The Formulaic Privacy Policy

Effective Date: May 2, 2025

Hello and welcome to The Formulaic's Privacy Policy! Rach and Rye LLC d/b/a The Formulaic, Inc. ("The Formulaic," "we," "us," or "our") is a U.S.-based digital fitness service provider. We value your privacy and are committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use and share it, and the rights and choices you have. It is designed to comply with applicable U.S. laws such as California's CCPA/CPRA, the European Union's General Data Protection Regulation (GDPR) as applicable, as well as other relevant privacy regulations.

Please read this policy carefully. By using The Formulaic's websites, applications, and services (collectively, our "Services"), you agree to the practices described in this Privacy Policy. If you have any questions, feel free to contact us using the information in the Contact Us section at the end.

Information We Collect

We collect various types of information from and about you when you use our Services. This includes information you provide to us directly, data collected automatically about your use of our Services, and information from third parties (like when you use a Google or Facebook login). Below we explain the categories of information we collect.

1. Information You Provide to Us:

When you interact with The Formulaic, you may provide personal information, including:

2. Information from Third-Party Services:

We support social login options to make it easier for you to create an account and sign in. If you choose to register or log in via a third-party service like "Sign in with Google" or "Log in with Facebook," we will receive certain information from those services:

3. Information We Collect Automatically:

Like many digital services, The Formulaic and our third-party partners (such as analytics providers and advertising partners) automatically collect certain information about your device and how you interact with our Services. This may include:

4. Information We Do Not Collect (Sensitive Health Information)

By being transparent about what we collect and what we don't, we aim to give you control and clarity. If you ever have questions about the information you are asked to provide, please contact us.

How We Use Your Information

We use the personal information we collect for the following purposes, all in line with operating a digital fitness service and improving our offerings. We strive to only use your data in ways that you would expect from a fitness service, and if we want to use it for any unrelated purpose, we will seek your permission or ensure we have an appropriate legal basis. Specifically, The Formulaic uses your information to:

Lawful Bases for Processing (GDPR):

If you are in the European Economic Area (EEA), United Kingdom, or another region with similar laws (like Italy or Spain), we must have a valid legal basis to process your personal information. We generally rely on the following lawful bases:

If you have questions about the legal basis for specific processing, please contact us and we will explain our practices in more detail.

Cookies & Tracking Technologies

Like most online services, The Formulaic uses cookies and similar tracking technologies to provide, protect, and improve our Services. This section explains what these technologies are and how we use them, as well as your choices regarding them.

1. What Are Cookies and Tracking Technologies?

2. How We Use These Technologies:

We use cookies and similar tools for a few key purposes:

3. Third-Party Cookies and Partners:

We work with third parties that deploy their own cookies or tracking tech through our Services. Key examples include:

4. Your Choices: Managing Cookies and Tracking:

We believe you should have control over the data collected by cookies and similar technologies. Here's how you can manage your preferences:

By using our Services, you consent to the use of cookies and tracking technologies as described (to the extent consent is required by law). We aim to be transparent about our practices, but if you have any questions or if there's something you're unsure about in our use of cookies, please contact us.

How We Share Your Information

We understand that sharing of personal information is a sensitive topic. The Formulaic does not sell your personal information to third parties for money. However, we do share certain information with third parties in order to run our business and provide our Services to you. We also may share data for advertising purposes as described, which could be considered a "sale" or "sharing" under some privacy laws (like the CCPA/CPRA's definitions – see Your California Privacy Rights for details). In all cases of sharing, we only share the minimum information necessary for the purpose, and we have contracts or safeguards in place to protect your data. Here are the types of third parties and situations in which we share user information:

If you ever have questions about who we share your information with, please contact us. We can provide more detailed information depending on your inquiry, and for residents of certain jurisdictions (like California), we detail additional specifics in the relevant section below.

International Data Transfers

The Formulaic is based in the United States, and the majority of our systems and data storage are located in the U.S. If you are using our Services from outside the U.S. (for example, in Italy, Spain, or elsewhere in Europe), this means that your personal information will likely be transferred to and processed in the United States, as well as potentially other countries where our service providers are located or have servers (for instance, our cloud hosting or content delivery providers might use data centers globally).

Privacy Laws and Protections: Different countries have different data protection laws. The U.S. may not have the same level of data protection as the laws in your home country. However, if we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the U.S. or any other country that hasn't been deemed "adequate" by the EU, we take steps to ensure your data is afforded a high level of protection. Our measures include:

By using the Service or providing us information, you consent to the transfer of your personal data to the U.S. and other jurisdictions as described in this policy (to the extent this consent is required and valid in your jurisdiction). Where consent is not the basis for transfer, we assure you that we will handle your data in accordance with this policy and applicable law regardless of where it is processed.

