1. Scope and who is responsible
Power Zone Studio LLC is responsible for the Power Zone app. Power Zone is operated by Raphaela Lucarelli.
This policy applies only to the Power Zone mobile app and the Power Zone web pages and server actions used for app-account support and deletion. It is not a complete privacy policy for the rest of the powerzone.fit marketing website, the Ask Power Zone chatbot, or unrelated website integrations.
The Power Zone app account is separate from the studio client account managed through Arketa. Deleting the app account does not cancel a studio membership, subscription, class booking, purchase, personal-training arrangement, waiver, or payment, and does not erase Arketa records.
Adult audience
The Power Zone app is intended for adults aged 18 and older. It is not directed to children.
2. Information we process
Account, authentication, and studio linking
Supabase Auth processes the email address used to request a six-digit sign-in code, authentication identifiers, session information, and sign-in timestamps. The Power Zone app profile stores first and last name, app-account status, and studio-link status. App authentication sessions are stored on the device using operating-system secure storage.
Server-side linking associates an eligible app account with its Arketa studio client record. Private linking data may include an Arketa client identifier and a keyed, versioned digest of a normalized email address. A digest is pseudonymous, not anonymous: Power Zone's restricted systems may use it to recognize the same underlying member for linking and replay prevention even though it is not stored as readable email text in the app database.
Attendance, activity, and app features
The app processes a Power Zone copy of recorded attendance derived from Arketa, including the relevant class occurrence and confirmation state. It derives member-facing totals, streaks, milestones, attendance insights, weekly-goal progress, and challenge progress from that information.
Depending on the features used, app data also includes challenge enrollment, favorite instructors, a weekly attendance goal, referral codes and attribution, Power Points ledger entries and displayed balance, reward-redemption requests and outcomes, and notification preferences. Current class schedules and member booking information are requested through Power Zone's server integration with Arketa; Arketa remains the system of record for studio bookings and attendance.
Installation and push-notification information
If notifications are enabled, the app uses a randomly generated installation identifier, platform type, Expo push token, token-registration timestamps and status, notification preferences, notification intent, and delivery ticket or receipt state. The installation identifier is not derived from an email, hardware serial, advertising identifier, or device fingerprint. The current app implementation does not store device name or model, operating-system version, advertising identifiers, precise or coarse location, contacts, locale, or device timezone as part of push registration.
QR camera and check-in information
Camera access is requested only after a member chooses to scan a studio class QR code. The camera decodes QR data locally. Power Zone does not take photographs, record video or audio, upload camera frames, or persist camera images or frames. The decoded QR payload exists only long enough to submit the check-in or show a safe retry state, then is cleared.
The server records a limited QR presence receipt, trusted receive time, and private class binding. It stores a digest rather than the raw rotating QR token. QR check-in does not collect GPS, Wi-Fi, or Bluetooth information and does not replace Arketa as the attendance authority.
App-account deletion web service
The secure deletion page processes the account email and six-digit verification code through same-origin POST requests. After successful verification, it uses a short-lived authentication cookie and a separate recovery cookie. Both are unavailable to browser scripts, use strict same-site handling, and are limited to the deletion API path. The authentication cookie lasts no more than nine minutes; the recovery cookie lasts for the browser session unless the flow clears it sooner.
A non-credential browser-session marker records only that a deletion request was submitted so a reload can return to status checking. Emails, verification codes, authentication sessions, and recovery credentials are not placed in URLs, chatbot messages, or deletion-flow analytics. The deletion route does not load the site chatbot.
Support communications
If a person contacts app support, Power Zone processes the contact details, message, and troubleshooting information that person chooses to provide. This may include the affected screen, device type or model, operating-system version, app version, approximate incident time, short error text, and a cropped or redacted screenshot.
Do not send passwords, email verification codes, authentication or recovery tokens, or full screenshots containing sensitive personal or payment information.
3. How we use information
- Authenticate an app account, keep its session working, and protect account access.
- Link the app account to the appropriate studio client record without letting the mobile app select an Arketa client identifier.
- Show schedules, bookings, attendance, progress, goals, challenges, favorites, referrals, Power Points, rewards, and notification preferences.
- Receive a QR presence signal while leaving final attendance authority with Arketa.
- Deliver notifications a member has permitted and apply the member's notification choices.
- Prevent duplicate awards, claims, redemptions, or other one-time outcomes and preserve current product accounting and fulfillment integrity.
- Provide app support, investigate limited troubleshooting information, secure the service, and complete or recover an app-account deletion request.
The current app does not include an advertising identifier or an app-usage analytics SDK. That statement is limited to the mobile app and does not describe every part of the broader Power Zone website.
4. Services involved
Power Zone uses the following services for the app and its account-support/deletion flow:
- Supabase
- Provides email-code authentication, session handling, the hosted app database, server functions, and the controlled account-deletion worker. It processes the account, authentication, app-feature, deletion, and operational information described in this policy. Supabase Auth initiates verification emails and processes the destination address and related authentication-delivery state.
- Arketa
- Remains the system of record for studio clients, memberships, subscriptions, purchases, bookings, attendance-source records, waivers, payments, and related studio services. Power Zone's server reads limited Arketa information for app linking, schedules, bookings, and attendance synchronization. App-account deletion removes the current app link but does not instruct Arketa to delete or change its records.
- Expo and mobile-platform notification delivery
- Expo's push service and the applicable device-platform notification service process push delivery tokens and notification message payloads, tickets, and receipts when notifications are enabled. A notification already handed to a delivery provider or device cannot be recalled.
