Fitbit Privacy Policy

Last update: 2 August 2024

Note: If you use your Fitbit devices and services with a Google Account, then your data will be handled as described in the Google Privacy Policy, and as explained in more detail in these FAQs on privacy.

We believe that transparency is the key to any healthy relationship. At Fitbit, we're all about healthy. We appreciate that you are trusting us with information that is important to you, and we want to be transparent about how we use it.

Here, we describe the privacy practices for our devices, applications, software, websites, APIs, products and services (the 'Services'). You will learn about the data that we collect, how we use it, the controls that we give you over your information and the measures that we take to keep it safe.

Specifically, we'll cover:

INFORMATION THAT WE COLLECT

When you use our Services, we collect the following types of information, some of which may be considered consumer health data as defined in certain US state laws, such as the Washington My Health My Data Act and Nevada Senate Bill 370.

INFORMATION THAT YOU PROVIDE US

ACCOUNT INFORMATION
Some information is required to create an account on our Services, such as your name, email address, password, date of birth, gender, height, weight and in some cases, your mobile telephone number. This is the only information that you have to provide to create an account with us. You may also choose to provide other types of information, such as a profile photo, biography, country information and community username.

ADDITIONAL INFORMATION
To help improve your experience or enable certain features of the Services, you may choose to provide us with additional information, like your logs for food, weight, sleep, water or female health tracking; an alarm; and messages on discussion boards or to your friends on the Services.

You may also connect with friends on the Services or invite friends who have not yet joined by providing their email addresses, accessing social networking accounts or using the contact list on your mobile device. We do not store your contact list, and delete it after it is used for adding contacts as friends.

If you contact us or participate in a survey, contest or promotion, we collect the information that you submit, such as your name, contact information and message.

PAYMENT AND CARD INFORMATION
Some Fitbit devices support payments and transactions with third parties. If you activate this feature, you must provide certain information for identification and verification, such as your name, credit, debit or other card number, card expiry date and CVV code. This information is encrypted and sent to your card network, which upon approval sends back to your device a token, which is a set of random digits for engaging in transactions without exposing your card number. For your convenience, we store the last four digits of your card number and your card issuer’s name and contact information. You can remove the token from your account using your account settings. We do not store your transaction history.

If you purchase Fitbit merchandise on our website, you provide your payment information, including your name, credit or debit card number, card expiry date, CVV code and billing address. We do not store this payment information. We store your delivery address to fulfil your order. Note that third-party payment processors may retain this information in accordance with their own privacy policies and terms.

LIVE COACHING SERVICES
Our live coaching services are a platform for you to communicate with a live health, fitness or wellness coach ('Live Coaching Services'). Coaches may be provided by third parties, such as your employer or insurance company, or by our third-party coaching service providers. If you use our Live Coaching Services, we collect information about such use, including the plan, goals and actions that you record with your coach, your calendar events, communications with your coach, notes that your coach records about you and other information submitted by you or your coach.

INFORMATION THAT WE RECEIVE FROM YOUR USE OF OUR SERVICES

DEVICE INFORMATION
Your device collects data to estimate a variety of metrics, like the number of steps that you take, your distance travelled, calories burned, weight, heart rate, sleep stages, active minutes and location. The data collected varies depending on which device you use. Learn more about the features of our various devices and how you can use MobileTrack. When your device syncs with our applications or software, data recorded on your device is transferred from your device to our servers.

GEOLOCATION INFORMATION
The Services include features that use precise geolocation data, including GPS signals, device sensors, Wi-Fi access points and mobile tower IDs. We collect this type of data if you grant us access to your location. You can always remove our access using your Fitbit device or mobile device settings. We may also derive your approximate location from your IP address.

USAGE INFORMATION
When you access or use our Services, we receive certain usage or network activity information. This includes information about your interaction with the Services, for example, when you view or search content, install applications or software, create or log in to your account, pair your device to your account or open or interact with an application on your Fitbit device.

We also collect data about the devices and computers that you use to access the Services, including IP addresses, browser type, language, operating system, Fitbit or mobile device information (including device and application identifiers), the referring web page, pages visited, location (depending on the permissions that you have granted us) and cookie information.

INFORMATION THAT WE RECEIVE FROM THIRD PARTIES

If you choose to connect your account on our Services to your account on another service, we may receive information from the other service. For example, if you connect to Facebook or Google, we may receive information like your name, profile picture, age range, language, email address and friend list. You may also choose to grant us access to your exercise or activity data from another service. You can stop sharing the information from the other service with us by removing our access to that other service.

