Privacy Policy
Version 2026-08-07 · Effective 7 August 2026
1. Who we are
This policy covers the ThriverPlus website and leaderboard service, operated by ThriverPlus. For privacy questions or to exercise your rights, contact privacy@thriverplus.com.
2. When we are a controller, and when we are a processor
This distinction determines who you should contact about your data.
- Account holders — gym staff, followers and platform administrators. We are the controller (under the Malaysian PDPA, the “data user”). We decide how your account data is used, and you can contact us directly.
- Athletes entered by a gym — the gym is the controller / data user. We are its processor (“data processor”), acting on its documented instructions. Publishing the leaderboard publicly is part of those instructions. If you are an athlete, contact the gym that entered you first; we will help them respond, and we will act directly if they do not.
Where we use technical and aggregate data to keep the Service secure and working, we act as a controller in our own right.
3. What personal data we collect
3.1 Account data
Your email address, a securely hashed password, authentication timestamps and session records, the organisations you belong to or follow, and the record of which legal documents you accepted and when (see section 8).
3.2 Athlete data, entered by a gym
First and last name, category or division, scores, and rankings. Optionally a contact email address for the athlete, which is visible only to that gym’s own staff and is never published on a leaderboard.
3.3 Feedback
If you send us feedback in the app, we store your message, your account identifier, and any screenshot you choose to attach. Screenshots are kept in private storage. Do not include information in a screenshot that you do not want us to see.
3.4 Technical and operational data
Server request logs and error reports held by our hosting providers, including IP address, browser user agent and timestamps. Sign-in events including IP address, recorded by our authentication provider. A change log that records edits to events, games, athletes and scores — including who made the change and the previous values — used for dispute resolution and abuse investigation.
3.5 What we do not collect
We do not ask for or want health data, injury or medical information, ethnicity, religious belief, biometric data, government identifiers or payment card numbers. Gyms are contractually prohibited from entering such data. We do not collect athletes’ dates of birth or ages.
4. Where the data comes from
Directly from you when you create an account, use the Service or contact us; from a gym when it enters you as an athlete or invites you as staff; and automatically from your device and our infrastructure when you use the Service.
5. What we use it for, and our lawful bases
| Purpose | Data | GDPR / UK GDPR basis | PDPA basis |
|---|---|---|---|
| Create and run your account; authenticate you | Account data | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract (s. 6(2)(b)) |
| Publish leaderboards and event results | Athlete data | The gym’s basis: consent (Art. 6(1)(a)) or legitimate interests in publishing competition results (Art. 6(1)(f)) | Consent, or one of the s. 6(2) exceptions relied on by the gym |
| Send service emails — confirmation, password reset, staff invitations | Email address | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract (s. 6(2)(b)) |
| Keep the Service secure, prevent abuse, investigate incidents | Technical data, change log | Legitimate interests in a secure service (Art. 6(1)(f)) | Legitimate interests of the data user (s. 6(2)(f)) |
| Prove that you accepted our terms, privacy notice and waiver | Consent record | Legal obligation and legitimate interests (Art. 6(1)(c), (f)) | Compliance with legal obligation (s. 6(2)(c)) |
| Fix bugs and improve the product | Feedback, technical data | Legitimate interests in improving the Service (Art. 6(1)(f)) | Legitimate interests of the data user (s. 6(2)(f)) |
We do not use your personal data for advertising, and we do not sell it. We do not build profiles of you across other websites.
6. Public visibility of athlete names and results
This is the most significant privacy characteristic of the Service, so we state it plainly.
Published publicly, readable by anyone without an account, and indexable by search engines: an athlete’s first and last name, their category or division, their scores, their ranking, the event and game names, and the organising gym’s name and logo. This applies once an event is scheduled, live or finished. Draft events are private to the gym.
Never published: athlete contact email addresses, account email addresses, passwords, feedback messages and screenshots, and the change log.
The gym that runs the event decides who to enter and how their name is displayed. If you are an athlete and want your name shortened, anonymised or removed, ask that gym; if you cannot reach them, contact us at privacy@thriverplus.com and we will act.
7. Children and junior athletes
ThriverPlus accounts are for people aged 16 and over. We do not knowingly collect personal data directly from children.
Gym events often include competitors under 18. Those athletes are entered by the gym and do not have accounts, and we do not record ages, so we cannot identify which entries belong to minors. Under our Terms of Use the gym must hold parental or guardian consent both to the child’s participation and to publication of their name and results, and must consider whether publishing a full name is appropriate. We recommend displaying juniors by first name and last initial.
