Stepholt app legal information
General App Privacy Policy
This policy explains the types of personal information that may be handled through mobile Apps designed, developed, published or supported by Stepholt.
This policy explains the types of personal information that may be handled through mobile Apps designed, developed, published or supported by Stepholt.
Where Stepholt operates an App, Stepholt Ltd is normally the controller. For client-owned Apps, the client is normally the controller and Stepholt may act as developer or processor. Read the app-specific notice and store disclosures alongside this policy.
1. Scope and who is responsible
This policy covers personal information processed through mobile Apps designed, developed, published or technically supported by Stepholt Ltd.
Where Stepholt operates an App, Stepholt Ltd is normally the controller. Where an App is built for a client, that client is normally the controller and Stepholt may process information as its developer or service provider.
An app-specific notice takes priority for exact collection, purposes, providers and controller details.
Stepholt Ltd
Blue Tower, Blue, MediaCityUK, Salford Quays, Manchester M50 2ST, United Kingdom
Registered in England and Wales. Company number 17283481.
Email: hello@stepholt.com
App support: https://stepholt.com/app-support/
2. Information an App may collect
Depending on the App and features used, information may include:
| Category | Examples | Typical purpose |
|---|---|---|
| Account | Name, email, username, profile image, password hash, organisation | Create and manage access |
| Support | Messages, screenshots, correspondence | Answer questions and diagnose issues |
| Community content | Profiles, posts, comments, reviews, images and videos | Provide social features |
| Transactions | Order, subscription, booking or purchase references | Provide paid services and support |
| Technical | Device model, OS, app version, IP address, identifiers and diagnostics | Security, compatibility and fault diagnosis |
| Usage | Screens visited, interactions and preferences | Operate and improve the App |
| Location | Approximate or precise location where enabled | Maps, local content or verification |
| Media and files | Selected photos, videos, documents and metadata | Uploads and app workflows |
| Notifications | Push token and notification settings | Send requested notifications |
Not every App collects every category. Payment card details are normally entered directly into Apple, Google, Stripe or another payment provider.
3. How information is collected
- directly from you when registering, uploading content or contacting support;
- automatically from the App, device and connected services;
- from an employer, membership organisation, school, club, client or administrator managing access;
- from Apple, Google, social sign-in or identity providers you choose;
- from ecommerce, booking, payment, CRM or content systems connected to the App; and
- from security, analytics, crash-reporting and infrastructure providers.
4. How information may be used
- create, authenticate and manage accounts;
- provide app features, memberships, bookings, purchases and content;
- display content you choose to share;
- send transactional messages, security alerts and requested notifications;
- respond to support and investigate faults;
- protect users, prevent fraud and maintain security;
- measure performance and improve accessibility and usability;
- administer subscriptions, competitions or rewards;
- meet legal, accounting and safeguarding obligations; and
- send marketing only where permitted.
5. Lawful bases
Where UK data protection law applies, processing may rely on contract, legitimate interests, consent, legal obligation, vital interests or public task, depending on the App and purpose.
Where special-category information is processed, the responsible controller must identify an additional legal condition in app-specific information.
6. Device permissions
An App may request camera, photographs, files, microphone, location, contacts, calendar, Bluetooth, notifications or biometric login access. Access should only be requested for a described feature.
You can normally manage permissions in device settings. Refusing an optional permission may prevent the related feature but should not affect unrelated features.
8. International transfers
Some providers may process information outside the UK. Restricted transfers should use an approved mechanism such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to standard contractual clauses or another lawful safeguard.
9. Retention
Information is kept only as long as reasonably needed for account operation, support, security, legal obligations and dispute resolution.
Retention depends on account status, contracts, statutory periods, financial records, safeguarding duties and backup cycles. Information is then deleted, anonymised or securely isolated.
10. Security
Proportionate measures may include access controls, encrypted connections, secure authentication, least-privilege access, backups, monitoring and software updates.
No mobile or internet service can guarantee absolute security. Use a strong unique password and report suspected compromise promptly.
11. Your choices and rights
Depending on the law and circumstances, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent and human review of certain automated decisions.
Rights are not absolute and may be subject to identity checks, exemptions and retention duties. For a client-owned App, requests may need to be sent to that client as controller.
12. Account and data deletion
Where an App allows account creation, it should provide an in-app deletion route or direct you to a web request method, subject to lawful exceptions.
Use the App’s settings, named support contact or Stepholt App Support page. Identify the App and account email, but never send your password.
Some information may be retained for legal, financial, security, safeguarding or dispute reasons.
13. Children’s privacy
Apps not designed for children should not knowingly collect information from a child below the stated minimum age without appropriate authority.
Apps likely to be accessed by children should apply age-appropriate design, privacy by default, clear language, data minimisation and appropriate safeguards.
14. Notifications and marketing
Service notifications may include security alerts, account messages, booking updates or membership information. Optional push notifications can usually be managed in the App or device settings.
Marketing email, SMS or push messages are sent only where permitted, with an unsubscribe or preference method.
15. Analytics and similar technology
Apps may use diagnostics, local storage, device identifiers, SDKs and similar technology for essential operation, security, preferences, analytics and crash reporting.
Where consent is required for non-essential storage, access or tracking, it should be requested first. Apple privacy details and Google Play Data safety disclosures should match actual App and third-party SDK practices.
16. Changes to this policy
This policy may be updated for changes in Apps, technology, law or providers. Material changes will receive additional notice or consent where required.
17. Contact and complaints
Contact and complaints
For a client-owned App, contact the organisation named in that App first. For Apps controlled by Stepholt, or where you are unsure:
Stepholt Ltd
Blue Tower, Blue, MediaCityUK, Salford Quays, Manchester M50 2ST, United Kingdom
Registered in England and Wales. Company number 17283481.
Email: hello@stepholt.com
App support: https://stepholt.com/app-support/
You may also complain to the UK Information Commissioner’s Office. We encourage you to contact the responsible controller first.
Each App must be reviewed before release so its policy, permissions, Apple privacy details and Google Play Data safety answers match its actual data and SDKs.