Privacy Policy
- Version:
- 1.2
- Effective from:
- 30.09.2026
- Published:
- 30.09.2026
This English translation is provided for information only. The Polish version is the binding version.
This Policy explains what personal data we process in the BEON.RUN service (https://beon.run), for what purposes, on what legal basis, to whom we disclose it, how long we keep it and what rights you have. It fulfils the information obligation under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).
§ 1. Controller
- The controller is Radosław Balcerzak, a sole trader operating under the business name balcerzak.it RADOSŁAW BALCERZAK, NIP 7631978291, REGON 300843692, address: ul. Słoneczna 11/B, 64-730 Rosko, Poland (the “Controller”, “we”).
- Contact on personal data matters: e-mail [email protected] (in Polish or English; messages are read and answered by a person) or by post to the address above. The contact details are also available on the Contact page. The Controller has not appointed a data protection officer.
§ 2. What data we process
- Account data: e-mail address, password hash (never the password itself), display name, language, Account status, dates of creation, verification and last login.
- Profile: username, bio, location text you type, profile picture (re-encoded without EXIF metadata), visibility settings.
- Activities and GPS: activity type, times, distance, pace or speed, route points (latitude and longitude, accuracy, altitude, speed, heading, time), routes and GPX files, goals, records, badges, challenges, calendar.
- Streams: video and audio from the camera and microphone (transmitted live), title, description, visibility, times, viewer counters; technical connection data (publisher sessions, tokens, presence – kept briefly).
- Recordings: video files and their metadata (only in Plans with recording).
- Chat and community: chat message content, guest name (if you write without an Account), comments, likes, follows, notifications; moderation state (blocks, mutes – temporary).
- Group activities and events: invitations, participation, choice of GPS/Stream sharing, event registrations, tracking consents; for Organizers – organizer data (name, legal form, address, contact person, optionally NIP, REGON, KRS).
- Web Push notifications: the browser endpoint address and encryption keys (needed for delivery) and the browser and OS family (e.g. “Chrome · Android”).
- Payments: Stripe customer and subscription identifiers, Plan, period, status. We do not store payment card data.
- Creator Support: data described in § 7.
- Document acceptances: Account identifier, document, version, date and time, and IP address at the time of accepting documents that require acceptance (currently the Support Recipient Terms).
- Technical data: IP address (used for abuse protection as a rate-limit key and recorded in server logs), cookies and browser storage (see the Cookie Policy), analytics data – only with consent (§ 8).
- Support requests (Help / Support): reply e-mail address, category, subject, message, language, request number, the link to your Account (if you write while logged in), identifiers you give (e.g. of an Activity, Stream or order), the page the form was sent from and – only if you leave "Technical information" ticked – browser, system, screen size, language and time. We never collect passwords, cookies or tokens.
- E-mail delivery log: recipient address, type of message, language, status and time of sending, number of attempts and the category of any error – without the message content. We do not use tracking pixels in e-mails.
§ 3. Purposes and legal bases
- Creating and maintaining the Account, providing the Service (Activities, Streams, GPS, chat, social features, groups, events, recordings, data export) – Article 6(1)(b) GDPR (performance of a contract).
- Handling paid Plans – Article 6(1)(b) GDPR; keeping billing records – Article 6(1)(c) GDPR (tax and accounting obligations).
- Handling Creator Support (Recipient status verification, payment register, statements, fee) – Article 6(1)(b) GDPR for Support Recipients; Article 6(1)(f) GDPR for Supporters (enabling the payment and displaying the message); Article 6(1)(c) GDPR for tax obligations, possibly including DAC7.
- Transactional e-mails (e.g. address verification, password reset and change, subscription status, support confirmations and replies, event decisions) – Article 6(1)(b) GDPR; optional e-mails (event reminders, news, commercial information) – only with your consent in the Account settings (Article 6(1)(a) GDPR), with an unsubscribe link in every message.
- Handling support requests – Article 6(1)(b) GDPR where the request concerns your Account or the services you use, and Article 6(1)(f) GDPR (legitimate interest: answering enquiries, documenting the handling).
