Privacy Policy
Footwork · websites and apps that stand on their own feet · Version v1 · Effective 2026-10-04
This policy explains what personal data Footwork · websites and apps that stand on their own feet collects on https://breakandcode.com and in its app, how it is collected, what it is used for, who receives it, how long it is kept, and how you can withdraw consent and have your data deleted.
Who is responsible
Dance Healthy (registered 86264559), Herenstraat 32, 1506DL Zaandam, is the controller responsible for your personal data under the Algemene Verordening Gegevensbescherming (AVG) / General Data Protection Regulation (EU) 2016/679.
Contact: riki@coffeeanddance.nl
What we collect, and how
- What your browser sends when you visit. Your IP address and browser details are used at the moment you visit, to deliver the page and to stop abuse (for example by limiting how many requests one address can make in an hour). Our request logs record the page that was asked for and the result, not your IP address; a few warnings, such as a sign-up turned away as automated, note the email address involved
- Your account, which you give us when you sign up: your name, your email address and, if you add it, your phone number. Your password is stored only as a bcrypt hash, never in a form anyone can read. If you turn on two-step sign-in, the secret behind your authenticator app is stored encrypted
- Payments, when you buy something: the amount, what it was for and Stripe's reference for the payment, and, if you order goods to be delivered, the delivery address and phone number you enter. Card details go only to Stripe
- What you upload: the images, files and text you add
- Visit statistics, only if you choose "Accept all" on the cookie notice: the page you viewed, the site you came from, your type of device, your country and your language. Instead of your IP address we keep a code that changes every day, so a visit cannot be traced back to you or linked to another day
- Google Analytics, only if you choose "Accept all" on the cookie notice in a web browser: the site owner's visit statistics from Google, which receives the pages you view, your device and browser, and your IP address, and sets its own cookies. It is never loaded inside the app
- Push notifications, if you allow them: the token your device uses to receive them
- Your location, only when you use a feature that needs it and only after you allow it on your device. It is used for that request and not stored
- Proof of your consent: when you accept the terms and this policy we record the time, the version you accepted, your IP address and your browser, because the law requires us to be able to show that you agreed (AVG Art. 7(1))
We collect nothing else. We do not collect health data, contacts, your precise location in the background, or anything from other apps on your device.
What we use it for, and on what basis (AVG Art. 6)
- To give you what you asked for (performance of a contract, Art. 6(1)(b)): running your account, handling your order and payment
- To keep the service secure and stop abuse (our legitimate interest, Art. 6(1)(f)), weighed against your rights and never used to profile you
- To keep financial records (legal obligation, Art. 6(1)(c), under Artikel 52 AWR)
- To be able to show you agreed (legal obligation, Art. 6(1)(c) with Art. 7(1))
- Only with your consent (Art. 6(1)(a)), which you can withdraw at any time: visit statistics, Google Analytics, push notifications, location
We make no decisions about you by automated means alone and we do not build profiles of you.
Giving us your name and email address is needed to open an account; without them we cannot. Everything else is optional.
Who receives it
The following companies process personal data for us, each under a data processing agreement (AVG Art. 28) that binds them to protect it to the same standard as this policy and to use it only on our instructions:
- Railway Corp.: Application and database hosting
- Cloudflare, Inc.: Delivering this site's domain and protecting it against network abuse
- Stripe, Inc. and Stripe Payments Europe Ltd.: Payment processing (PCI-DSS Level 1). You pay on Stripe's own page, so card details go only to Stripe and never reach us
- Bunny.net (BunnyWay d.o.o.): Image and video storage and delivery
- Brevo (Sendinblue SAS): Sending the emails this site sends you
- Mailgun Technologies, Inc.: Back-up email delivery, used only if Brevo is unavailable
- Apple Inc. (APNs): Delivering iOS push notifications
Where this site uses the following, your browser contacts them directly, and they process that data under their own privacy terms and Google's EU data protection terms, which bind them to the protection the GDPR requires:
- Google Ireland Ltd. / Google LLC (Google Analytics): Visit statistics for the site owner. Loaded only in a web browser after you choose "Accept all" on the cookie notice, and never inside the app
The people who run this site can see your details in order to run it. We do not sell, rent or trade your personal data, and we do not share it with anyone for their own advertising.
