PRIVACY POLICY

Updates to Our Privacy Policy


At Runtastic, we’re continuously striving to provide you with the best possible experience – and your privacy is important to us.

The recent updates due to the new EU General Data Protection Regulation (GDPR), effective as of May 25, 2018:

  • make it easier for you to understand which data we collect and how we use it

  • give you increased control over your data

  • and provide a detailed explanation of your rights as a user.

  1. In General
    1. We, the team of runtastic GmbH, FN 334397k, Pluskaufstraße 7, 4061 Pasching, Austria (see our imprint) (“Runtastic“), email address: dataprotection@runtastic.com (“Email Address”), process your personal data when you use our apps (“Apps”, go here for a list of all Apps) or website (“Website” and, together with the Apps, “Products”). The processing of your personal data takes place in compliance with the General Data Protection Regulation (“GDPR“) and the Austrian data protection act in its current form.

    2. In this privacy policy (“Privacy Policy”) we want to provide you with information about us, the nature, scope and purposes of the data collection and use, giving you insights into the processing of your personal data.

  2. Controller
    1. Controller. The controller of data processing is Runtastic. You can contact us via email under the Email Address.

    2. Data Protection Officer. Our data protection officer can be contacted under the Email Address. Should you have any questions regarding the processing of your personal data, please do not hesitate to contact him/her.

  3. Which Data We Collect And Process
    1. In General. Runtastic processes personal data that you as a user of the Products make available to us, for example by using our Products, and that others provide to us (“Data”).

    2. Data You Provide to Us.

      Registration Information

      Mandatory Information: You have to provide us with certain information in order to register with us:

      • email address or phone number;
      • first and last name;
      • gender;
      • birthdate.

      Optional Information: Certain information is optional during registration and can also be added or deleted later on by you, such as:

      • personal information: height and weight, address (street, postcode, city, country), profile picture, family status;
      • units: distance, weight, temperature;
      • reason and motivation: sports level; description; motivation for doing sports;
      • education and job: school, university; company, type of job;
      • contact information: phone number, website; Twitter, Skype.

      Health & Fitness Activity Information

      • fitness activities: e.g. start time, duration, distance, calories, elevation, heart rate, and location data;
      • nutrition logging: e.g. time, calories, meal information (name, type, macronutrients, micronutrients);
      • personal goals: e.g. yearly running goal, weight goal;
      • training plan information: e.g. start date, training plan, associated fitness activities;
      • event participation: e.g. event name, time, location;
      • routes: e.g. name, description, location data;
      • photos: including location data;
      • LIVE Tracking, see Section 5.2;
      • equipment information: e.g. shoe information (brand, model, size, color, picture).

      Friendship and Group Information

      • sent friendship requests: time, user;
      • accepted friendship requests: time, user;
      • group participation: group name, time joined.

      Payment and Subscription Information. We use payment providers (e.g. Apple, Google, Adyen, PayPal) to process payments. Although we do not store any credit card information ourselves, we store a payment ID number that is given out by the respective provider and can be allocated to a person by that payment provider, as well as duration of your subscription, price, currency, VAT (based on country info), and payment provider.

      Phone Book Contact List

      If you explicitly allow us to access your phone book, we will compare the email addresses of your contacts with email addresses from registered users of Runtastic and send you a list with friend suggestions. We do not store this information in any way.

    3. Data from Others.

      Registration via Facebook or Google

      If you register a Runtastic account via social login, we will receive the following information:

      • Facebook Inc. (1601 South California Avenue, Palo Alto, CA 94304, USA, “Facebook”): First and last name, email address, gender, birthdate, profile picture;
      • Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA, “Google”): First and last name, email address, gender, birthdate; and profile picture.

      Facebook Friend List

      We will receive information about your friends on Facebook if you explicitly allow us to access it. We will use this information to make friend suggestions in the Products, but do not store it.

      Import Fitness Activity Information from Connected Accounts

      General. We offer an automatic import of your fitness activity information from other platforms like Garmin, Nokia Health (Withings), and Fitbit. You have to explicitly agree to connect your account from those platforms to your Runtastic account beforehand in order to import such data.

      Apple HealthKit. We use Apple’s (Apple Inc., 1 Infinite Loop, Cupertino, CA 95014, USA; “Apple”) HealthKit (for more information see here ) framework, which provides a central repository for health and fitness data on iPhone and Apple Watch and – with the user’s explicit consent – lets apps communicate with the HealthKit store to access and share this data. We process the following Data, obtained through the HealthKit framework and the Apple CoreMotion processor (for more information see here ), for the purposes described below and with explicit consent by the user: steps, calories, distance, duration, and heart rate. New data attributes may be added to the HealthKit framework, which will be portrayed in the Product and which you have to consent to. Runtastic and Runtastic’s analytics service providers may analyze engagement data for research purposes designed to provide a personalized experience and motivate engagement in healthy habits. Runtastic does not use information gained through the HealthKit framework for advertising or similar services. You can always stop Runtastic from accessing your data by changing the settings of your mobile device.

