Activly · personal data
Privacy Policy
In short: Activly is our internal app for a company sports challenge. We collect only what the game needs: your account, your activities (date, discipline, kilometres) and — only if you turn it on yourself — GPS tracks from files, your home location and data from your Strava account. Routes and your home location are visible to you alone. You can delete everything in the app or with a single e-mail.
1. Data controller
The controller of your personal data is Notinote Sp. z o.o., ul. 3 Maja 49C/6, 61-728 Poznań, Polska ("we", "the Organiser"). For anything related to personal data, write to office@notinote.me.
2. Scope
This policy covers the Activly application at https://activly.dyname.pl, including the home page, the participant panel and the administrator panel. The app is intended solely for employees and contractors of the Organiser taking part in an internal sports challenge. Participation is voluntary.
3. What data we process
| Category | Data | Source |
|---|---|---|
| Account | name, e-mail (login), password hash (bcrypt), role (participant / administrator) | you, or the administrator creating your account |
| Campaign participation | declared kilometres per discipline, team assignment | you (or the administrator at your request) |
| Activities | date, time, discipline (run / bike / inline skate), distance in km, source of the entry | manual entry, GPX/CSV file, Strava, administrator import |
| GPS tracks | a reduced sequence of points (about one per 10 s) from a file you uploaded yourself; start time and duration | only from files you upload — never from the Strava API |
| Home location | a single pair of coordinates you set on the map | you, voluntarily |
| Derived data | points, badges, a "commute" flag, a "trained together" match with another participant | computed from the above |
| Strava (if you connect your account) | athlete ID, access tokens, activity IDs and — for runs, rides and inline skating — type, distance, start date and time. Start and end points are compared with your home and the office at import time and only the result "commute: yes/no" is stored. The route is fetched only when you click to view it and is never stored. | from the Strava API, after your authorisation |
| Technical data | IP address and server logs (standard HTTP logs), a session token in your browser | automatic |
We do not collect health data: no heart rate, weight, sleep or other physiological measurements — only distance, time and type of activity.
4. Purposes and legal bases
- Running the challenge (account, activities, points, badges, teams) — performance of the contract formed by the Terms accepted when the account is created (Art. 6(1)(b) GDPR).
- GPS tracks, home location, Strava connection — your voluntary consent, given by uploading a file, setting your home or clicking "Connect with Strava" after reading the consent screen (Art. 6(1)(a) GDPR). You can withdraw consent at any time in the app.
- Security and logs — our legitimate interest in protecting the app and accounts (Art. 6(1)(f) GDPR).
5. Who can see your data
Team campaign
Participants see on the shared board: your name, team, kilometres per discipline, points, earned badges and — for a group training — the first names of the people you were on the route with. Your declaration is hidden ("?") until you fulfil it. Nobody but you sees map routes, your home location, start/end points or your list of activities broken down by source.
Individual campaign
There is no board, ranking or totals. The app shows each person only their own data.
Campaign administrator
A designated person in the company sees the participant list, declarations, activities (date, discipline, km, source) and office locations in order to run the game and help with accounts. They have no access to your routes or home location.
6. Strava — specific rules
Connecting Strava is optional. We built it so that Strava talks only to you, in line with the Strava API Agreement and API Policy:
- We fetch only your activities, with your token, after your authorisation on Strava. No other athletes' data is retrieved.
- By default every detected activity waits for your "count it". You may enable automatic counting — then you agree that your runs, rides and skates immediately become your own submission to the challenge.
- We do not store routes, titles, heart rate or any other activity content. Routes are shown to you on demand and not stored.
- Withdrawing consent: the "disconnect" button in the app, or removing Activly on Strava (Settings → My Apps). Tokens and pending activities are deleted immediately. Counted activities remain as your own submissions, detached from Strava — unless you choose "disconnect and delete all Strava activities", in which case we delete them at once and confirm how many were removed.
- Edits and deletions made on Strava are reflected promptly (within 48 hours at the latest).
- How Strava processes your data is described in the Strava Privacy Policy.
7. Recipients
- Hosting: a virtual server at OVH (OVH SAS, European Union). Data does not leave the EEA.
- Strava, Inc. (USA) — only if you connect your account; Strava passes your data to us at your instruction.
- OpenStreetMap Foundation — map tiles and address search (Nominatim) load directly from OSM servers into your browser; OSM sees your IP address and the map area you view.
- Google Fonts — fonts on the home page are loaded from Google servers (IP address).
We do not sell data, use it for advertising, use it to train AI models, or share it with anyone outside this list.
8. Retention
- Account and results: until the account is deleted (at your request or when you leave the company).
- GPS tracks and home location: until you delete them or the account is deleted.
- Strava data: tokens and pending activities — until you disconnect; counted activities — as results (or immediately, if you choose so).
- Server logs: 30 days.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, objection, and to withdraw consent at any time (without affecting the lawfulness of earlier processing). You may also lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych) or your local authority.
Most of this you can do yourself in the app: delete a single activity, a GPS track, your home location, or disconnect Strava (with the option to delete activities). To delete your whole account, ask the campaign administrator or write to office@notinote.me — the account and all related data are then permanently removed. We answer requests without undue delay, within 30 days at most.
10. Security
The connection is encrypted (HTTPS). Passwords are stored only as bcrypt hashes. Strava access tokens are kept on the server and never reach the browser or other users. Only the technical administrator has server access. In the event of a data breach we will notify you and the competent authorities as required by GDPR, and Strava within 24 hours of discovery.
11. Cookies and browser storage
We use no tracking cookies and no analytics. The app stores in your browser (localStorage) only a session token (so you don't have to log in every time) and your chosen theme. Logging out deletes the token.
12. Changes
We will announce material changes to this policy in the app. The current version is always available at this address.