1. Who we are
The Noah coaching platform (the “Platform”, “Service”, or “Noah”), available at nfitcoach.com, is operated by N Fit Personal Training(“N Fit”, “we”, “us”, or “our”), a personal training business based in Penang, Malaysia. We are the data controller responsible for your personal data processed through the Platform.
For any privacy question or request, contact us at nfitptofficial@gmail.com. Our full contact details are at the end of this policy.
2. Scope
This policy applies to personal trainers (“Coaches”) and their clients (“Clients”) who use the Platform to manage coaching, scheduling, training programs, nutrition tracking, and payments. It covers the Noah web application and related services. It does not cover third-party services we integrate with, which have their own privacy policies (see Section 7).
3. Information we collect
3.1 Account & identity
- Name, email address, and the password you set (passwords are stored only as secure hashes by our authentication provider — we never see them in plain text).
- Account role (Coach or Client) and, for Clients, the Coach you are connected to.
- Optional profile details such as phone number, country, and time zone.
3.2 Coaching & training data
- Sessions and bookings — scheduled times, session history, delivery mode (online or in person), and service type.
- Workout data — exercises, sets, reps, weights, and notes recorded during sessions or homework.
- Nutrition logs you choose to record — foods, calories, macronutrients, water intake, and notes.
- Homework assignments and completions.
- Progress metrics you choose to record, such as body weight and strength tracking.
- Session sign-off signatures, where used to confirm a completed session.
- Feedback or bug reports you submit through the Platform.
Some of this is health- and fitness-related information that you voluntarily provide so your Coach can deliver the coaching service. You can choose what to record.
3.3 Google account data (optional sign-in)
If you choose “Continue with Google”, Google shares your basic profile (name, email address, and profile identifier) with us to create or sign you into your account. We do not receive your Google password.
3.4 Google Calendar data (optional integration)
If you connect Google Calendar, we access your calendar events to keep your training schedule in sync. See Section 4 for the full, detailed disclosure of what we access, why, and how we protect it.
3.5 Payment data
Payments for session packages are processed by Stripe. We do not collect or store your full card number or CVC — that is handled directly by Stripe. We retain records of your purchases, such as package, amount, currency (MYR), transaction status, and the resulting session-credit balance.
3.6 Technical & usage data
- Authentication session tokens and essential cookies/local storage needed to keep you signed in and operate the app.
- Basic technical data such as device/browser type and server log information used for security and reliability.
4. Google user data & Google Calendar
Connecting Google Calendar is optional and used only to synchronise your training sessions between Noah and your calendar.
4.1 Scopes we request and why
- openid, email, profile — to authenticate you and create your account using your Google identity.
- https://www.googleapis.com/auth/calendar.events — to create, update, and delete the calendar events that represent your Noah training sessions, and to read the events on your connected calendar within a limited scheduling window so we can show your availability and avoid double-booking. We use this access only to operate scheduling and session sync. We do not change events that we did not create for your Noah sessions, and we never use your calendar data for advertising or any unrelated purpose.
4.2 What we store
- Google OAuth access and refresh tokens, used to keep your calendar in sync (the refresh token lets the sync continue without asking you to sign in repeatedly).
- The connected Google account email, the calendar identifier, and the scopes you granted.
Tokens are stored securely and access is restricted by row-level security so that only your account’s data is reachable. We use this access solely to provide the calendar-sync feature.
4.3 Limited Use & Google API Services User Data Policy
Noah’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, information obtained through Google APIs is:
- used only to provide and improve the Noah scheduling and calendar-sync features you have enabled;
- not sold, and not used or transferred for advertising, ad-targeting, or to build advertising profiles;
- not used to train generalized or third-party artificial intelligence or machine-learning models;
- not read by humans, unless we have your explicit consent, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymized.
4.4 Revoking access
You can revoke Noah’s access to your Google account at any time from your Google Account permissions page at myaccount.google.com/permissions. Revoking access immediately stops calendar sync, because Google will no longer honour the tokens. To have the Google tokens we stored deleted from our systems, email us at nfitptofficial@gmail.com or delete your account, and we will remove them.
5. How we use your information
- To provide and operate the Platform — accounts, coaching, scheduling, workouts, nutrition tracking, and homework.
