Privacy Policy
Effective Date: August 8, 2026
Point Chalet, LLC, a California limited liability company doing business as "Switchback" ("Switchback," "we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Switchback website, mobile app, watch app, and related services (the "Service").
By using the Service, you consent to the practices described in this Privacy Policy. Please also review our Terms of Service, which govern your use of the Service.
1. Data Controller
For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, the Data Controller is:
Point Chalet, LLC d/b/a Switchback
A California limited liability company
1401 21st St, Ste R, Sacramento, CA 95811
Email: support@switchback.fit
Point Chalet, LLC d/b/a Switchback is responsible for deciding how your personal information is collected, used, and protected in connection with the Service.
2. Information We Collect
We collect only the information necessary to provide and improve the Service. The specific categories of data we collect are:
2.1 Account Information
- Email address -- required for account creation, authentication, and communication
- Display name -- optional, used for personalization within the Service
2.2 Workout and Program Data
- Program and schedule -- the program you choose to track, the day you start on, and your position in the program
- Workout logs -- the exercises, reps, weights, and completion data you record, used to track your progress and recall your previous numbers
- History and calendar -- your completed workouts and the days you have finished
2.3 Device Pairing Data
- Paired-device records -- when you pair a Garmin watch, we store a device pairing token and basic device information (such as the model and a label you can set) so the watch can sync securely with your account
2.4 Billing Data
- Trial and subscription status -- your trial start and end, selected billing interval, and access status
- Stripe customer identifier -- a reference ID used to link your account to your Stripe payment record
2.5 Consent Records
- Consent timestamps -- when you accepted the Terms of Service and Privacy Policy
- Consent version identifiers -- which version of the Terms and Privacy Policy you accepted
3. Information We Do Not Collect
Transparency about what we do not collect is equally important. Switchback does not collect:
- Payment card information -- all payment data is handled entirely by Stripe, our payment processor. We never see, store, or have access to your credit card numbers, expiration dates, or security codes.
- Heart-rate and detailed activity metrics -- when you complete a workout on a Garmin watch, metrics such as heart rate, calories, and training effect are recorded to your Garmin account through Garmin Connect. That data is handled by Garmin, not by Switchback (see Section 6).
- Advertising or cross-context tracking data -- we do not build advertising or behavioral profiles
We do not use any cookies beyond those strictly necessary for authentication (see Section 13).
4. How We Use Your Information
We use your information solely for the following purposes:
- Account authentication -- verifying your identity when you sign in to the Service and authenticating your paired devices
- Providing tracking -- storing your workout logs, recalling your previous numbers, and syncing your data across the web, your phone, and your watch
- Billing -- managing your subscription and coordinating with Stripe for payments
- Service improvement, security, and abuse prevention -- maintaining the reliability, performance, and security of the Service
We do not use your information for advertising or ad targeting, remarketing or behavioral profiling, sale to third parties, or any purpose unrelated to providing and improving the Service.
5. Third-Party Processors
We share your information only with the following third-party service providers, each of which processes data solely on our behalf and in accordance with our instructions:
| Processor | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Google Cloud / Firebase | Authentication (Firebase Auth), database (Firestore), Cloud Functions, push notifications (Firebase Cloud Messaging), and web hosting | Email address, display name, workout and program data, paired-device records, and subscription data | Firebase Privacy |
| Stripe | Payment processing and subscription management | Email address (for receipts and invoicing). Payment card information is provided directly to Stripe by you and is never transmitted through our systems. | Stripe Privacy Policy |
| SMTP2GO | Transactional email delivery (account emails, billing and renewal notices, terms update notices) | Email address (for delivery only) | SMTP2GO Privacy Policy |
We do not share your information with any other third parties. We do not sell, rent, or trade your personal information.
6. Garmin Devices and Garmin Connect
The Switchback watch app runs on your Garmin device. To use it, you pair your watch to your Switchback account and sync through the Garmin Connect Mobile app.
When you complete a workout on your Garmin watch, it is recorded as an activity in your Garmin account through Garmin Connect, which may include metrics such as heart rate, calories, and training effect. That activity data is collected and handled by Garmin under Garmin's own terms and privacy policy, not by Switchback. Switchback receives only the workout logs you record (such as the exercise, reps, and weight), which sync to your Switchback account.
Your use of Garmin devices, the Garmin Connect Mobile app, and your Garmin account is governed by Garmin's terms and privacy policy. Please review Garmin's policies to understand how Garmin handles your data.
7. Data Retention
We retain your information only for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
- Account information, workout and program data, and paired-device records -- retained for the duration of your account. Permanently deleted when you delete your account.
- Audit logs (account creation and deletion events) -- retained for a limited period for security and compliance, then automatically deleted.
