Privacy Policy
This policy outlines the type of data collected when using the «BEBEST» Application, how it is used and how it is shared.
The Director of publication of this application is:
Mr. Clément RIGAL (Président) and Mrs. Anaïs ROLLAND (CEO — Directrice Générale)
E-mail: info@bebestapp.com
Siret number: [SIRET À COMPLÉTER — immatriculation en cours]
This site comes under the international treaties and the French legislation on royalties and intellectual property and is in conformity with the provisions of Law No. 2004-575 of June 21, 2004 for Confidence in the Digital Economy.
This page is used to inform visitors regarding our policies with the collection, use, and disclosure of Personal Information if anyone decides to use our Service.
If you choose to use our Service, then you agree to the collection and use of information in relation to this policy. The Personal Information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.
The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at BeBest unless otherwise defined in this Privacy Policy.
Principle of anonymous data use
The legal basis for data protection can be found in the General Data Protection Regulation (GDPR).
When you access our Apps, some information, such as IP address, is transferred. You are also providing information about the end device used (smartphone, tablet, etc.), time of visit to the app, the so-called referrer and volume of data transferred.
We cannot use this data to identify an individual user. We only use this information to determine how attractive our offers are and to improve their performance or content, if necessary, and make their design even more appealing to you.
Collection and processing of personal data
We only collect personal data if you provide it to us, for example when you contact us, in particular by registering a BeBest account, placing an order, requesting information or publishing personal data in our BeBest App in your profile. We use the personal data you provide only to the extent that your data is necessary for rendering or processing our services.
We store your data for as long as is necessary to achieve the intended purpose or until you delete your account or for as long as legal retention periods require data to be stored. Your data is subsequently deleted in accordance with legal requirements or processing is restricted.
In the case of use purely for information, i.e. if you do not register or send us information another way, we only collect personal data which your browser transfers to our servers.
The personal data collected via the Application, website and BEBEST platform are as follows:
- Create an Account: when creating the User's account, his name, first name, e-mail address and date of birth.
- Login: when the User logs on to the Application and platform, they shall record, in particular, his/her surname, first name, login, usage, location and payment details.
- Profile: using the benefits provided on the Application allows you to fill in a profile, including surnames, forenames, date of birth, gender, list of all exercises performed by the User, list of favorite exercises, sport(s) practiced by the User, preferred session duration, available equipment, targeted muscle groups.
- Payment: in connection with the payment of products and services offered on the Application and the platform, they record financial data relating to the User's bank account or credit card.
Using our login system, you can create a BeBest account for yourself that you can use to log in to the App. In the process, we use cookies – small files – on your browser in order to identify you. All data that you enter into your account is stored within a database with the provider named below.
Information Collection and Use
For a better experience, while using our Service, we may require you to provide us with certain personally identifiable information. The information that we request will be retained on your device and is not collected by us in any way.
The app does use third party services that may collect information used to identify you.
Link to privacy policy of third party service providers used by the app:
- Google Play Services
- Google Analytics for Firebase
- Firebase Crashlytics
Registering with Google
We also offer you the opportunity to create your BeBest account using your Google account, or to link your BeBest account to your Google account. You can register or log in to BeBest using your Google account if you simply use Google instead of the other options while registering your BeBest account. You will then be forwarded to Google (where you must be logged in or require an account) and receive an explanation of which of your data we need from Google, namely your public profile information such as first and last name, gender, and the email address you are using there. This information is required for identification purposes in order to create a secure BeBest account for you. Your Google account and your BeBest account will be permanently linked using your email address. We store your email information in-house and will send you information using this address as needed. We can also tell that you have logged in using Google. As soon as you log in to Google, you can log in to BeBest. We will not submit any information on you to Google without your consent.
Important: We do not record your Google login data in any way, and cannot post anything to your Google profile without your having expressly consented to this.
You can learn how Google handles privacy settings using Google's privacy policy and terms of use; these also include the applicable conditions for the previously specified option of logging in and registering to BeBest.
Registration with Apple
You can also register and log in using the «Apple Login» function from your Apple account. When you log in with your Apple ID for the first time, the app will prompt you to enter your name and your email address so that an account can be set up for you. We store your email information in-house and will send you information using this address as needed. You will not be tracked by Apple and a profile of you will not be created while you are using the «Register with Apple ID» function. Apple only collects information required for you to log in and manage your account.
You will stay logged into our app automatically as long as you stay logged in on your device.
