Activly · personal data

Privacy Policy

Version of 7 September 2026 · Organiser: Notinote Sp. z o.o.

In short: Activly is our internal app for a company sports challenge. We collect only what the game needs: your account, your activities (date, discipline, kilometres) and — only if you turn it on yourself — GPS tracks from files, your home location and data from your Strava account. Routes and your home location are visible to you alone. You can delete everything in the app or with a single e-mail.

1. Data controller

The controller of your personal data is Notinote Sp. z o.o., ul. 3 Maja 49C/6, 61-728 Poznań, Polska ("we", "the Organiser"). For anything related to personal data, write to office@notinote.me.

2. Scope

This policy covers the Activly application at https://activly.dyname.pl, including the home page, the participant panel and the administrator panel. The app is intended solely for employees and contractors of the Organiser taking part in an internal sports challenge. Participation is voluntary.

3. What data we process

CategoryDataSource
Accountname, e-mail (login), password hash (bcrypt), role (participant / administrator)you, or the administrator creating your account
Campaign participationdeclared kilometres per discipline, team assignmentyou (or the administrator at your request)
Activitiesdate, time, discipline (run / bike / inline skate), distance in km, source of the entrymanual entry, GPX/CSV file, Strava, administrator import
GPS tracksa reduced sequence of points (about one per 10 s) from a file you uploaded yourself; start time and durationonly from files you upload — never from the Strava API
Home locationa single pair of coordinates you set on the mapyou, voluntarily
Derived datapoints, badges, a "commute" flag, a "trained together" match with another participantcomputed from the above
Strava (if you connect your account)athlete ID, access tokens, activity IDs and — for runs, rides and inline skating — type, distance, start date and time. Start and end points are compared with your home and the office at import time and only the result "commute: yes/no" is stored. The route is fetched only when you click to view it and is never stored.from the Strava API, after your authorisation
Technical dataIP address and server logs (standard HTTP logs), a session token in your browserautomatic

We do not collect health data: no heart rate, weight, sleep or other physiological measurements — only distance, time and type of activity.

4. Purposes and legal bases

5. Who can see your data

Team campaign

Participants see on the shared board: your name, team, kilometres per discipline, points, earned badges and — for a group training — the first names of the people you were on the route with. Your declaration is hidden ("?") until you fulfil it. Nobody but you sees map routes, your home location, start/end points or your list of activities broken down by source.

Individual campaign

There is no board, ranking or totals. The app shows each person only their own data.

Campaign administrator

A designated person in the company sees the participant list, declarations, activities (date, discipline, km, source) and office locations in order to run the game and help with accounts. They have no access to your routes or home location.

6. Strava — specific rules

Connecting Strava is optional. We built it so that Strava talks only to you, in line with the Strava API Agreement and API Policy:

7. Recipients

We do not sell data, use it for advertising, use it to train AI models, or share it with anyone outside this list.

8. Retention

9. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability, objection, and to withdraw consent at any time (without affecting the lawfulness of earlier processing). You may also lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych) or your local authority.

Most of this you can do yourself in the app: delete a single activity, a GPS track, your home location, or disconnect Strava (with the option to delete activities). To delete your whole account, ask the campaign administrator or write to office@notinote.me — the account and all related data are then permanently removed. We answer requests without undue delay, within 30 days at most.

10. Security

The connection is encrypted (HTTPS). Passwords are stored only as bcrypt hashes. Strava access tokens are kept on the server and never reach the browser or other users. Only the technical administrator has server access. In the event of a data breach we will notify you and the competent authorities as required by GDPR, and Strava within 24 hours of discovery.

11. Cookies and browser storage

We use no tracking cookies and no analytics. The app stores in your browser (localStorage) only a session token (so you don't have to log in every time) and your chosen theme. Logging out deletes the token.

12. Changes

We will announce material changes to this policy in the app. The current version is always available at this address.