Privacy policy
Version of 29 September 2026
This is a translation. The Polish version is the binding one.
1. Controller and contact
The controller of your personal data (within the meaning of the GDPR) is:
- Rafał Wasil, sole trader operating as WASIL RAFAŁ
- Address: ul. Rezydencka 11, Grzepnica, 72-003 Dobra (Szczecińska), Poland
- Tax ID (NIP): 8512906989 · REGON: 320846551 · registered in CEIDG (Poland)
- Help: support@gridhunt.app
- Data protection matters: privacy@gridhunt.app
- Electronic delivery address (Poland): AE:PL-37059-17121-TTEWJ-25
We have not appointed a data protection officer (we are not required to). For all data matters, write to privacy@gridhunt.app. This policy covers gridhunt.app, the iPhone and Apple Watch apps, the Connect IQ apps (Garmin), the Karoo extension and the Integrations described in the terms of service.
2. What data we process
- Account: your name or display name, email address, profile picture (image address from the sign-in provider), language, the identifier from your sign-in provider (Strava, Apple, Google, Facebook), and your settings and consents (with dates). Others see the display name you set in Gridhunt (see Strava data and public features).
- Activities: name, sport type, date, distance and GPS track. From the track we calculate claimed tiles and keep a simplified route to show you. We delete the raw GPS points of activities imported from other services after processing. For rides recorded in the Gridhunt iPhone app we keep the original file (GPX) so it can be reprocessed or sent to Strava. For each activity we record its source (e.g. the Strava API, an uploaded file, a recording in the Gridhunt app, a connected app), because the source decides where the activity may be shown.
- Targets and routes: areas you want to claim and planned routes (GPX files).
- Integrations: your account ID and name in the connected service, the granted scope and access tokens (encrypted). We don’t know your passwords for these services. The exception is the current komoot connection: you enter your password once, it is used only to obtain a token and is never saved.
- Devices: the name of a paired device (Garmin, Karoo, Wahoo), when it last connected and a hash of its token. During a ride the device sends its current position to fetch the tiles around you; we don’t store that position.
- Community: friendships, reports of “impossible” tiles, votes, comments and photos (with EXIF metadata, which may include where and when the photo was taken), and your leaderboard and public-link settings.
- Premium: your Stripe customer and subscription IDs, plan, status, period, country, amounts and receipts. We never see your card details.
- Technical and security data: event logs (sign-ins, settings changes, payments) with IP address, abuse-prevention counters (email address, IP) and server logs.
- Contact: the content of messages you send us (help, complaints, GDPR requests).
- Error reports and bug reports: when the Gridhunt app or website hits an error, we send a technical report with your consent: error type, stack trace, app version, device or browser model, OS version and your last steps in the app (e.g. screens opened). The report does not contain your email; we automatically remove email addresses, tokens and coordinates from it. Your ride’s position and state are included only if you tick “Include ride context”. You decide each time, or once for all in Settings → Privacy (“ask / always / never”). We link a report to your account only if you ask us to; you then see its status in “My reports”. Reports you submit yourself (description, device details, optional screenshot) are processed the same way; a screenshot is passed to the team as an attachment only with your consent. Legal basis for error reports: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in settings; for bug reports: performance of the contract (Art. 6(1)(b) GDPR).
3. Where the data comes from
Most data you provide yourself, or it is created when you use Gridhunt. Some comes from services you choose to connect:
- Sign-in: Strava, Apple, Google and Facebook give us your name, email (if they share it), profile picture and an identifier.
- Activities: (1) your Strava connection via the Strava API (automatic import after you connect your account); (2) files and archives you upload (GPX, FIT, TCX, ZIP), including an account archive exported from Strava or Garmin Connect; (3) rides recorded in the Gridhunt apps (iPhone, Apple Watch, Android in the future); (4) other connected apps: Wahoo, Garmin Connect, Suunto, COROS, Polar, Ride with GPS (some Integrations are in preparation); (5) komoot. We delete uploaded files after processing, at the latest after 7 days; the activities and tiles calculated from them remain.