- Protecting forms against bots and abuse (Cloudflare Turnstile) on the Help / Support, sign-up and password reset pages – Article 6(1)(f) GDPR (security of the Service). This is not analytics and does not depend on the statistics consent.
- Web Push notifications – Article 6(1)(b) GDPR; sent only if you enable them on a given device.
- Security, abuse prevention, content moderation, handling notices and appeals – Article 6(1)(f) GDPR (legitimate interest) and Article 6(1)(c) GDPR (obligations under Regulation (EU) 2022/2065).
- Handling complaints – Article 6(1)(c) GDPR (Consumer Rights Act) and (b).
- Proof of document acceptance, establishing, pursuing and defending claims – Article 6(1)(f) GDPR.
- Retaining payment, refund, dispute, fee, settlement and payout records after Account deletion (§ 12(3)) – Article 6(1)(c) GDPR (tax and accounting obligations) and Article 6(1)(f) GDPR (establishing, exercising and defending claims, fraud prevention).
- Visit statistics (Google Analytics 4) – Article 6(1)(a) GDPR (consent) in connection with Article 399 of the Polish Electronic Communications Law.
- Necessary cookies – Article 6(1)(b) and (f) GDPR; no consent is required for storage necessary to provide the service (Article 399(3) of the Electronic Communications Law).
Providing data when creating an Account is voluntary but necessary to create it. Sharing location, camera and microphone is voluntary – without them the related features cannot be used.
§ 4. Location (GPS)
- Location is collected only when you enable GPS before starting an Activity or Stream and allow it in the browser or in the device settings. The GPS state (active / disabled) is always visible. We do not collect location in the background or covertly.
- The current position is kept briefly in the server cache (Redis) and expires automatically (about 10 minutes after the last update); auxiliary data of an active Activity – at most 24 hours. The position is delivered to Viewers who have access to the Stream.
- The route history is stored in the database in sampled form (not every reading), after rejecting obviously wrong points. It is visible to you; to others only according to your visibility settings. After a Stream ends, Viewers see only a summary unless you share the route.
- When a route is published, the Service hides its start and end (about 200 m) by default to make it harder to identify e.g. your home address. The full geometry can be published only after explicit confirmation.
- When you are offline, unsent GPS points are kept temporarily in browser storage (IndexedDB) and deleted once sent, when the Activity ends or after 24 hours.
- We do not write coordinates to server logs. We do not send GPS data to analytics tools.
- In Organizers' events your position is visible to the event's Viewers only after you consent to tracking for that event; you can end it.
- Location monitoring may require a data protection impact assessment.
§ 5. Streams, image and recordings
- Stream video and audio are delivered through our media server to Viewers in real time. Without recording enabled they are not stored permanently.
- Recordings (in Plans with recording) are private: accessible to you and – in justified cases, logged in the audit log – to the Service administrators. They are deleted automatically after the retention period of the Plan (e.g. 180 days), earlier on your request or together with the Account. They are not backed up.
- If other people appear in your Stream, you decide on the broadcast and are responsible for the lawful use of their image (see the Terms, § 6).
§ 6. Visibility of data to others
- Public – profile, Activities, Streams, routes and events visible to everyone, including search engines; a public profile may show badges and the numbers of followers and followed accounts.
- Unlisted – visible to anyone with the link; not indexed and not shown in lists.
- Private – only for you (and participants of a private group, where applicable).
- Goals, records and statistics are private. Chat messages are seen by everyone with access to the given Stream. Your display name is shown with your messages and comments.
- A public Stream address does not reveal your e-mail address or internal identifiers.
§ 7. Payments and Creator Support
- Subscriptions: payments are handled by Stripe under Managed Payments – a Stripe group entity – Link, LLC (United States) – is the seller of the subscription and processes payment and billing data (including card data, billing address, invoice details) as a separate controller under its own privacy policy. We receive and store only customer and subscription identifiers, the Plan, period and status.
