 days.

We have concluded a data processing agreement with Sentry. Further information: sentry.io/privacy.

6. Communication

6.1. Mailgun

To send transactional emails (e.g. password resets and order confirmations), we use Mailgun from Mailgun Technologies, Inc., 112 E Pecan St #1135, San Antonio, TX 78205, USA. We use Mailgun in the EU region; all data is processed exclusively on servers within the EU. No transfers to third countries take place. The legal basis is Article 6(1)(b) GDPR. Email log data is deleted after 30 days.

We have concluded a data processing agreement with Mailgun. Further information: mailgun.com/legal/privacy-policy.

6.2. Push notifications

With your consent, the app sends push notifications to your device. Permission is requested through the system permission dialog when you first launch the app.

  • iOS: Apple Push Notification Service (APNs) - Apple Inc., Cupertino, CA 95014, USA (DPF-certified)
  • Android: Firebase Cloud Messaging (FCM) - Google LLC, Mountain View, CA 94043, USA (DPF-certified)

The legal basis is Article 6(1)(a) GDPR. You can disable push notifications at any time in your device’s system settings.

7. Payment

7.1. RevenueCat

We use RevenueCat to manage in-app subscriptions. The provider is RevenueCat, Inc., 633 Tasman Drive, San Jose, CA 95134, USA.

RevenueCat processes your subscription status, purchase time, selected plan, and an anonymized user ID. Credit card or bank account data is not transmitted to RevenueCat; it remains with the relevant payment provider (App Store or Google Play).

The legal basis is Article 6(1)(b) GDPR (performance of a contract). Transfers to the USA are based on standard contractual clauses under Article 46(2)(c) GDPR. Subscription data is stored for the duration of the contractual relationship and 3 years afterward.

We have concluded a data processing agreement with RevenueCat. Further information: revenuecat.com/privacy.

8. Third-Party Login

8.1. Login with Meta (Facebook)

The app offers login with a Meta account. The provider is Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. When you use Meta login, your name and email address are retrieved from Meta after your express consent. The legal basis is Article 6(1)(b) GDPR for account creation and Article 6(1)(a) GDPR for data transmission to Meta. Transfers to the USA are based on the EU-US Data Privacy Framework; Meta Platforms is DPF-certified.

Further information: facebook.com/privacy/policy.

8.2. Login with Google

The app offers login with a Google account. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When you use Google login, your name and email address are retrieved from Google after your express consent. The legal bases are Article 6(1)(b) and Article 6(1)(a) GDPR. Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified.

Further information: policies.google.com/privacy.

8.3. Sign in with Apple

The app offers login with an Apple ID. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. Apple optionally allows you to share an anonymized relay email address instead of your real email address. The legal bases are Article 6(1)(b) and Article 6(1)(a) GDPR. Transfers to the USA are based on the EU-US Data Privacy Framework; Apple Inc. is DPF-certified.

Further information: apple.com/legal/privacy.

9. User Rights

9.1. Account deletion

You can delete your account and all associated personal data directly in the app: Profile → Settings → Delete account. Data subject to statutory retention requirements is deleted only after the relevant period expires.

9.2. Data subject rights

As a data subject, you have the following rights:

  • Right of access (Article 15 GDPR)
  • Right to rectification (Article 16 GDPR)
  • Right to erasure (Article 17 GDPR)
  • Right to restriction of processing (Article 18 GDPR)
  • Right to data portability (Article 20 GDPR)
  • Right to object (Article 21 GDPR)

The restrictions under sections 34 and 35 of the German Federal Data Protection Act (BDSG) apply to the rights of access and erasure.

9.3. Right to lodge a complaint

You have the right to complain to the competent data protection supervisory authority about our processing of your personal data.

9.4. Withdrawal of consent

You can withdraw consent at any time with effect for the future, directly in the app settings or by emailing info@b-42.com.

9.5. Objection to direct marketing

Under Article 21(2) GDPR, you have the right to object at any time to processing of your data for direct marketing purposes.

9.6. Changes to this privacy policy

We reserve the right to amend this privacy policy at any time in compliance with applicable data protection regulations. The current version is available in the App Store and at b-42.com/en-us/datenschutz-b42-nutrition.

9.7. Contact

SFY GmbH
Industriestraße 15
84149 Velden
Germany
Email: info@b-42.com

B42 Logo

The platform for modern football development.

Solutions

  • For Players
  • For Coaches & Clubs
  • For Academies

More products

  • B42 Prevention
  • B42 Nutrition

Company

  • Blog
  • About us
  • Press
  • Resources
  • FAQ
  • Support

Legal

  • Legal Notice
  • Terms
  • Privacy Policy

© 2026 B42. All rights reserved.

We use Google Tag Manager, Google Analytics and the Meta Pixel for statistics and marketing — only with your consent. PostHog runs anonymously without cookies either way. Privacy policy