      Google Fit. We use Google’s Fit SDK (for more information see here ) which is an open platform that lets users control their fitness data. We process the following Data, obtained through the Google Fit SDK, for the purposes described below and with explicit consent by the user: steps, calories, distance, duration, and heart rate. New data attributes may be added to the Google Fit framework, which will be portrayed in the Product and which you have to consent to.

      adidas

      If you explicitly agree to connect your adidas account with Runtastic, certain information may be exchanged between adidas and Runtastic. Please see the separate adidas – Runtastic Privacy Notice for more information on such data exchange (e.g. which data, for what purposes, storage period).

    4. Service Use

      Google Analytics

      This Website uses Google Analytics, a web analysis service of Google. Google Analytics uses cookies. See our Cookie Policy for more information on cookies and how to opt-out of them. We use Google Analytics to analyze and constantly improve the use of our Products. The Products use Google Analytics in conjunction with the option “_anonymizeIP()”. This means, IP addresses are processed in a shortened form in order to prevent transmission of any personal data. The basis for the processing of Data are our legitimate interests.

      Google Analytics for Mobile

      General. For Apps on iOS and Android we use Google’s Google Analytics for Mobile (for more information see here ). User data is transmitted in an anonymized form to Google. Our Apps use identification for mobile devices, including the Google Advertising ID (“GAID”) and the ID for Advertising for iOS (“IDFA”), as well as technologies similar to cookies for the use execution of the Analytics for mobile service.

      Purpose. We use Google Analytics to analyze and constantly improve the use of our Products. Through the statistics we are able to improve our services and make them more interesting for users. In those special cases in which personal data is transmitted to the USA, Google is certified via EU-US privacy shield. The basis for the processing of Data are our legitimate interests.

      Google DoubleClick for Publishers

      We use Google DoubleClick for Publishers (“DFP”) in all Products. DFP uses cookies or similar technologies to provide the user with user-relevant advertisements, improve the reports on campaign performance, and prevent users from seeing the same advertisements multiple times. Via cookie ID, Google records which advertisements have been shown in which browser and can prevent advertisements from being shown multiple times. See our Cookie Policy for more information on cookies and how to opt-out of them. According to Google, DFP cookies do not process personally identifiable information. The basis for the processing of Data are our legitimate interests.

      Adjust

      For Apps on iOS and Android we use the services of Adjust GmbH (Saarbrücker Str. 37a, 10405 Berlin, Germany, “Adjust”). This allows us to us to track and analyze which marketing channels or sources are producing the best results for directing users to download the Products and to help us understand how our users are using our app. For this purpose, Adjust processes mobile identifiers such as the IDFA, GAID or similar mobile identifiers. For more information on Adjust, see here , especially section 3. To opt out of tracking by Adjust please go here. The basis for the processing of Data are our legitimate interests.

      Runtastic Event Tracking

      When you are using our Products, we will collect certain event information (e.g. opening a Runtastic app, starting a sport activity, visiting our Website) and send them to our servers. This allows us to analyze and constantly improve the use of our Products.

      Facebook Analytics

      For Apps on iOS and Android we use Facebook Analytics (for more information see here ). This allows us to us to track and analyze which marketing channels or sources, in connection with Facebook, are producing the best results for directing users to download the Products and to help us understand how our users are using our app. For this purpose, Facebook Analytics processes mobile identifiers such as the IDFA, GAID or similar mobile identifiers. For more information on Facebook Analytics, see here. The basis for the processing of Data are our legitimate interests.

    5. Cookies and Similar Technologies.

      Cookies

      What Are Cookies. The Website uses 'cookies' – small text files that are placed on your computer, mobile device and/or stored by the browser. The basis for the processing of Data via cookies are our legitimate interests.

      Cookie Policy. For more information on the cookies we use, which, if any, personal data they collect, and how to disable them, please see our Cookie Policy here.

      Plug-Ins

      The Runtastic Products include social media plug-ins, such as (i) Facebook; (ii) Google +, 1600 Amphitheatre Parkway, Mountain View, CA 94043; (iii) Twitter, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; and (iv) WhatsApp, WhatsApp Inc., 650 Castro Street, Suite 120-219, Mountain View, CA 94041, USA.

