Warsaw Running Club

Privacy Policy

Warsaw Running Club

Last Updated: March 9, 2025

Welcome to the Warsaw Running Club website ("we," "us," or "our"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit or use our website. We are committed to safeguarding your privacy and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) as implemented in Poland (RODO), the Polish Personal Data Protection Act, and other relevant regulations.

Warsaw Running Club is an informal, unregistered group offering free participation in running events followed by optional coffee meetups. We do not conduct commercial activities, process payments, or generate revenue. For any questions regarding this Privacy Policy, please contact us at contact@warsawrunningclub.pl.

1. Data We Collect

We collect the following personal data from users of our website:

  • Name: Your first name or full name (optional, provided during registration).
  • Email Address: To enable account registration, login, and communication.
  • Password: Encrypted and inaccessible to us, used for secure account authentication.
  • Event Registration Information: Details of your participation in specific runs (e.g., sign-up or cancellation status).
  • Consent Preferences: Mandatory acceptance of this Privacy Policy and Terms of Service, and optional consent for marketing communications or cookies.
  • Usage Data: Automatically collected data such as IP address, browser type, device information, pages visited, and interaction with the website, gathered via Google Pixel, Facebook Pixel, and CookieYes.

We do not process payment data, as participation in our events is free, and any coffee purchases are handled directly with partnered cafés.

2. How We Collect Your Data

We collect your personal data in the following ways:

  • Directly from You: When you register an account, log in, sign up for or cancel a run, provide consent, or contact us via email.
  • Automatically: Through cookies and tracking technologies (Google Pixel, Facebook Pixel, CookieYes) when you browse our website, subject to your consent where required.

A cookie banner powered by CookieYes informs you about the use of cookies and allows you to manage your preferences.

3. Purpose and Legal Basis for Processing Your Data

We process your personal data for the following purposes and based on the following legal grounds:

  • Account Management and Event Registration: To create and manage your account and facilitate run participation (Legal basis: Art. 6(1)(b) GDPR – performance of a contract).
  • Communication: To respond to inquiries and provide updates about runs (Legal basis: Art. 6(1)(b) GDPR – performance of a contract; Art. 6(1)(f) GDPR – legitimate interests).
  • Marketing: To send you updates or promotions about Warsaw Running Club activities, only with your explicit consent (Legal basis: Art. 6(1)(a) GDPR – consent).
  • Website Analytics and Improvement: To analyze usage trends and enhance our website via Google Pixel and Facebook Pixel, subject to your consent (Legal basis: Art. 6(1)(a) GDPR – consent; Art. 6(1)(f) GDPR – legitimate interests, balanced with your rights).
  • Cookie Management: To manage cookie preferences and ensure compliance with data protection laws via CookieYes (Legal basis: Art. 6(1)(c) GDPR – legal obligation).

4. Cookies and Tracking Technologies

We use the following cookies and tracking technologies:

  • Necessary Cookies: Essential for website functionality (e.g., session management), managed by CookieYes. No consent required (Art. 6(1)(b) GDPR).
  • Analytics Cookies: Google Pixel collects data (e.g., IP address, pages visited) for usage analytics, with consent managed by CookieYes (Art. 6(1)(a) GDPR).
  • Marketing Cookies: Facebook Pixel tracks user interactions for marketing insights, with consent managed by CookieYes (Art. 6(1)(a) GDPR).

You can manage your cookie preferences at any time via the CookieYes banner. For more details, see our Cookie List in the banner.

5. How We Store and Process Your Data

Your personal data is stored and processed using the following services:

  • Amazon Web Services (AWS): For hosting, authentication (Cognito), storage (DynamoDB), email delivery (SES), and functionality (Lambda, API Gateway, IAM, CloudWatch, Amplify). Data is stored in the EEA, compliant with GDPR.
  • Zoho Mail: For email communication (e.g., responding to inquiries). Zoho complies with GDPR via EU data centers or standard contractual clauses.
  • Google Pixel: For analytics, with data processed globally, subject to GDPR safeguards (e.g., anonymization, consent).
  • Facebook Pixel: For marketing insights, with data processed by Meta, subject to GDPR compliance via EU-US Data Privacy Framework or equivalent measures.
  • CookieYes: For cookie consent management, hosted in the EEA with GDPR-compliant security.

6. Data Retention

We retain your personal data as follows:

  • Account Data: Until you delete your account, after which it is permanently removed within 30 days, unless legally required to retain it longer.
  • Usage Data: Retained for up to 26 months (Google Pixel) or as per Meta’s retention policy (Facebook Pixel), unless you withdraw consent earlier.
  • Consent Records: Kept as long as your account exists or until consent is withdrawn, with logs retained for 5 years to demonstrate compliance (Art. 5(2) GDPR).

7. Sharing Your Data

We share your personal data only with:

  • AWS: As our data processor for hosting and functionality.
  • Zoho Mail: For email services.
  • Google: For analytics via Google Pixel, with consent.
  • Meta: For marketing via Facebook Pixel, with consent.
  • CookieYes: For cookie management.
  • Legal Authorities: If required by law or to protect our rights.

We do not sell or share your personal data with third parties for their own purposes.

8. Your Rights

Under GDPR/RODO, you have the following rights:

  • Access: Request a copy of your data.
  • Rectification: Correct inaccurate data.
  • Erasure: Delete your account and data.
  • Restriction: Limit processing of your data.
  • Objection: Object to processing based on legitimate interests (e.g., analytics).
  • Data Portability: Receive your data in a machine-readable format.
  • Withdraw Consent: Revoke consent for marketing or cookies at any time, without affecting prior processing.

To exercise these rights:

  • Edit your account settings or withdraw consent via the website or CookieYes banner.
  • Delete your account directly on the website.
  • Contact us at contact@warsawrunningclub.pl.

We will respond to your request within one month, free of charge, unless the request is complex or excessive.

9. International Data Transfers

Data processed by Google Pixel and Facebook Pixel may be transferred outside the EEA (e.g., to the US). We ensure compliance through:

  • EU-US Data Privacy Framework (if applicable).
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Additional safeguards (e.g., data anonymization).

10. Contact Us

For questions, requests, or concerns about your data, please contact us at:

We do not currently have a designated Data Protection Officer (DPO), as our informal club does not meet the threshold requiring one under GDPR. However, we take data protection seriously and will assist you promptly.

11. Complaints

If you believe we have not handled your data appropriately, you have the right to lodge a complaint with a supervisory authority. In Poland, this is:

  • Urząd Ochrony Danych Osobowych (UODO)
  • Address: ul. Stawki 2, 00-193 Warsaw, Poland
  • Website: www.uodo.gov.pl
  • Phone: +48 606 950 000

You may also contact the supervisory authority in your country of residence or where an alleged infringement occurred.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Updates will be posted on our website with a revised "Last Updated" date. Please review it periodically.

Thank you for trusting Warsaw Running Club with your data. We’re here to ensure your experience is safe and enjoyable!