- To synchronise sessions with Google Calendar when you enable it.
- To process payments and maintain your session-credit balance via Stripe.
- To communicate with you about your account, bookings, and support requests.
- To secure the Platform, prevent abuse, and debug issues.
- To comply with legal obligations.
- To maintain and improve the features you use.
Where required by Malaysia’s Personal Data Protection Act 2010 (PDPA) and other applicable law, we rely on your consent and on the necessity of processing to perform the coaching service you have requested.
Some information you choose to record — such as body weight, training, and nutrition data — is health-related and may be treated as sensitive personal data under the PDPA. We process this information only with your explicit consent, which you give by choosing to record it, and you may withdraw that consent at any time (which may mean the related coaching features no longer function for you).
6. How information is shared within coaching
Noah is a tool used between a Coach and their Clients. The coaching and training data a Client records (such as sessions, workouts, nutrition logs, and progress) is visible to the Coach connected to that Client so they can deliver the service. Access is scoped by row-level security and by the permissions a Coach has been granted. We do not make your personal data visible to unrelated Coaches or Clients.
7. Service providers we share data with
We share data with the following providers strictly to operate the Platform. They process data on our behalf under their own terms and privacy policies:
- Supabase — database, authentication, file storage, and realtime services that host your account and coaching data (privacy policy).
- Amazon Web Services (AWS) — cloud infrastructure used to host the application and send transactional email (privacy notice).
- Stripe — payment processing for session-package purchases (privacy policy).
- Google — sign-in and Google Calendar synchronisation, where you enable them (privacy policy).
We do not sell your personal data. We may disclose information if required by law, to enforce our terms, to protect rights and safety, or as part of a business transfer (in which case we will provide notice consistent with this policy).
8. Data storage, location & security
Your data is hosted on Supabase and AWS infrastructure, primarily in the Singapore (ap-southeast-1) region, which may mean your data is processed outside Malaysia. We protect data with encryption in transit, row-level security access controls, restricted access to credentials and tokens, and the security practices of our providers. No method of transmission or storage is completely secure, but we take reasonable measures to safeguard your information.
Because our infrastructure is located outside Malaysia, using the Service involves transferring your personal data abroad. We make these transfers because they are necessary to provide the Service you have requested and with your consent, and our providers are bound by contractual data-protection obligations. Some subprocessors (such as Stripe and Google) process the data they handle on their own global infrastructure under their respective policies.
9. Data retention
We retain your personal data for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. As a guide, we delete or anonymize your account and coaching data within 30 days of a verified deletion request, except where we must retain certain records — for example, financial and tax records, which we keep for the period required by Malaysian law (generally up to seven years).
10. Your rights & choices
Subject to applicable law, including Malaysia’s PDPA, you can:
- access the personal data we hold about you and request a copy;
- correct inaccurate or incomplete data;
- withdraw a consent you previously gave, including revoking Google access or asking us to stop processing certain data;
- limit or stop the processing of your personal data for direct marketing;
- request deletion of your account and personal data, and object to certain processing, where applicable law provides these rights.
To exercise any of these rights, email nfitptofficial@gmail.com. We will respond within a reasonable timeframe. If a Coach manages your Client account, we may direct certain requests to that Coach where appropriate.
We use your contact details to send you service messages about your account, bookings, and support. We do not sell your data or use it for third-party advertising. If we ever send you optional marketing messages, you can opt out at any time by contacting us or using the unsubscribe option in the message.
11. Children
The Platform is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16 without verified parent or guardian consent. If you believe a child has provided us personal data without such consent, contact us and we will take steps to delete it.
12. Cookies & local storage
We use only the cookies and browser local storage necessary to sign you in, keep your session active, and operate core features. We do not use third-party advertising or cross-site tracking cookies.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Platform. Your continued use of the Service after changes take effect means you accept the updated policy.
14. Contact us
If you have questions, concerns, or requests about this Privacy Policy or your personal data, contact:
- N Fit Personal Training
- 21 Lengkok Ariff, Georgetown, Penang 11600, Malaysia
- Email: nfitptofficial@gmail.com
- Phone: +60 18-980 2511