      Such plug-ins can recognize a user’s IP address and the page visited on the Runtastic.com platform and, possibly, store cookies, so that the services offered by Runtastic work properly. Some Apps may use functions of third parties (e.g. Facebook) through the third party’s SDK (Software Development Kit), which may process general device data (e.g. device ID, etc.). Social media plug-ins and widgets are hosted either by third-party providers or directly by us. Your interactions with these plugins are subject to this Privacy Policy or the privacy policy of any third party that offers such feature. The basis for the processing of Data via plug-ins are our legitimate interests.

      RUNTASTIC IS NOT RESPONSIBLE FOR THE USE OF, OR GUIDELINES REGARDING THE USE OF, PERSONAL DATA BY THIRD-PARTY PROVIDERS.

      Users may recognize the respective plug-ins of third parties, e.g. by the respective logo or other characteristics typical for the respective social media platform on our Website. You can find an overview of Facebook plug-ins here. You can find an overview of Google+ plug-ins here. You can find an overview of Twitter plug-ins here.

      If a user interacts with the plug-ins, e.g. by clicking on the Facebook “Like” button or entering a comment, while being logged in to said user's Social Media account on Facebook, Google+, or Twitter, a user links the contents of the Runtastic Website to his/her respective social media profile. Thereby, Facebook/Google+/Twitter can associate a user's visit or use of the Products with said user's social media account. Runtastic, as the provider of the Products, does not have any knowledge of the content of the transmitted data or its usage by Facebook, Google+, or Twitter. Users can find more information on the issue of data transmission in the privacy policy of the respective social media platform:

      If users do not want to have the respective social media platform associate their visits to our Website with their social media account, users must log out from their social media account.

      Do Not Track Signals

      The Products do not recognize or respond to browser-initiated Do Not Track signals. To learn more about Do Not Track signals, you can visit https://allaboutdnt.com.

    6. Device and Location Information.

      When you visit or leave our Products, we receive

      • the URL of both the site you came from and the one you go to next, as well as date and time stamp and time zone;
      • IP address, access status/HTTP status code;
      • transmitted data volume;
      • proxy server, operating system, web browser (including language and version of the browser software) and add-ons;
      • device identifier and features; and/or
      • ISP or your mobile carrier; and/or
      • GPS information or other phone-related location data (e.g. via WiFi or Bluetooth), after your explicit opt-in.
  4. Why We Process Data (“Purposes”)
    1. Operating the Products. We process your Data to be able to provide you with a seamless user experience when using the Products.

      Providing Services. To operate the Products and provide the services, including to

      • authenticate your access to an account;
      • track and display your health and fitness activities
      • show your training progress and statistics; and

      Connect with Friends. To make it easier for you to find and connect with others. We may use the information you have shared within the Products, including GPS data, to suggest connections between you and people you may know. For example, we may associate information that we learn about you through your and your friends’ use of the Products, and information you and others provide, to suggest people you may know or may want to transact with through our Products.

      Customer Support. To investigate, respond to your requests, and resolve complaints and service issues, e.g. to contact you about a question you submitted to our customer service team.

    2. Business Needs. We process your Data to manage our business needs.

      Performance. We process Data to monitor, analyse and improve the use of our Products, as well as protect the security or integrity of the Products, and their performance and functionality. For example, we analyze user behaviour and perform research about the way you use our Products.

      Research and Development. We process Data, including public feedback, to conduct research for the further development of our Products, in order to provide you and others with a better, more intuitive and personalized experience, and drive user growth and engagement in our Products.

      Advertising. We target and measure the performance of ads to registered users and visitors directly or through DFP (see 3.4 above) using the following data, whether separately or combined:

      • gender;
      • age;
      • language;
      • activity data (sport type, distance, duration).

      Marketing General. We process Data to deliver (tailored) marketing materials about Runtastic products and online services to you.

      Email/Push Message Marketing. With your explicit consent we will send you marketing emails or push messages with information on fitness and health-related topics. We will ask you to confirm your email address before you receive any marketing emails.

      We would like to inform you that we assess your user behavior when reading the emails with the help of so-called web beacons or tracking pixels. The information created by this is then linked to the information collected in 3.6, your email address, and an individual ID. With this merged information, we can create a user profile to personalize our marketing emails / push messages. We collect data on when you read our emails, or which links you click, and combine this with your actions in the Product.

      We store and use your Data for the purpose of email marketing or marketing on the Website by Runtastic. You can revoke your consent to the marketing emails and push messages at any time, by clicking the link at the end of the email or changing your privacy settings concerning push messages. We store the tracking information as long as you are subscribed to our marketing emails.

      Retargeting. You might see marketing messages (ads) on the platforms listed below, if you give us your explicit consent to share your advertising identifier (IDFA, GAID) with those platforms. In addition, other users who have similar characteristics to you on those platforms could see marketing messages on those platforms as well (i.e. Facebook Lookalike audience). An opt-out is possible at any time in your privacy settings. It may take a few days after the opt-out until you are removed from all audiences.

