MiniHiki — Privacy Policy
Last updated: 6 September 2026 Application: MiniHiki (iOS, Android) Data controller: Niku Peltokangas Address: Seinäjoki, Finland Data protection contact: Niku Peltokangas Email: privacy@minihiki.com
1. General
MiniHiki is a physical activity motivation app for children, in which a coach (usually a parent or an adult acting in a coaching role) plans daily exercises for children, and the children complete them on their own device.
This privacy policy describes what personal data we collect, how we process it and what rights you have. The app is designed specifically for use by children under 13, so our privacy practices follow the EU General Data Protection Regulation (GDPR), in particular Article 8 (child's consent) and Articles 12–22 (rights of the data subject).
Geographic availability of the service: The service is available in those countries where distribution of the app has been opened in the Apple App Store and Google Play. The distribution area is limited to the EU/EEA and the United Kingdom, and the service is not directed at residents of other countries.
2. Whose data we process and why
2.1 Coach (adult)
- Email address and password — for signing in (Firebase Authentication).
- Team name — displayed within the app.
- Club name and sport — when a team is created, a sport (e.g. football) and a club (e.g. Ilves) are selected. These are used to categorise the team and for aggregated statistics (see section 2.5).
Legal basis: contract (GDPR 6(1)(b)) — providing the service requires signing in.
2.2 Child (under 18)
- First name or nickname (no surname) — visible to the child themselves and to the coach of the same team.
- Avatar emoji — chosen by the child or the coach.
- Completions and stars — which exercises the child has done and when.
- Pseudonymous Firebase identifier (UID) — an internal user identifier, processed as personal data in accordance with GDPR Recital 26 (pseudonymised data is still personal data, not anonymous data).
We do not collect:
- The child's surname
- The child's exact date of birth
- Photos or videos of the child (a coach may add images to exercise instructions, but these are not images of individuals)
- Location data
- Contact details (phone, email)
- Any data from advertising networks or third-party analytics
Legal basis: guardian's consent (GDPR 6(1)(a) and 8(1)). A child cannot be added to a team without the guardian's confirmation.
2.3 Guardian
- Email address — for the purpose of the guardian's confirmation and communication (sending login codes, GDPR requests).
Legal basis: legal obligation (GDPR 6(1)(c) and 8(2)) and contract (6(1)(b)).
2.4 Subscription and payment data (coach)
If a coach takes out a paid subscription, the payment is handled in full by Stripe (Stripe Payments Europe, Ltd., Ireland). The payment takes place on Stripe's own page (Stripe Checkout), so we never see or process:
- Card numbers, CVC codes or bank credentials
- Any other payment instrument details
Stripe acts as our processor and itself stores the billing data, including the payer's email address and name, as well as invoices and receipts for the period required by accounting obligations.
From Stripe we store in our own system only the following data:
- Customer and subscription identifiers (
customer id,subscription id) — pseudonymous identifiers which, combined with your account, are personal data - Product and price identifiers and the subscription tier (e.g. Coach, Team)
- Subscription status and timestamps (start, renewal, cancellation, termination, payment failure)
- Monthly price and VAT country
We do not store receipts or invoices in our own system — they are held by Stripe, which acts as the source system for accounting purposes.
We use this data for:
- Verifying that a subscription is valid (access to paid features)
- Meeting tax and accounting obligations (EU legislation requires receipts to be retained for 6 years)
- Fraud prevention and preventing duplicate use
Separation of data after account deletion: When a user deletes their account, we transfer the minimum data required for accounting (time of payment, amount, VAT country, product ID) to a separate accounting register without any reference to a user identifier or email address. After this, transaction data can no longer be linked to an individual by reasonable means. The user account itself and its related data are deleted immediately (see section 6).
Legal basis: contract (6(1)(b)) and legal obligation (6(1)(c) — accounting, value added tax).
The payment processor's own privacy practices:
- Stripe: https://stripe.com/privacy
2.5 Aggregated statistical data (not personal data)
For the purpose of developing the service we collect aggregated statistical data which cannot be linked to an individual:
- Counters by sport and club — how many teams have been created per sport and club.
- Daily completion counts per sport — how many exercises have been marked as done.
- Number of active teams per day — how many teams show activity (based on team ID, not individual users).
This data is stored in a separate Firestore collection (analytics) which
contains no user identifiers, names, email addresses or any other personal
data. The data is used solely for developing the service and for business
planning (e.g. which sports are most popular).
