Train to Mountain is committed to protecting your personal data. This policy explains what data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (GDPR) and Dutch law. It covers both our website and waitlist (Section 2) and the Train to Mountain mobile app (Section 3).
The data controller responsible for your personal data is:
If you have any questions about how we handle your data, or wish to exercise any of your rights, please contact us at the email above.
This section covers our website and the waitlist. For data collected in the Train to Mountain app, see Section 3. We collect only the minimum data necessary for the stated purpose.
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Email address | To send you updates about Train to Mountain's launch and relevant product news | Consent (Art. 6(1)(a) GDPR) | Until you withdraw consent or request deletion |
| Name | To address you personally in our emails | Consent (Art. 6(1)(a) GDPR) | Same as email address |
| Training goal (optional) e.g. your target peak, objective, or timeline, if you choose to share it |
To understand your goal so we can tailor early-access onboarding and the updates we send you | Consent (Art. 6(1)(a) GDPR) | Same as email address |
| Signup source (hero / cta) | Internal analytics to understand which part of the page generated sign-ups | Legitimate interest (Art. 6(1)(f) GDPR) | Same as email address |
| Analytics data (only if you accept cookies) Includes: pseudonymised IP address, device type, browser, referring website, pages visited, session duration, approximate location (country-level) |
To understand how visitors find and use the site so we can improve it. Anonymised aggregate only - we never try to identify individual visitors. | Consent (Art. 6(1)(a) GDPR) - collected only if you click "Accept" on our cookie banner. Default is denied. | 14 months (Google Analytics default retention), then automatically deleted |
Through our website and waitlist we do not collect sensitive personal data (Article 9 GDPR), financial information, precise location data, or any data from children under the age of 16. Health and fitness data processed in the Train to Mountain app is described in Section 3 and processed only with your explicit consent.
This section applies when you create an account and use the Train to Mountain mobile app, as opposed to browsing our website or joining the waitlist. The data controller (Section 1) and your GDPR rights (Sections 7 and 8) apply here too.
We collect only the minimum data needed to generate and run your training plan.
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Account details (email address, name, authentication credentials) | To create and secure your account and sign you in | Contract (Art. 6(1)(b) GDPR) | For the life of your account; deleted on account deletion |
| Training profile & goal (target peak or objective, timeline, experience level, training environment and available hours, and other onboarding answers) | To generate a training plan tailored to you | Contract (Art. 6(1)(b) GDPR) | For the life of your account |
| Wearable & activity data ingested via Spike (e.g. heart rate, workouts and activities, training load, and related fitness metrics from your connected device or provider) | To measure readiness, calibrate intensity, and adjust your plan | Explicit consent (Art. 9(2)(a) GDPR) - health/fitness data | Until you disconnect your wearable, withdraw consent, or delete your account |
| Training and plan data you generate in the app (scheduled sessions, workout logs, readiness and progress metrics) | To run, track and adapt your plan | Contract (Art. 6(1)(b) GDPR) | For the life of your account |
| Push-notification device token (only if you enable notifications) | To send reminders, missed-day and workout recaps | Consent (Art. 6(1)(a) GDPR) | Until you disable notifications or delete the app |
| Crash and diagnostic data (error reports, device model, OS version, app version; collected via Sentry) | To detect crashes and keep the app stable | Legitimate interest (Art. 6(1)(f) GDPR) | Up to 90 days, then automatically deleted |
Because wearable data is special-category (Article 9) health data, we process it only with your explicit consent, which you give when you connect a wearable, and which you can withdraw at any time by disconnecting the wearable or deleting your account. The app does not currently ask for injury or medical information.
Your training plan is generated using an automated process that sends relevant profile and training inputs (such as your goal, timeline, experience level, training environment and plan structure) to our AI plan-generation provider (see 3.3 below). Your raw wearable data streams are not sent to the AI provider; readiness and training-load calculations run on our own systems. This automated processing supports the training service you have requested; it does not produce legal or similarly significant decisions about you within the meaning of Article 22 GDPR.