If you are in the EU/EEA, UK, or Switzerland and have questions or concerns about international data transfers, you can contact us (see Contact Us section). In some cases, you have the right to request details of the safeguards we use (for example, a copy of the SCCs relevant to your data – though we may need to redact some parts for confidentiality).

We also want to note: The Formulaic does not engage in cross-border transfers that are not necessary. We don't, for example, unnecessarily route EU user data to unrelated third countries. Transfers happen mainly because our main operations are in the U.S. and we use U.S.-based cloud services. We will continue to monitor the legal landscape and collaborate with our users and regulators to ensure compliance with international data transfer rules.

Data Retention

We retain personal information for as long as needed or permitted in light of the purpose(s) for which it was collected and consistent with applicable law. The criteria we use to determine retention periods include:

When we no longer have a legitimate need to retain your personal information, we will securely dispose of it or anonymize it (so it can no longer be associated with you). For example, we might aggregate and anonymize usage data so it can be used for statistical purposes without identifying any user.

If you decide to delete your account, we will delete or de-identify your personal data, except for information we are required or permitted to keep by law (as outlined above). We describe how you can delete your account or request deletion in the Your Rights section below.

Data Security

We take the security of your personal information seriously. The Formulaic implements a variety of administrative, technical, and physical safeguards designed to protect your data against unauthorized access, theft, and loss. However, no method of transmitting or storing data is 100% secure, so we cannot guarantee absolute security. We encourage you to also do your part in protecting your information.

Security Measures We Use Include:

Your Responsibilities: You play an important role in keeping your information secure. Please maintain the secrecy of your account credentials. Do not share your password with others, and use unique, strong passwords for our Service and your email account (since email can be used for password resets). If you suspect any unauthorized access or suspect that your account or information has been compromised (for example, you notice unfamiliar activity on your account), please notify us immediately so we can help secure your account.

Despite our efforts, no security measure is perfect. Cyber threats evolve rapidly, and there's always some risk. We cannot fully guarantee the security of data transmitted to our site; any transmission is at your own risk. Once we receive your data, we do our best to protect it on our systems. If you have questions about the security of The Formulaic, feel free to reach out via the contact information below.

Your Privacy Rights and Choices

You have important rights and choices regarding your personal information. Depending on where you live, you may be entitled to exercise certain privacy rights under applicable laws like the GDPR for EU users (including users in Italy and Spain) and the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) for California residents. We are committed to honoring your rights and have outlined them here in a user-friendly way. Even if you do not reside in these regions, we provide many of these controls to all our users as a matter of transparency and fairness.

Rights for EEA/UK/Swiss Users (GDPR Data Subject Rights)

If you are located in the European Economic Area (EEA) or a country with similar laws (such as the United Kingdom or Switzerland), you have the following rights regarding your personal data, under the GDPR and local implementations of it. These include:

How to Exercise These Rights: You can exercise your rights by contacting us (see Contact Us below). For certain requests, we might need to verify your identity to ensure we're protecting your information from unauthorized access (for example, we don't want to give your data to someone pretending to be you). Verification might involve confirming your email address or asking for information that confirms you are the account owner. We will respond to your request as soon as possible, and at least within the timeframes required by law (generally within one month for GDPR, with possible extension if the request is complex – but we will inform you if an extension is needed).

There is usually no fee for exercising your rights. However, if a request is manifestly unfounded or excessive (for example, repetitive), we may either charge a reasonable fee or refuse to act on it, but we would provide an explanation in such cases.

We want you to have control over your data, so please do reach out if you have any questions or requests regarding your personal information.

California Privacy Rights (and Similar U.S. State Laws)

If you are a California resident, you have specific privacy rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) (effective January 1, 2023). Other states like Colorado, Connecticut, Virginia, and Utah have also passed consumer privacy laws with similar rights. The Formulaic is committed to extending appropriate rights and choices to users in the U.S. as well. In this section, we focus on California rights for simplicity, but if you are a resident of another state with privacy laws, you can exercise similar rights and we will honor them in accordance with applicable law.

Categories of Personal Information Collected: The CCPA requires us to disclose the categories of personal information we collect and purposes, which largely align with what we've described throughout this policy. In the past 12 months, we may have collected the following categories (as defined by California law):

Purposes for Collecting/Using Personal Information: We collect and use the above information for the business and commercial purposes outlined in How We Use Your Information, such as providing the Service, personalization, marketing, security, analytics, and so forth. All these purposes are ones the CCPA/CPRA consider "business purposes" or "commercial purposes" for which personal information may be used.

