Privacy Policy

This policy explains what Blitcore (“Centifit”, “we”, “us”) collects when you use the Centifit app and centifit.com, why we collect it, who processes it for us, and the choices you have. We process personal data in line with the Nigeria Data Protection Act and other laws that apply to you. Questions: centifit@blitcore.com.

1. What we collect

  • Account details — name, email address, date of birth, handle, and password (stored by our authentication system, never in plain text).
  • Profile — the photo, bio, city, sports, and skill ratings you add or earn.
  • Location — your precise location while you use the app, if you grant it, to show facilities and sessions near you and order them by distance. It is never shown to other players. You can instead search a city and never share your location at all.
  • Content you create — Moments photos, captions, comments, messages, and ratings.
  • Bookings and payments — what you book and join, and payment records from our payment providers. We never receive or store your full card number.
  • Device and diagnostics — a push notification token if you enable notifications, and crash reports and basic device info when something goes wrong, so we can fix it.

2. What we use it for

  • Running the service: discovery, bookings, sessions, chat, the feed.
  • Processing payments and splitting session costs.
  • Sending notifications you’ve enabled (game updates, messages, reminders) and occasional service announcements from the Centifit team.
  • Safety and moderation: reviewing reported content and accounts, and enforcing our community rules.
  • Support, debugging, and making Centifit work better.

We do notsell your personal data, and we do not track you across other companies’ apps or websites for advertising.

3. Who sees it

  • Other players — your profile, Moments, and activity, according to your privacy settings. A private account limits this to approved followers.
  • Facilities and hosts— the details they need to run a game you’ve booked or joined (your name and booking information).
  • Service providers that process data for us: payment providers (Paystack, Stripe) for payments; Amazon Web Services for storing photos and data; Google Maps and Google Places for maps, geocoding, and place search; Expo for delivering push notifications; Sentry for crash reporting; and Anthropic, whose AI model powers Centifind — your Centifind questions are sent to it through our servers to generate answers. These providers process data only to provide their service to us.
  • Facility scheduling systems — some facilities connect their own booking software (such as SimplyBook) to Centifit. When you book with such a facility, the booking details it needs sync to the system that facility controls.
  • Authorities — if the law requires it, or to protect players from serious harm.

Some of these providers process data outside Nigeria. Where they do, we rely on their contractual data-protection commitments.

4. Your choices and rights

  • Privacy settings — make your account private and control who sees your stats, ratings, sessions, and social graph, per element, in Settings.
  • Permissions — location, camera, photos, calendar, and notifications are each optional and controlled in your device settings. The app works without them, with reduced features. Calendar access is used only to add a booking you choose to your own device calendar; we never read your calendar.
  • Your content — delete your own Moments and comments any time. Block and report tools are on every player and piece of content.
  • Access, correction, deletion — edit your profile in the app, and delete your account in Settings or by following these steps. You can also ask us about the data we hold on you at centifit@blitcore.com, and you may lodge a complaint with the Nigeria Data Protection Commission or your local data protection authority.

5. Organisations and facility staff

Facilities run their side of Centifit through an organisation dashboard. For staff accounts we hold work contact details, role, and an audit log of administrative actions taken in the dashboard — kept so organisations can see who changed what. Data facilities receive about players (bookings, session rosters) must be used only to run those games, under their agreement with us.

6. Retention

We keep your data while your account is active.

When you delete your account, your sign-in is destroyed and your profile is anonymised straight away — name, email, phone, date of birth, photo and location are erased, and your follows, saved places and notification tokens go with them. From that moment you cannot be found or followed, and anywhere a past game still lists you, you appear only as “Deleted player”.

Your remaining content — Moments, comments and ratings — is destroyed 30 days later. The delay is a grace period in case the deletion was a mistake or a booking dispute is still open.

An anonymous record stays behind, because bookings and payments must keep a valid owner for the venue’s accounts and for our own financial and legal obligations. It holds nothing that identifies you and cannot be traced back to you. Data may also persist in encrypted backups for a short period before those are rotated out.

7. Security

Data moves over encrypted connections, passwords are handled by a dedicated authentication system, and access to production data is restricted. No system is perfectly secure — if we learn of a breach affecting you, we’ll notify you as the law requires.

8. Children

Centifit is for people aged 13 and over. We don’t knowingly collect data from children under 13; if you believe a child is using the service, contact us and we’ll act on it.

9. Cookies and our websites

centifit.com sets no advertising or cross-site tracking cookies. The organisation dashboard uses only the cookies and storage it needs to keep staff signed in.

10. Changes

We’ll update this policy as the service evolves and note the new effective date at the top. Material changes get an in-app or email notice first.

11. Contact

Blitcore — Centifit · centifit@blitcore.com