W.ALLFIT PRIVACY POLICY
January 2026
Women All Fit SARL
Bd Lala Yacout et Rue Al-Arar, Immeuble 9, 4ème étage, Appartement 17
Résidence Calis, Sidi Belyout, Casablanca, Morocco
Email: team@w-allfit.com
This Privacy Policy complies with Moroccan Law 09-08 on Personal Data Protection and Moroccan Law 31-08 on Consumer Protection.
ARTICLE 1: DATA CONTROLLER
The data controller is Women All Fit SARL, a company incorporated under Moroccan law:
Address: Bd Lala Yacout et Rue Al-Arar, Immeuble 9, 4ème étage, Appartement 17, Résidence Calis, Sidi Belyout, Casablanca, Morocco
Email: team@w-allfit.com (Data Protection Inquiries)
ARTICLE 2: CNDP REGISTRATION
[PENDING - Authorization application in progress. This section will be updated with the CNDP authorization number upon approval.]
As required by Moroccan Law 09-08, we are in the process of obtaining prior authorization from the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) for processing health-related data.
ARTICLE 3: DATA WE COLLECT
3.1 Account Data: Email address, password (encrypted), name (optional), phone number (optional).
3.2 Age Verification Data: Date of birth (required), age confirmation checkbox status. We collect this to verify you meet our minimum age requirement of 18 years. We may request additional identity verification documents if needed.
3.3 Profile Data: Age, weight, height, fitness goals, workout preferences, dietary restrictions.
3.4 Fitness Data: Workout history, exercise preferences, progress photos (optional).
3.5 Nutritional Data: Meal preferences, dietary restrictions, meal tracking.
3.6 Location Data: If enabled, approximate location for workout suggestions. You can disable this in device settings.
3.7 Biometric Data: If you upload progress photos with facial recognition features, we may process biometric identifiers. EXPLICIT CONSENT REQUIRED: We will obtain your separate, explicit consent before processing any biometric data. You may withdraw this consent at any time through your account settings.
3.8 Payment Data: Subscription status, purchase history, payment dates. Note: We do NOT store your full credit card number. Payment processing is handled by Apple (iOS) or LemonSqueezy (Android/Web).
3.9 Technical Data: Device type, operating system, app version, IP address, usage analytics.
3.10 Accessibility Preferences: Any accessibility settings you configure (text size, contrast preferences, notification preferences).
ARTICLE 4: HOW WE USE YOUR DATA
4.1 Service Delivery: Providing personalized workouts and meal plans.
4.2 Account Management: Managing your subscription and preferences.
4.3 Age Verification: Verifying that users meet our minimum age requirement of 18 years.
4.4 Improvement: Analyzing usage to improve the Application, including accessibility features.
4.5 Communication: Sending service updates, renewal reminders, and promotional content (with consent).
4.6 Legal Compliance: Complying with Moroccan law and responding to legal requests.
4.7 Safety: Ensuring the security and integrity of the Application.
ARTICLE 5: LEGAL BASIS FOR PROCESSING
Under Moroccan Law 09-08:
5.1 Contract Performance: Processing necessary to provide our services.
5.2 Consent: For health data, marketing communications, and sharing with third parties.
5.3 Legitimate Interest: For analytics, fraud prevention, age verification, and service improvement.
5.4 Legal Obligation: Compliance with Moroccan commercial and tax laws.
ARTICLE 6: CONSENT REQUIREMENTS
6.1 Health Data: We obtain explicit consent before processing any health or fitness data.
6.2 Marketing: Marketing communications require your explicit opt-in consent.
6.3 Third-Party Sharing: We will obtain your consent before sharing data with third parties for their own purposes.
6.4 Withdrawal: You may withdraw consent at any time by contacting team@w-allfit.com or through app settings.
ARTICLE 7: PAYMENT PROCESSING
7.1 iOS Payments (iPhone only; iPad not supported): Processed by Apple via In-App Purchase in USD. We receive only transaction confirmations, not your card details. Apple's privacy policy governs their processing.
7.2 Android/Web Payments: Processed by LemonSqueezy in MAD. We receive only transaction confirmations, not your full card number. LemonSqueezy's privacy policy governs their processing.
ARTICLE 8: DATA SHARING
We share data with:
(a) Payment Processors: Apple and LemonSqueezy for payment processing.
(b) Cloud Providers: For secure data storage.
(c) Analytics Services: Firebase for anonymized usage analytics.
(d) Legal Authorities: When required by Moroccan law.
All service providers are contractually required to:
- Maintain confidentiality;
- Implement appropriate security measures;
- Use data only for specified purposes;
- Comply with applicable data protection laws.
