Privacy Policy

Last updated: 1 August 2026  ·  Version 2.2  ·  Applicable law: GDPR (EU) 2016/679  ·  Dutch Data Protection Act (UAVG)

Train to Mountain is committed to protecting your personal data. This policy explains what data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (GDPR) and Dutch law. It covers both our website and waitlist (Section 2) and the Train to Mountain mobile app (Section 3).

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

If you have any questions about how we handle your data, or wish to exercise any of your rights, please contact us at the email above.

2. What Data We Collect and Why (Website & Waitlist)

This section covers our website and the waitlist. For data collected in the Train to Mountain app, see Section 3. We collect only the minimum data necessary for the stated purpose.

Data Purpose Legal Basis Retention
Email address To send you updates about Train to Mountain's launch and relevant product news Consent (Art. 6(1)(a) GDPR) Until you withdraw consent or request deletion
Name To address you personally in our emails Consent (Art. 6(1)(a) GDPR) Same as email address
Training goal (optional)
e.g. your target peak, objective, or timeline, if you choose to share it
To understand your goal so we can tailor early-access onboarding and the updates we send you Consent (Art. 6(1)(a) GDPR) Same as email address
Signup source (hero / cta) Internal analytics to understand which part of the page generated sign-ups Legitimate interest (Art. 6(1)(f) GDPR) Same as email address
Analytics data (only if you accept cookies)
Includes: pseudonymised IP address, device type, browser, referring website, pages visited, session duration, approximate location (country-level)
To understand how visitors find and use the site so we can improve it. Anonymised aggregate only - we never try to identify individual visitors. Consent (Art. 6(1)(a) GDPR) - collected only if you click "Accept" on our cookie banner. Default is denied. 14 months (Google Analytics default retention), then automatically deleted

Through our website and waitlist we do not collect sensitive personal data (Article 9 GDPR), financial information, precise location data, or any data from children under the age of 16. Health and fitness data processed in the Train to Mountain app is described in Section 3 and processed only with your explicit consent.

3. The Train to Mountain App (In-App Services)

This section applies when you create an account and use the Train to Mountain mobile app, as opposed to browsing our website or joining the waitlist. The data controller (Section 1) and your GDPR rights (Sections 7 and 8) apply here too.

3.1 What the App Collects and Why

We collect only the minimum data needed to generate and run your training plan.

Data Purpose Legal Basis Retention
Account details (email address, name, authentication credentials) To create and secure your account and sign you in Contract (Art. 6(1)(b) GDPR) For the life of your account; deleted on account deletion
Training profile & goal (target peak or objective, timeline, experience level, training environment and available hours, and other onboarding answers) To generate a training plan tailored to you Contract (Art. 6(1)(b) GDPR) For the life of your account
Wearable & activity data ingested via Spike (e.g. heart rate, workouts and activities, training load, and related fitness metrics from your connected device or provider) To measure readiness, calibrate intensity, and adjust your plan Explicit consent (Art. 9(2)(a) GDPR) - health/fitness data Until you disconnect your wearable, withdraw consent, or delete your account
Training and plan data you generate in the app (scheduled sessions, workout logs, readiness and progress metrics) To run, track and adapt your plan Contract (Art. 6(1)(b) GDPR) For the life of your account
Push-notification device token (only if you enable notifications) To send reminders, missed-day and workout recaps Consent (Art. 6(1)(a) GDPR) Until you disable notifications or delete the app
Crash and diagnostic data (error reports, device model, OS version, app version; collected via Sentry) To detect crashes and keep the app stable Legitimate interest (Art. 6(1)(f) GDPR) Up to 90 days, then automatically deleted

Because wearable data is special-category (Article 9) health data, we process it only with your explicit consent, which you give when you connect a wearable, and which you can withdraw at any time by disconnecting the wearable or deleting your account. The app does not currently ask for injury or medical information.

3.2 Automated Plan Generation

Your training plan is generated using an automated process that sends relevant profile and training inputs (such as your goal, timeline, experience level, training environment and plan structure) to our AI plan-generation provider (see 3.3 below). Your raw wearable data streams are not sent to the AI provider; readiness and training-load calculations run on our own systems. This automated processing supports the training service you have requested; it does not produce legal or similarly significant decisions about you within the meaning of Article 22 GDPR.

