Перейти к содержимому

Privacy policy

Обновлено: 21 августа 2026 г.

We collect the minimum a course platform needs to work: an address to sign you in and deliver access to, a record of what you bought, and a record of what you have watched. We do not sell it, rent it, or use it to advertise to you.

Who is responsible for it

The controller of your personal data is [legal name of the company], [registered address], Poland, NIP [NIP]. Write to hello@movebetter.example about anything on this page. We have not appointed a data protection officer; that address reaches the people who can act.

What we collect

  • Account — your email address, and, if you fill them in, your first name, last name, profile photo and preferred interface language.
  • Purchases — which course, when, the amount and currency charged, and the customer identifier Stripe assigns to you.
  • Learning — which lessons you have opened and which you have marked complete.
  • Sessions — the devices you are signed in from and when each was last used, so that the two-device limit works and you can end a session you no longer recognise.
  • Technical — server logs, and IP addresses used briefly to rate-limit sign-in and checkout so those forms cannot be abused.

We never see or store card numbers. There is no advertising pixel here, no third-party analytics service, and no tracking of you across other websites.

How we count visits

We measure how many people reach the site, how many open a course page, how many start checkout and how many complete a purchase. Nothing about this leaves our servers: the numbers are computed in our own database, and no analytics company receives them.

We do not store your IP address or your browser's user agent for this. Instead, each day they are turned into a one-way code — a keyed hash that cannot be reversed back into an address — and only that code is saved. The key changes with the calendar date, so today's code and yesterday's code for the same person do not match, and there is no way to follow anyone from one day to the next. Alongside it we keep the page that was opened, the interface language, the site you arrived from, and any campaign tag in the link.

Nothing is written to, or read from, your device to make this work — no cookie, no local storage, nothing at all. That is why this site has never asked you to accept anything. Our interest in knowing which pages people find useful is what allows us to do this without asking, and it is balanced against the fact that none of it identifies you.

Why we are allowed to hold it

  • To give you what you bought and to run your account — performance of our contract with you, GDPR Art. 6(1)(b).
  • To keep invoices and accounting records — a legal obligation, Art. 6(1)(c).
  • To keep the service secure and to prevent abuse of the sign-in and checkout forms — our legitimate interest, Art. 6(1)(f).

We have no newsletter and send no marketing email. The email you get from us is either a sign-in link you asked for or a notice about a course you bought.

Who else sees it

Only the companies that make the service run, each of them acting on our instructions under a data processing agreement:

  • Stripe — takes payments and issues receipts. Stripe is its own controller for payment data; we receive the outcome, the amount, and a customer identifier.
  • Resend — delivers our email: sign-in links and course access notices.
  • Cloudflare — hosts and delivers the course video.
  • [object storage provider] — stores images and files, including a profile photo if you upload one.
  • [hosting provider] — runs our servers and the database.

Nobody else. We would disclose data to a public authority only where the law obliges us to.

Where it is kept

Our servers and database are in [country the servers are in]. Some of the processors above operate outside the European Economic Area; where they do, the transfer relies on the European Commission's standard contractual clauses or on an adequacy decision such as the EU–US Data Privacy Framework.

How long we keep it

  • Your account, and your progress through the lessons: until you ask us to delete it.
  • Orders and the accounting records behind them: five years from the end of the accounting year, because Polish tax law requires it. This is why deleting your account does not delete your invoices.
  • Sessions: they expire sixty days after they were last used, and immediately when you sign out.
  • Sign-in links and codes: fifteen minutes.
  • Server logs: [how long server logs are kept].

Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it over in a portable form, or stop processing it where we rely on our legitimate interest. Write to hello@movebetter.example and we answer within one month.

If you believe we have mishandled your data, you can complain to the Polish supervisory authority — Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw — or to the authority of the EU country you live in.

Cookies

We set only the cookies the site cannot work without. They are listed one by one in the Cookie policy.

Children

The service is not directed at children under sixteen and we do not knowingly create accounts for them. If you believe a child has an account here, write to us and we will delete it.

Security

Traffic to the site is encrypted. There is no password to steal: sign-in is a one-time link or code that expires in fifteen minutes. Sessions are limited to two devices, and you can end any of them yourself from your account page.

Changes to this policy

We publish the new version here with a new date at the top. If a change materially affects what we do with your data, we will say so on this page rather than change it quietly.