We may partner with third parties, such as employers and insurance companies that offer Fitbit Services to their employees and customers. In such cases, those companies may provide us with your name, email address or similar information (like a telephone number or subscriber ID) so that we can invite you to participate or determine your eligibility for particular benefits, such as discounts or free services.

HOW WE USE INFORMATION

We use the information that we collect with your consent or to provide the Services that you request, including for the following purposes.

PROVIDE AND MAINTAIN THE SERVICES
Using the information that we collect, we are able to deliver the Services to you and honour our Terms of Service contract with you. For example, we need to use your information to provide you with your Fitbit dashboard tracking your exercise, activity and other trends; to enable the community features of the Services; and to give you customer support.

For the Services' community features, we may use your information to help you find and connect with other users and to allow other users to find and connect with you. For example, your account contact information allows other users to add you as a friend. When another user has your email or mobile phone number in their contact list, we show that user that you are a user of the Services.

If you use the Live Coaching Services, we use your information to connect you with coaches, allow you to communicate with them through our Services, and help you achieve your goals to lead a healthier, more active life. For example, the goals that you provide allow you to develop a personal plan and set of actions in consultation with your coach.

IMPROVE, PERSONALISE AND DEVELOP THE SERVICES
We use the information that we collect to improve and personalise the Services and to develop new ones. For example, we use the information to troubleshoot and protect against errors; perform data analysis and testing; conduct research and surveys; and develop new features and Services, which may include generative artificial intelligence models.

When you allow us to collect precise location information, we use that information to provide and improve features of the Services, such as recording where a workout took place or mapping an activity.

We also use your information to make inferences and show you more relevant content as part of providing the services that you request. Here are some examples:

  • Information like your height, weight, gender and age allows us to improve the accuracy of your daily exercise and activity statistics like the number of calories that you burned and the distance that you travelled.
  • Based on your sleep data, we may make inferences about your sleeping patterns and provide you with customised insights to help you improve your sleep.
  • We may personalise exercise and activity goals for you based on the goals that you previously set and your historical exercise or activity data.

COMMUNICATE WITH YOU
We use your information when needed to send you Service notifications and respond to you when you contact us. We also use your information to promote new features or products that we think you would be interested in. You can control marketing communications and most Service notifications by using your notification preferences in account settings or via the 'Unsubscribe' link in an email.

PROMOTE SAFETY AND SECURITY 
We use the information that we collect to promote the safety and security of the Services, our users and other parties. For example, we may use the information to authenticate users, facilitate secure payments, protect against fraud and abuse, respond to a legal request or claim, conduct audits and enforce our terms and policies.  

HOW INFORMATION IS SHARED

We never sell the personal information of our users. We do not share your personal information except in the limited circumstances described below.

WHEN YOU AGREE OR DIRECT US TO SHARE
You may direct us to disclose your information to others, such as when you use our community features, like the forums, seven-day leaderboard and other social tools. For certain information, we provide you with privacy preferences in account settings and other tools to control how your information is visible to other users of the Services.

You may also direct us to share your information in other ways, for example, when you give a third-party application access to your account or give your employer access to information when you choose to participate in an employee wellness programme. Remember that their use of your information will be governed by their privacy policies and terms. You can revoke your consent to share with third-party applications or employee wellness programmes using your account settings.

FOR EXTERNAL PROCESSING
We transfer information to our corporate affiliates, service providers and other partners who process it for us, based on our instructions, and in compliance with this policy and any other appropriate confidentiality and security measures. These partners provide us with services globally, including for customer support, information technology, payments, sales, marketing, data analysis, research and surveys.

FOR LEGAL REASONS OR TO PREVENT HARM
We may preserve or disclose information about you to comply with a law, regulation, legal process or governmental request; to assert legal rights or defend against legal claims; or to prevent, detect or investigate illegal activity, fraud, abuse, violations of our terms or threats to the security of the Services or the physical safety of any person.

Please note: Our policy is to notify you of legal processes that seek access to your information, such as search warrants, court orders or subpoenas, unless we are prohibited by law from doing so. In cases where a court order specifies a non-disclosure period, we provide delayed notice after the expiry of the non-disclosure period. Exceptions to our notice policy include exigent or counterproductive circumstances, for example, when there is an emergency involving a danger of death or serious physical injury to a person.

We may share non-personal information that is aggregated or de-identified so that it cannot reasonably be used to identify an individual. We may disclose such information publicly and to third parties, for example, in public reports about exercise and activity, to partners under agreement with us or as part of the community benchmarking information that we provide to users of our subscription services.