Use of personal data
The purpose of the personal data collected from Users is to provide BEBEST Application related services, improve them and maintain a secure environment. Specifically, the uses are as follows:
- Access and use of the Application by the User and related services;
- Management of the functioning, optimization and improvement of the Application and the platform;
- Organisation of the terms of use of payment services;
- Verification, identification and authentication of data transmitted by the User;
- Implementation of user support;
- Fraud prevention and detection, malware and security incident management; management of possible disputes with Users;
- Sending commercial and advertising information, according to the User's preferences.
| Data | Purpose of processing | Legal basis of processing | Storage period |
|---|---|---|---|
| First name | Direct address & presentation | Performing the contractual relationship | Up to 30 days after deletion of the customer account |
| Last name | Direct address & presentation | Performing the contractual relationship | Up to 30 days after deletion of the customer account |
| Email address | Customer account identification | Performing the contractual relationship | Up to 30 days after deletion of the customer account |
| Password | Customer account identification | Performing the contractual relationship | Up to 30 days after deletion of the customer account |
| IP address at login | Data transfer at registration to web server | Performing the contractual relationship | 13 months |
| Gender | Suitable user experience | Performing the contractual relationship | 13 months |
Google Analytics
We use the Google Analytics service from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) to analyze our website visitors. Google uses cookies to track the use of the online product or service by users and the information is generally transferred to a Google server in the USA and stored there.
Google will use this information on our behalf to evaluate the use of our online products and services by users, to compile reports on the activities within these online products and services and to provide us with further services associated with the use of these online products and services and the use of the internet. Pseudonymous user profiles can be created from the processed data.
We use Google Analytics only with IP anonymization enabled. This means that Google will truncate the IP address of users within Member States of the European Union or in other states that are party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. The IP address transmitted by the user's browser is not merged with other Google data. Users can prevent cookies from being stored by adjusting the settings to their browser software accordingly. We have made data protection friendly default settings.
The legal basis for the use of this service is Art. 6 paragraph 1 sentence 1 letter f GDPR. Users can prevent the collection of data generated by cookies by downloading and installing the available browser plug-in. As a guarantee pursuant to Art. 44 ff of the General Data Protection Regulation (GDPR), Google has signed the EU standard contractual clauses. For more information on data processing by Google Analytics, please refer to the privacy policy of the provider.
Firebase by Google
We use the Firebase service from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) in order to derive application behavioral analytics. We use that information to see how users interact with our website and app.
Firebase is part of the Google Cloud Platform and offers numerous services for developers. Some Firebase services process personal data. In most cases, the personal data is limited to so-called «Instance IDs», which are provided with a time stamp. These «Instance IDs» assigned by Firebase are unique and thus allow the linking of different events or processes. This data does not represent personally identifiable information for us, nor do we make any efforts to personalize it subsequently. We process these aggregated data to analyze and optimize usage behavior, for example by evaluating crash reports.
Currently, we use the following Firebase services:
- Google Analytics for Firebase: Google Analytics uses the data to provide analytics and attribution information. The precise information collected can vary by the device and environment. Google Analytics retains ID-associated data for 60 days, and retains aggregate reporting and campaign data without automatic expiration, unless the Firebase customer changes their retention preference in their Analytics settings or deletes their project. For Analytics for Firebase, Google uses not only the «Instance ID» described above, but also the advertising ID of the end device. You can restrict the use of the advertising ID in the device settings of your mobile device. For Android: Settings > Google > Ads > Reset Ad ID. For iOS: Settings > Privacy > Advertising > No ad tracking.
- Firebase Remote Config: Remote Config uses Instance IDs to select configuration values to return to end-user devices. Firebase retains Instance IDs until the Firebase customer makes an API call to delete the ID. After the call, data is removed from live and backup systems within 180 days.
- Firebase Dynamic Links: Dynamic Links uses device specs on iOS to open newly-installed apps to a specific page or context. Dynamic Links only stores device specs temporarily, to provide the service.
- Firebase Cloud Messaging: Firebase Cloud Messaging is used to transmit push messages or so-called in-app messages (messages that are only displayed within the respective app). A pseudonymized push reference is assigned to the mobile device, which serves as a target for the push messages or in-app messages. The push messages can be deactivated and reactivated at any time in the settings of the mobile device. Firebase Cloud Messaging uses Instance IDs to determine which devices to deliver messages to. Firebase retains Instance IDs until the Firebase customer makes an API call to delete the ID. After the call, data is removed from live and backup systems within 180 days.
- Firebase Realtime Database: Realtime Database uses IP addresses and user agents to enable the profiler tool, which helps customers understand Firebase usage patterns and platform failures. Realtime Database retains IP addresses and user agent information for a few days, unless a customer chooses to store it for longer.