- iPhone and Apple Watch app: the GPS track of a recorded ride (also in the background while you record), and photos from the camera or library when you report a tile. The watch app reads your heart rate from Apple Health (HealthKit) to show it during the ride and saves the workout to Apple Health. We do not send HealthKit data, including heart rate, to our servers.
- Garmin and Karoo devices: they only download data from Gridhunt (tiles, target, routes, your first name and last-name initial); they don’t upload activities.
4. Purposes and legal bases
- Providing the Service (account, sign-in by email link or provider, tile counting, map, targets, planner, friends, devices, Integrations, data export and deletion, help): performance of a contract, Art. 6(1)(b) GDPR.
- Premium and payments (subscription, trial, entitlements): performance of a contract, Art. 6(1)(b). Complaints, withdrawals, tax and accounting duties: legal obligation, Art. 6(1)(c) GDPR.
- Square leaderboard and helping others in the planner: your consent (you turn them on in Settings), Art. 6(1)(a) GDPR; you withdraw it by turning the option off.
- Analytics with cookies (Google Analytics 4, Microsoft Clarity) and Google advertising signals: consent, Art. 6(1)(a) GDPR.
- Security, preventing abuse and leaderboard cheating, content moderation (DSA), cookieless statistics, establishing and defending legal claims: our legitimate interests, Art. 6(1)(f) GDPR.
5. Who can see your data
By default, only you. We show your data to others only in the situations below, which you turn on yourself:
- Friends (after both sides accept): your claimed tiles (z14 and z17), your activity count, and your number of rides and kilometres per year. They don’t see routes, dates or targets. You can end a friendship at any time.
- Square leaderboard (“Show me on the leaderboard”): signed-in users see your display name (see below), avatar, the size and location of up to 10 of your squares and the tiles inside them. They don’t see routes or dates. We look up the place name for each square’s centre with OpenStreetMap Nominatim, sending only coordinates. Turning the option off removes you from the leaderboard immediately. Keep in mind that a square’s location may reveal the area where you live or train.
- Helping others in the planner: others learn only that “someone” rode through a tile that is an OpenStreetMap obstacle, never your name, routes or dates. Turning the option off removes your contribution.
- Public link (Settings → Sharing): anyone with the link sees your display name, your claimed z14 tiles by year and your targets (name and outline). They don’t see routes or z17 tiles. The link doesn’t expire on its own and isn’t indexed by search engines. Turning it off deletes it; regenerating it creates a new one.
- Reports of “impossible” tiles, comments and photos are visible to all signed-in users together with your name and avatar.
- Friend invitations: anyone with your invite link sees your display name.
Only data from outside the Strava API. Everything described above is calculated only from activities that did not come through the Strava API. We never show data obtained through the Strava API to anyone else in any form, even when these options are on (see Strava data and public features). Others see the display name you set in Gridhunt, never the name or profile photo from your Strava account. Video reels are created by your browser or phone and never reach our servers.
Only the service provider has administrative access. We look at an activity’s GPS track only when the activity has been automatically flagged as passing through a tile reported as impossible, and every such view is logged. A person decides whether to exclude the activity.
6. Strava data and public features
We record the source of every activity. The source decides who can see the tiles calculated from it.
- Strava API: for you only. Activities imported automatically after you connect your Strava account, and the tiles and routes calculated from them, are shown only to you: on your map, in your statistics, the planner, your rides and reels created on your device. We never use them in the square leaderboard, friends features, your public link, community aggregates (helping others in the planner) or marketing material. The Strava API rules require this.
- Public sources. Features that show anything to others use only files and archives you upload (including a ZIP archive exported from Strava or Garmin Connect), rides recorded in the Gridhunt apps, devices and other connected apps (e.g. Wahoo, Garmin, Ride with GPS, komoot). They work only when you turn them on (see Who can see your data).