A parent or guardian can ask us to remove or anonymise a child’s entry at privacy@thriverplus.com. We will act on such requests as a priority.
8. The consent you gave at sign-up
When you created your account you ticked a box confirming that you accept our Terms of Use and Participant Waiver and consent to the processing described here. We record, for each document, which version you accepted, the exact wording shown to you, where it was shown, and a server-generated timestamp. That record is stored so that neither you nor we can alter it after the fact, and you can ask us for a copy at any time.
You can withdraw consent by asking us to close your account. Withdrawal does not affect processing that already happened, or processing we carry out on another lawful basis such as our own legal obligations.
9. Cookies
We use strictly necessary cookies only — the session cookies that keep you signed in and protect the sign-in process. We do not use advertising cookies, analytics cookies or cross-site tracking, so there is no cookie banner to click. Blocking these cookies will prevent you from signing in.
10. Who we share data with
We do not sell personal data and we do not share it for anyone else’s marketing. We use the following service providers (sub-processors), each under a data processing agreement:
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication and file storage | All stored data | Singapore |
| Vercel | Website hosting and content delivery | Request logs, IP addresses | United States and global edge network |
| Resend | Transactional email — confirmations, password resets, invitations | Email address, message content | United States |
We also share data where the law requires it, to establish or defend legal claims, or as part of a merger or sale of our business — in which case we will tell you before your data becomes subject to a different privacy policy.
A gym’s staff can see the athlete data for their own organisation only. Gyms cannot see each other’s data.
11. International transfers
Our database is hosted in Singapore, and our hosting and email providers operate from the United States and other countries. If you are in the EEA or the UK, this means your data is transferred outside those regions. We rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) in our agreements with those providers.
For transfers out of Malaysia, we rely on section 129 of the PDPA — transferring only where the recipient is subject to a law substantially similar to the PDPA or provides an adequate level of protection, or where the transfer is necessary to perform our contract with you.
12. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account is open, then deleted within 30 days of closure |
| Athlete data and published results | For as long as the gym keeps the event published, or until the gym or the athlete asks for removal |
| Consent record | For the life of the account, and deleted with it. We keep it as long as we may need to demonstrate consent |
| Change log (previous values of edited records) | 24 months, then deleted. Used only for security, disputes and abuse investigation |
| Feedback and screenshots | 24 months from resolution |
| Server and sign-in logs | As retained by our providers, typically 30–90 days |
| Backups | Rolling, overwritten within 30 days |
Deleting your account also deletes your consent record, because the record exists to document your relationship with us and is not needed once that relationship and its data are gone.
13. How we protect data
- Encryption in transit (HTTPS) and at rest.
- Passwords stored only as salted hashes — we never see your password.
- Row-level security in the database, so each gym’s staff can reach only their own organisation’s data, enforced by the database itself rather than by application code alone.
- Athlete contact details and feedback screenshots held in staff-only and private storage.
- A change log recording who modified what.
- Access to production systems limited to those who need it.
No service can promise perfect security. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant regulator and, where required, you — within the deadlines the law sets, including the 72-hour and 7-day requirements under the amended Malaysian PDPA.
14. Your rights
14.1 If the GDPR or UK GDPR applies to you
You have the right to access your data; to have inaccurate data corrected; to have data erased; to restrict or object to processing, including processing based on legitimate interests; to data portability; and to withdraw consent at any time.
14.2 Under the Malaysian PDPA
You have the right to access and correct your personal data, to withdraw consent, to prevent processing likely to cause damage or distress, to prevent processing for direct marketing (we do none), and — under the 2024 amendments — to data portability.
14.3 If you are a California resident
You have the right to know what we collect and why, to access and delete it, to correct it, and to non-discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising.
14.4 How to exercise your rights
Email privacy@thriverplus.com. We will respond within one month, or within 21 days for a PDPA access or correction request. We may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If you are an athlete rather than an account holder, contact the gym that entered you first — they control that data and can edit or remove your entry immediately. Copy us in if you would like us to help.
15. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. Leaderboard rankings are a straightforward calculation from the scores your gym enters.
16. Complaints
Please raise concerns with us first at privacy@thriverplus.com. You also have the right to complain to a supervisory authority: the Personal Data Protection Department (JPDP) in Malaysia, the Information Commissioner’s Office in the UK, or your national data protection authority in the EEA.
17. Changes to this policy
Each version of this policy carries a version date, shown at the top of this page. For material changes we will give reasonable notice by email or in the app before they take effect, and we will ask you to accept the new version where the law requires it. We keep a record of which version you accepted.
