PRIVACY POLICY - EASY-TRACKLY APPLICATION
Effective from July 30, 2026
1. Introduction
This Privacy Policy sets out the rules for the processing and protection of personal data of users of the "easy-trackly" application (hereinafter: "Application") in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR").
2. Data Controller
The controller of your personal data is Marcin Milewicz IT Consulting, conducting business under the name Marcin Milewicz IT Consulting (address: Prawocińska 23c/2, Siechnice 55-011, Poland), Tax ID (NIP): 8982259501, REGON: 386752577 (hereinafter: "Controller").
For matters related to personal data protection, you can contact the Controller:
- by email: contact@easytrackly.app
- by mail: Prawocińska 23c/2, Siechnice 55-011, Poland
3. Purposes and Legal Bases for Data Processing
We process your personal data for the following purposes:
3.1. Service Provision (Article 6(1)(b) GDPR)
- registration and maintenance of User Account (Coach or Athlete),
- enabling use of Application functionality (training planning, activity tracking, communication),
- payment processing and invoicing,
- data synchronization with external services (e.g., Strava, Garmin) – upon your request.
3.2. Direct Marketing (Article 6(1)(a) GDPR)
- sending newsletters and news information – only with your consent,
- informing about promotions and new Application features.
3.3. Legal Obligations (Article 6(1)(c) GDPR)
- issuing and storing invoices,
- handling complaints,
- responding to requests from public authorities.
3.4. Legitimate Interests of the Controller (Article 6(1)(f) GDPR)
- analyzing Application usage patterns for improvement purposes,
- ensuring security and preventing abuse,
- pursuing or defending against legal claims.
3.5. Processing of Athlete Data on Behalf of the Coach (Data Processing Entrustment)
In the case of Athletes' personal data entered into the Application by Coaches, the Controller acts as a processor within the meaning of Article 28 GDPR. The controller of such data within the meaning of the GDPR is the Coach who decided to enter the Athlete's data into the Application.
Detailed terms and conditions of the entrustment of Athletes' personal data processing, including the scope of entrustment, processor obligations, list of sub-processors, and data deletion procedures, are set out in § 14 of the Terms of Service, available at: easytrackly.app/legal/terms.
4. Categories of Processed Data
Depending on how you use the Application, we process:
4.1. User Account Data
- first and last name,
- email address,
- password (stored in encrypted form),
- phone number (optional),
- profile picture (optional),
- language preferences.
4.2. Athlete Data (entered by Coaches)
- athlete's name and surname,
- athlete's email address,
- sport discipline, skill level,
- age, weight, height,
- join date, cooperation status.
4.3. Training Activity Data
- activity type (running, cycling, swimming, strength training, walk),
- date, duration, distance,
- comments and notes,
- data source (manual entry, Strava, Garmin, other).
4.4. Payment Data
- billing data (we do not store payment card data),
- transaction history,
- subscription status.
4.5. Technical Data
- IP address,
- browser and device type,
- session and login data.
4.6. Analytical Data (Product Telemetry)
We run our own basic measurement of how the Application is used, stored in our own database rather than with an external analytics provider. We record:
- the event name (e.g. page view, sign-up started, account created) and the time it occurred,
- the path within the Application where the event occurred (without query parameters),
- the traffic source: campaign parameters (utm_source, utm_medium, utm_campaign) and the referring site's host name (without the full URL),
- your Account identifier – if the event occurred while you were logged in,
- a random browser identifier allowing us to link repeat visits by the same person – only with your consent(Article 6(1)(a) GDPR). The identifier is stored in your browser's local storage and we remove it immediately once consent is withdrawn.
Without your consent we record the event without any identifier and without a stored traffic source – all that is then known is that the event occurred, with no way to link it to a person or to another visit. Such measurement relies on our legitimate interest (Article 6(1)(f) GDPR – section 3.4 above).
We do not record email addresses, names, or training data in these events.
5. Personal Data Recipients
Your personal data may be transferred to the following categories of recipients:
5.1. External Integrations (upon your request)
- Strava (Strava, Inc.) – sports activity synchronization after connecting your account.
- Garmin (Garmin Ltd.) – sports activity synchronization and workout delivery to device after connecting your account.
5.2. Communication Services
- Resend (Resend, Inc.) – sending transactional emails (registration confirmations, password resets) and newsletters (with consent).
5.3. Hosting and Infrastructure Services
- Supabase – database hosting and authentication.
- Vercel – web application hosting and analytics (Vercel Analytics).
5.4. Analytics Services
The product telemetry described in section 4.6 is our own – it stays within our infrastructure and is not shared with any of the providers below. In addition to it, we use:
- Vercel Analytics – collection of anonymous data about page visits (number of visits, most popular pages, traffic sources). Vercel Analytics does not use cookies and does not track users across sessions.
