B42 App Privacy Policy
Last updated on September 9, 2026
This privacy policy applies to the B42 App (iOS and Android). The separate B42 Websites Privacy Policy applies to our websites b-42.com, elite.b-42.com, pro.b-42.com, and prevention.b-42.com. The separate CoachZone Privacy Policy also applies to B42 CoachZone (teams.b-42.com) and the Teams section in the app.
1. Data Protection at a Glance
General information
The following information provides a simple overview of what happens to your personal data when you use our app. Personal data means any data that can identify you personally. Detailed information is provided in the full privacy policy below.
Who is responsible for data collection in this app?
Data is processed by the app operator. Contact details are provided in section 2.2.
How do we collect your data?
Some data is collected when you provide it to us, for example during registration or use of the app. Other data is collected automatically by our IT systems when the app operates (e.g. device information, operating system, and the time the app starts).
What data do we collect and why?
Some data is collected to ensure the app operates correctly. Other data may be used to analyze user behavior. Details are provided in the following sections.
Analytics tools and third-party tools
Your usage behavior may be statistically evaluated while the app operates. This is done using analytics tools described in detail in section 4. Analysis takes place only after your express consent when you first launch the app.
2. General Information and Mandatory Disclosures
2.1. Data protection
The operators of this app take protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy.
Please note that data transmission over the internet may have security vulnerabilities. Complete protection against access by third parties is not possible. Communication between the app and our servers is exclusively encrypted using SSL/TLS.
2.2. Controller
The controller responsible for data processing in this app is:
SFY GmbH
Industriestraße 15
84149 Velden
Germany
Phone: +49 160 97978139
Email: info@b-42.com
Represented by Managing Director Andreas Gschaider.
2.3. Withdrawal of your consent to data processing
Many processing operations are possible only with your express consent. You can withdraw consent at any time, directly in the app settings (“Profile” tab → icon at the top right) or by emailing us. The lawfulness of processing carried out before withdrawal remains unaffected.
2.4. Right to lodge a complaint with the competent supervisory authority
In the event of data protection violations, you have the right to lodge a complaint with the competent supervisory authority. The competent authority is the state data protection commissioner of the federal state in which our company is based. A list of authorities is available at: www.bfdi.bund.de.
2.5. Right to data portability
You have the right to receive, or have a third party receive, data that we process automatically based on your consent or in performance of a contract, in a commonly used, machine-readable format.
2.6. Access, rectification, and erasure
Within applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its source and recipients, and the purpose of processing, and, where applicable, a right to rectification or erasure. Contact info@b-42.com at any time for this purpose.
2.7. Transfers to third countries
Some services used in this app are based in the USA. Where we transfer data to the USA, we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (DPF) of July 10, 2023, provided the relevant provider is DPF-certified. Otherwise, we rely on standard contractual clauses under Article 46(2)(c) GDPR. The applicable legal bases are stated for each service.
3. Data Collection in the App
3.1. Categories of data collected
We process the following categories of personal data:
Identity data
First and last name, date of birth, email address, gender, and information forwarded to us through your Meta or Google account. We use this data to verify your identity and provide your account. This data is stored for the duration of the contractual relationship and 3 years after it ends.
Contact data
Email address and other communication channels you have used to contact us. We use this data to contact you when needed. Retention period: 3 years after the last contact.
Profile picture
Users can voluntarily upload a profile picture. It is displayed in the public profile and is visible to other B42 users (see “Behavioral and profile information” below). The profile picture is stored for the duration of the contractual relationship and can be changed or deleted at any time in the app settings. The legal basis is Article 6(1)(a) GDPR (consent through voluntary upload).
Body and training information
Height, weight, fitness level, desired training focus, and playing position (e.g. center back). We use this data to better tailor our training plans and product recommendations to your needs. Retention period: for the duration of the contractual relationship.