- One ride, one copy. When the same ride arrives from several sources, we keep one copy in this order: a recording in the Gridhunt app, a Garmin device (Connect IQ), an uploaded file or archive, other connected apps, komoot and, last, the Strava API. An activity from a Strava ZIP archive replaces the same activity obtained earlier through the Strava API.
- Strava API: 7 days at most. We keep an activity obtained through the Strava API, and the tiles and routes calculated from it, for at most 7 days after it was fetched. After that we delete it, unless you import the same activity yourself (a ZIP archive or a file) or record it in the Gridhunt app — then your copy from that source stays. Deleting an activity on Strava removes only the copy obtained through the Strava API, never a copy you uploaded yourself.
- Making your Strava history public. If you want your past Strava activities to count on the leaderboard and for friends, download your account archive from Strava and upload the ZIP file to Gridhunt. Step-by-step guide: Data sources.
- Public name. Others see the display name you set in Gridhunt. If you haven’t set one, we show the name from another sign-in method (email, Apple, Google, Facebook) only if you haven’t connected Strava; otherwise a neutral label with a number. We never show others the name or profile photo from your Strava account.
7. Recipients of data
Processors acting on our behalf (under data processing agreements):
- Microsoft Ireland Operations Ltd. (Azure): servers, database, file storage, Key Vault (encryption keys), logs and monitoring (Application Insights), and sending sign-in link emails (Azure Communication Services). Region: West Europe (Netherlands); email data location: Europe.
- Cloudflare, Inc. (USA): DNS, CDN, attack protection (WAF) and Cloudflare Web Analytics. Traffic to the site, including your IP address, passes through Cloudflare.
- Google Ireland Ltd. (Google Analytics 4) and Microsoft Ireland Operations Ltd. (Clarity): only with your consent, see cookies.
- Microsoft Ireland Operations Ltd. (Azure DevOps): handling of errors and reports by the team. It receives the technical description of the error or the text of the report, the number of occurrences and an internal identifier, without your name, email or the raw error report.
Independent controllers (processing data under their own terms):
- Stripe: Stripe Payments Europe, Ltd. (Ireland) and Sold through Link, LLC (USA), under Stripe Managed Payments. They handle payment, taxes, receipts, fraud prevention and transaction support. We pass them your email, name, user ID and language; you give your card details directly to Stripe. Policies: stripe.com/privacy, link.com/privacy.
- Services you connect: Strava, komoot, Wahoo, Garmin, Suunto, COROS, Polar, Ride with GPS and sign-in providers (Apple, Google, Meta/Facebook). At your request we send them data (e.g. a ride to Strava or a route to Wahoo) and fetch activities from them.
- Apple (App Store, Apple Health on your device) and Garmin (Connect IQ store): under their own terms.
Map services: your browser loads map tiles from OpenFreeMap (tiles.openfreemap.org), which sees your IP address and the area you view. Our server asks OpenStreetMap Nominatim for place names and Overpass API servers for road data, sending only coordinates or an area and nothing about you. Routing (BRouter) runs on our own server. Your browser loads avatars from Google, Facebook or Strava directly from those companies’ servers.
We may also disclose data to public authorities where the law requires it, and to advisers (accountants, lawyers) bound by professional secrecy.
8. Transfers outside the EEA
Our servers are in the EU. Data may reach countries outside the European Economic Area, mainly the USA, through Cloudflare, Google, Microsoft (Clarity), Stripe/Link and the services you connect. The legal basis is the European Commission’s adequacy decision (EU-US Data Privacy Framework, where the recipient is certified) or standard contractual clauses (Art. 46(2)(c) GDPR). We will send you information about the safeguards on request. When you connect a service based outside the EEA, the transfer happens at your request under your contract with that service.
9. How long we keep data
- Account, activities, tiles, targets, routes, friendships: until you delete your account. We delete accounts immediately, with no grace period. Database and file backups expire after 7 days.
