Privacy
Your data, handled as yours.
What we collect, why we collect it, who we share it with, and the rights you have. Written in plain English. Compliant with UK GDPR and the Data Protection Act 2018.
Contents
- Who we are (data controller)
- What this policy covers
- The data we collect
- Why we collect it, and our lawful basis
- Special category health data
- Who we share it with
- International transfers
- How long we keep it
- How we keep it safe
- Your rights under UK GDPR
- Cookies and similar technology
- Children
- Changes to this policy
- How to contact us about privacy
1. Who we are (data controller)
Smoov Shakes UK Limited is a company registered in England and Wales, company number 14918686. Our registered office is in London, United Kingdom.
We are the data controller for the personal data described in this policy. For any question about how we handle your data, write to: privacy@smoovuk.com.
We are not required to appoint a Data Protection Officer under UK GDPR, but the same address — privacy@smoovuk.com — handles all data-protection queries.
2. What this policy covers
This policy covers all personal data we collect through our website (living.smoovuk.com), the SMOOV Living iOS app, the membership application form, the Healf Zone test workflow, and any email or message you send us directly.
It does not cover external sites or apps we link to — including the Apple App Store, Healf Limited, Terra, Whoop, Oura, and Garmin. Each of those services operates under its own privacy policy.
3. The data we collect
Identity and contact
Your name, email address, phone number (if you give it), member number, and postal address (only if we ship your test kit to you).
Application data
The answers you give in your membership application — including lifestyle notes, goals, current routines, and dietary information.
Payment data
Card payments are handled by Stripe. We receive payment confirmation, the last four digits of your card, your billing country, and your Stripe customer ID. We do not see or store full card numbers at any point.
Biomarker data (special category — health)
The results of your Healf Zone blood test, received from Healf Limited with your explicit consent. This is "special category" health data under UK GDPR Article 9.
Wearable data (special category — health)
Heart-rate variability, resting heart rate, sleep, recovery scores, steps, training load, menstrual cycle information (where you choose to share it), and similar metrics from Whoop, Oura, Apple Health, Garmin, and other devices you connect via the Terra platform. This is also "special category" health data under UK GDPR Article 9.
App usage data
Which screens you open, when you sign in, your device type, and your operating system version. Anonymous diagnostic data to help us fix crashes. We do not use third-party analytics software that profiles you across other apps or websites.
Communications
The content of emails, in-app messages, and contact form submissions you send us.
Server logs
IP address, request timestamp, and basic request metadata. Retained for security and abuse prevention only.
4. Why we collect it, and our lawful basis
Running your membership
We process your identity, contact, and application data to accept and administer your membership. Lawful basis: contractual necessity (UK GDPR Art. 6(1)(b)).
Taking payment
We process payment confirmation and the associated Stripe data to charge and record your membership fee. Lawful basis: contractual necessity.
Generating and updating your protocol
We process your biomarker results and wearable data to build and refresh your personal protocol. Lawful basis: your explicit consent to process special category health data (UK GDPR Art. 9(2)(a)). You give this consent in the app when you accept the welcome flow or connect each wearable.
Transactional emails
Sign-in links, billing receipts, test logistics, and protocol updates are sent on the basis of contractual necessity and legitimate interest.
Optional marketing
Event invites, product news, and similar communications are sent only with your separate, specific consent. You can withdraw this at any time by clicking "unsubscribe" in any marketing email or writing to us.
Legal obligations
Tax records, fraud prevention, and responses to lawful requests from authorities. Lawful basis: legal obligation (UK GDPR Art. 6(1)(c)).
Security and dispute handling
Server logs and records needed to defend the business against legal claims. Lawful basis: legitimate interest, balanced against your rights and interests.
5. Special category health data — how we handle it
Your biomarker results and wearable data are "special category" data under UK GDPR Article 9. We process them solely on the basis of your explicit, informed consent, and only for the purposes you gave that consent for: generating your protocol and displaying your numbers in the app.
We will never use your health data to set insurance prices, market third-party products to you, or share it for any research purpose without a separate consent process and, where required, an appropriate ethics review.
You can withdraw your consent at any time by writing to privacy@smoovuk.com or using the relevant controls inside the app. On withdrawal, we will stop all processing of your special category health data immediately.
6. Who we share it with
We share data only with the processors and sub-processors needed to deliver your membership. We do not sell your data. We do not share it with advertisers or data brokers.