- Support – Supporters: the payment is processed by Stripe for the Support Recipient (the seller of that payment). We store payment metadata: amount, currency, date, status (including refunds and disputes), context (Stream, Activity or profile), Stripe transaction identifiers, the signature you enter or the “anonymous” flag, the message (if you add one), whether it was hidden (by the Support Recipient or BEON.RUN) and – if you are logged in – the link to your Account. In the Service the Support Recipient sees the amount, the signature (unless you choose anonymity) and the message; as the payment is made on the Recipient's Stripe account, the Recipient may see in their Stripe dashboard the transaction data collected by Stripe under Stripe's rules. We do not receive card or BLIK data.
- Support – Support Recipients: identity verification (KYC), bank details and documents are collected and stored by Stripe – we do not receive them. In the Service we keep a settlement profile: recipient type (individual / sole trader / company), country, e-mail, Stripe connected account ID, verification status and the account capabilities and requirements reported by Stripe, as well as the declaration of being of age. We collect the full name or name, business name, address, tax residence and NIP or other tax identification number only when required by law (e.g. for invoicing the fee or DAC7 reporting) – we do not collect them at present. We do not store PESEL numbers, document numbers, bank accounts or document scans. We also keep Support settings, goals, the payment register with the fee, payouts synchronised from Stripe and monthly statements.
- We share with Stripe the data needed to create a connected account (e.g. e-mail, display name, profile address). Stripe acts towards the Support Recipient under its own agreement (Stripe Connected Account Agreement / Stripe Services Agreement).
- If the Provider turns out to be a reporting platform operator under the rules implementing Directive (EU) 2021/514 (DAC7), it may have to collect additional data from Support Recipients (e.g. date of birth, tax identification number, account number) and report it to the Head of the National Revenue Administration.
§ 8. Analytics
- We use Google Analytics 4 only after you consent in the cookie banner (the “Analytics” category) and only on selected public pages (e.g. home, pricing, feature pages, registration, login, stream and event lists). Analytics never runs in the logged-in app or on Stream, profile or route pages.
- We use Google Consent Mode v2 in basic mode: the Google script is loaded only after consent. We do not send Google your e-mail address, username, GPS data, identifiers or URL parameters. Google signals and ad personalisation are disabled.
- You can withdraw consent at any time (“Cookie settings” in the footer). Withdrawal does not affect the lawfulness of processing before it.
§ 9. Recipients
Data may be disclosed to:
- the server infrastructure (hosting) provider – k.pl (KORBANK S.A., Poland);
- Cloudflare – DNS, proxy and traffic protection services (it sees, among other things, the IP address and request data); transfers outside the EEA – § 10;
- the e-mail provider – cyber_Folks S.A. (Poland), hosting the [email protected] mailbox and sending the Service's e-mails;
- Cloudflare – Turnstile – checking that a form is sent by a person (processes e.g. the IP address, the User-Agent header and technical browser signals); transfers outside the EEA – § 10;
- Stripe – payments (§ 7);
- Google Ireland Ltd. – Google Analytics 4, only with consent (§ 8);
- OpenStreetMap Foundation – your browser downloads map tiles directly from OpenStreetMap servers, which receive your IP address and the map area displayed;
- browser push service providers (e.g. Google Firebase Cloud Messaging, Apple Push Notification service, Mozilla, Microsoft) – only once Web Push is enabled; notification content is encrypted and contains no GPS data or e-mail address;
- other Users and Viewers – according to your visibility settings; Organizers – for events you registered for;
- public authorities – where required by law.
§ 10. Transfers outside the EEA
The Service's server is located in Poland. Some recipients (Stripe, Google, Cloudflare, push service providers) may transfer data to countries outside the European Economic Area, in particular the USA. Such transfers are based on the European Commission's implementing decision of 10 July 2023 on the adequate level of protection under the EU–US Data Privacy Framework – for certified entities – or on standard contractual clauses. The OpenStreetMap Foundation is based in the United Kingdom, which is covered by a European Commission adequacy decision under the GDPR (renewed in December 2025). You can obtain a copy of the safeguards by contacting us.
§ 11. Retention
- Account, profile, Activity, GPS route, Stream, chat and community data – until you delete the Account or the item. Your activity history is available until you delete it – currently regardless of the Plan. We will notify you in advance if plan-dependent history retention limits are introduced.