If we are involved in a merger, acquisition or sale of assets, we will continue to take measures to protect the confidentiality of personal information and give affected users notice before transferring any personal information to a new entity.

FOR JOINT PROCESSING OF PROFILE INFORMATION
From 6 June 2023, Fitbit users have the opportunity to move their accounts to Google. This means that some Fitbit users will be part of the Google service while others may remain part of the Fitbit service. As a result, to ensure that our users can still view their friends lists (including where your friends move their service to Google), Fitbit and Google will share with each other limited profile information about their Fitbit users, notably the user's name, photo and friends list. For more information, see the JOINT PROCESSING FOR PROFILE INFORMATION section below.

YOUR RIGHTS TO ACCESS AND CONTROL YOUR PERSONAL DATA

We give you account settings and tools to access and control your personal data, as described below, regardless of where you live. If you live in certain jurisdictions, you may have legal rights with respect to your information, which your account settings and tools allow you to exercise, as outlined below.

Accessing and exporting data. By logging in to your account, you can access much of your personal information, including your dashboard with your daily exercise and activity statistics. Using your account settings, you can also download information in a commonly used file format, including data about your activities, body, foods and sleep. Learn more here.

Editing and deleting data. By logging in to your account and using your account settings, you can change and delete your personal information. For instance, you can edit or delete the profile data that you provide and delete your account if you wish. Learn more here.

If you choose to delete your account, please note that while most of your information will be deleted within 30 days, it may take up to 90 days to delete all of your information, like the data recorded by your Fitbit device and other data stored in our backup systems. This is due to the size and complexity of the systems that we use to store data. We may also preserve data for legal reasons or to prevent harm, including as described in the How information is shared section.

Objecting to data use. We give you account settings and tools to control our data use. For example, through your privacy settings, you can limit how your information is visible to other users of the Services; using your notification settings, you can limit the notifications that you receive from us; and under your application settings, you can revoke the access of third-party applications that you previously connected to your Fitbit account. You can also use the Fitbit application to unpair your device from your account at any time.

DATA RETENTION

We keep your account information, like your name, email address and password, for as long as your account is in existence because we need it to operate your account. In some cases, when you give us information for a feature of the Services, we delete the data after it is no longer needed for the feature. For instance, when you provide your contact list for finding friends on the Services, we delete the list after it is used for adding contacts as friends. We keep other information, like your exercise or activity data, until you use your account settings or tools to delete the data or your account because we use this data to provide you with your personal statistics and other aspects of the Services. We also keep information about you and your use of the Services for as long as necessary for our legitimate business interests, for legal reasons and to prevent harm, including as described in the How we use information and How information is shared sections.

ANALYTICS AND ADVERTISING SERVICES PROVIDED BY OTHERS

We appreciate the importance of taking additional measures to protect children's privacy.

Fitbit allows parents to set up accounts for their children to use with selected Fitbit devices ('Children's Account'). Children's Accounts are subject to a separate privacy policy for Children's Accounts which explains what information we collect to set up these accounts, what information we collect from a child's use of our Services and how we use and share that information. Parents or guardians must consent to the use of their child's data in accordance with the privacy policy for Children's Accounts in order to create such an account.

Persons under the age of 13, or any higher minimum age in the jurisdiction where that person resides, are not permitted to create accounts unless their parent has consented in accordance with applicable law. If we learn that we have collected the personal information of a child under the relevant minimum age without parental consent, we will take steps to delete the information as soon as possible. Parents who believe that their child has submitted personal information to us and would like to have it deleted may contact us at [email protected].

OUR POLICIES FOR CHILDREN

We appreciate the importance of taking additional measures to protect children's privacy.

Fitbit allows parents to set up accounts for their children to use with selected Fitbit devices ('Children's Account'). Children's Accounts are subject to a separate privacy policy for Children's Accounts which explains what information we collect to set up these accounts, what information we collect from a child's use of our Services and how we use and share that information. Parents or guardians must consent to the use of their child's data in accordance with the privacy policy for Children's Accounts in order to create such an account.

Persons under the age of 13, or any higher minimum age in the jurisdiction where that person resides, are not permitted to create accounts unless their parent has consented in accordance with applicable law. If we learn that we have collected the personal information of a child under the relevant minimum age without parental consent, we will take steps to delete the information as soon as possible. Parents who believe that their child has submitted personal information to us and would like to have it deleted may contact us at [email protected].

INFORMATION SECURITY

We work hard to keep your data safe. We use a combination of technical, administrative and physical controls to maintain the security of your data. This includes using Transport Layer Security ('TLS') to encrypt many of our Services. No method of transmitting or storing data is completely secure, however. If you have a security-related concern, please contact customer support.