3.3 App Data Processors (Third Parties)

Each of the following acts as a data processor on our behalf under a Data Processing Agreement:

ServicePurposeLocationSafeguards
Spike (Spike Technologies, Inc.) Aggregates and delivers wearable and activity data from your connected device or provider US GDPR Data Processing Addendum; Spike Privacy Policy
OpenAI Automated generation of your training plan from your profile inputs US Data Processing Addendum incl. Standard Contractual Clauses; API data is not used to train OpenAI models; OpenAI DPA
TransIP Hosting the app backend and database storing your account, profile, training and wearable data EU (Netherlands) Data Processing Agreement under GDPR; data remains in the EEA
Sentry (Functional Software, Inc.) Crash and error reporting for the app EU data residency (event data stored in the EU) Data Processing Addendum incl. Standard Contractual Clauses; Sentry DPA
Apple (TestFlight / APNs) Beta app distribution and delivery of push notifications US / global Apple's data processing terms; Standard Contractual Clauses
Expo (Expo, Inc.; only if you enable notifications) Routing push notifications to Apple's notification service US Data Processing Agreement under GDPR; Expo Privacy Policy
Mijndomein (Mijndomein.nl) Sending transactional account emails (email verification, password reset) EU (Netherlands) Data Processing Agreement under GDPR; data remains in the EEA

No other third parties receive your app data. We do not sell your data or share it for third-party marketing.

3.4 International Transfers (App)

Spike, OpenAI, Apple and Expo process data in the United States. These transfers are protected by Standard Contractual Clauses under Article 46 GDPR as incorporated in each provider's Data Processing Agreement. Our backend hosting (TransIP), transactional email (Mijndomein) and Sentry crash-report storage remain within the EU. See also Section 6.

3.5 Deleting Your App Data

During the beta you can reset your goal, plan and training data at any time in the app under Settings → Tester reset → Reset goal and plan, and you can request full account deletion by contacting info@traintomountain.com. On account deletion we erase your account, profile, goal, training data and wearable data, subject to your rights under Section 7 and any retention required by law. Disconnecting your wearable stops any further ingestion of wearable data.

4. How We Use Your Data (Website & Waitlist)

Your waitlist email address will only be used to:

We will never sell your data. With your consent, we share limited website-interaction data with Meta through the Meta Pixel solely to measure and improve our own advertising (see Section 9); we do not share your data for any other party's marketing, and we do not use your waitlist data for automated decision-making or profiling. Automated plan generation in the app is described in Section 3.2.

5. Data Processors (Third Parties) - Website & Waitlist

We use the following third-party services (app processors are listed in Section 3.3). Except where noted, each acts as a data processor on our behalf under a Data Processing Agreement. For the Meta Pixel, Meta and Train to Mountain act as joint controllers for the collection and transmission of the pixel data, governed by Meta's Controller Addendum:

ServicePurposeLocationSafeguards
MailerLite (UAB "MailerLite") Stores the name, email address, and training goal you submit when you join the waitlist, and sends you waitlist and early-access emails EU (Vilnius, Lithuania) Data Processing Agreement under GDPR (incorporated into MailerLite's Terms of Use); all sub-processors EU-based; MailerLite DPA
Web3Forms (a product of Web3Creative) Receives the details you submit through our contact form and our guiding-company enquiry form (name, email and message, plus for operators your business, role and operating area) and forwards them to us by email so we can respond to your enquiry United States (Amazon Web Services, US-East); operator registered in India Transmitted over HTTPS and encrypted at rest; submissions retained about 30 days then deleted. Data is transferred outside the EEA (to the US); Web3Forms states it complies with the GDPR but does not offer a separate Data Processing Agreement, so we limit what is sent to only your name, email, and message. See the Web3Forms Privacy Policy
Google Analytics 4 (Google Ireland Ltd) Aggregated, anonymised usage analytics (only loaded if you accept cookies) EU (primary); transfers to US possible Google's Data Processing Terms; IP anonymisation enabled; EU-US Data Privacy Framework + SCCs; Google Privacy Policy
Netlify, Inc. Website hosting and content delivery (serves pages, static assets) Global CDN (servers in EU and US) Standard Contractual Clauses (SCCs) under Art. 46 GDPR; Netlify Privacy Policy
Microsoft Clarity (Microsoft Corporation) Aggregated, pseudonymised analysis of how visitors interact with pages (session recordings and heatmaps), only loaded if you accept cookies Global (Microsoft Azure infrastructure) Microsoft Products and Services Data Protection Addendum (DPA); Standard Contractual Clauses; EU-US Data Privacy Framework; Microsoft Privacy Statement
Meta Platforms Ireland Ltd (Meta Pixel) Advertising measurement and retargeting: helps us see which of our ads led to a visit and show our ads to people who have visited our site. Only loaded if you accept cookies. For this pixel, Meta acts as a joint controller with us for the collection and transmission of the data. EU (Ireland); transfers to US possible Meta Controller Addendum and Standard Contractual Clauses; EU-US Data Privacy Framework; Meta Privacy Policy