ARTICLE 9: THIRD-PARTY SERVICES
9.1 Third-Party Services: The Application may integrate with third-party services in the future. This Privacy Policy will be updated accordingly.
9.2 Third-Party Privacy: Any third-party services will be governed by their own privacy policies. We encourage you to review those policies.
9.3 Data Sharing Commitment: We will NOT share your health or fitness data with third parties for advertising, marketing, or data brokering purposes.
ARTICLE 10: INTERNATIONAL DATA TRANSFERS
10.1 Transfer Locations: Your data may be transferred to and processed in countries outside Morocco, including EU Member States and the United States (for cloud infrastructure and payment processing).
10.2 Legal Basis: International transfers are made in compliance with Moroccan Law 09-08, Article 43, based on: (a) transfers to countries with adequate protection (EU, EEA, UK, Canada, Switzerland); (b) your explicit consent; or (c) CNDP authorization with appropriate safeguards.
10.3 Safeguards: We implement standard contractual clauses and appropriate technical measures to protect your data during international transfers.
ARTICLE 11: DATA RETENTION
Account Data: Duration of account activity + 3 years.
Age Verification Data: Duration of account activity + 3 years (required for legal compliance).
Health/Fitness Data: Subscription duration + 1 year.
Payment Data: 10 years (Moroccan commercial law requirement).
Backup Deletion: Within 90 days of primary data deletion.
ARTICLE 12: DATA SECURITY
We implement:
- TLS 1.3 encryption in transit;
- AES-256 encryption at rest;
- Bcrypt password hashing;
- Access controls and authentication;
- Regular security audits;
- Employee training on data protection.
ARTICLE 13: YOUR RIGHTS (Moroccan Law 09-08)
Under Moroccan Law 09-08, you have the right to:
13.1 Right of Access (Article 7): Request confirmation of whether we process your data and obtain a copy.
13.2 Right of Rectification (Article 8): Request correction of inaccurate data. WE COMMIT TO RESPONDING WITHIN TEN (10) CLEAR DAYS as required by law.
13.3 Right of Objection (Article 9): Object to processing for legitimate reasons or for direct marketing.
13.4 Right of Deletion: Request deletion of your data, subject to legal retention requirements.
13.5 How to Exercise Your Rights: Contact team@w-allfit.com with proof of identity.
13.6 CNDP Complaint: You may lodge a complaint with the CNDP at www.cndp.ma.
ARTICLE 14: ANALYTICS AND TRACKING
14.1 We use Firebase Analytics for anonymized usage analytics.
14.2 iOS App Tracking Transparency: We comply with Apple's ATT framework. You will be prompted to allow or deny tracking when you first use the app.
14.3 Opt-Out: You can opt out of analytics in your device settings or within the app.
ARTICLE 15: PUSH NOTIFICATIONS
15.1 Permission: We request your permission before sending push notifications.
15.2 Types: Workout reminders, motivational messages, subscription renewal alerts, app updates.
15.3 Control: You can enable/disable notifications in app settings or device settings.
ARTICLE 16: CHILDREN'S PRIVACY
16.1 Age Restriction: The Application is strictly for users 18 years of age and older. We do not knowingly collect data from anyone under 18.
16.2 Age Verification: We require date of birth confirmation and an age verification checkbox during registration.
16.3 Reporting Underage Users: If you believe a user is under 18, please report to team@w-allfit.com.
16.4 Action on Discovery: If we discover that we have collected data from a user under 18, we will immediately terminate their account and delete their data.
ARTICLE 17: ACCESSIBILITY DATA
17.1 We collect accessibility preferences you set within the app to provide you with a better experience.
17.2 This data is used solely to customize your app experience and improve our accessibility features.
17.3 Accessibility preference data is deleted when you delete your account.
ARTICLE 18: DATA BREACH NOTIFICATION
18.1 In the event of a data breach affecting your personal data, we will notify the CNDP as required by law.
18.2 We will notify affected users within 72 hours of becoming aware of a breach that poses a high risk to your rights and freedoms.
ARTICLE 19: CHANGES TO THIS POLICY
19.1 We will notify you of material changes 30 days in advance via email and/or in-app notification.
19.2 SENSITIVE DATA CHANGES: Any changes affecting the processing of health data, biometric data, or international transfers will require your separate, explicit consent before taking effect. You may refuse such changes, and your refusal will not affect the services you receive under the existing policy.
ARTICLE 20: CONTACT
Data Protection Contact:
Women All Fit SARL
Bd Lala Yacout et Rue Al-Arar, Immeuble 9, 4ème étage, Appartement 17
Résidence Calis, Sidi Belyout, Casablanca, Morocco
Email: team@w-allfit.com
CNDP Contact:
Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel
Website: www.cndp.ma
Last Updated: January 2026
Last Updated: January 2026