- Firebase Cloud Storage: Cloud Functions uses IP addresses to perform event management and HTTP functions according to the end user's actions. Cloud Functions only records IP addresses temporarily, to provide the service.
- Firebase Crashlytics: Firebase Crashlytics uses stack traces to associate crashes with a project, send email alerts to project members and display them in the Firebase console, and report crashes to Firebase clients. It uses Crashlytics installation UUIDs to measure the number of users affected by a crash and minidump data to process NDK crashes. The minidump data is stored while the crash session is being processed and then deleted. Refer to the stored device information examples for more details on the types of user information collected. Firebase Crashlytics retains crash stack traces, extracted minidump data, and associated identifiers (including Crashlytics installation UUID) for 90 days.
- Firebase Hosting: Hosting uses IP addresses of incoming requests to detect abuse and provide customers with detailed analysis of usage data. We keep the IP hosting data for a few months.
Firebase will use this information on our behalf for the above mentioned reasons.
The legal basis for the use of this service is Art. 6 paragraph 1 sentence 1 letter f GDPR. As a guarantee pursuant to Art. 44 ff of the General Data Protection Regulation (GDPR), Google has signed the EU standard contractual clauses.
Sharing personal data with third parties
Personal data may be shared with third party companies in the following cases:
- When the User uses the payment services, for the implementation of these services, the platform puts the User in touch with third party banking and financial companies with which it has concluded a contract.
- When the platform uses the services of service providers to provide user support, payment services and possible advertising. These service providers have limited access to the User's data in connection with the performance of these services and have a contractual obligation to use them in accordance with the provisions of the applicable regulations on the protection of personal data.
- If required by law, the platform can carry out data transmission to follow up on claims against the platform and comply with administrative and judicial procedures.
- If the platform is involved in a merger, acquisition, sale of assets or receivership, it may be required to sell or share all or part of its assets, including personal data. In this case, the Users will be informed before personal data are transferred to a third party.
Transfer of personal data
Due to the organization of the company responsible for the platform, possibly within an international group, the User authorizes the platform and BeBest to transfer, store and process its information in the United States. The laws in force in this country may differ from those applicable in the User's place of residence within the European Union. By using the platform or BEBEST Application, the User consents to the transfer of his/her personal data to the United States.
The platform remains responsible for personal data that is shared with third parties under the Standard Contractual Clauses (SCC).
The platform guarantees to respect the highest level of security for the transfer of personal data to the United States.
Security and confidentiality
The platform implements organizational, technical, software and physical measures in digital security to protect personal data against unauthorized alteration, disruption and access. In order to meet this commitment, BEBEST uses the services of third-party companies specialized in the storage and security of digital data. However, it is important to note that the Internet is not a completely secure environment and the platform cannot guarantee the security of transmission or storage of information on the Internet.
Implementation of Users' rights
In accordance with the regulations applicable to personal data, Users have the following rights:
- They can update or delete their personal data by logging in to their account and configuring the account settings.
- They can delete their account by accessing their profile on the BEBEST Application or by writing to: info@bebestapp.com
- They can exercise their right of access, to know the personal data concerning them, by writing to the following e-mail address: info@bebestapp.com. In this case, prior to the implementation of this right, the platform may request proof of the User's identity in order to verify its accuracy.
- If the personal data held by the platform are inaccurate, they may request an update of the information by accessing their profile on the BEBEST Application or by writing to the following e-mail address: info@bebestapp.com
- Users may request the deletion of their personal data in accordance with applicable data protection laws by writing to the following e-mail address: info@bebestapp.com
Evolution of the privacy and personal data protection policy
The platform reserves the right to make any changes to this clause relating to the protection of personal data at any time. If a modification is made to this clause, the platform undertakes to publish the new version on its Application. It will also inform the User of the change by e-mail, within a minimum of 15 days before the effective date. If the User does not agree with the terms of the new wording of the personal data protection clause, he/she may delete his/her account and unsubscribe from the services offered by BEBEST.
Guarantee
With regard to the protection of personal data, the User acknowledges that he/she is solely responsible for the use he/she makes of the BEBEST Application and the information he/she shares. It is also the responsibility of any User to take all appropriate measures to protect his/her own data and/or software stored on his/her computer and telephone equipment against any damage. BeBest shall in no way be held legally liable for damages of any kind caused to Users, their terminals, computer and telephone equipment and data stored therein, nor for any consequences that may result from this on their personal, professional or commercial activities.