Privacy policy
JPJR Fitness Pro · last updated 9 September 2026
Who this covers
This policy covers JPJR Fitness Pro, the coaching plugin, and
the sign-in service we operate at oauth.jpjr.ca. It is published by
JPJR Code, a business established in Quebec, Canada, contactable at
code@jpjr.ca.
It does not cover a trainer’s own website. The plugin is installed on the trainer’s server and stores its data in their database. The trainer decides what to collect from their clients and is responsible for that data; each of them should publish their own policy, and the plugin includes an editor for exactly that. We have no access to any of it.
What we operate, and what it holds
The only service JPJR Code runs is the Google sign-in broker. It exists because Google requires a single registered return address, and a plugin installed on hundreds of independent websites cannot have one.
It stores nothing. No database, no session, no logs of who connected. It passes an authorisation between Google and the trainer’s own site and forgets it. The trainer’s site holds the resulting credentials, encrypted, in its own database, and talks to Google directly from then on.
Google Calendar
If a trainer connects a Google Calendar, we request permission to read the calendar’s busy times, to see the list of their calendars so they can choose one, and to create and update events for sessions booked through their site.
What is stored
The start time, end time and busy/free status of events on the selected calendar, so the booking page does not offer a time the trainer is already committed to. Also the event identifier and, for events the plugin created itself, its own reference.
We do not store event titles, descriptions, attendees, locations or attachments. Where Google returns those, they are read to determine availability and then discarded.
What is written
An event on the selected calendar for each session booked through the site, updated if the session moves and removed if it is cancelled. The plugin only ever modifies events it created itself, identified by a private property it sets. It never alters or deletes anything else on a calendar.
Who sees it
Nobody but the trainer. Their clients see only that a time slot is unavailable — never why, and never any detail from the calendar.
How long it is kept
Busy times are kept only for the booking window currently on offer and are replaced on each sync. Disconnecting the calendar, from Settings → Calendar in the app, deletes the stored access tokens and the mirrored busy times immediately. Access can also be revoked at any time at myaccount.google.com/permissions.
Sharing
Google user data obtained through this integration is never sold, never used for advertising, and never transferred to anyone else. It is not used to train any model, ours or anyone’s.
JPJR Fitness Pro’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies and analytics
The sign-in broker sets no cookies and runs no analytics. It has no tracking of any kind.
Your rights
Because we hold no personal data of our own, there is normally nothing for us to export or delete. Anything held about a trainer’s clients lives on the trainer’s own site, and requests should go to them; the plugin implements WordPress’s own export and erasure tools so they can answer.
If you believe we hold something about you, write to code@jpjr.ca and we will answer within 30 days.
Changes
If this policy changes materially we will update the date at the top. Continued use of the software after a change does not by itself constitute agreement to it; where consent is required, it is asked for again.
Contact
JPJR Code — code@jpjr.ca