Transfers outside the EEA
Railway, Cloudflare, Stripe, Mailgun, Apple and Google are based in, or work with sub-processors in, the United States. Those transfers are covered by the EU–US Data Privacy Framework where the company is certified under it, and otherwise by the European Commission's Standard Contractual Clauses (AVG Art. 46(2)(c)). Ask us at the address below for a copy of the safeguards.
How long we keep it
- Request logs, which hold no IP address and no account details: only as long as our hosting provider keeps its logs, and never combined with anything that identifies you
- Your account: until you delete it. Deletion happens at once and cannot be undone
- Financial records: 7 years, as Dutch tax law requires (Artikel 52 AWR). They are kept apart from your account and used for nothing else
- Proof of consent: with your account, and deleted with it
- Visit statistics: kept as statistics; they contain no IP address and no identifier that lasts beyond a day
- Push tokens: until you turn notifications off, after which the token is switched off and never used again
- Location: not stored at all
- App health signals: 30 days
Mobile app
The Footwork · websites and apps that stand on their own feet app shows this same service, so everything above applies to it. In addition:
- App health signals: when the app opens or loses its connection it tells us the app version, the phone's system version and what happened, with no identifier and nothing about you. We keep these for 30 days to find faults
- Push notifications: the device token Apple (APNs) gives the app, used only to deliver notifications you have allowed
- Face ID, Touch ID or fingerprint lock when you open the app: the check happens on your device, by your phone's own system. The app is told only whether it succeeded; no biometric data ever reaches us
- Location, only for a feature you are using and only after you allow it. Precise coordinates are not stored
- Camera, microphone and photo library, only at the moment you use a feature that needs them, never in the background
- No tracking: the app contains no advertising SDK, reads no advertising identifier and shares nothing with data brokers. It loads no advertising or measurement tag.
- No cookie notice in the app, because nothing in it needs your consent: optional visit statistics and Google Analytics are switched off inside the app
You can withdraw any permission at any time in your device's settings, and the app keeps working apart from the feature that needed it.
This app follows Apple's App Store Review Guidelines (§5 Privacy) and its App Privacy answers describe exactly the data in this policy.
Cookies
Strictly necessary cookies, which keep you signed in and remember your cookie choice, are set without asking because the site cannot work without them. Optional cookies (visit statistics, Google Analytics) are used only after you choose "Accept all" on the cookie notice. The Cookie Policy on this site lists every cookie by name.
Children
This site is meant for people aged 16 and over, and you have to be 16 or older to open an account. If you are a parent or guardian and believe a child under 16 has given us their details, write to riki@coffeeanddance.nl and we will delete them.
Your rights, and how to withdraw consent
You have the right to see the data we hold about you, to have it corrected or deleted, to restrict or object to how it is used, and to receive it in a portable format (AVG Art. 15–22). You can download your data yourself from your account page, and delete your account there too. For anything else, write to riki@coffeeanddance.nl. We answer within one month.
Where we rely on your consent you can withdraw it at any time, as easily as you gave it, and without affecting what was done before:
- Cookies: open this site with ?cookie-settings at the end of the address (for example https://breakandcode.com/?cookie-settings) and the cookie notice comes back, with your earlier choice forgotten and this site's own Google cookies removed
- App permissions: your device's settings
- Everything else: delete your account (see below), or write to us
If you are unhappy with how we handle your data, you can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live.
Deleting your account
You can delete your account yourself, in the app or on the site, at any time: sign in, open your account, and choose Delete my account (you will find it under Data or Security). You confirm with your password, and with your two-step code if you turned that on. Deletion takes effect immediately and nobody has to approve it. If you cannot sign in, write to riki@coffeeanddance.nl from the address on the account and we delete it within 30 days, normally the same day. The page "Deleting your account" on this site explains exactly what is removed and what the law requires us to keep.
Security
Everything travels over an encrypted connection (TLS). Passwords are stored only as bcrypt hashes and two-step secrets are encrypted. Only the people who run the site can see your details, each through their own account.
Data breaches
A breach that is likely to put your rights at risk is reported to the Autoriteit Persoonsgegevens within 72 hours, and to you without undue delay where the risk is high (AVG Art. 33–34).
Changes
Material changes are announced on this page with a new version number and effective date, and where a change affects how your data is used you will be asked to accept it again.
Contact
Dance Healthy, Herenstraat 32, 1506DL Zaandam
riki@coffeeanddance.nl
Governing law: the Netherlands.