Privacy Policy

Effective date: August 22, 2026

1. Scope and roles

This policy explains what Corva Fitness LLC, a Delaware limited liability company ("Corva," "we," "our"), collects, why, who can see it, how long we keep it, and your choices. It covers the Corva apps and Corva-operated admin systems, for Clients and Trainers alike except where a section names one role. Corva is the controller of Platform data; the processors in Section 5 handle data on our instructions or as independent regulated services (Stripe, Checkr).

2. What we collect, and why

• Identity and account: legal name, email, date of birth (collected to enforce our 18+ rule; never shown on profiles), gender (used for matching preferences; shown only as users choose), and a required profile photo. Client photos must clearly show the face; this is a Trainer-safety feature. • Trainer professional data: certifications and CPR/AED credentials (documents and metadata, reviewed by Corva), training styles, specializations, rates, availability, prompts, and training locations. • Client matching data: fitness goals, coaching-style preferences, motivations, fitness level, trainer-gender preference, and general location (neighborhood or city). Exact addresses are collected only when booking at-home Sessions and are disclosed to the Trainer only after acceptance. • Payments: processed by Stripe. We store tokens and references only: Stripe customer ID, payment method brand and the card's last four digits, and payment, transfer, and refund identifiers. Card numbers never reach our systems. • Identity verification (Clients, at-home bookings only): performed by Stripe Identity. Your government ID images and selfie go directly to Stripe; Stripe performs the document check and biometric face match. We store only the status, a Stripe session reference, and a timestamp. We instruct Stripe to redact the underlying images after verification completes, so the images cease to exist and only the verdict remains; Corva personnel do not access verification images except before redaction where strictly necessary for support, with access limited and documented. • Trainer screening: performed by Checkr, a consumer reporting agency. We send Checkr only name, email, work location, and a reference ID; Checkr collects sensitive screening inputs (such as SSN and date of birth) directly from the Trainer under Checkr's own FCRA disclosures. We receive statuses, results, and assessments; we link to full reports in Checkr's dashboard rather than importing them. • Activity records: booking requests and Sessions (times, mode, prices, statuses), payment and payout statuses, cancellations and their timing, reschedule proposals, decline reasons and optional decline messages (Section 4 describes who sees them), PIN attempt counts, completion records, reports, blocks, and suspensions. • Messages: in-app messages between matched users, retained while the accounts and conversation exist. • Trainer notes: private free-text notes a Trainer keeps about a Client, visible only to the authoring Trainer. Access is restricted at the database layer; even our client apps cannot read another party's notes. Ordinary-course admin access does not exist; see Section 4. • Device and technical data: push notification tokens (via Expo), app version, and operational logs needed to run and secure the service. We do not serve third-party advertising and do not sell personal information.

3. How we use information

• Operate the marketplace: matching (your preferences against Trainer attributes), booking, charging at acceptance, payouts, completion, and support. • Safety and integrity: at-home identity verification, Trainer credential and background screening, the trust line Trainers see on requests (join date, completed-session count, and, on at-home requests, verified status), block and report handling, strike tracking, fraud prevention, and enforcement. • Legal compliance, dispute resolution, tax and accounting.

4. Who can see what

• Between users: Trainers see a requesting Client's name, photo, request details, trust line, and (at-home) verified badge; exact address only after acceptance. Clients see Trainer public profiles including rates and profile content; credential and screening indicators are not separately displayed, and only Trainers who have passed Corva's review and screening appear on the Platform. A Client declined with the reason "Not comfortable taking this request" sees only a generic notice, and that reason goes to Corva alone; every other decline reason, and any message the Trainer writes with a decline, is shown to the Client on the request. • Corva administrators: see operational records (applications, bookings, payment and payout statuses, disputes, reports, screening statuses, verification status flags). Administrators cannot browse message content. Messages become viewable only as evidence attached to a user report or dispute, in a read-only labeled view, and every access writes an audit log entry before content is shown; if the log write fails, access is refused. Trainer notes: admin access only pursuant to legal process or a documented safety investigation, logged the same way. • Processors and partners: Stripe (payments, payouts, identity verification), Checkr (screening), Supabase (hosting and database), Mapbox (address search and static maps; receives the text you search and coordinates), Resend (delivers sign-in code emails), Expo (push delivery), Google (creates Meet links for virtual Sessions). Each receives only what its function requires. • Legal and safety disclosures: we disclose information when required by law, to enforce our agreements, or when we believe in good faith it is necessary to protect the safety of users or the public, including to law enforcement. • Corporate events: if Corva is acquired or merges, data transfers with the business under this policy's commitments.

5. Processor list (current)

Stripe, Inc. (payments, Connect payouts, Stripe Identity); Checkr, Inc. (background screening); Supabase (infrastructure and database hosting); Mapbox (geocoding and maps); Resend (transactional email); Expo (push notifications); Google (Meet links). We will update this list as providers change.

6. Retention

• Account and profile data: while your account exists. Deleting your account anonymizes your profile (name, date of birth, gender, contact details, city and state, bio, and address are removed), deletes your photos, permanently disables sign-in, and withdraws or declines your pending requests; deletion is refused while you have upcoming confirmed Sessions, reviews you wrote remain attributed to "Corva client", and any private notes a Trainer kept about you are deleted. • Booking, payment, dispute, and enforcement records: retained after account deletion as required for tax, accounting, dispute defense, and legal compliance, then deleted or de-identified: seven years for financial records, three years for enforcement records. • Messages: retained while the conversation's accounts exist; removed with account deletion except where preserved as report or dispute evidence. • Verification and screening: our status flags and references follow the account; underlying documents follow Stripe's and Checkr's regulated retention (and, for Stripe Identity, the redaction default above).

7. Your rights and choices

• In-app: edit profile data, manage payment methods, notification settings, block and report, and delete your account. • Verification is optional: declining it only disables at-home booking. • Access, correction, deletion requests: email connect@corvafitness.com; we verify the request is from the account holder and respond within 30 days. Where state privacy law grants additional rights, we honor them.

8. Security

Controls in production: row-level security on every user-facing table; server-side triggers enforcing money, verification, suspension, and prompt rules independent of the app; column-level protection and definer-function access for sensitive fields (Trainer notes, identity flags); signature-verified webhooks; secrets held server-side; card, ID, and screening data held by Stripe and Checkr rather than Corva. No system is perfectly secure; if a breach affects you, we will notify you as required by law.

9. Children

The Platform is for adults 18 and over. We do not knowingly collect data from anyone under 18 and delete such accounts on discovery.

10. Changes and contact

Material changes will be presented in the app before they apply to you. Contact: connect@corvafitness.com; mail: Corva Fitness LLC, c/o Resident Agents Inc., 8 The Green, Suite R, Dover, DE 19901.