Each of the following acts as a data processor on our behalf under a Data Processing Agreement:
| Service | Purpose | Location | Safeguards |
|---|---|---|---|
| Spike (Spike Technologies, Inc.) | Aggregates and delivers wearable and activity data from your connected device or provider | US | GDPR Data Processing Addendum; Spike Privacy Policy |
| OpenAI | Automated generation of your training plan from your profile inputs | US | Data Processing Addendum incl. Standard Contractual Clauses; API data is not used to train OpenAI models; OpenAI DPA |
| TransIP | Hosting the app backend and database storing your account, profile, training and wearable data | EU (Netherlands) | Data Processing Agreement under GDPR; data remains in the EEA |
| Sentry (Functional Software, Inc.) | Crash and error reporting for the app | EU data residency (event data stored in the EU) | Data Processing Addendum incl. Standard Contractual Clauses; Sentry DPA |
| Apple (TestFlight / APNs) | Beta app distribution and delivery of push notifications | US / global | Apple's data processing terms; Standard Contractual Clauses |
| Expo (Expo, Inc.; only if you enable notifications) | Routing push notifications to Apple's notification service | US | Data Processing Agreement under GDPR; Expo Privacy Policy |
| Mijndomein (Mijndomein.nl) | Sending transactional account emails (email verification, password reset) | EU (Netherlands) | Data Processing Agreement under GDPR; data remains in the EEA |
No other third parties receive your app data. We do not sell your data or share it for third-party marketing.
Spike, OpenAI, Apple and Expo process data in the United States. These transfers are protected by Standard Contractual Clauses under Article 46 GDPR as incorporated in each provider's Data Processing Agreement. Our backend hosting (TransIP), transactional email (Mijndomein) and Sentry crash-report storage remain within the EU. See also Section 6.
During the beta you can reset your goal, plan and training data at any time in the app under Settings → Tester reset → Reset goal and plan, and you can request full account deletion by contacting info@traintomountain.com. On account deletion we erase your account, profile, goal, training data and wearable data, subject to your rights under Section 7 and any retention required by law. Disconnecting your wearable stops any further ingestion of wearable data.
Your waitlist email address will only be used to:
We will never sell your data. With your consent, we share limited website-interaction data with Meta through the Meta Pixel solely to measure and improve our own advertising (see Section 9); we do not share your data for any other party's marketing, and we do not use your waitlist data for automated decision-making or profiling. Automated plan generation in the app is described in Section 3.2.
We use the following third-party services (app processors are listed in Section 3.3). Except where noted, each acts as a data processor on our behalf under a Data Processing Agreement. For the Meta Pixel, Meta and Train to Mountain act as joint controllers for the collection and transmission of the pixel data, governed by Meta's Controller Addendum:
| Service | Purpose | Location | Safeguards |
|---|---|---|---|
| MailerLite (UAB "MailerLite") | Stores the name, email address, and training goal you submit when you join the waitlist, and sends you waitlist and early-access emails | EU (Vilnius, Lithuania) | Data Processing Agreement under GDPR (incorporated into MailerLite's Terms of Use); all sub-processors EU-based; MailerLite DPA |
| Web3Forms (a product of Web3Creative) | Receives the details you submit through our contact form and our guiding-company enquiry form (name, email and message, plus for operators your business, role and operating area) and forwards them to us by email so we can respond to your enquiry | United States (Amazon Web Services, US-East); operator registered in India | Transmitted over HTTPS and encrypted at rest; submissions retained about 30 days then deleted. Data is transferred outside the EEA (to the US); Web3Forms states it complies with the GDPR but does not offer a separate Data Processing Agreement, so we limit what is sent to only your name, email, and message. See the Web3Forms Privacy Policy |
| Google Analytics 4 (Google Ireland Ltd) | Aggregated, anonymised usage analytics (only loaded if you accept cookies) | EU (primary); transfers to US possible | Google's Data Processing Terms; IP anonymisation enabled; EU-US Data Privacy Framework + SCCs; Google Privacy Policy |
| Netlify, Inc. | Website hosting and content delivery (serves pages, static assets) | Global CDN (servers in EU and US) | Standard Contractual Clauses (SCCs) under Art. 46 GDPR; Netlify Privacy Policy |
| Microsoft Clarity (Microsoft Corporation) | Aggregated, pseudonymised analysis of how visitors interact with pages (session recordings and heatmaps), only loaded if you accept cookies | Global (Microsoft Azure infrastructure) | Microsoft Products and Services Data Protection Addendum (DPA); Standard Contractual Clauses; EU-US Data Privacy Framework; Microsoft Privacy Statement |
| Meta Platforms Ireland Ltd (Meta Pixel) | Advertising measurement and retargeting: helps us see which of our ads led to a visit and show our ads to people who have visited our site. Only loaded if you accept cookies. For this pixel, Meta acts as a joint controller with us for the collection and transmission of the data. | EU (Ireland); transfers to US possible | Meta Controller Addendum and Standard Contractual Clauses; EU-US Data Privacy Framework; Meta Privacy Policy |
No other third parties receive your personal data.
