Legal
Privacy policy
MacroMove processes personal data to run the web app. No ad trackers, no sale of data.
Last updated: 14 June 2026
1. Who is responsible?
MacroMove (macromove.nl) is the data controller for personal data collected via the website and apps. MacroMove hosts the service centrally on its own infrastructure (Netcup, Netherlands/EU); users do not self-host their own instance.
Privacy questions: privacy@macromove.nl.
2. What data do we process?
Depending on your use, we may process:
- Account data — email address, display name, password hash, optional two-factor settings and sessions.
- Health and fitness logs — weight, nutrition, training, supplements, wellbeing, vitals and journal notes you enter or sync.
- Device and sync data — linked MacroSync devices, ingest timestamps and technical sync metadata (no raw MAC addresses in the UI).
- Optional wearable context — data the MacroSync Android app sends to your account via MacroSync ingest; the website does not pair BLE itself.
- Essential cookies — session cookie (mm_session), language cookie (mm_locale) and security cookies; no third-party tracking or advertising cookies.
3. Why do we use data?
We use data only to:
- Provide and secure your account and the MacroMove PWA.
- Display, store and synchronise your health and fitness data.
- Perform actions you request (export, deletion, consent management).
- Limited logging for security, abuse prevention and troubleshooting — without external analytics.
4. Legal bases (GDPR)
We process data based on:
- Performance of contract — account, sync and core service features.
- Legitimate interest — security, fraud prevention and stability improvements, with minimal data.
- Consent — where required for optional processing (e.g. optional sync or communication); revocable in the privacy centre.
- Legal obligation — when the law requires it.
5. Hosting, storage and third parties
Data is stored in PostgreSQL on servers operated by MacroMove (macromove.nl). We do not sell personal data or share it with ad networks.
We do not use Google Analytics, third-party tracking pixels or external font/script CDNs in the app runtime. Fonts and assets are self-hosted.
Email delivery and push notifications may use first-party infrastructure; only necessary data is processed.
6. Retention
We keep account data while your account is active. After account deletion we erase or anonymise data according to our deletion process.
MacroSync ingest payloads and offline queues have configurable retention (limited by default); see the privacy centre for current settings.
Sessions and audit log entries are cleaned up periodically.
7. Security
We apply appropriate technical and organisational measures: encrypted connections (HTTPS), hashed passwords, HttpOnly session cookies, RBAC access control and encrypted storage of sensitive fields where applicable.
No system is completely risk-free; report security incidents via contact@macromove.nl.
8. Your rights
Under GDPR you have rights of access, rectification, erasure, restriction, portability and objection where applicable.
Signed-in users can exercise many rights directly in the privacy centre: export (JSON), manage consents and request account deletion.
- Privacy centre (signed in): /privacy
- Export data: /account/export
- Delete account: /account/delete
- Consents: /account/consents
9. Contact
Privacy questions: privacy@macromove.nl. General questions: contact@macromove.nl. We typically respond within a few business days.