Privacy Policy
Last updated: September 28, 2026
1. Who we are
Grix is operated by Web2Fly, a digital solutions company registered in France. When we say "we", "us", or "our", we mean Web2Fly as the data controller for Grix.
Contact: contact@web2fly.com
2. Data we collect
Account data
When you sign up, we collect your name, email address, phone number, and optionally your timezone and coaching specialty.
Profile image
If you upload a profile photo, it is compressed client-side (resized to 256px, converted to WebP format, max ~100 KB) before being stored securely in our cloud storage. Your avatar may appear on your public Smart Booking pages.
Client data
Coaches store information about their clients (name, email, phone, session history, notes, tags). This data is entered and controlled by the coach. Phone numbers are validated on entry and stored in international format when their country is certain.
Session & Smart Booking data
We store session details (date, time, duration, price, status, location, payment status), Smart Booking configurations, and availability schedules you create.
Usage data
We collect anonymized usage analytics (pages visited, features used) to improve the product. No personal data is shared with third-party analytics providers without your consent.
Cookies & local storage
We use essential cookies for authentication, language preference, and cookie consent. We also use browser local storage for theme preference and UI state. See our Cookie Policy for details.
3. How we use your data
- Service delivery: To provide, maintain, and improve Grix — including session management, Smart Booking, notifications, and dashboard analytics.
- Authentication: To verify your identity and secure your account.
- Notifications: To send Smart Booking confirmations, payment reminders, and session alerts (in-app and email).
- Image processing: To compress and store your profile photo for display on your account and public Smart Booking pages.
- Product improvement: To understand usage patterns and improve features (anonymized data only).
- Legal compliance: To comply with applicable laws and respond to lawful requests.
4. Data sharing
We do not sell your personal data. We share data only with the following service providers, strictly to operate Grix:
- Supabase (database & file storage, EU region) — stores your account data, client records, sessions, and uploaded files.
- Vercel (application hosting, EU deployment — Paris region) — serves the application and runs server-side logic.
- Web2Fly SMTP (transactional email via Infomaniak) — delivers Smart Booking confirmations, session reminders, and account notifications.
- Upstash (rate limiting) — processes anonymized request metadata to protect against abuse.
All sub-processors maintain appropriate data protection standards and process data within the EU or under adequate safeguards (Standard Contractual Clauses).
If you connect Google Calendar, Grix exchanges the data described in section 5c with your Google account, at your request. Google is not a Grix sub-processor: it is your own Google account, governed by Google's privacy policy.
5. Data retention & deletion
We retain your data for as long as your account is active. When you delete your account (Settings → Delete Account):
- All personal data is permanently and immediately erased — including your profile, clients, sessions, Smart Bookings, availability, and uploaded files.
- An anonymized audit log entry is kept to confirm the deletion occurred.
- This action is irreversible. There is no recovery period.
Certain records may be retained where required by law (e.g., billing records under applicable tax regulations).
5b. Advertising data
When you accept marketing cookies, Grix may collect and share limited data with Google Ads and Meta (Facebook / Instagram) to measure the effectiveness of our advertising campaigns.
What we collect
- Ad click identifiers (gclid, fbclid) stored in first-party cookies on your device when you arrive via an ad.
- UTM parameters (source, medium, campaign) if present in the URL of your landing page.
How it is shared
- Your email address is hashed with SHA-256 before any transmission. The original address is never sent to ad platforms.
- Click identifiers are sent alongside conversion events (account creation, subscription purchase) via server-to-server APIs (Google Ads Enhanced Conversions, Meta Conversions API).
- No browsing history, session content, or coach/client data is shared with ad platforms.
Your opt-out
You can withdraw your marketing cookie consent at any time via the cookie banner. Revoking consent prevents future pixel loads and conversion sends. Previously transmitted conversion data cannot be deleted from ad platform servers — contact contact@web2fly.com to request a manual opt-out from our conversion lists.
