Version française : Politique de confidentialité

Privacy Policy

Version 2.2 · Last updated: July 26, 2026 · Drafted in accordance with GDPR (EU), Quebec Law 25, and PIPEDA (Canada). The French version is the binding reference; this English version is provided for convenience.

In one sentence

OwnDesk only stores what is necessary to run your gym (account, bookings, payments, athletic performance, community). No reselling, no third-party advertising tracking, no sharing with marketing partners. Ever.

1. Data controller

OwnDesk is a trademark operated by Fabien Barcelo, self-employed in Canada. Official contact: support@owndesk.co. Mailing address: 3040, rue de la Comtesse, Laval (Québec) H7E 0H8, Canada.

For the data of members of a gym located in the European Union, the controller is the gym itself, established in the Union, and OwnDesk acts as a processor on its instructions. OwnDesk has not designated a representative within the meaning of Article 27 of the GDPR on that basis. This position is reviewed with each new client established in the European Union.

Roles differ depending on the processing activity:

  • Data of a gym's members (profile, bookings, attendance, records and scores, follow-up notes, payments collected by the gym, community, messaging): the gym is the data controller, since it decides what information it collects and how it is used. OwnDesk acts as a processor, on the gym's instructions. For this data, your first point of contact is your gym; OwnDesk forwards any request sent to it directly.
  • Gym account and platform data (owner account, OwnDesk subscription contract and billing, security, support, internal usage measurement, commercial prospecting): OwnDesk is the data controller.

2. Person responsible for the protection of personal information

For any question regarding your data or to exercise your rights, contact the person responsible for personal information protection: support@owndesk.co (with “personal data” in the subject for priority). Response within 30 days. OwnDesk has not appointed a data protection officer within the meaning of Article 37 GDPR, as such an appointment is not required given its processing activities.

3. Data collected and legal bases

CategoryExamplesLegal basis (GDPR art.6)
IdentityName, email, phone, profile photoContract performance
Athletic activityBookings, attendance, PRs, goals, challengesContract performance
PaymentsTransaction history (amount, date, status). Card stored by Stripe only.Contract performance + legal obligation (taxation)
Declared healthSelf-declared health notes or injuries (explicit consent)Consent (GDPR art.9)
TechnicalServer logs (IP, user-agent), session cookiesLegitimate interest (security)
CommunicationsInternal messages, community posts, PR photosContract performance

4. Subprocessors (GDPR Article 28)

OwnDesk uses the following subprocessors:

SubprocessorUseLocation
SupabaseDatabase + authentication + file storageUnited States (us-east-1)
StripePayment processing (PCI-DSS Level 1)United States
VercelWeb hosting + CDNUnited States (iad1)
ResendTransactional emailsUnited States
SentryError observabilityUnited States
AnthropicArtificial intelligence features (Claude API): classification of internal messages sent to the gym, automated replies to text messages received by the gym, FR/EN translation of sessions, analysis of files during a migration from another software, internal triage of technical errors, drafting and classification of commercial prospecting emails. Identifying data (name, email, phone) is masked before sending when analysing a migration file.United States

Most of our subprocessors host and process data in the United States: Supabase (database, authentication, file storage), Vercel (web hosting), Sentry (error observability), Resend (transactional emails), Stripe (payments) and Anthropic (artificial intelligence features). These processing operations outside Quebec involve a transfer of personal information outside Quebec, the European Union and Canada. To frame it, OwnDesk relies on the Standard Contractual Clauses of the European Commission (SCC 2021) as well as applicable adequacy decisions.

5. Retention period

  • Active account: as long as the account is in use.
  • Account deletion: your profile is anonymized immediately (name, email address, phone, photo and biography erased) and access is permanently revoked. Booking and payment history is kept in anonymized form for the gym's accounting obligations.
  • Technical logs: retained according to the retention periods of our hosting and monitoring providers. Internal audit logs (support access, billing events, import events) are kept with no retention limit set to date.
  • Tax and transactional data: retained for as long as required by applicable accounting and tax obligations.
  • Self-declared health notes: deletable at any time from the profile. Otherwise kept for the duration of the account.
  • Photos and community posts: deletable at any time.
  • After deletion of an account linked to a gym: if amounts are still owed to the gym at the time of deletion, an identity record (name, email address, phone) is retained so the gym can recover them. That record is erased as soon as the amount is settled or the gym writes it off. Where nothing is owed, no record is created.