- Power Zone website service
- Hosts the app support, privacy, and deletion pages. The deletion server forwards email-code authentication to Supabase and keeps its temporary authentication and recovery credentials in the restricted cookies described above; those credentials are not exposed to browser scripts.
- WhatsApp, when chosen
- The support page contains a normal outbound WhatsApp link. If a person chooses it, WhatsApp processes that person's account and message under its own terms, and Power Zone receives the information the person sends. WhatsApp is not embedded in the deletion flow and a WhatsApp message does not authorize account deletion.
5. Retention and app-account deletion
While the app account is active
Power Zone keeps account and app-feature information while it supports the active app account and the features described above. QR class sessions and member presence receipts are subject to implemented housekeeping through 30 days after the class starts; deleting an app account removes its member QR receipt earlier. Push routing identifiers remain only while useful for an eligible installation and are disabled or removed through permission, sign-out, stale-device, provider-error, and account-deletion handling.
Support communications are kept as needed to handle and follow up on the inquiry. This policy does not represent a fixed automatic deletion schedule for support mail.
What app-account deletion removes
A completed request hard-deletes the Supabase Auth user, identities, and refresh sessions; the app profile and name; the current app-to-Arketa link; the Power Zone attendance copy; challenge enrollment; favorite instructors; weekly goal; notification preferences; push devices and unsent notification work; member QR receipts; referral code; and ordinary member rate-limit rows. The app clears its local authenticated resources and session.
Deletion does not cancel or erase Arketa-managed studio services or records. Shared class, instructor, catalog, and aggregate operational records that do not identify the member are not app-account data and remain.
Limited records retained after deletion
Power Zone retains a narrow Power Points ledger, reward-redemption records, referral attribution and closure records, an already-frozen challenge-reward decision until its existing batch settles, a durable member identity, the closed app-account identifier and state, and deletion-request/recovery records. These records support current product accounting, fulfillment or cancellation, recovery from an interrupted deletion, and prevention of duplicate claims, awards, redemptions, refunds, or other one-time outcomes.
Retained durable identifiers may include a random private identifier, an Arketa client identifier when known, or a versioned keyed email digest while a pre-link fact still depends on it. They are pseudonymous, not anonymous, because restricted server processes can recognize the same underlying member. They do not restore the deleted profile, app history, preferences, or sign-in.
An already-frozen challenge decision remains only until its finalization batch settles or is invalidated. A pending redemption may still be fulfilled or cancelled after account deletion. Recording that outcome ends its pending status; it does not automatically delete the redemption or associated ledger records. Those records remain subject to the retention purposes and conditions described below. Other retained business, anti-replay, closed-account, and terminal deletion-request records currently use the documented purpose and related-record conditions rather than a fixed number of years. The current system does not apply an automatic terminal purge schedule to those record classes, so this policy does not promise one.
Power Points, redemptions, and re-registration
Any unused Power Points will no longer be available and will not return if a member creates a new app account. Power Points are non-cash loyalty units and cannot be cashed out. The historical ledger remains detached for accounting and duplicate-outcome integrity and is not displayed or spendable by a new account.
A pending reward request is not canceled by deleting the app account. Power Zone may still complete or cancel it using limited retained fulfillment records. Any outcome remains attached to the closed account and does not create usable points in a new account.
Re-registering with the same verified email creates a fresh app-account generation, not a restoration. The new account begins with no restored app preferences or history and zero usable prior Power Points. Normal studio linking may associate it with the same Arketa client, while the durable identity continues to prevent duplicate one-time outcomes.
Notifications already in delivery
Account deletion immediately fences new notification handoffs and suppresses unsent work. A notification already handed to Expo, the device-platform provider, or the device cannot be recalled. It may settle once, but it is not eligible for a new or retry delivery after the deletion fence.
6. Security
Power Zone uses controls designed to limit access and reduce exposure, including verified email-code authentication, operating-system secure storage for mobile sessions, private database schemas and row-level access rules, server-only administrative credentials, HTTPS for the published web flow, strict POST and origin validation, bounded request bodies and timeouts, and browser-script-inaccessible, path-scoped deletion cookies. Authentication and recovery credentials are excluded from URLs and application logs.
These safeguards reduce risk but cannot guarantee absolute security. Members should protect access to their email account and device and should never share a verification code or recovery credential.
7. Member choices
- Choose whether to grant camera and notification permissions through the device operating system.
- Change available notification preferences in the app or disable notification permission in device settings.
- Sign out without deleting the app account.
- Request app-account deletion in the app or through the secure public deletion page.
- Contact app support about account information, privacy questions, a pending redemption, or deletion assistance.
Uninstalling the app or contacting support does not by itself delete an app account. A support email, phone call, or WhatsApp message is not authorization to delete an account. The verified-email deletion request and recovery/status process remains authoritative.
Studio membership, booking, payment, waiver, and Arketa-client questions are separate from app-account deletion and must be handled through the applicable studio or Arketa workflow.
8. Contact Power Zone
For Power Zone app support, privacy questions, or deletion enquiries, contact Power Zone Studio LLC at manager@powerzone.fit. The operator/contact is Raphaela Lucarelli.
Phone: +1 941 226 4863. You may also use the plain WhatsApp contact link (opens in a new tab), but do not send passwords, verification codes, or recovery credentials through messaging.
