Kivara — Privacy Policy
Last updated: March 2026
3R Digital Solutions ("we", "us", "our") builds and operates Kivara, a platform for trainers and athletes to manage classes, attendance, payments, appointments, competitions, communications, and training activity. This privacy policy describes how we collect, use, store, share, and protect your information in connection with Kivara, including our integration with Garmin Connect and the Garmin API.
By creating a Kivara account, connecting your Garmin account, or using features that rely on Garmin data, you agree to the terms outlined in this policy.
1. Information we collect
1.1 Account information
When you register for Kivara, we collect your name, email address, phone number (optional), role (trainer or athlete), and profile details such as photo and membership type. Trainers may also provide gym or business information.
1.2 Training and class data
Kivara collects information you provide or generate through the platform, including:
- Class types, schedules, and rosters
- Attendance records
- Payment information and history (payment proof, status, amounts)
- Appointments and availability
- Competition enrollment and history
- Messages, campaign content, and delivery status
1.3 Garmin activity data
When you connect your Garmin account to Kivara, we receive activity and training data that you have authorized Garmin to share with us via the Garmin API. We do this only with your explicit consent when you link your account or authorize the connection.
This may include:
- Training and activity dates
- Activity summaries and metrics (e.g. duration, distance, speed, pace, type of activity)
- Fitness and health-related data you choose to share (e.g. steps, heart rate, calories, sleep data), where applicable
- Device information (e.g. device type or identifier) necessary to associate activities with your account
We treat activity and health-related data as sensitive. We apply enhanced safeguards and only collect the data necessary for training follow-up and coaching workflows.
1.4 Device and usage information
We may collect technical information from the device used to access Kivara, such as device type, operating system, and app usage patterns, to operate and improve the service.
2. How we use your information
- To provide Kivara's services: Manage classes, attendance, payments, appointments, competitions, and communications between trainers and athletes.
- To display training activity: Import, process, and display your Garmin activity data to you and your designated trainers, so trainers can follow plan adherence and athletes can review their progress.
- To send notifications: Deliver push notifications, WhatsApp messages, and in-app notifications related to your classes, payments, appointments, competitions, and training.
- To operate and improve Kivara: Analyze usage, troubleshoot issues, and enhance functionality in a secure and reliable way.
We do not use Garmin activity data or health-related data for advertising. We do not use it for purposes unrelated to training and the services you have requested.
3. Legal basis for processing
- Your consent: You give explicit consent when you create your account, connect your Garmin account, or authorize access to your activity data. You may withdraw this consent at any time.
- Contractual necessity: Processing is necessary to provide the services you have requested (e.g. managing your classes, allowing trainers to follow your training plan).
- Legitimate interest: For purposes such as improving Kivara, ensuring security, and analyzing usage trends, where these interests do not override your rights.
4. How we share your information
We do not sell, rent, or trade your personal data or Garmin activity data. We do not share it with third parties for their marketing or advertising purposes.
We may share your information only in these circumstances:
- With your trainers and authorized users: Trainers assigned to you can see your class enrollment, attendance, payment status, and training activity from Garmin. Athletes see their own data and class/trainer information relevant to them.
- With Garmin: To access your activity data via the Garmin API, as authorized by you when you connect your account.
- With service providers: Trusted third-party providers who assist us in running Kivara (e.g. cloud hosting, push notification delivery, WhatsApp Business API), under strict confidentiality and data-processing obligations.
- When required by law: If required by court order, subpoena, or applicable regulation.
5. Data retention and security
We retain your data only as long as necessary to provide Kivara's services or as required by law. You may request deletion of your data at any time.
We apply technical and organizational measures to protect your data, including:
- Encryption: Data transmitted between your device, the Garmin API, and our systems is encrypted (e.g. TLS)
- Secure storage: Data is stored on secure, compliant infrastructure with encryption at rest
- Access controls: Access to personal data is restricted to authorized personnel with appropriate authentication
- Secure Garmin access: We use OAuth 2.0 to access your Garmin data, in line with Garmin's API and security guidelines
6. Third-party services
Kivara integrates with the Garmin API (Garmin Connect). That integration is subject to Garmin's own Privacy Policy. We encourage you to review Garmin's policy to understand how they collect and handle your data.
Kivara may also use third-party services for push notifications (e.g. Firebase Cloud Messaging), messaging (e.g. WhatsApp Business API via Twilio or Meta Cloud API), hosting, and analytics. These providers process data on our behalf under contractual obligations.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data, subject to legal retention requirements
- Restrict or object to certain processing
- Data portability: Request a copy of your data in a structured, machine-readable format
- Withdraw consent and revoke the connection between Kivara and your Garmin account at any time (via your Garmin account settings or Kivara's settings). Withdrawing consent may limit your ability to use features that rely on Garmin data.
To exercise these rights, contact us using the details below. We will respond within the timeframes required by applicable law (e.g. within 30 days where required under laws such as GDPR).
8. Children's privacy
Kivara is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected such data, we will promptly delete it.
9. Changes to this policy
We may update this privacy policy from time to time. The "Last updated" date at the top will be revised when we do. We will notify users of material changes via the app, email, or other reasonable means. We encourage you to review this page periodically.
10. Contact
For privacy-related questions or requests about Kivara:
3R Digital Solutions
Email: [email protected]