6. Your rights

In accordance with GDPR and Quebec Law 25, you can at any time:

  • Access your data from your OwnDesk profile (JSON export).
  • Rectify via your profile settings.
  • Delete (“right to be forgotten”): from the profile or by email to support@owndesk.co. Processed within 30 days, except for legal retention obligations. Owner accounts of a gym with active members cannot be deleted in self-service and must request it at support@owndesk.co.
  • Portability: receive your data in a structured, machine-readable format (JSON).
  • Restrict or object to processing: write to us with the reason.
  • Withdraw your consent at any time (especially for health notes).
  • Complaint: with the CAI (Quebec Access to Information Commission) or the data protection authority of your country.

7. Data breach notification

In the event of a personal data breach likely to pose a risk to your rights, OwnDesk notifies:

  • the CNIL or the competent supervisory authority of the European Union within 72 hours of becoming aware of it (GDPR, Art. 33);
  • the Commission d'accès à l'information du Québec promptly where the incident presents a risk of serious injury (Quebec Law 25);
  • the Office of the Privacy Commissioner of Canada as soon as feasible where the breach presents a real risk of significant harm (PIPEDA);
  • affected Users without unreasonable delay, by email, describing the nature of the breach, likely consequences, and measures taken.

8. Cookies and trackers

OwnDesk uses three categories of trackers. First, strictly necessary cookies for the operation of the Service, exempt from consent:

  • login session (Supabase auth): session duration, or 30 days if “remember me” is enabled;
  • UI preferences (dark mode, language): 1 year, deletable from the browser.

No analytics tracker. OwnDesk uses no audience measurement: no PostHog, no Google Analytics, no equivalent. No profiling, no journey tracking, no sharing for advertising purposes. There is therefore nothing to consent to, and no cookie banner: the only files stored are those listed above, strictly necessary to operate. For any question, write to support@owndesk.co.

Our error monitoring tool receives the error message, the technical stack trace and the page involved. It records no session video and transmits neither IP address nor request header. This monitoring relies on our legitimate interest in the security and continuity of the Service.

Finally, a performance measurement of pages (load time, responsiveness). It sets no cookie and writes nothing on your device. It only receives the path of the page you visited, without address parameters and without any identifier that would let us recognise you from one visit to the next.

On payment pages, our payment provider's script is loaded from its own domain and sets its own trackers, necessary for fraud prevention.

In all cases, no third-party advertising tracking is used (Google Ads, Meta Pixel, TikTok…).

9. Minors

The age at which a person can consent alone to the processing of their data varies by jurisdiction: 14 in Quebec under Law 25, and between 13 and 16 in the European Union depending on the Member State (15 in France). Below that threshold, the consent of the holder of parental responsibility is required. The Owner of a gym warrants that they collect this consent for underage Members before inviting them to the Platform.

10. Access by OwnDesk personnel (support)

For technical support, troubleshooting, and the security of the Platform, the publisher of OwnDesk may access the account of a gym's Owner and view their interface as they see it. This access is configured to prevent any action on their behalf.

  • Purpose: support, troubleshooting, and security only. No use for marketing or profiling.
  • Scope: access restricted to the publisher (Fabien Barcelo), sole holder of administrator credentials, protected by two-factor authentication and time-limited.
  • Logging: accesses are recorded in an internal register (who accessed, which account, when, and for how long), in line with the accountability principle.
  • Your rights: you may request the log of support accesses made to your account by writing to support@owndesk.co.

11. Changes

This policy may change. Each version is published on this page, and the “last updated” date at the top of the document is authoritative. If a change is substantial, we invite you to read it again: continued use of the Service means you have been informed.

See also the terms of service.