No other third parties receive your personal data.

6. International Data Transfers

Your data may be transferred to and processed on servers outside the European Economic Area. For the website and waitlist, specifically:

Transfers relating to the app are described in Section 3.4. All transfers are protected by legally recognised safeguards under GDPR Article 46, providing an adequate level of protection for your personal data.

7. Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights, which you can exercise at any time by contacting us at info@traintomountain.com:

We will respond to all requests within 30 days as required by GDPR Article 12.

8. Right to Lodge a Complaint

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens (AP)
Website: www.autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500
Address: Hoge Nieuwstraat 8, 2514 EL Den Haag, The Netherlands

You may also lodge a complaint with the supervisory authority in the EU member state where you live or work.

9. Cookies and Analytics (Website)

We use two analytics tools, Google Analytics 4 and Microsoft Clarity, to understand how visitors find and use the site so we can improve it, and the Meta Pixel to measure and improve our advertising (including showing our ads to people who have visited the site). The Meta Pixel is an advertising technology that involves cross-site measurement by Meta. All three are off by default and load only if you accept cookies.

Analytics is off by default. When you first visit Train to Mountain, a cookie banner appears asking for your consent. Google Analytics does not load or set any cookies until you click "Accept". If you click "Reject", no analytics cookies are set and no data is sent to Google. Your choice is remembered locally in your browser.

If you accept cookies, the following may be set:

CookiePurposeRetention
_ga Distinguishes unique visitors (pseudonymous) 2 years
_ga_XP9ENFJ5T8 Persists session state for Google Analytics 4 2 years
_fbp Meta Pixel: identifies the browser for advertising measurement and retargeting (set only if you accept cookies) 3 months

For Google Analytics we have enabled IP anonymisation, and Google's advertising signals (ad personalisation, ad user data, ad storage) stay denied until you accept cookies. If you accept, advertising cookies, including the Meta Pixel, are enabled so we can measure our advertising; if you reject, they are never set. The analytics data cannot be used to identify you personally, and we never combine it with your email address or any other information you provide.

How to change your mind: To revoke consent, clear your browser's site data for traintomountain.com and reload the page. The cookie banner will reappear so you can choose again. You may also contact us to request deletion of any analytics data associated with your visit.

We also use one essential, non-tracking technology: a small piece of browser storage (localStorage) to remember your cookie banner choice so we do not show it to you on every visit. This is not a cookie and contains only the word "granted" or "denied".

10. Data Security

We take reasonable technical and organisational measures to protect your personal data against accidental loss, destruction, alteration, or unauthorised disclosure or access. Signup submissions are transmitted via HTTPS and handled by MailerLite under industry-standard security practices. In the app, all data is transmitted via HTTPS, authentication tokens are kept in your device's secure storage, and wearable connection credentials are encrypted at rest on our servers.

11. Children's Data

Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it immediately.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify waiting list subscribers of any material changes by email. The "last updated" date at the top of this page will always reflect the most recent version. Continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact

For any privacy-related questions, requests to exercise your rights, or to report a concern:

We aim to respond within 5 business days for general enquiries, and within 30 days for formal GDPR rights requests.