Healf Limited
Registered in England and Wales. Performs your blood test and returns results to us. Healf acts as a separate controller for the laboratory process itself; we become the controller for your results once we receive them.
Terra API Inc.
Registered in the United States. Provides the wearable-data integration layer. Data transferred to the US is covered by UK ICO Standard Contractual Clauses with UK International Data Transfer Addendum.
Stripe Payments UK Ltd / Stripe Payments Europe Ltd
Processes your membership payment. Certified PCI-DSS Level 1.
Vercel Inc.
Registered in the United States. Hosts our website and API. Data transfers covered by UK SCCs with UK addendum.
Turso (ChiselStrike Inc.)
Registered in the United States. Provides our primary database, hosted in AWS eu-west-1 (Ireland). Data is stored in the European Economic Area.
Resend Inc.
Registered in the United States. Delivers our transactional emails. Data transfers covered by UK SCCs with UK addendum.
Apple Inc.
Distributes the SMOOV Living app through the App Store. Apple receives only what its own privacy policy describes.
Slack Technologies LLC
Registered in the United States. Used for internal team communications where strictly necessary. Data transfers covered by UK SCCs with UK addendum. Member data is not routed through Slack as a matter of policy.
7. International transfers
Where your data leaves the UK — primarily to US-based processors listed above — we rely on the UK ICO Standard Contractual Clauses and the UK International Data Transfer Addendum, combined with our own assessment that the transfer is appropriate given the type of data and the safeguards in place.
You can request a copy of the relevant safeguards by writing to privacy@smoovuk.com.
8. How long we keep it
- Identity and contact data — for the life of your membership, then 6 years after it ends (to meet tax and accounting obligations).
- Biomarker and wearable data — for the life of your membership, then anonymised within 30 days of your membership ending, unless you request deletion sooner.
- Payment records — 6 years (statutory requirement).
- Email and message history — 3 years after last contact.
- Server logs — 90 days.
On a valid deletion request, we will delete or anonymise your data within 30 days, except where we are required by law to retain it. Where we must retain data, we will tell you which categories and why.
9. How we keep it safe
We apply the following protections:
- Encryption in transit (TLS 1.2 or higher) and encryption at rest for the database.
- Database access tokens scoped to the minimum necessary for each service.
- Two-factor authentication on all internal admin accounts.
- Due diligence review before onboarding any new processor.
- Magic-link authentication for member accounts — 15-minute, one-time tokens — meaning no passwords are stored.
In the event of a personal data breach that is likely to affect your rights or freedoms, we will notify you, the ICO, and — where required — any other relevant authority within 72 hours of becoming aware.
10. Your rights under UK GDPR
You have the following rights regarding your personal data. To exercise any of them, write to privacy@smoovuk.com. We will respond within one calendar month.
- Access — receive a copy of the personal data we hold about you.
- Rectification — ask us to correct anything that is inaccurate or incomplete.
- Erasure — ask us to delete your data (subject to any legal retention obligations).
- Restriction — ask us to pause processing while a query or dispute is being resolved.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Object — to processing based on legitimate interest, or to any marketing communications (this is honoured immediately).
- Withdraw consent — for any processing that relies on consent, including all special category health data.
Complaining to the ICO
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Post: Wycliffe House, Water Lane, Wilmslow, SK9 5AF
- Phone: 0303 123 1113
We would always prefer to resolve any concern directly first — please contact us before going to the ICO.
11. Cookies and similar technology
The SMOOV Living marketing site (living.smoovuk.com) uses one strictly necessary session cookie for sign-in, and a small number of strictly necessary security cookies.
We do not use any analytics, advertising, or third-party tracking cookies. We do not integrate any cross-site tracking technologies on this site.
The iOS app uses secure local storage on your device to hold your session token only. No cross-app tracking technologies are used in the app.
12. Children
SMOOV Living is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data in error, please write to privacy@smoovuk.com and we will delete it promptly.
13. Changes to this policy
Material changes to this policy will be sent to you by email at least 14 days before they take effect. The version date at the top of this page will be updated at the same time.
We keep earlier versions of this policy on file and can provide them on request.
14. How to contact us about privacy
By email: privacy@smoovuk.com
By post: Smoov Shakes UK Limited, London, United Kingdom.
We will respond to all privacy enquiries within one calendar month.