Location data
The B42 App offers GPS tracking for running sessions if you have granted the app the relevant permission. Processing depends on your age:
- Users under 16: GPS coordinates are displayed exclusively in real time during the current session. Individual GPS points are not stored.
- Users aged 16 and over: GPS data is stored to evaluate and visualize your running performance. Data is automatically deleted after 24 months; aggregated evaluations are retained for the duration of the contractual relationship. The legal basis is Article 6(1)(a) GDPR (express consent).
Marketing communications
Marketing emails and in-app communications (e.g. product news and offers) are directed exclusively to users aged 16 and over. The legal basis is Article 6(1)(a) GDPR (consent). You can withdraw consent at any time in the app settings or by emailing info@b-42.com.
Purchase information
Payment provider, B42 subscription duration, price, currency, VAT, and the payment number assigned by the payment provider (e.g. Apple, Google). We do not store credit card information ourselves. Payment data is subject to statutory retention requirements and is stored for 10 years (sections 146 and 147 of the German Fiscal Code, AO).
Behavioral and profile information
Your usage behavior in the app. We use this data to improve our products and provide suitable content. Retention period: 12 months, after which it is anonymized.
The information in your public profile represents you in the B42 App. Other users can see your first and last name (if provided), profile picture, completed workouts, and performance test results. Your B42 Player Card is also visible to other users. To allow your achievements and progress to inspire other users, you agree to the use of your B42 Player Card on other SFY GmbH communication channels.
Social media information
Information we receive through your interactions with us on social media such as Facebook, Instagram, or Google, including publicly available information such as your social media handles and public posts. We receive this information directly from social networks or through third-party agencies with which we have appropriate agreements.
Device information
Information about your device, including IP address, date and time of app use, device identifiers, device type, operating system and version, and browser type (in web view). This data is needed for network security and error diagnosis. Retention period: 30 days.
Activity information
Fitness data such as selected training program, training start and end times, and completed activities. We use this data to operate our products, support your performance goals, and provide suitable product recommendations. Completed workouts and your full training history are stored permanently so you can review your development at any time; they are retained until you actively delete your account (see section 11.1). The legal basis is Article 6(1)(b) GDPR (performance of a contract).
3.2. Account and profile data
Full use of the app requires an account, which can be created through registration or login with Meta, Google, or Apple. The required email address is stored on our server and used exclusively for login functionality and sending important transactional emails (e.g. password resets and order confirmations). The legal basis is Article 6(1)(b) GDPR.
3.3. Age-dependent processing
After registration, users enter their date of birth in the app. Based on this information, certain features and processing operations are controlled according to age:
- GPS storage for running sessions, health integrations (Apple Health, Fitbit, Polar, Garmin), and marketing communications are available exclusively to users aged 16 and over (see section 7 BDSG).
- For users under 16, the corresponding consent is not requested; the features remain disabled.
Date of birth is stored for the duration of the contractual relationship. The legal basis is Article 6(1)(b) GDPR (performance of a contract, since age-dependent feature control is part of the usage agreement).
4. Analytics Tools
4.1. PostHog
This app uses PostHog, a product and analytics tool provided by PostHog Inc. We use the EU cloud version; all data is processed and stored exclusively on servers within the European Union (Frankfurt, Germany). No personal data is transferred to third countries.
PostHog enables us to analyze how users use the app (e.g. screens viewed, click paths, and session duration) to improve it in a targeted way. We also use PostHog for error analysis to identify and resolve problems in user flows (e.g. abandoned actions and faulty screens). Data is processed in pseudonymized form.
We also use PostHog Workflows to trigger automated actions based on user behavior (e.g. contextual in-app messages). This processing also takes place exclusively on PostHog’s EU servers.
PostHog is used only after your express consent when you first launch the app. The legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time in the app settings. Collected usage data is automatically deleted after 12 months.
We have concluded a data processing agreement with PostHog. Further information: posthog.com/privacy.
