RUNOPOLISMiles make cities

Privacy Policy for the weekly Runopolis city race.

Connect with Strava

We import your public Strava profile and public runs via OAuth, and show name, photo, and kilometer totals on public leaderboards. You can withdraw and delete in Runopolis or revoke access in Strava. By connecting you also agree to the Terms.

Runopolis

Privacy Policy

Last updated: August 23, 2026

Who we are

Runopolis (“we”, “us”) is a public weekly running leaderboard operated independently of Strava. We connect to your Strava account so we can show kilometers by person and by city. For privacy requests, email [email protected].

Runopolis and Strava are separate, independent controllers of the personal data each of us processes. We are not joint controllers. Strava’s Privacy Policy controls data you share with Strava. If this policy conflicts with Strava’s Privacy Policy for that data, Strava’s policy controls.

Your consent

Connecting with Strava is your consent that we may collect the data below and publish your name, username, profile photo, and aggregated public-run kilometers on public leaderboards and profiles. That sharing is the purpose of the product. If you do not want this information public, do not connect Strava.

You can withdraw consent at any time by deleting your data in Runopolis or by revoking Runopolis in your Strava app settings. Withdrawal stops further access and deletes the Strava-derived data we hold about you. See also our Terms & Conditions.

Where the data comes from

We collect athlete identity and activity data from Strava through OAuth and the Strava API (including webhooks). We do not collect GPS or activity history from your phone, watch, or another fitness app. City and country labels are derived from a start coordinate Strava provides, using OpenStreetMap Nominatim geocoding. We do not keep those start coordinates after the city is assigned. Session cookies are created by us.

Data we collect

When you connect with Strava, we may store:

  • Profile details from Strava (name, username, athlete id, profile photo URL)
  • OAuth tokens needed to read your public profile and public activities and keep them in sync
  • Public run and trail-run summaries (distance, start time, sport type)
  • City, country, and country code derived from a start coordinate
  • A signed session cookie so you stay logged in on this device
  • Sync and webhook timing so we can update your runs and limit manual refreshes

We do not import activities marked private or followers-only on Strava. We do not store raw GPS traces, route maps, or activity titles.

How we use data

Legal basis: your consent when you connect Strava. We use this information to:

  • Operate public leaderboards and public profiles
  • Map public runs to cities and countries for rankings
  • Keep your public activity history up to date via sync and Strava webhooks
  • Secure the service and prevent abuse

We do not sell your personal data. We do not use your activities for advertising, analytics products, or AI training.

What is public

Leaderboards and profiles on Runopolis are public. Your display name, username, profile photo, and aggregated kilometers by city or country may be visible to anyone who visits the site and may be indexed by search engines. We do not publish raw GPS traces, full route maps, or private Strava activities.

Access, withdrawal, and deletion

You can view the data we display about you on your public profile, and download a JSON copy from the account menu (Download my data). You can delete it in Runopolis (Delete my data). You can also revoke Runopolis in Strava. Either action deletes your account, tokens, imported runs, and leaderboard entries. After you use Delete my data, we show a written confirmation page. Revocation through Strava is processed via webhook, usually immediately and in any event within 30 days.

This does not limit your right to export your original Strava data with Strava’s bulk export tool, free of charge, from your Strava account settings.

Processors and third parties

We rely on these subprocessors to run the service. On request we will provide this list to Strava, including each processor’s name, role, and location:

  • Strava, Inc. / Strava Ireland Limited — authentication and activity API (United States / Ireland)
  • Supabase — database and hosting (EU, currently Frankfurt)
  • OpenStreetMap Nominatim — reverse geocoding of a start coordinate to a city (community-operated; we send only a coordinate, not your name)

Those providers process data only to run the service. We do not sell or license Strava data to advertisers, data brokers, or AI providers. When you connect, we send OAuth and webhook identifiers to Strava so the integration can work. Strava treats that under its own privacy policy.

Strava API usage data

Strava may monitor and collect usage data about our access to the Strava API and may use that usage data for any business purpose, including providing enhancements to the Strava API or platform, developer or user support, and ensuring compliance with Strava’s API terms.

International transfers

If personal data moves from the EEA, United Kingdom, or Switzerland to a country without an adequacy decision, that transfer is intended to be covered by the European Commission Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, or an analogous mechanism, as incorporated by the Strava API Policy.

Cookies and sessions

We use an essential session cookie to keep you signed in. We do not use third-party advertising cookies.

Retention

We keep your account and imported public-run summaries while your account remains on Runopolis. A short-lived geocode cache (no more than seven days) may store rounded location buckets used only to assign a city. If you revoke access or ask us to delete your data, we delete the Strava-derived personal data we hold about you.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, and to withdraw consent. Use Delete my data, revoke access in Strava, or email us. If we receive a request that should go to Strava, we will point you to Strava.

Children

Runopolis is not directed at children under 16. If you believe a child has provided personal data, contact us so we can delete it.

Security and breaches

We use access-controlled hosting, encrypted transport, and service-role database access to protect stored tokens and activity summaries. If we discover a security breach involving Strava data, we will notify Strava in writing at [email protected] as soon as possible and no later than 24 hours after discovery.

Changes

We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.