Your data may be transferred to and processed on servers outside the European Economic Area. For the website and waitlist, specifically:
Transfers relating to the app are described in Section 3.4. All transfers are protected by legally recognised safeguards under GDPR Article 46, providing an adequate level of protection for your personal data.
As a data subject in the EU/EEA, you have the following rights, which you can exercise at any time by contacting us at info@traintomountain.com:
We will respond to all requests within 30 days as required by GDPR Article 12.
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens (AP)
Website: www.autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500
Address: Hoge Nieuwstraat 8, 2514 EL Den Haag, The Netherlands
You may also lodge a complaint with the supervisory authority in the EU member state where you live or work.
We use two analytics tools, Google Analytics 4 and Microsoft Clarity, to understand how visitors find and use the site so we can improve it, and the Meta Pixel to measure and improve our advertising (including showing our ads to people who have visited the site). The Meta Pixel is an advertising technology that involves cross-site measurement by Meta. All three are off by default and load only if you accept cookies.
Analytics is off by default. When you first visit Train to Mountain, a cookie banner appears asking for your consent. Google Analytics does not load or set any cookies until you click "Accept". If you click "Reject", no analytics cookies are set and no data is sent to Google. Your choice is remembered locally in your browser.
If you accept cookies, the following may be set:
| Cookie | Purpose | Retention |
|---|---|---|
_ga |
Distinguishes unique visitors (pseudonymous) | 2 years |
_ga_XP9ENFJ5T8 |
Persists session state for Google Analytics 4 | 2 years |
_fbp |
Meta Pixel: identifies the browser for advertising measurement and retargeting (set only if you accept cookies) | 3 months |
For Google Analytics we have enabled IP anonymisation, and Google's advertising signals (ad personalisation, ad user data, ad storage) stay denied until you accept cookies. If you accept, advertising cookies, including the Meta Pixel, are enabled so we can measure our advertising; if you reject, they are never set. The analytics data cannot be used to identify you personally, and we never combine it with your email address or any other information you provide.
How to change your mind: To revoke consent, clear your browser's site data for traintomountain.com and reload the page. The cookie banner will reappear so you can choose again. You may also contact us to request deletion of any analytics data associated with your visit.
We also use one essential, non-tracking technology: a small piece of browser storage (localStorage) to remember your cookie banner choice so we do not show it to you on every visit. This is not a cookie and contains only the word "granted" or "denied".
We take reasonable technical and organisational measures to protect your personal data against accidental loss, destruction, alteration, or unauthorised disclosure or access. Signup submissions are transmitted via HTTPS and handled by MailerLite under industry-standard security practices. In the app, all data is transmitted via HTTPS, authentication tokens are kept in your device's secure storage, and wearable connection credentials are encrypted at rest on our servers.
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it immediately.
We may update this privacy policy from time to time. We will notify waiting list subscribers of any material changes by email. The "last updated" date at the top of this page will always reflect the most recent version. Continued use of our services after changes constitutes acceptance of the updated policy.
For any privacy-related questions, requests to exercise your rights, or to report a concern:
We aim to respond within 5 business days for general enquiries, and within 30 days for formal GDPR rights requests.