Skip to content
Recovery Stack
  • Protocols
  • Foundations
  • Reviews
  • Directory
  • Methodology
  • Get the checklist →

Privacy

Privacy policy.

Short version: we keep one thing about you (your email, if you ask for the checklist), we use no cookies, and we never sell anything.

Last updated: 20 September 2026

Who is responsible

The data controller is the publisher of this site, identified on the legal notice page. For any question about your data, write to partnerships@recoverystackforall.com.

What we collect, and why

The site collects personal data in exactly one place: the email form on the checklist page. Everything else on the site can be read without giving us any information about you.

1. Sending you the HYROX Recovery Checklist

DataYour email address, the date, and the fact that you asked for the checklist.
PurposeSend you the PDF you asked for.
Legal basisPerformance of your request (RGPD art. 6-1-b).
RetentionUntil you ask us to delete it, or 3 years after your last interaction with us, whichever comes first.
Who has accessThe publisher. Cloudflare (database hosting, USA). Resend (email delivery, USA).
Outside the EUYes. Cloudflare and Resend are US companies. Transfers are covered by their standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

2. Occasional emails about new protocols (newsletter)

DataYour email address.
PurposeTell you when a new protocol or guide is published. No sequence, no daily emails.
Legal basisYour consent, given by ticking the newsletter box on the checklist form (RGPD art. 6-1-a). The box is never pre-ticked.
RetentionUntil you unsubscribe, or 3 years after your last interaction with us.
Who has accessThe publisher. Cloudflare (database). Resend (email delivery and contact list).
Withdrawing consentEvery email carries an unsubscribe link. One click, no login, effective immediately.

3. Audience measurement

DataPage viewed, referrer, screen size, browser family, country. Your IP address is discarded at reception and never stored. No cookie, no local storage, no persistent identifier: visitors are counted with a hash that changes every day and cannot be linked back to you.
PurposeKnow which pages are read and where readers come from.
Legal basisLegitimate interest (RGPD art. 6-1-f). Configured to meet the CNIL exemption for audience measurement, so no consent banner is shown.
Retention12 months.
Who has accessThe publisher. PostHog (EU Cloud, servers in Frankfurt, Germany; the company is US-based).

4. Server logs and security

DataTechnical request logs (IP address, timestamp, URL, user agent) kept by the hosting provider to run and protect the service.
PurposeSecurity, abuse prevention, service operation.
Legal basisLegitimate interest (RGPD art. 6-1-f) and legal obligation to retain connection data (French LCEN art. 6-II).
RetentionAs set by Cloudflare's own retention policy for its edge logs (short, measured in days). The publisher does not export or keep these logs.
Who has accessCloudflare.

5. Contact by email

If you email us, we keep the exchange for as long as needed to answer you and, at most, 3 years. Basis: your request. Access: the publisher, and the email provider used to receive mail.

What we do not do

  • No advertising pixel (Meta, TikTok, Google Ads).
  • No embedded video, map, or chat widget that would load third-party scripts.
  • No fonts loaded from Google: the site's fonts are served from our own domain.
  • No sale or rental of your email address, to anyone, ever.
  • No profiling, no automated decision affecting you.

Cookies and trackers

This site sets no cookies and uses no local storage on your device. That is why there is no cookie banner: there is nothing to consent to.

NameIssuerPurposeDurationCategory
PostHog analytics scriptPostHog (EU)Counts page views. Runs in "cookieless" mode: no cookie, no storage, daily rotating hash.None stored on your deviceAudience measurement, exempt from consent
__cf_bm, cf_clearance (only if Cloudflare challenges a request)CloudflareBot protection and security of the hosting layer.Up to 30 minutes / sessionStrictly necessary, exempt

Affiliate links on review pages lead to third-party merchants. Once you leave this site, the merchant's own cookie policy applies, and the merchant may know you came from Recovery Stack. Nothing is set on your device by this site when you click.

Your rights

Under the RGPD you can ask us, at any time, to:

  • Access the data we hold about you;
  • Correct it;
  • Delete it (we will remove your email from our database and from Resend);
  • Object to a processing based on legitimate interest;
  • Restrict a processing while a request is being handled;
  • Receive your data in a portable format (for an email address, that is the email itself);
  • Withdraw consent to the newsletter, via the unsubscribe link in any email.

Write to partnerships@recoverystackforall.com. We answer within one month. We may ask you to confirm the request from the email address concerned, to make sure nobody else deletes your data.

If you believe your rights are not respected, you can lodge a complaint with the French supervisory authority, the CNIL: www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

Changes to this policy

If we add a form, a script, or a vendor, this page is updated before the change goes live, and the date at the top changes. We do not notify past subscribers of minor wording changes.

Recovery Stack

Recovery protocols tested on a real body with Garmin data. Science + first-person experience. No wellness fluff.

Free checklist

8 protocols for the 48 hours after a race. Free, no spam.

Get the checklist →

Contact

Partnerships, feedback, press.

partnerships@recoverystackforall.com
© 2026 Recovery Stack
Methodology About Legal notice Privacy Cookies Affiliate disclosure