- Microsoft Clarity – user behavior analysis (heatmaps, session recordings) – only with your consent.
5.5. Public Authorities
Where required by law, data may be disclosed to relevant public administration authorities, courts, or law enforcement agencies.
6. Data Transfers Outside the European Economic Area
Some of our service providers may process data outside the EEA, particularly in the USA:
- Supabase (USA) – database and authentication. Data stored in the EU region (Frankfurt, eu-central-1). Service access from the USA is based on Standard Contractual Clauses (SCC) and a Data Processing Agreement.
- Strava (USA) – data transfer is based on Standard Contractual Clauses (SCC) approved by the European Commission,
- Garmin (USA/Switzerland) – data transfer is based on Standard Contractual Clauses (SCC) approved by the European Commission,
- Vercel (USA) – data processed in EU region (Frankfurt), but certain operations may take place in the USA based on SCC.
In all cases of data transfer outside the EEA, we apply appropriate safeguards provided for in the GDPR.
7. Data Retention Period
We store your personal data for the following periods:
- Account data – throughout the period of using the Application, and after account deletion – for 30 days for archival purposes (recovery possibility),
- Billing data – for the period required by tax law (5 years from the end of the tax year),
- Marketing data – until consent is withdrawn or an effective objection is raised,
- Analytical data in our database (the events described in section 4.6) – no longer than 13 months from the moment the event was recorded; older events are deleted by an automated job that runs daily,
- Analytical data in external tools (Vercel Analytics, Microsoft Clarity) – according to the retention periods applied by those providers, which are beyond our control,
- Data for claim purposes – for the limitation period of claims (generally 3 years).
8. Your Rights
Under the GDPR, you have the following rights regarding the processing of your personal data:
8.1. Right of Access (Article 15 GDPR)
You have the right to obtain confirmation whether we process your data and to access it.
8.2. Right to Rectification (Article 16 GDPR)
You can request rectification of inaccurate data or completion of incomplete data.
8.3. Right to Erasure – "Right to be Forgotten" (Article 17 GDPR)
In certain cases, you can request deletion of your personal data.
8.4. Right to Restriction of Processing (Article 18 GDPR)
You can request restriction of data processing in certain situations.
8.5. Right to Data Portability (Article 20 GDPR)
You have the right to receive your data in a structured, commonly used format (JSON/CSV) and to transmit it to another controller.
8.6. Right to Object (Article 21 GDPR)
You can object to data processing based on the Controller's legitimate interest, including profiling.
8.7. Right to Withdraw Consent
If processing is based on consent, you can withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
8.8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority – in Poland this is the President of the Personal Data Protection Office (PUODO) (ul. Stawki 2, 00-193 Warsaw).
How to exercise your rights? Send an email to contact@easytrackly.app with a description of your request. We will respond within 30 days of receiving the request.
9. Cookies and Similar Technologies
The Application uses the following types of cookies:
9.1. Essential Cookies
Necessary for proper Application operation (e.g., maintaining login sessions). Consent is not required.
9.2. Analytical Cookies
Used to analyze how the Application is used for improvement purposes. We use them based on your consent.
With your consent we also store a random identifier and a remembered traffic source in your browser's local storage, used by our own telemetry described in section 4.6. These are not cookies, but a technology with a similar effect – which is why they require the same consent. Once consent is withdrawn, we remove both entries from the browser immediately.
Note: Vercel Analytics, which we use for basic traffic analytics, does not use cookies and operates in a privacy-first manner. Data is anonymized and does not allow identification of individual users.
9.3. Marketing Cookies
Used to personalize marketing content. We use them only with your consent.
Cookie Management: You can change cookie settings in your browser settings or use the cookie banner on your first visit to the Application.
10. Data Security
We apply appropriate technical and organizational measures to protect your personal data, including:
- data transmission encryption (SSL/TLS),
- password storage in encrypted form (bcrypt),
- access control – only authorized persons have access to data,
- regular backups,
- security monitoring and auditing.
11. Privacy Policy Changes
- The Controller reserves the right to change this Privacy Policy in case of technical, legal, or organizational changes.
- We will inform you of significant changes via email and notification in the Application.
- The current version of the Privacy Policy is always available at: easytrackly.app/legal/privacy.
12. Contact
For matters related to personal data processing, please contact us:
- Email: contact@easytrackly.app
- Mailing address: Prawocińska 23c/2, Siechnice 55-011, Poland
Privacy Policy compliant with GDPR (Regulation (EU) 2016/679).