- Current GPS position – about 10 minutes; technical Stream and chat moderation data – from a few minutes to 24 hours.
- Recordings – according to the Plan (e.g. 180 days) or until deleted earlier.
- “Download my data” archive – 24 hours.
- Server logs – until overwritten by log rotation (at most 5 files of 10 MB per service); there is no fixed period in days – how long they are kept depends on the number of events.
- Support settings and goals – until the Account is deleted. Support payment, refund, dispute, platform fee, settlement, payout and statement records, document acceptance records and the Provider's accounting documents (e.g. fee invoices, if issued) – for the period required by law, in particular tax and accounting law (generally 5 years from the end of the year in which the tax liability arose), or necessary to establish, exercise or defend claims (including fraud and payment disputes) – also after the Account is deleted, then detached from the Account and linked to a pseudonymous reference (§ 12(3)). Stripe keeps its own records under its own policy.
- Support requests – for as long as needed to handle the request and then until any related claims become time-barred; complaints, content notices (DSA) and payment disputes – under the rules in this section for those matters. E-mail delivery log (no content) – for as long as needed to investigate delivery problems. The exact periods for ordinary requests and the delivery log will be stated in the next version of this Policy; until then the data is not deleted automatically.
- Complaints – for 6 years from the final closure of the complaint. Content notices and moderation decisions (including entries in the administrative action log) – currently kept without automatic deletion.
- After Account deletion the username is reserved for 365 days (we keep only the name and dates); admin log entries are anonymised; settlement records are retained as described in the Support data item; invoices and payment records issued by Stripe remain with Stripe under its own obligations.
§ 12. Account deletion and data export
- In the Account settings (Privacy and data) you can download a ZIP archive of your data and delete the Account.
- Account deletion is irreversible. We delete or anonymise, among other things, Account and profile data, Activities, routes, Streams, recordings (files are deleted and verified first), the profile picture, follows, likes, comments, notifications and push subscriptions; your chat messages in other people's Streams are anonymised (“Deleted user”); a paid subscription is cancelled and your Stripe customer record is deleted. If you are a Support Recipient, your Stripe connected account is closed (Stripe keeps its own records – including verification data, balance and transaction history – under its own policy), and your Support settings and goals are deleted.
- Not all data is deleted immediately. Payment, refund, dispute, platform fee, settlement, payout and statement records, document acceptance records and data required by tax and accounting law are retained after the Account is deleted – detached from the Account and linked to a pseudonymous reference – for the period required by law (in particular tax and accounting law) or necessary to establish, exercise or defend claims, including fraud and payment disputes (§ 11). They are deleted when that period ends.
- If you supported other Support Recipients, your signature and message are removed from public view (including TOP lists) when your Account is deleted. The payment amount remains in the Recipient's settlements and in the settlement records, without the link to your Account.
- Browser storage is cleared on the Account deletion confirmation page.
§ 13. Your rights
You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), to object to processing based on legitimate interest (Article 21) and to withdraw consent at any time. You can exercise most rights yourself in the Account settings; for anything else write to [email protected] (messages are read and answered by a person). We respond within one month (Article 12(3) GDPR).
You have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) (Article 77 GDPR).
§ 14. Automated decisions
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you (Article 22 GDPR). Only technical mechanisms run automatically, e.g. masking of profanity in chat and rejecting obviously wrong GPS points. The feed of followed people's activities is chronological, not algorithmic.
§ 15. Minors
An Account may be created only by an adult who is at least 18 years old. The Support Recipient feature is available only to adults. If we learn that an Account was created by a person who does not meet the age requirement, we may delete it.
§ 16. Security
We use, among other things, encrypted connections (HTTPS/TLS), password hashing, rate limiting, CSRF protection, HttpOnly cookies, service isolation and data minimisation in logs (no passwords, tokens or coordinates).
§ 17. Changes to this Policy
We will notify you of material changes to this Policy through the Platform and, where available, may also notify you by e-mail. Each version has a number and an effective date. The Polish version is binding.