Privacy policy
As of 11 October 2026
1. Who is responsible for your data
The controller is Tomasz Błażusiak, Kamperstr. 29, 40589 Düsseldorf, Germany, email kontakt@gruppeo.com, contact form: gruppeo.com/en/kontakt.html. The service is run privately and on a non-commercial basis. No data protection officer has been appointed, as this is not required.
2. What data we collect and why
- Account: email address (for logging in), password, if you set one (stored only as a bcrypt hash, nobody can see it), nickname, the date you confirmed you are an adult, and the version and date on which you accepted the terms of use. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- Meetups: content you publish (title, description, start place and time, route, distance, pace and other details). It is public, together with your nickname. Legal basis: Art. 6(1)(b) GDPR.
- Sign-ups: which meetups you have joined and since when. Your nickname is only visible to the organiser of the meetup in question; others only see the number of participants. Legal basis: Art. 6(1)(b) GDPR.
- Profile (optional): a short “About me” description and the sports or types of bike you do or use. The profile is only visible to logged-in users, together with the month you registered and your upcoming meetups. Your avatar is made up of the initials of your nickname; we do not collect photos. You can change or delete the description at any time. Legal basis: Art. 6(1)(b) GDPR.
- Email notifications: When someone joins or leaves your meetup, or when the organiser of a meetup you have joined posts a message, cancels it or changes the date or time, we send a combined email via Brevo (at most one per hour), in the language of the page you last used (we store it in your profile). We store the events for 30 days. You can turn notifications off in the account window. Legal basis: Art. 6(1)(b) GDPR.
- Comments on meetups: the content of the comment, the time it was posted and your nickname. Comments are only visible to logged-in users. You can delete your comment at any time; the organiser can delete comments on their meetup. Legal basis: Art. 6(1)(b) GDPR.
- Groups and group chat: the groups you belong to, your role (admin or member), the date you joined, the time you last read the chat (for the unread message counter), and the content of your messages with the time sent and your nickname. The member list and chat are only visible to members of the group. The name, description and meetups of a public group are visible to everyone. You can delete your messages or leave the group at any time; group admins can remove messages and members. The chat is not end-to-end encrypted, so do not share sensitive data there. Legal basis: Art. 6(1)(b) GDPR.
- Reports and moderation: the content of the report, the reason, optionally your email address, and the moderation decision. Legal basis: obligations under the Digital Services Act (DSA), Art. 6(1)(c) GDPR, and our legitimate interest in the security of the service, Art. 6(1)(f) GDPR.
- Contact form: your email address and the content of your message, so that we can reply. Legal basis: Art. 6(1)(b) or (f) GDPR.
- Technical data: Each time a page is accessed, the hosting and database servers record in their logs, among other things, the IP address, the time and the address requested. This data is used to run and protect the service. Legal basis: Art. 6(1)(f) GDPR.
We do not collect your name, phone number, date of birth or your device’s location. We do not use advertising or profiling and we do not sell data; the only statistics are the anonymous visitor counts described in section 4.
3. Cookies and browser storage
The service does not use advertising or analytics cookies, which is why there is no cookie banner. The visitor statistics (section 4) work without cookies and without storing anything in your browser. When you log in, we store the session token in your browser’s storage (localStorage), along with which moderation notices you have already seen. Whether or not you are logged in, we also store there the page language you have chosen and whether the welcome window has been closed. This is technically necessary to provide the service you have requested (§ 25(2) no. 2 TDDDG). Logging out deletes the session token.
4. Who we share data with
We use service providers that process data on our behalf under data processing agreements (Art. 28 GDPR):
- Supabase Inc. (USA): database and login. The data is stored in a data centre in Frankfurt am Main (Germany).
- Netlify Inc. (USA): website hosting and content delivery network.
- Brevo (Sendinblue SAS) (France): sending emails with login links and notifications.
- OVH (France): domain and forwarding of the kontakt@gruppeo.com address.
Visitor statistics: We count page views with GoatCounter (goatcounter.com). Each time a page is viewed, the browser sends GoatCounter the address of the page (without parameters, i.e. without meetup or invitation numbers), the page you came from, the screen size and, as with any connection, the IP address and browser type. GoatCounter does not store the IP address or any identifier; it recognises unique visits by a short-lived, anonymous hash. We only see total numbers, not individuals. Legal basis: our legitimate interest in understanding how the service is used, Art. 6(1)(f) GDPR.
Access from the USA is possible in the case of Supabase and Netlify. The transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (if the provider is certified) or on standard contractual clauses (Art. 46(2)(c) GDPR).
Map: Your browser loads the map tiles directly from the servers of the OpenStreetMap Foundation (United Kingdom). In doing so, the tile server learns your IP address and the area of the map you are viewing. The European Commission has adopted an adequacy decision for the United Kingdom. Legal basis: Art. 6(1)(f) GDPR (displaying the map, without which the service does not work).
Drawing a route along roads: If the “Follow roads” option is switched on while you draw a route, your browser sends the coordinates of each pair of consecutive route points to the public BRouter server (brouter.de, Germany), which returns the course of the road. In doing so, the server learns your IP address and these coordinates. We do not transmit any account data. You can switch the option off and draw straight lines. Legal basis: Art. 6(1)(f) GDPR.
5. How long we keep data
- Account and profile: until the account is deleted. Deletion also removes your meetups, sign-ups, comments, group memberships and chat messages.
- Meetups together with the participant list and comments: automatically 12 months after the start date.
- Group chat messages: automatically after 12 months. Group membership: until you leave the group, or the group or your account is deleted. A group with no members is deleted together with its chat.
- Reports: 12 months after they have been dealt with, at the latest after 24 months.
- Messages from the contact form: 12 months after they have been dealt with, at the latest after 24 months.
- Technical logs: according to the providers’ settings, usually a few days to a few weeks.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest (Art. 15–21 GDPR). You can exercise the most important of these yourself in the account window: download all your data in JSON format and delete your account with one click. For anything else, write to us.
You can also lodge a complaint with a supervisory authority, for example in your country of residence. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (North Rhine-Westphalia Commissioner for Data Protection and Freedom of Information, Düsseldorf).
7. Do you have to provide data?
You can view the map and meetups without an account. To publish meetups and join them, you need an account, and for that an email address, a nickname and confirmation that you are at least 18 years old. We do not make automated decisions and we do not profile users.
8. Changes
If we change this policy, we will publish the new version on this page with a new date.