Because aggregated statistical data is not personal data within the meaning of the GDPR (Recital 26 — information which cannot by reasonable means be linked to an identified person), the GDPR's obligations concerning the processing of personal data do not apply to it. We do not transfer this data to third parties.
3. Guardian's confirmation (GDPR Article 8)
Before the data of a child under 13 is stored in the service:
- The coach adds the child to a team and enters the guardian's email address.
- An email is sent to the guardian containing a confirmation link and the child's login codes.
- The guardian clicks the link and confirms their consent. Only after this can the child sign in to the app.
- The guardian may withdraw their consent at any time by clicking the link in the same email or by contacting privacy@minihiki.com.
4. Data retention and location
- Location: All data is stored in Google Cloud Firestore and Firebase Storage, in location eur3 (europe-west). Data does not leave the EU in normal use.
- Retention period for user data: Data is retained for as long as the user is active. If a user has not signed in for 24 months, the accounts and their related data are deleted automatically.
- Retention period for subscription and payment data: Receipts, invoices and transaction data are retained for 6 years as required by the Finnish Accounting Act (1336/1997), after which they are permanently deleted. When a user account is deleted, accounting data is separated from identifiers linked to user data (see section 2.4) so that it can no longer be linked to an individual by reasonable means. The account itself is deleted immediately.
- Retention period for the marketing list: An email address is removed from the marketing mailing list as soon as you unsubscribe, and no later than within 7 days.
- At the guardian's request, a child's data is deleted immediately (see section 6).
5. Disclosures to third parties
We use the following sub-processors for processing data:
| Service | Purpose | Location | Privacy policy | |---|---|---|---| | Google Firebase (Auth, Firestore, Cloud Functions, FCM) | Authentication, data storage, push messages | EU (europe-west) | https://firebase.google.com/support/privacy | | Apple iCloud / APNs | iOS push messages | EU/USA | https://www.apple.com/legal/privacy/ | | Google Play Services | Android push messages | EU | https://policies.google.com/privacy | | Resend (resend.com) | Guardian confirmation messages, password resets, coach newsletters | USA (EU SCC) | https://resend.com/legal/privacy-policy | | Stripe (Stripe Payments Europe, Ltd.) | Processing of subscription payments, invoicing and receipts | Ireland (EU), parent company USA | https://stripe.com/privacy |
We do not sell or rent personal data to third parties. We do not use third-party advertising networks, analytics services or SDKs in relation to children's data.
5.1 International transfers of data
Although the servers and the data are located in the EU (europe-west), some of the sub-processors we use (Google LLC, Apple Inc., Stripe, Inc.) have US parent companies, and their personnel may have technical access rights to the data in connection with maintenance or support requests. Under the GDPR, such access is interpreted as a transfer of data to a third country.
We protect transfers with the following mechanisms:
- EU-U.S. Data Privacy Framework (DPF) — Google LLC, Apple Inc. and Stripe, Inc. are DPF-certified companies (European Commission adequacy decision of 10 July 2023, C(2023) 4745).
- European Commission Standard Contractual Clauses (SCC, 2021/914) — applied as a supplementary safeguard to all sub-processors that have access rights from the USA or elsewhere outside the EU.
- Technical safeguards — all data is encrypted at rest (AES-256) and in transit (TLS 1.2+), which reduces the risk of access by third-country authorities.
We do not transfer personal data to countries for which the European Commission has not issued an adequacy decision or for which SCC clauses are not in force.
6. Rights of the data subject
You (or a guardian on behalf of a child under 13) have the following rights:
- Access — to request a copy of all data stored about you or your child.
- Rectification — to correct inaccurate data.
- Erasure ("right to be forgotten") — in the app, a coach can delete their
own account and all of their team's data with the button "Settings → Delete
account". Locking of the account and the principal deletion of data from the
active database take place immediately when the button is pressed (in
accordance with Apple App Store Guideline 5.1.1(v)). A guardian may request
the deletion of a child's data either directly from the coach or by
contacting privacy@minihiki.com.
- Immediately: Firebase Auth credentials, user profile, the child's data, completions, teams and related documents are deleted within seconds.
- Up to 30 days: Google's and Apple's system-level backups are overwritten through the normal rotation cycle.
- 6 years (pseudonymised): transaction data required for accounting (see sections 2.4 and 4) — separated so that it can no longer be linked to an individual.
- Withdrawal of consent — see section 3.
- Data portability — to request your data in a machine-readable format.