OUR INTERNATIONAL OPERATIONS AND DATA TRANSFERS

We operate internationally and transfer information to the United States and other countries for the purposes described in this policy. Please note that the countries where we operate may have privacy and data protection laws that differ from, and are potentially less protective than, the laws of your country. For a list of the locations where we have offices, please contact us.

We rely on multiple legal bases to lawfully transfer personal data to third countries around the world. These include the following:

1. Adequacy decisions

European Commission's, the United Kingdom's and Switzerland's adequacy decisions.

2. EU-US Data Privacy Framework
As described in this Data Privacy Framework certification, Fitbit LLC complies with the EU-US and Swiss-US Data Privacy Frameworks (DPF) and the UK Extension to the EU-US DPF as set forth by the US Department of Commerce regarding the collection, use and retention of personal information from the EEA, Switzerland and the UK, respectively. Fitbit LLC has certified that it adheres to the DPF Principles through Google LLC and remains responsible for any of your personal information that is shared under the Onward Transfer Principle with third parties for external processing on Fitbit's behalf, as described in the 'How information is shared' section of our privacy policy. To learn more about the DPF, and to view the certification, please visit the DPF website.

If you have an enquiry regarding our privacy practices in relation to Fitbit's DPF certification, we encourage you to contact us. Fitbit is subject to the investigatory and enforcement powers of the US Federal Trade Commission. You may also refer a complaint to your local data protection authority and we will work with them to resolve your concern. In certain circumstances, the DPF provides the right to invoke binding arbitration to resolve complaints not resolved by other means, as described in Annex I to the DPF Principles.

3. Standard contractual clauses
We rely on standard contractual clauses and supplementary measures. You may obtain copies of the standard contractual clauses by contacting us.

EUROPEAN PRIVACY DISCLOSURES

If you live in the European Economic Area (EEA), United Kingdom (UK) or Switzerland, please review these additional privacy disclosures under the European Union's General Data Protection Regulation ('GDPR').

YOUR DATA CONTROLLER
Fitbit International Limited, an Irish company, is your data controller and provides the Services if you live in the EEA, UK or Switzerland. For our contact information, please see the Who we are and how to contact us section.

JOINT PROCESSING FOR PROFILE INFORMATION 
From 6 June 2023, Fitbit users will have the opportunity to move their accounts to Google. This means that some Fitbit users will be part of the Google service while others may remain part of the Fitbit service.

As a result, to ensure that our users can still view their friends lists (including where your friends move their service to Google), Fitbit and Google will share with each other limited profile information about their Fitbit users, notably the user's name, photo and friends list ('Joint Processing').

(1) Fitbit International Limited and Google Ireland Limited (for users in the EEA or Switzerland) and (2) Fitbit International Limited and Google LLC (for users in the UK) are joint controllers for this Joint Processing, with Fitbit and Google remaining responsible for their respective obligations under data protection law. To exercise your rights in respect of the Joint Processing, including your right of objection (see HOW TO EXERCISE YOUR LEGAL RIGHTS), you can contact Fitbit at the details listed below. You can also view Google's Privacy FAQs here.

HEALTH AND OTHER SPECIAL CATEGORIES OF PERSONAL DATA
To the extent that information we collect is health data or another special category of personal data subject to the GDPR, we ask for your explicit consent to process the data. We obtain this consent separately when you take actions leading to our obtaining the data, for example, when you pair your device to your account, grant us access to your exercise or activity data from another service, or use the female health tracking feature. You can use your account settings and tools to withdraw your consent at any time, including by stopping use of a feature, removing our access to a third-party service, unpairing your device, or deleting your data or your account.

OUR LEGAL BASES FOR PROCESSING PERSONAL DATA
For personal data subject to the GDPR, we rely on several legal bases to process the data, including:

  • When you have given your consent, which you may withdraw at any time using your account settings and other tools; 
  • When the processing is necessary to perform a contract with you, like the Terms of Service; and
  • Our legitimate business interests, such as in improving, personalising and developing the Services, marketing new features or products that may be of interest, and promoting safety and security as described in the How we use information section.

HOW TO EXERCISE YOUR LEGAL RIGHTS 
Please review the Your rights to access and control your personal data section for how your account settings and tools allow you to exercise your rights under the GDPR to access and control your personal data.