4.2. Automated processing and personalized content
PostHog Workflows analyzes your usage behavior and may automatically trigger contextual in-app messages or content based on it (e.g. reminders about unfinished training sessions). This processing serves exclusively to improve your app experience.
No automated decision-making within the meaning of Article 22 GDPR takes place; that is, no decisions with legal or similarly significant effects on you are made exclusively by automated means (e.g. no automatic termination, account suspension, or credit checks). The legal basis is Article 6(1)(a) GDPR (consent).
5. Stability and Troubleshooting
5.1. Firebase / Google Crashlytics
To detect and resolve app errors and crashes, we use Firebase Crashlytics, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When an error occurs in the app, the following data is transmitted automatically to Firebase:
- Anonymized user ID (randomly generated, cannot be used to infer your identity)
- Device type, operating system, and app version
- Time of the error
- Error log and stack trace
- Geographic location (country only)
This data is used exclusively to diagnose and resolve errors. The legal basis is Article 6(1)(f) GDPR (legitimate interest in stable app operation). Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified. Crash data is automatically deleted after 90 days.
We have concluded a data processing agreement with Google. Further information: firebase.google.com/support/privacy.
5.2. Sentry
In addition to Firebase Crashlytics, we use Sentry for error tracking and performance monitoring. The provider is Sentry, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
When errors occur, Sentry collects:
- Anonymized user ID
- Device type, operating system, and app version
- Time and type of error
- Error log and stack trace
- Performance metrics (e.g. loading times)
The legal basis is Article 6(1)(f) GDPR (legitimate interest in stable app operation). We use Sentry in the EU region; all data is processed and stored exclusively on servers within the European Union. No personal data is transferred to third countries. Error data is automatically deleted after 90 days.
We have concluded a data processing agreement with Sentry. Further information: sentry.io/privacy.
6. Communication
6.1. Mailgun
We use Mailgun to send transactional emails (e.g. password resets, order confirmations, and important account information). The provider is Mailgun Technologies, Inc., 112 E Pecan St #1135, San Antonio, TX 78205, USA.
Mailgun processes your email address and the content of each email. This data is not used for marketing. The legal basis is Article 6(1)(b) GDPR (performance of a contract). We use Mailgun in the EU region; all data is processed and stored exclusively on servers within the European Union. No personal data is transferred to third countries. Email log data is deleted after 30 days.
We have concluded a data processing agreement with Mailgun. Further information: mailgun.com/legal/privacy-policy.
6.2. Push notifications
With your consent, the B42 App sends push notifications to your device (e.g. training reminders and important app updates). Permission is requested through your operating system’s permission dialog when you first launch the app.
The following services are used to send notifications:
- iOS: Apple Push Notification Service (APNs) - provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (DPF-certified)
- Android: Firebase Cloud Messaging (FCM) - provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (DPF-certified)
A device-specific push token (an anonymized device identifier) is transmitted to the respective service and does not allow direct identification of you. The legal basis is Article 6(1)(a) GDPR (consent). You can disable push notifications at any time in your device’s system settings. After deactivation or deletion of your account, the push token is deleted immediately.
7. Payment
7.1. RevenueCat
We use RevenueCat to manage in-app subscriptions and purchases. The provider is RevenueCat, Inc., 633 Tasman Drive, San Jose, CA 95134, USA.
RevenueCat processes your subscription status, purchase time, selected plan, and an anonymized user ID. Credit card or bank account data is not transmitted to RevenueCat; it remains with the respective payment provider (App Store or Google Play).
The legal bases are Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest in reliable subscription management). Transfers to the USA are based on standard contractual clauses under Article 46(2)(c) GDPR. Subscription data is stored for the duration of the contractual relationship and 3 years afterward.
We have concluded a data processing agreement with RevenueCat. Further information: revenuecat.com/privacy.
8. Third-Party Login
8.1. Login with Meta (Facebook)
The B42 App offers login with a Meta account (formerly Facebook). The provider is Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA.