- Stripe payment and invoicing records -- retained by Stripe in accordance with Stripe's data retention policies and as required for accounting, tax reporting, and legal compliance. These records persist even after account deletion because Switchback is legally required to maintain financial records.
8. Your Rights Under GDPR (EU/EEA Users)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation:
- Right of access (Art. 15) -- You have the right to request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) -- You have the right to request correction of inaccurate personal data.
- Right to erasure (Art. 17) -- You have the right to request deletion of your personal data ("right to be forgotten").
- Right to restriction of processing (Art. 18) -- You have the right to request that we restrict the processing of your personal data under certain circumstances.
- Right to data portability (Art. 20) -- You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21) -- You have the right to object to the processing of your personal data based on legitimate interests.
You may exercise these rights by:
- Using the "Download My Data" feature in your account settings (for access and portability)
- Using the "Delete Account" feature in your account settings (for erasure)
- Emailing support@switchback.fit for any rights request
We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.
9. Your Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know -- You have the right to know what personal information we collect, how we use it, and with whom we share it.
- Right to delete -- You have the right to request deletion of your personal information.
- Right to correct -- You have the right to request correction of inaccurate personal information.
- Right to opt-out of sale or sharing -- You have the right to opt out of the sale or sharing of your personal information.
- Right to non-discrimination -- We will not discriminate against you for exercising your privacy rights.
Switchback does not sell personal information. Switchback does not share personal information for cross-context behavioral advertising.
We do not offer financial incentives for the collection, sale, or deletion of personal information. To exercise your CCPA rights, use the "Download My Data" or "Delete Account" features in your account settings, or email support@switchback.fit.
10. Legal Basis for Processing (GDPR Art. 6)
We process your personal information based on the following legal grounds:
- Contract performance (Art. 6(1)(b)) -- Processing necessary to provide the Service you requested when you created an account, including account management, tracking your workouts, and subscription management.
- Legitimate interests (Art. 6(1)(f)) -- Processing necessary for our legitimate interests, including service improvement, fraud prevention, and security. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a)) -- Where we rely on your consent for specific processing activities. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
11. International Data Transfers
Switchback is based in the United States, and your data is processed and stored in the United States. Firestore data is stored in the United States multi-region (nam5). Backend services run in the Google Cloud us-central1 region.
If you access the Service from outside the United States, including from the European Union or European Economic Area, your personal data will be transferred to the United States. These transfers are governed by:
- Google Cloud / Firebase -- Google's Data Processing Addendum and standard contractual clauses for international data transfers
- Stripe -- Stripe's Data Processing Agreement and standard contractual clauses
- SMTP2GO -- SMTP2GO's data processing terms for email delivery
12. Children's Privacy
The Service is intended for adults and is not directed to anyone under the age of 18. We do not knowingly collect personal information from children under 16 years of age.
If we become aware that we have collected personal information from a child under 16, we will take immediate steps to delete that information from our systems. If you believe that a child under 16 has provided personal information to us, please contact us at support@switchback.fit.
13. Cookies and Tracking Technologies
Switchback uses essential authentication cookies only. These cookies are strictly necessary for the Service to function and are used solely for Firebase Auth session management (maintaining your logged-in state).
We do not use:
- Analytics cookies
- Marketing or advertising cookies
- Third-party tracking cookies or pixels
- Web beacons or similar tracking technologies
- Cross-site tracking of any kind
Under GDPR, strictly necessary cookies do not require explicit consent. However, we inform you of their use through our cookie notice. You can manage cookies through your browser settings, but disabling essential cookies may prevent you from using the Service.
14. Security
We implement specific technical measures to protect your information:
- HTTPS everywhere -- all communication between your device and our servers is encrypted using TLS
- Content Security Policy (CSP) -- prevents cross-site scripting attacks and unauthorized code execution
- HTTP Strict Transport Security (HSTS) with preload -- ensures your browser always connects via HTTPS
- Firebase security rules -- granular access controls ensure users can only access their own data
- Data encrypted at rest -- all data stored in Google Cloud is encrypted at rest using Google's default encryption
- Principle of least privilege -- access to systems and data is restricted to the minimum necessary for each component to function
- X-Frame-Options: DENY -- prevents the Service from being embedded in iframes on other sites
- Referrer-Policy -- controls what referrer information is sent with requests to protect your browsing privacy
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to implementing industry best practices.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will provide advance notice via email to the address associated with your account, update the "Effective Date" at the top of this Privacy Policy, and post the updated Privacy Policy on the Service. Your continued use of the Service after the notice period constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Point Chalet, LLC d/b/a Switchback, 1401 21st St, Ste R, Sacramento, CA 95811
Email: support@switchback.fit
If you are located in the European Union or European Economic Area, you also have the right to contact your local Data Protection Authority with questions or complaints about our data practices.