18. Contact
ThriverPlus — privacy@thriverplus.com.
19. Notis Privasi (Bahasa Malaysia)
Notis ini dikeluarkan menurut Akta Perlindungan Data Peribadi 2010. Sekiranya terdapat percanggahan antara versi Bahasa Malaysia dan versi Bahasa Inggeris, versi Bahasa Inggeris di atas akan terpakai.
19.1 Siapa kami
ThriverPlus ialah perkhidmatan papan pendahulu langsung untuk acara kecergasan, dikendalikan oleh ThriverPlus. Hubungi kami di privacy@thriverplus.com.
19.2 Data peribadi yang kami proses
- Pemegang akaun: alamat e-mel, kata laluan yang dicincang (hashed), rekod log masuk, organisasi yang anda sertai atau ikuti, dan rekod persetujuan anda.
- Atlet yang dimasukkan oleh gimnasium: nama pertama dan nama akhir, kategori atau bahagian, skor dan kedudukan. Alamat e-mel atlet (jika ada) hanya dapat dilihat oleh kakitangan gimnasium tersebut dan tidak diterbitkan.
- Data teknikal: log pelayan, alamat IP, cap masa, dan log perubahan rekod.
Kami tidak mengumpul data kesihatan, maklumat perubatan, bangsa, agama, data biometrik, nombor pengenalan diri, atau nombor kad pembayaran.
19.3 Tujuan pemprosesan
Untuk membuka dan mengurus akaun anda; untuk menerbitkan papan pendahulu dan keputusan acara; untuk menghantar e-mel perkhidmatan seperti pengesahan akaun, tetapan semula kata laluan dan jemputan kakitangan; untuk memastikan keselamatan perkhidmatan dan menyiasat penyalahgunaan; untuk membuktikan persetujuan anda kepada terma kami; dan untuk membaiki serta menambah baik produk.
Pemberian data peribadi adalah wajib untuk membuka akaun — tanpa alamat e-mel dan kata laluan, kami tidak dapat menyediakan perkhidmatan ini kepada anda.
19.4 Data yang diterbitkan secara awam
Nama atlet, kategori, skor dan kedudukan diterbitkan secara awam pada papan pendahulu. Maklumat ini boleh dilihat oleh sesiapa sahaja tanpa perlu log masuk dan mungkin diindeks oleh enjin carian. Alamat e-mel, kata laluan, maklum balas dan log perubahan tidak pernah diterbitkan.
19.5 Pendedahan kepada pihak ketiga
Data anda mungkin didedahkan kepada penyedia perkhidmatan kami — Supabase (pangkalan data dan pengesahan, Singapura), Vercel (pengehosan laman web, Amerika Syarikat) dan Resend (e-mel transaksi, Amerika Syarikat) — serta kepada pihak berkuasa apabila dikehendaki oleh undang-undang. Kami tidak menjual data peribadi anda dan tidak mendedahkannya untuk tujuan pemasaran pihak lain.
19.6 Pemindahan ke luar Malaysia
Data disimpan di Singapura dan diproses di negara lain oleh penyedia perkhidmatan kami. Pemindahan ini dibuat menurut seksyen 129 Akta tersebut, iaitu apabila penerima tertakluk kepada undang-undang yang setara atau memberikan perlindungan yang mencukupi, atau apabila pemindahan itu perlu bagi pelaksanaan kontrak kami dengan anda.
19.7 Tempoh penyimpanan
Data akaun disimpan sepanjang akaun anda aktif dan dipadam dalam tempoh 30 hari selepas penutupan. Data atlet disimpan selagi acara diterbitkan oleh gimnasium. Log perubahan dan maklum balas disimpan selama 24 bulan.
19.8 Hak anda
Anda berhak untuk mengakses data peribadi anda, membetulkan data yang tidak tepat, menarik balik persetujuan anda, menghadkan pemprosesan yang boleh menyebabkan kerugian atau tekanan, menghalang pemprosesan untuk pemasaran langsung, dan meminta kemudahalihan data. Hantarkan permintaan anda ke privacy@thriverplus.com. Kami akan membalas dalam tempoh 21 hari.
Jika anda seorang atlet dan bukan pemegang akaun, sila hubungi gimnasium yang memasukkan nama anda terlebih dahulu — mereka mengawal rekod tersebut dan boleh mengubah atau memadamkannya dengan segera.
19.9 Aduan
Sila hubungi kami dahulu di privacy@thriverplus.com. Anda juga berhak membuat aduan kepada Jabatan Perlindungan Data Peribadi (JPDP), Malaysia.