Privacy Policy

Effective date: [INSERT EFFECTIVE DATE] · Applies to the AIA Vitality Steps Challenge microsite (this website)

This Privacy Policy explains what personal data the AIA Vitality Steps Challenge ("the Challenge", "we", "us") collects when you use this website, how we use it, who we share it with, and the choices you have. By registering for or using the Challenge, you agree to the collection and use of information as described here, and to our Terms of Service.

1. Who we are

[INSERT COMPANY LEGAL NAME], of [INSERT REGISTERED ADDRESS], operates this microsite as the data controller for the personal data described below. If you have questions about this policy or how your data is handled, contact us at [INSERT CONTACT EMAIL].

2. Information we collect

When you register and use the Challenge, we collect:

  • Account details — your full name and email address, provided directly or via Google/Facebook sign-in (see Section 3).
  • Profile details — gender and age, collected once after your first login to personalise your experience.
  • Activity data — the daily step counts you log, the dates you logged them, your login streak, badges earned, and daily mission completions.
  • Screenshot uploads — if you submit a screenshot from a fitness app or device (e.g. Garmin Connect, Strava, your phone's health app) as proof of steps, we store that image on our servers for review.
  • Technical data — a small login cookie that keeps you signed in (see Section 5). We do not use tracking or advertising cookies.

We do not collect payment information, government ID numbers, or precise location data through this microsite.

3. Signing in with Google or Facebook

If you choose "Continue with Google" or "Continue with Facebook", that provider asks you to authorise sharing your name and email address with us. We only request your basic profile and email — we do not request or access your posts, friends list, contacts, or any other data, and we never post to your Google or Facebook account on your behalf. Your use of Google or Facebook sign-in is also subject to that provider's own privacy policy.

4. How we use your information

  • To create and authenticate your account, including passwordless "magic link" login by email.
  • To operate the Challenge: recording your steps, calculating your personal and the community's total progress toward the campaign goal, maintaining your login streak, and awarding badges and daily mission points.
  • To review and verify screenshot submissions before crediting the steps shown in them.
  • To keep you signed in between visits, so you don't need to log in every time (see Section 5).
  • To send you operational emails, such as your one-time login link.
  • To understand overall participation (e.g. total community steps) — reported only in aggregate, not tied to your identity, when shared publicly or with AIA Vitality.

5. Cookies

This site uses two cookies, both strictly necessary for the Challenge to function — no advertising or analytics cookies are set:

  • Session cookie — a temporary cookie that identifies you while you're actively using the site.
  • Remember-me cookie — a longer-lived cookie containing a random token (not your password) that keeps you signed in on the same device and browser across visits. You can end this at any time by clearing your browser's cookies for this site.

6. Who we share your information with

We do not sell your personal data. We share it only with:

  • Service providers who host our website, database, and send emails on our behalf, solely to operate the Challenge.
  • Google or Facebook, to the extent needed to complete sign-in, if you use those options.
  • AIA Vitality, in aggregate or de-identified form (e.g. total community steps), for campaign reporting.
  • Authorities, where required by law.

7. Data retention

We keep your account and activity data for the duration of the Challenge and for a reasonable period afterward — up to [INSERT RETENTION PERIOD, e.g. 12 months] — for record-keeping and to resolve any disputes, unless you ask us to delete it sooner.

8. Your rights

You can ask us to access, correct, or delete the personal data we hold about you, or withdraw your consent to further processing, by contacting [INSERT CONTACT EMAIL]. Deleting your account will end your participation in the Challenge and remove your logged data, subject to any legal retention requirements. See our Data Deletion Instructions for exactly what's removed and how to request it.

9. Children's privacy

The Challenge is not directed at, and should not be used by, individuals under 13 years of age. We do not knowingly collect personal data from children under 13.

10. Security

Login is passwordless — we never ask you to create or store a password. Login and remember-me cookies are transmitted only over HTTPS and are not accessible to page scripts. We take reasonable technical and organisational measures to protect your data, but no method of transmission or storage is 100% secure.

11. Changes to this policy

We may update this policy from time to time, for example if the Challenge's features change. The effective date at the top of this page will always reflect the latest version.

12. Contact us

Questions, requests, or concerns about this policy or your data can be sent to [INSERT CONTACT EMAIL].