- Complaint — you may lodge a complaint with the data protection
supervisory authority of your country of residence if you suspect a data
protection infringement:
- Finland and the rest of the EU/EEA: Office of the Data Protection Ombudsman, https://tietosuoja.fi/en (or the corresponding authority in your own country)
- United Kingdom (UK GDPR): Information Commissioner's Office (ICO), https://ico.org.uk
These rights are based on the EU General Data Protection Regulation (GDPR) and, correspondingly in the United Kingdom, on the Data Protection Act 2018 / UK GDPR. In substance the rights are practically identical in both areas.
Contact: privacy@minihiki.com. We respond within 30 days.
7. Information security
- All data is encrypted at rest (Google Cloud) and in transit (TLS 1.2+).
- Firebase access rules restrict reading of data to members of the same team — other users cannot read a team's data.
- The coach's password is stored in Firebase Authentication; we neither see it nor are able to recover it.
- A child signs in with a team code (6 characters) + their own code (4 characters) — no password and no email address for the child. The codes are generated randomly and delivered to the guardian by email together with the guardian's confirmation (see section 3).
- Invalidating codes: If codes fall into the wrong hands or a guardian suspects misuse, the coach can change or invalidate the codes at any time from team management in the app. Old codes stop working immediately. A guardian may request new codes from the coach or from privacy@minihiki.com.
8. Notifications and messages
8.1 Push notifications
The app may send push notifications (exercise reminders, messages from the coach) to your device if you have allowed them. You can disable them at any time in your device settings.
8.2 Functional emails (to all users)
We send email for functional reasons without separate marketing consent. These include:
- Guardian confirmation requests and login codes
- Password resets
- Important account changes (e.g. password change, email change)
- Responses to GDPR requests
- Notifications relating to a subscription (e.g. failed renewal, declined payment, end of subscription)
- Any security notifications
Legal basis: contract (GDPR 6(1)(b)) and legitimate interest (6(1)(f)).
8.3 Newsletters and product updates (coaches only, opt-in)
We send coaches by email:
- Announcements about new features and updates
- Usage tips and guidance
- The most important product news
These messages are sent only to coach users who have explicitly given their consent to this communication (opt-in). We do not send newsletters to guardians or to children. We do not send advertisements for third-party products, nor do we sell email address lists.
Legal basis: consent (GDPR 6(1)(a) and section 200 of the Finnish Act on Electronic Communications Services 917/2014). Direct marketing to a natural person by email requires prior consent.
Giving and withdrawing consent:
- Consent is requested via a separate checkbox during registration (default: not selected) or in the app settings.
- Consent can be withdrawn at any time as easily as it was given (GDPR 7(3)):
- From the Settings → Email communication settings toggle in the app
- From the one-click unsubscribe link at the end of every newsletter ("Unsubscribe")
- By contacting privacy@minihiki.com
- Withdrawal is processed immediately and the email address is removed from the marketing mailing list no later than within 7 days.
- You cannot opt out of functional emails (section 8.2) for as long as you have an active account — these are necessary for the operation of the service and are not based on marketing consent.
9. Cookies and tracking technologies
The app does not use cookies (it is not a web application). Firebase uses device-specific pseudonymous identifiers (Firebase Installation ID, FCM token) to deliver notifications. These identifiers are personal data in accordance with GDPR Recital 26 (a pseudonymous identifier that can be linked to a user account), but they are not used for cross-tracking between different apps or websites, nor for advertising purposes.
10. Minors and Apple / Google Play requirements
The app is listed in the iOS and Google Play stores in the children's use category:
- Apple App Store: Age Rating 4+
- Google Play: Everyone (IARC)
We comply with:
- Apple Kids Category Guidelines
- Google Play Families Policy
- EU GDPR Article 8 (child's consent in information society services)
- UK GDPR / Age Appropriate Design Code (ICO)
COPPA (United States): The service is not directed at residents of the United States, and it is not available in the United States App Store or Google Play store (see the distribution limitation in section 1). For this reason the United States Children's Online Privacy Protection Act (COPPA) does not apply to the service. If the distribution area is later extended to the United States, this privacy policy and the practices for processing children's data will be updated to meet COPPA requirements before release.
11. Changes to this policy
If we make significant changes to this policy, we will notify users in the app and by email to coaches. Minor updates are made by updating the "Last updated" date at the beginning of this document.
12. Contact details
Data protection matters and GDPR requests: privacy@minihiki.com
Technical support: [support@minihiki.fi]
Postal address: Seinäjoki, Finland
Supervisory authority: Office of the Data Protection Ombudsman Lintulahdenkuja 4, 00530 Helsinki, Finland https://tietosuoja.fi/en