When you use Meta login, your name and email address are retrieved from Meta after your express consent. This data is used exclusively to create and manage your B42 account. Data is transmitted to Meta only after you explicitly click the “Continue with Facebook” button.
The legal basis is Article 6(1)(b) GDPR (performance of a contract) for account creation and Article 6(1)(a) GDPR (consent) for data transmission to Meta. Transfers to the USA are based on the EU-US Data Privacy Framework; Meta Platforms is DPF-certified.
Further information about privacy at Meta: facebook.com/privacy/policy.
8.2. Login with Google
The B42 App offers login with a Google account. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When you use Google login, your name and email address are retrieved from Google after your express consent. This data is used exclusively to create and manage your B42 account. Data is transmitted to Google only after you explicitly click the “Continue with Google” button.
The legal basis is Article 6(1)(b) GDPR (performance of a contract) for account creation and Article 6(1)(a) GDPR (consent) for data transmission to Google. Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified.
Further information about privacy at Google: policies.google.com/privacy.
8.3. Sign in with Apple
The B42 App offers login with an Apple ID. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
When you use “Sign in with Apple,” Apple transmits your name and email address to the B42 App after your consent. Apple optionally allows you to share an anonymized relay email address so your real email address is not transmitted to SFY GmbH. In that case, B42 communicates with you exclusively through the forwarding address provided by Apple.
The legal basis is Article 6(1)(b) GDPR (performance of a contract) for account creation and Article 6(1)(a) GDPR (consent) for data transmission to Apple. Transfers to the USA are based on the EU-US Data Privacy Framework; Apple Inc. is DPF-certified.
Further information about privacy at Apple: apple.com/legal/privacy.
9. Teams Feature (CoachZone)
The B42 App includes a Teams section through which coaches and clubs can manage athletes, share training plans, and view performance data. This section is technically connected to B42 CoachZone (teams.b-42.com) and uses the same platform.
9.1. Specific role structure
The data protection arrangements in the Teams section differ from the other app features:
- Athletes use the Teams section to receive their coach’s content and share their own training data. SFY GmbH is the controller for this data.
- Coaches and club administrators who collect, manage, or evaluate athlete data through the app are themselves controllers for that processing within the meaning of the GDPR. In this context, SFY GmbH processes athlete data exclusively as a processor under Article 28 GDPR.
Athletes who wish to obtain access to their data stored in the Teams section or request its deletion should contact their coach or club. SFY GmbH supports fulfillment of data subject rights at the controller’s request and can be reached at info@b-42.com.
9.2. Data processed in the Teams section
The following data may be processed in the app’s Teams section:
- Athletes’ names, playing positions, and profile pictures
- Training results, performance data, and test results
- Attendance and training history
- Internal team communication (e.g. announcements and lineups)
The legal basis for processing by SFY GmbH as processor is Article 6(1)(b) GDPR (performance of a contract with coaches/clubs). Athlete data is deleted no later than 30 days after the contractual relationship with the respective coach/club ends.
The full privacy policy for the CoachZone platform, including the tools used and further details, is available at b-42.com/en-us/datenschutz-coachzone.
10. Health Integrations
The B42 App allows runs and activities to be synchronized through external health and fitness platforms. This feature is available exclusively to users aged 16 and over. Data from these integrations is considered health data under Article 9 GDPR (special categories of personal data). Processing takes place exclusively on the basis of your express consent under Article 9(2)(a) GDPR. You can disconnect the integration at any time in the app settings.
10.1. Apple Health
On iOS devices, you can grant the B42 App access to your Apple Health data. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
If you enable the integration, the app reads only the Apple Health data you have explicitly authorized (e.g. running distance, step count, heart rate, and calories burned). Data is transferred only to the B42 App and used there to display and evaluate your activities. It is not shared with third parties.
Transfers to the USA are based on the EU-US Data Privacy Framework; Apple Inc. is DPF-certified. Further information: apple.com/legal/privacy.