In addition to the various controls that we offer, in certain circumstances, you can seek to restrict our processing of your data, or object to our processing of your data based on our legitimate interests, including as described in the How we use information section. Under the GDPR, you have a general right to object to the use of your information for direct marketing purposes. Please see your notification settings to control our marketing communications to you about Fitbit products. Our Cookie use statement describes your options for controlling how we and our partners use cookies and similar technologies for advertising. Please note that you can always delete your account at any time.

If you need further assistance regarding your rights, please contact our data protection officer at [email protected], and we will consider your request in accordance with applicable laws. You also have a right to lodge a complaint with your local data protection authority or with the Irish Data Protection Commission, our lead supervisory authority, whose contact information is available here.

CALIFORNIA PRIVACY DISCLOSURES

If you are a California resident, please review the following additional privacy disclosures under the California Consumer Privacy Act ('CCPA').

HOW TO EXERCISE YOUR LEGAL RIGHTS
You have the right to understand how we collect, use and disclose your personal information, to access your information, to request that we delete certain information and to not be discriminated against for exercising your privacy rights. You may exercise these rights using your account settings and tools as described in the Your rights to access and control your personal data section, for example:

  • By logging in to your account and using your account settings, you may exercise your right to access your personal information and to understand how we collect, use and disclose it. Learn more here.
  • Your account settings also let you exercise your right to delete personal information. Learn more here.

If you need further assistance regarding your rights, please contact our data protection officer at [email protected], and we will consider your request in accordance with applicable laws.

CATEGORIES OF INFORMATION WE COLLECT, USE AND DISCLOSE FOR BUSINESS PURPOSES

As described in the Information that we collect section, we collect the categories of personal information listed below. We receive this information from you, your device, your use of the Services, your coach if you use our Live Coaching Services, third parties (like the other services that you have connected to your Fitbit account, or your employer or insurance company if they offer you Fitbit Services as an employee or customer), and as otherwise described in this policy. We use and disclose these categories of information for the business purposes described in the How we use information and How information is shared sections, respectively. The categories are:

  • Identifiers, like your name or username, email address, postal address, phone number, IP address, account ID, device ID, cookie ID and other similar identifiers.
  • Demographic information, such as your gender, age, health information and physical characteristics or description, which may be protected by law.
  • Commercial information, including your payment information and records of the Services or devices that you purchased, obtained or considered (for example, if you added them to your shopping basket on the Fitbit online shop but did not purchase them).
  • Biometric information, such as your exercise, activity, sleep or health data, including the number of steps that you take, distance travelled, calories burned, weight, heart rate, sleep stages, active minutes, female health data, Live Coaching Services data and any similar information to which you grant us access from another service.
  • Internet or other electronic network activity information, such as the usage data that we receive when you access or use our Services. This includes information about your interactions with the Services and about the devices and computers that you use to access the Services.
  • Geolocation data, including GPS signals, device sensors, Wi-Fi access points and mobile tower IDs, if you have granted us access to that information.
  • Electronic, visual or similar information, such as your profile photo or other photos.
  • Professional or employment-related information, including any information (like your name, email address or similar information) that your employer provides to us so that we can invite you to participate in or determine your eligibility for Fitbit Services that they offer to their employees.
  • Other information that you provide, including account information, such as your biography or country; information for features of the Services, for example, an alarm, information about your friends and logs for food, weight, sleep, water or female health tracking; Live Coaching Services data (provided by you or your coach); messages on the Services; and information recorded by your device which may vary depending on the device that you use.
  • Inferences drawn from any of the above, including the number of calories that you burned, distance that you travelled, sleep insights and personalised exercise and activity goals.

We never sell the personal information of our users. We do work with partners who provide us with advertising services as described in the Analytics and advertising services provided by others section. To learn more about how these partners collect data and your options for controlling the use of your information for interest-based advertising, please read our Cookie use statement

CHANGES TO THIS POLICY

We will notify you before we make material changes to this policy and give you an opportunity to review the revised policy before deciding if you would like to continue to use the Services. 

WHO WE ARE AND HOW TO CONTACT US

If you have questions about this policy or need help exercising your privacy rights, please contact our data protection officer at [email protected].

If you live in the EEA, UK or Switzerland, you may also contact us at:

Fitbit International Limited
Attn: Legal Department (Privacy Policy)
Gordon House, 4 Barrow St, Grand Canal Dock
Dublin 4, D04 V4X7, Ireland

If you reside elsewhere, you may contact us at:

Fitbit LLC
Attn: Legal Department (Privacy Policy)
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

true
Search
Clear search
Close search
Google apps
Main menu
5242677373572170222
true
Search Help Centre
true
true
true
false
false