- Strava data: when you disconnect Gridhunt (in Gridhunt Settings or on Strava), we delete all activities obtained through the Strava API and the data calculated from them (tiles, routes). Activities from files you uploaded yourself (including a Strava ZIP archive) and rides recorded in Gridhunt remain until you delete them or your account. Otherwise, activities obtained through the Strava API are deleted no later than 7 days after they were fetched, and an activity you delete on Strava is removed straight away (only the Strava API copy).
- Other Integrations: when you disconnect, we revoke access and delete the tokens; imported activities stay until you delete them or your account.
- Uploaded files: deleted after processing, at the latest after 7 days.
- Tile reports and comments: after account deletion they remain without your name and avatar; photos are deleted.
- Security logs with IP address: 12 months; abuse-prevention counters: up to 30 days; server logs: 30 days.
- Subscription data: with us until account deletion; Stripe/Link keeps receipts and transaction data for as long as tax law requires.
- Correspondence and complaints: up to 3 years after the matter is closed (defence of claims).
- Analytics: Google Analytics 14 months; Clarity: recordings up to 30 days, aggregated data up to 13 months.
- Error reports: raw reports for 90 days; all reports linked to your account are deleted together with it. Bug reports: while the case is open, then as correspondence; after account deletion they remain without any link to you.
10. Your rights
You have the right to access your data and get a copy, to rectification, erasure, restriction of processing and data portability, to object to processing based on our legitimate interests, and to withdraw consent at any time (without affecting the lawfulness of earlier processing).
- Yourself: in Settings you can download your data (a JSON file with your profile, activities, tiles, targets, friends and subscription), correct it, disconnect Integrations, turn off the leaderboard, planner help and public link, and delete your account.
- By email: to privacy@gridhunt.app; we reply within one month. We may ask you to confirm that the request comes from the account holder.
- Complaint: to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl), or to the data protection authority in your country.
Providing data is voluntary, but without an email address or a sign-in provider account you can’t create an account, and without activities we can’t count tiles.
12. Security
Connections are encrypted (HTTPS) and data is encrypted at rest. Tokens for Strava and other services are additionally encrypted (AES-256-GCM) with a key held in Azure Key Vault. Device tokens and pairing codes are stored only as hashes. There are no Gridhunt passwords, because you sign in with an email link or through a provider. Administrative access is restricted and logged. If a personal data breach puts you at risk, we will notify you and the supervisory authority as the GDPR requires.
13. Children
Gridhunt is for people aged 16 and over. We don’t knowingly collect data from younger children; if we find out, we delete the account. If you are a parent and think your child has created an account, write to privacy@gridhunt.app.
14. Profiling, AI and selling data
- We don’t make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you (Art. 22 GDPR). The only automated step is flagging activities for review by a person (see above).
- We don’t use your data to train artificial intelligence models, and we don’t share it with others for that purpose.
- We don’t sell personal data or share it with advertisers or data brokers.
15. Changes to this policy and change history
We will tell you about significant changes in the app or by email before they take effect. If a change requires your consent, we will ask for it.
- 29 September 2026. (pending legal review) Error reports and bug reports: data collected, consent and the “ask / always / never” setting, 90-day retention of raw reports, deletion together with the account, Azure DevOps (Microsoft) as processor.
- 29 September 2026. Data sources: data obtained through the Strava API is visible only to the account owner and is not used in the leaderboard, friends features, public links or community data; public features use uploaded files and archives, recordings in the Gridhunt apps and other connected sources; source priority for duplicates; display name set in Gridhunt; what happens to data when you disconnect Strava. Strava API data is kept for at most 7 days unless you upload or record the same activity in Gridhunt; deleting an activity on Strava does not remove your uploaded copy.
- 28 September 2026. New version: full controller details, purposes and legal bases, new data sources (komoot, Wahoo, Garmin and others, the iPhone and Apple Watch app, devices), Stripe Managed Payments, public links, tile reports, retention periods, rights, minimum age 16, the gridhunt.app address.
- Before: early-access version describing cookies and analytics.