10.2. Fitbit / Google
B42 offers integration with Fitbit devices and services. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Fitbit is a Google product).
If you enable the Fitbit integration, activity data such as completed runs, distance, heart rate, and calories burned is retrieved through the Fitbit Web API. The legal basis is Article 9(2)(a) GDPR (express consent). Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified.
We have concluded a data processing agreement with Google. Further information: fitbit.com/legal/privacy-policy.
10.3. Polar
B42 offers integration with Polar watches and the Polar Flow service. The provider is Polar Electro Oy, Professorintie 5, 90440 Kempele, Finland.
If you enable the Polar integration, training data such as completed activities, GPS routes, heart rate, and calories burned is retrieved through the Polar Accesslink API. Because Polar Electro Oy is based in Finland (EU/EEA), no third-country transfer takes place. The legal basis is Article 9(2)(a) GDPR (express consent).
We have concluded a data processing agreement with Polar Electro Oy. Further information: polar.com/de/legal/privacy-policy.
10.4. Garmin
B42 offers integration with Garmin devices and the Garmin Connect service. The provider is Garmin International, Inc., 1200 E. 151st Street, Olathe, KS 66062, USA.
If you enable the Garmin integration, activity data such as completed runs, GPS routes, heart rate, and calories burned is retrieved through the Garmin Connect API. The legal basis is Article 9(2)(a) GDPR (express consent). Transfers to the USA are based on the EU-US Data Privacy Framework if Garmin International is DPF-certified; otherwise, they are based on standard contractual clauses under Article 46(2)(c) GDPR.
We have concluded a data processing agreement with Garmin. Further information: garmin.com/de-DE/privacy.
10.5. Retention of health data
Activity data imported from health integrations is stored for the duration of the contractual relationship. Imported data is deleted immediately after the respective integration is disconnected or your account is deleted.
11. User Rights
11.1. Account deletion
You can delete your B42 account and all associated personal data directly in the app: Profile → Settings (icon at the top right) → Delete account. Deletion covers all stored profile, training, health, and activity data. Data subject to statutory retention requirements (e.g. payment records under section 147 AO) is deleted only after the relevant period expires. After confirming deletion, you will receive a confirmation email.
11.2. Data subject rights
As a data subject, you have the following rights:
- Right of access (Article 15 GDPR): You can request information about the data processed about you.
- Right to rectification (Article 16 GDPR): You can request correction of inaccurate data.
- Right to erasure (Article 17 GDPR): You can request deletion of your data under certain conditions.
- Right to restriction of processing (Article 18 GDPR): You can request restriction of processing of your data.
- Right to data portability (Article 20 GDPR): You can receive your data in a machine-readable format.
- Right to object (Article 21 GDPR): You can object to processing of your data.
The restrictions under sections 34 and 35 of the German Federal Data Protection Act (BDSG) apply to the rights of access and erasure.
11.3. Right to lodge a complaint
You have the right to complain to the competent data protection supervisory authority about our processing of your personal data.
11.4. Withdrawal of consent
You can withdraw consent at any time with effect for the future, directly in the app settings or by emailing info@b-42.com. Processing carried out before withdrawal is unaffected.
11.5. Objection to direct marketing
Under Article 21(2) GDPR, you have the right to object at any time to processing of your personal data for direct marketing. After your objection, we will no longer process your data for this purpose.
11.6. Links to other websites
The app may contain links to other providers’ offerings. This privacy policy applies exclusively to SFY GmbH’s B42 App. We have no influence over other providers’ privacy practices.
11.7. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time in compliance with applicable data protection regulations. The current version is available at b-42.com/en-us/datenschutzerklaerung-app.
11.8. Contact
If you have questions about the collection, processing, or use of your personal data, please contact:
SFY GmbH
Industriestraße 15
84149 Velden
Germany
Email: info@b-42.com