Cookie Policy
Last updated: 18.11.2025 ยท Version: v2.0
General
This Cookie Policy ('Policy') explains how ROXFIT LIMITED ("ROXFIT", "we", "us", "our") uses local storage and visitor's personal data, obtained through the use of cookies and similar technologies on the Platform (https://www.roxfit.app/ - the "Platform"), what these technologies are and why they are used.
You should read this policy to understand what cookies are, how we use them, the types of cookies we use, the information we collect using cookies and how that information is used and how to control the cookie preferences. For further information about who we are, how you can contact us and how we process personal data, see our Privacy Policy.
Contents
- Key terms and definitions
- General information regarding the types of cookies
- Our use of cookies
- How to exercise your right to refuse and/or withdraw consent on our application of cookies
- Our use of other tracking technologies
- Your choices and controls
Key terms and definitions
Personal data: any information relating to an identified or identifiable natural person ('data subject').
Identifiable natural person: a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Platform visitor: a person who visits the ROXFIT Platform. A visitor is not considered as a single person but as a browser or a terminal. For example, a single user can access a website via different browsers (such as Chrome, Firefox or Edge), different computers (work and home) or different devices (smartphone and laptop).
Platform visit: a visit to a Platform where at least one page has been loaded.
Cookies: text files stored on a website visitor's computer or mobile device by a website's server. Each cookie is unique to the web browser and may contain personal information such as a unique identifier, website's domain name, digits and numbers.
Local storage: refers to data saved directly on your device by the app. It allows ROXFIT to remember your settings, preferences, and recent activity so that features work even without an internet connection. This data never leaves your device unless required for syncing core functionality.
SDK (Software Development Kit): a set of software tools provided by third parties (like Firebase, Mixpanel, or Sentry) that enable specific app features such as analytics, authentication, or crash reporting. These SDKs operate within the app's code and follow ROXFIT's privacy controls and data protection standards.
Push notification tokens: anonymous identifiers generated by your device's operating system to deliver notifications. ROXFIT associates the token with your user account to send relevant alerts (e.g., workout reminders). Tokens are only used if you grant permission through your device's system prompt.
Types of cookies
There are two types of cookies depending on their lifetime:
- Session cookies - these link your actions during a particular session. They expire each time you close the Website and do not remain on your device afterwards.
- Persistent cookies - these are stored on your device between sessions. They allow your preferences or actions to be remembered and remain on your device until they expire or you delete them.
By domain, there are first-party and third-party cookies:
- First-party cookies are set by our Website's domain.
- Third-party cookies are stored by a different domain to the Website's domain.
The cookies placed on your device may fall into the following categories by purpose:
- Strictly necessary cookies - essential for the operation of the Website and for you to use its features. For example, fraud prevention or login functionality. Without these cookies, services you have asked for may not be provided.
- Functional cookies - enable the Website to provide enhanced functionality and personalisation. If you do not allow these cookies, some or all of these services may not function properly.
- Analytical/performance cookies - allow us to count visits and traffic sources to measure and improve performance. These help us see which pages are most and least popular and how visitors move around the site.
For further information on cookies generally, visit www.aboutcookies.org or www.allaboutcookies.org.
Our use of cookies
We may use cookies to:
- Maintain user sessions across our Website;
- Ensure proper technical operation and stability of the Website.
| Cookie Name | Domain | Purpose | Type | Duration |
|---|---|---|---|---|
| roxfit_consent | roxfit.app | Remembers your cookie consent choice | Strictly necessary (first-party, local storage) | Until cleared |
| _ga | .roxfit.app | Google Analytics - distinguishes unique visitors | Analytical/performance (third-party) | 2 years |
| _ga_* | .roxfit.app | Google Analytics 4 - persists session state | Analytical/performance (third-party) | 2 years |
| _fbp | .roxfit.app | Meta (Facebook) Pixel - measurement and advertising | Analytical/performance (third-party) | 3 months |
Certain cookies and similar technologies are essential to enable performance of the Platform and are processed on the legal basis of contract performance (Article 6 (1) (b) GDPR) and our legitimate interest (Article 6 (1) (f) GDPR).
Other cookies and tracking tools are used to improve our website and tailor content, based on our legitimate interest in optimizing functionality, performance, and security (Article 6 (1) (f) GDPR). Within the app, analytics tracking (via Mixpanel and Firebase) is conducted under our legitimate interest and includes opt-in and opt-out options in Settings.
How to exercise your right to refuse and/or withdraw consent
The easiest way to change your choices regarding cookies on the Website is to use our cookie consent tool, accessible at any time via the "Your Consent Preferences" link in the footer. Strictly necessary cookies cannot be disabled.
You can also manage cookies via your browser's settings (see "Help", "Tools", or "Edit" menu). Disabling cookies through your browser does not delete them unless you manually clear your cache.
Our use of other tracking technologies
| Technology | Purpose | Data | Legal basis |
|---|---|---|---|
| Local Storage (SharedPreferences) | User preferences, settings, cached data (service delivery) | User email, workout settings, last health sync time, notification preferences, recently viewed content | Article 6 (1) (b) GDPR (contract performance) |
| Analytics Tracking (Mixpanel) | Usage analytics, feature adoption (platform analytics & improvement) | User ID, device info, app events, session duration, IP address | Article 6 (1) (f) GDPR (legitimate interests) |
| Crash Reporting (Sentry) | Bug detection, crash reports (platform maintenance & performance) | Error logs, stack traces, device info, app state at crash | Article 6 (1) (f) GDPR (legitimate interests) |
| Push Notification Tokens (Pushwoosh) | Push notification delivery (communication with users) | Device token (HWID), user ID, notification preferences | Article 6 (1) (b) and (f) GDPR |
| Firebase SDK | Authentication, analytics, remote config, crash analytics (security and fraud prevention, analytics) | User ID, device info, authentication state, app events, crash reports | Article 6 (1) (f) GDPR (legitimate interest) |
| Session Storage (Hydrated Bloc) | Maintain app state across sessions (account management, service delivery) | User session state, cached API responses, UI preferences | Article 6 (1) (b) GDPR (contract performance) |
Your choices and controls
Analytics Tracking (Mixpanel)
ROXFIT uses analytics tools (Mixpanel and Firebase) to understand app usage and improve features. Analytics are enabled by default and can be disabled anytime under Settings โ Privacy & Data โ "Help Improve ROXFIT". Turning analytics off will not affect access to app features.
Push Notifications
Push notifications are controlled through your device's system settings. Denying permission only affects notifications; the app remains fully functional.
Other Essential Storage
Local and session storage (Shared Preferences and Hydrated Bloc) are essential for the app's functionality and cannot be disabled.