Disclosure of Personal Information: In the last 12 months, we have disclosed the above categories of personal information to third parties for business purposes. The categories of third parties correspond to what we described in How We Share Your Information (service providers, advertising partners, payment processors, etc.). For example, we may disclose identifiers and internet activity to our analytics and advertising partners; we disclose customer records info to our payment processor to complete transactions; etc.

We do not sell personal information for money. However, the CCPA's definition of "sell" includes some transfers of data that involve benefit to us, even if no money is exchanged. Specifically, the use of third-party advertising cookies and the sharing of identifiers for targeted advertising might be considered a "sale" or "sharing" of personal information under California law. In CCPA terms:

Under these terms, The Formulaic may be deemed to have "sold" or "shared" identifiers and internet activity information (like cookie IDs, advertising IDs, usage data) to advertising partners (like Facebook, Google) for the purpose of showing you targeted ads. We want to be very transparent: we don't hand over your data to brokers or data resellers, but when we allow third-party advertising cookies on our site or use tools like Facebook Custom Audiences, those could fall under "sale"/"sharing" definitions because they involve providing personal info (e.g., a cookie ID or hashed email) to a third party (ad network) that then uses it to help target ads.

Your California Privacy Rights: As a California consumer, you have the following rights under CCPA/CPRA:

How to Exercise California/US Privacy Rights: If you are a California resident (or a resident of another state with similar rights) and you want to exercise your access, deletion, correction, or opt-out rights, you can contact us through the methods listed in Contact Us below. Please indicate which right you are requesting to exercise.

We will need to verify your identity to process certain requests, especially for access or deletion of data. This is to ensure we don't give someone else's data to you or delete someone else's data improperly. Verification might involve checking that the request comes from the email associated with your account or asking for additional information. For significant requests, we may require a signed declaration confirming your identity. If you have an account, logging into the account to make the request is often sufficient verification.

For opt-out of sale/sharing, we will honor that based on your request (usually verification is not needed for an opt-out request except to the extent we need to make sure we apply it correctly to your data).

Shine the Light: California's "Shine the Light" law (Civil Code § 1798.83) allows California residents to ask companies once a year for a notice describing what categories of personal information we share with third parties for their direct marketing purposes. However, The Formulaic does not share your personal information with unaffiliated third parties for their own direct marketing (without your consent). Therefore, we believe there's no such sharing to report under that law. If you have questions about this or require further information, you can contact us.

Additional Notes for Other Regions

Our goal is to provide a consistent and user-friendly experience regarding privacy rights, regardless of your location. We will continue to update our privacy practices as laws evolve, so you may see updates to this section from time to time.

Children's Privacy

The Formulaic's Services are not intended for children under the age of 13. We do not knowingly collect personal information from anyone under 13 years old. Additionally, if you are in the European Union (or countries with similar rules), our Services are not directed to children under the age at which parental consent is required (under GDPR, this age is 16 by default, but it may be lowered to 13 or 14 by certain countries – for example, 14 in Italy and Spain). We do not knowingly collect data from children under such ages either without appropriate consent.

If you are under the minimum age applicable in your country, please do not use The Formulaic or provide any personal information to us. If we learn that we have inadvertently collected personal information from a child without proper consent, we will take steps to delete that information promptly.

Parents or guardians who believe that The Formulaic might have collected personal information from their child can contact us (see Contact Us below) and request that the data be removed.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. When we make changes, we will update the "Effective Date" at the top of the policy. If the changes are significant, we may also provide a more prominent notice or seek your consent as required by law – for example, by emailing you or posting a notice in the app.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our Services after any update to this Privacy Policy will constitute your acknowledgment of the changes and agreement to be bound by the updated policy, as applicable.

For any material changes, especially those affecting users in jurisdictions with specific notice requirements (like the EU or California), we will take appropriate measures to inform you in advance and, if required, to obtain your consent.

Contact Us

Thank you for reading our Privacy Policy. We hope it clearly explains how we handle your personal information. If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, here's how you can reach us:

We are happy to answer questions or help resolve any issues you have about your privacy and our data practices. Your trust is extremely important to us, and we welcome your feedback.

Thank you for being a part of The Formulaic community! We are dedicated to safeguarding your privacy while you pursue your fitness journey with us. Remember, you are in control of your data – and we're here to help in any way we can to ensure you feel secure and empowered. Stay healthy and stay informed!