5c. Google Calendar
Connecting Google Calendar is optional: Grix works without it. If you connect it (Settings → Integrations), Grix accesses the Google data below, only for the features described in this section.
Data Grix accesses
- Events created by Grix (
calendar.events.ownedpermission): Grix creates, updates and deletes, in your primary Google calendar, the events that match your Grix sessions. Grix never reads, changes or deletes your other events. - Your busy times (
calendar.freebusypermission, optional on Google's screen): only the time intervals when you are busy (start and end). Grix never sees the title, attendees, description or location of your own events. - Your Google account email address (
openidandemailpermissions): to show you which account is connected.
Why
- To show your Grix sessions in your Google Calendar and keep them up to date (time, location, cancellation). These events are private and never contain your clients' contact details or your notes; a pending booking request shows as "tentative".
- To avoid offering a slot on your booking pages when you are already busy in Google Calendar.
Storage and security
- The OAuth tokens that give access to your calendar are encrypted (AES-256-GCM) before being stored in our database (EU). Grix also stores the email address of the connected account, the permissions granted, and the technical id of each event it created, so it can update or delete it.
- Your busy times are not stored: they are read when a booking page is computed, then kept for a few minutes at most in an in-memory cache to limit calls to Google.
Limited use
- Google data is only used for the features described above, which you can see in Grix.
- We do not sell this data and do not transfer it to anyone, except to our hosting providers (section 4) to run these features, or when the law requires it.
- It is never used for advertising, nor to train artificial intelligence or machine learning models.
- No one at Grix reads it, except with your explicit consent (for example for a support request), for security purposes, or to comply with the law.
Grix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revocation and deletion
- In Grix: Settings → Integrations → Google Calendar → Disconnect. Grix removes upcoming Grix events from your Google Calendar, revokes its access with Google and erases the tokens. Past events stay in your calendar as history.
- In your Google account: remove Grix's access at myaccount.google.com/permissions. Grix can then no longer access your calendar; the now unusable tokens are erased when you disconnect Google Calendar in Grix or delete your account.
- Account deletion: deleting your Grix account also removes upcoming Grix events from your Google Calendar, revokes the access and erases the tokens.
6. Your rights
Depending on your location, you have the following rights regarding your personal data:
For all users
- Access — View and export your personal data at any time (Settings → Export My Data). Your data is exported as a JSON file.
- Correction — Edit your profile, client records, and session details at any time through the application.
- Deletion — Permanently delete your account and all associated data (Settings → Delete Account).
- Portability — Download a machine-readable copy of all your data (JSON export).
Additional rights for European users (GDPR)
- Object to processing for marketing purposes.
- Restrict processing in certain circumstances.
- Lodge a complaint with your local data protection authority (e.g., CNIL in France).
Additional rights for California residents (CCPA/CPRA)
- Know what personal information is collected and how it is used.
- Delete your personal information.
- Opt-out of the sale of personal information — we do not sell your data.
- Non-discrimination — We will not treat you differently for exercising your privacy rights.
To exercise any of these rights, use the built-in tools in Settings or contact us at contact@web2fly.com.
7. Security
We implement industry-standard security measures including:
- Encryption at rest and in transit (TLS 1.3).
- Row-Level Security (RLS) ensuring strict data isolation between coaches — no coach can access another coach's data.
- Rate limiting on all API endpoints to prevent abuse.
- Server-side input validation (Zod) on all forms and actions.
- Content Security Policy (CSP) headers to prevent cross-site scripting.
- Regular security assessments and code audits.
8. International data transfers
Your data is processed and stored in the EU: database and file storage with Supabase, application hosting with Vercel (Paris region). No transfer outside the EU for core processing.
9. Children's privacy
Grix is not directed at children under 16. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us immediately.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision. Continued use after changes constitutes acceptance.
11. Contact
For privacy-related inquiries:
Web2Fly
Email: contact@web2fly.com
Website: web2fly.com