Privacy Policy
Privacy Policy (Datenschutzerklärung)
Last updated: 22 August 2026
1. Who we are
The controller responsible for processing your personal data is:
Maxim Trube
Hochdahler Markt 2
40699 Erkrath
Germany
Email: endurancemaxtrube@mailbox.org
You can contact us directly at that address about any privacy matter. You do not have to use the contact form.
2. What this policy covers
This policy applies to:
- maxtrubemd.com — our website, the library, user accounts and the contact form
- zones.maxtrubemd.com — the Training Zone Calculator ("Zones")
- assessment.maxtrubemd.com — the endurance knowledge quiz
Our YouTube channel and Telegram group are operated by those platforms, and their own privacy terms apply to your use of them.
3. What we collect, why, and on what legal basis
Visiting our websites
When you visit, our hosting providers record technical connection data, including your IP address, the time of the request, the page requested and your browser type. We use this to deliver the site and keep it secure.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a functioning, secure website and protecting it against misuse and attack.
Retention: for the period our hosting providers retain server logs, which is limited to what is necessary for security and operational purposes.
Taking the endurance quiz
The quiz at assessment.maxtrubemd.com does not ask for your email address and does not store your answers. Your results are shown to you and are not recorded against you. Apart from the connection data described above, we collect nothing when you take it.
Creating an account
We collect your first name, last name and email address, and store your password in hashed form. We use this to give you access to the library and to manage your account.
Legal basis: Art. 6(1)(b) GDPR — performance of our contract with you.
Retention: for as long as you have an account. You can ask us to delete your account at any time — email endurancemaxtrube@mailbox.org and we will do so within 30 days.
Contacting us
The contact form collects your first name, last name, email address, subject and message, and optionally your telephone number. We use this to answer you.
Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or a possible contract; otherwise Art. 6(1)(f) GDPR — our legitimate interest in responding to people who write to us.
Retention: 12 months after your enquiry is resolved. Where a message forms part of a contract or a business record, statutory retention periods apply instead.
Email you send us directly, rather than through the form, is handled the same way and stored with our email provider (see section 5).
Buying library access
We collect your account details, the plan you chose, the date of purchase, and your billing and transaction data. We use this to give you access, take payment and issue invoices. We never see or store your full card details — those go directly to Stripe.
Legal basis: Art. 6(1)(b) GDPR; and Art. 6(1)(c) GDPR together with §§ 147 AO, 257 HGB for the retention of accounting records.
Retention: for the period required by German tax and commercial law.
Using Zones
We collect:
- your email address and hashed password
- your biological sex, swimming pool length and sport preferences
- for each test: the sport, the date, the trial data you enter, and the values calculated from it — your critical speed or power, first threshold, speed at maximal oxygen uptake, and training zones
We use this to perform the calculation you have asked for and to show your progression over time.
Legal basis: Art. 6(1)(b) GDPR; and Art. 9(2)(a) GDPR where this amounts to health data — see section 4.
Retention: for as long as you have an active subscription, and for 12 months after it ends. We keep your test history for that period so that if you return after a break — an off-season, an injury, a change of focus — your progression is still there. After 12 months we delete it automatically. You can ask us to delete it sooner, or to send you a copy, at any time.
Emails we send you
We send account and contract emails: registration and password messages, order confirmations, cancellation confirmations and withdrawal acknowledgements. We record the address, content, time and delivery status.
We do not use open tracking or click tracking in these emails. We do not send marketing email.
Legal basis: Art. 6(1)(b) GDPR; and Art. 6(1)(c) GDPR for confirmations we are legally required to send.
Retention: for the period our email provider retains delivery records, which is limited to what is necessary to operate and troubleshoot the service.
4. Health data
Some of what we process may be health data, which receives special protection under Art. 9 GDPR.
For Zones, the test results you enter, the physiological values calculated from them and your biological sex may together constitute health data. We take a cautious view and treat them as such.
We process them on the basis of your explicit consent under Art. 9(2)(a) GDPR, which you give when you set up your account.
You can withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out beforehand. Because Zones cannot work without this data, withdrawing consent means we delete it and the service ends.
To withdraw, email us at endurancemaxtrube@mailbox.org. We will action it within 30 days.
5. Who else processes your data
We use the following service providers. Where they act on our instructions, we have data processing agreements with them under Art. 28 GDPR.
Webflow, Inc. — 398 11th St., Floor 2, San Francisco, CA 94103, USA
Hosts maxtrubemd.com and assessment.maxtrubemd.com, and handles forms and user accounts. Webflow acts as our processor for the data of people who use our sites, and as an independent controller for our own account and billing information. Sub-processors: webflow.com/legal/subprocessors
Stripe Payments Europe, Limited — Ireland
Processes payments. Stripe acts as our processor when it takes payment on our instructions, and as an independent controller when it monitors for fraud and complies with financial regulation. Payment is completed on Stripe's own platform; any cookies set during checkout are Stripe's and are covered by Stripe's cookie policy.
Supabase Pte. Ltd — 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513
Provides the database and sign-in for Zones. Our project is hosted in Frankfurt, Germany. Supabase acts as our processor. Sub-processors: supabase.com/legal/customer-resources/subprocessor-list
Vercel Inc. — 440 N Barranca Ave #4133, Covina, CA 91723, USA
Hosts and delivers Zones. Vercel acts as our processor for the data of people who use Zones, and as an independent controller for usage metadata and our own account information. Sub-processors: security.vercel.com
MailerSend, Inc. — 228 Park Ave S, PMB 54955, New York, NY 10003-1502, USA
Sends our account and contract emails. Message data is stored in a Google Cloud data centre in Belgium. MailerSend's representative in the EU under Art. 27 GDPR is MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland. Its sub-processors are Google Cloud EMEA Ltd (Ireland, data centre in Belgium), MailerLite Limited (Ireland), MailerLite, Inc. (USA), Vercom S.A. (Poland) and Bandwidth, Inc. (USA).
Mailbox.org (Heinlein Hosting GmbH) — Schwedter Str. 8/9b, 10119 Berlin, Germany
Provides our business email. Messages you send us, and our replies, are stored there. Mailbox.org acts as our processor and operates entirely within Germany.
Cloudflare provides security and bot protection as part of our hosting infrastructure and sets one session cookie described in section 7.
We do not sell your data. We do not use analytics, tracking pixels, advertising networks or marketing platforms, and we do not pass your data to anyone for advertising.
6. Transfers outside the EU
Some of our providers are established outside the European Economic Area, or process data outside it. Where that happens, the transfer is covered by appropriate safeguards under Art. 46 GDPR:
- Webflow (USA): the EU-U.S. Data Privacy Framework where Webflow is certified under it, otherwise the European Commission's Standard Contractual Clauses. The clauses are governed by Irish law, with the Irish Data Protection Commission as competent supervisory authority.
- Stripe (Ireland, with transfers to the USA and India): the EU-U.S. Data Privacy Framework, under which Stripe, Inc. is certified, together with Standard Contractual Clauses.
- Supabase (Singapore, hosting in Frankfurt): Standard Contractual Clauses, Module Two, governed by Irish law.
- Vercel (USA): Standard Contractual Clauses, governed by Irish law. Vercel's primary processing facilities are in the United States.
- MailerSend (USA, data centre in Belgium): Standard Contractual Clauses governed by Irish law, together with the EU-U.S. Data Privacy Framework, under which MailerSend, Inc. is certified.
Mailbox.org processes our business email entirely within Germany. No transfer outside the EU is involved.
You can obtain a copy of the safeguards in place by writing to us at endurancemaxtrube@mailbox.org.
7. Cookies and storage on your device
We use only what is technically necessary to run our sites. We do not use analytics, tracking pixels, advertising cookies or third-party tracking of any kind. Because everything we store is strictly necessary to provide the service you have asked for, it does not require your consent under § 25(2) no. 2 TDDDG, and we do not show a cookie banner.
This is what we store, and why:
On maxtrubemd.com and assessment.maxtrubemd.com
NameTypePurposeDuration_cfuvidCookieSet by Cloudflare to distinguish individual users sharing an IP address, so that security and rate-limiting work correctlySessionvisitedSession storageRecords that you have already seen a page element within the current visitSessionms_session_idLocal storageKeeps you signed in to your library account (Memberstack)Until sign-outms_groupsLocal storageRecords which parts of the library your account can access (Memberstack)Until sign-out
On zones.maxtrubemd.com
NameTypePurposeDurationsb-…-auth-tokenLocal storageKeeps you signed in to Zones (Supabase)Until sign-out_cfuvidCookieAs aboveSession
8. How long we keep your data
The period is given for each activity in section 3. In summary:
- Account and profile data: deleted within 30 days of your request
- Zones test history: 12 months after your subscription ends, then deleted automatically — or sooner on request
- Contact form messages: 12 months after your enquiry is resolved
- Invoices and accounting records: for the period required by German tax and commercial law
- Server and delivery logs: for the limited period our providers retain them for security and operational purposes
When data is no longer needed and no retention obligation applies, we delete it.
9. Your rights
You have the right to:
- access your data (Art. 15 GDPR)
- have inaccurate data corrected (Art. 16 GDPR)
- have your data erased (Art. 17 GDPR)
- restrict how we process it (Art. 18 GDPR)
- receive it in a portable format (Art. 20 GDPR)
- object to processing based on our legitimate interests (Art. 21 GDPR)
- withdraw consent you have given, at any time, with effect for the future (Art. 7(3) GDPR)
To exercise any of these, email endurancemaxtrube@mailbox.org. We will respond within one month.
You also have the right to complain to a data protection authority. Ours is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf
Telephone: 0211 38424-0
Email: poststelle@ldi.nrw.de
You may also complain to the supervisory authority where you live or work.
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal effects concerning you, or similarly significantly affects you, within the meaning of Art. 22 GDPR. The calculations Zones performs on the data you enter are not decisions of that kind — they are the service you asked for, and you decide what to do with the result.
11. Security
We protect your data with measures appropriate to its sensitivity:
- All connections to our sites are encrypted in transit using TLS.
- Passwords are never stored in readable form — only as cryptographic hashes.
- Data stored by our providers is encrypted at rest using AES-256.
- Access to the systems holding your data is restricted, logged, and protected by two-factor authentication.
- Our providers hold independent security certifications, including SOC 2 Type II and ISO 27001, and commission regular penetration testing by third parties.
- Backups are encrypted and stored separately from live systems.
No system can be guaranteed completely secure, but we review these arrangements as our services change.
12. Changes to this policy
We update this policy when our processing or the law changes. The current version is always on this page, with the date at the top.