      List of other platforms: Facebook, Instagram, Google, Twitter, Snapchat, MyTarget, and Pinterest.

    3. Compliance and Enforcement.

      Compliance. We process your Data to comply with our obligations and in compliance with all applicable laws and regulations.

      Enforcement. We process your Data, if we think it’s necessary for security purposes or to investigate possible fraud or other violations of our Terms & Conditions or this Privacy Policy and/or attempts to harm our members or visitors.

  5. Sharing of Personal Data
    1. General.

      We share Data with third parties

      • if this is necessary, for the Purposes,
      • due to a request from a national authority,
      • due to a court ruling,
      • if required by law,
      • if necessary to investigate and defend ourselves against any third-party claims or allegations,
      • to exercise or protect the rights and safety of Runtastic, our members, personnel, or
      • if you have (explicitly) consented beforehand.

      We attempt to notify you about legal demands for your Data when we think it is appropriate, unless prohibited by law or court order, or when the request is an emergency. We may dispute such demands when we believe that the requests are overbroad, vague or lack proper authority.

      Special categories of personal data, such as heart rate data or other health data, will never be shared with advertisers or similar agencies.

    2. Our Services.

      Profile. Your profile is fully visible to your friends on Runtastic by default. This means, as soon as you add friends in the Products, those people will be able to see your profile, including when you join groups and events. In your privacy settings you can also set your profile visibility to “Only me” or “Everybody”. Please note that your first name, last name, and profile picture are visible to everybody at all times. This is necessary to enable others to send you a friend request.

      News Feed. Our services allow viewing and sharing information, including through posts, likes, and comments. Certain actions, such as tracking an activity, starting a training plan, upgrading to Premium Membership or establishing a new friendship connection, will be automatically posted in the News Feed. By default setting, only you and your friends will be able to see such activities in their News Feed. You can modify the visibility anytime in your privacy settings.

      Leaderboard. If you track an activity, you will automatically join a weekly/monthly Leaderboard of accumulated distance, duration, or number of steps among your friends. This means, once you add friends, you will be part of the Leaderboard. You can opt out of this at any time in your privacy settings.

      LIVE Tracking. The Products include a “LIVE Tracking” feature (“LIVE Tracking”), which enables other Runtastic users to see the route and data, including heart rates, of your sports activity on certain of the Products. LIVE Tracking can only be either activated or deactivated for all other Runtastic users. LIVE Tracking is deactivated by default and can be activated by you at your own discretion. Once activated, it stays activated for new activities, unless you turn it off again. By activating the feature, you accept the responsibility for such activation at your own risk. If you do not want to give third parties access to your training route and data, then LIVE Tracking should not be activated.

      Heart Rate Monitor. Personal health information collected and stored by Runtastic, and subsequently shared by the user via Heart Rate Monitor, may not be protected under the American Health Insurance Portability and Accountability Act (HIPAA).

      HealthKit. If a registered user explicitly consents, Runtastic may share said registered user’s data obtained through the HealthKit framework with a third party for medical research.

    3. Services You May Use. Runtastic lets you connect to third-party services. For example, to enable you to connect other accounts to your Runtastic profile or for sharing your activities with friends.

      Health and Fitness Services. Runtastic transfers your information to other health and fitness services, such as Apple HealthKit, Google Fit or MyFitnessPal, only after you explicitly consent to the transfer when you connect to such services.

      Social Networks and Messenger Services. You can decide to share finished activities via Facebook, Twitter, WhatsApp, Telegram or any other messenger service you may use on your mobile device. Please note that we do not have any influence on or knowledge of the scope and the further use of the Data by the respective messaging service, and cannot take any responsibility for the use of your Data by the respective messaging provider. Please see the messaging service’s respective privacy policies for details.

    4. Service Providers and Other Third Party Services.

      Service Providers. We share your information to others, who help us provide and improve our Products (e.g. maintenance, analysis, audit, payments, fraud detection, marketing and development). Service providers will have access to your information as reasonably necessary to perform these tasks on our behalf, and are obligated not to disclose or use it for other purposes. We use processors such as Adjust, Google, Facebook, Amazon Web Services, Inc., Emarsys eMarketing Systems AG, Pushwoosh, Inc., NewRelic, Inc., Apptimize, Inc. or Zendesk, Inc.

      Third-Party Services.

      adidas. We may – with your explicit consent – share your Data with adidas AG (Adi-Dassler-Strasse 1, 91074 Herzogenaurach, Germany; “adidas”) for the purpose of seamless user experiences between adidas and Runtastic Products. Please see the separate adidas – Runtastic Privacy Notice for more information on such data exchange with adidas (e.g. which data, what purposes, storage period).

  6. How Long We Store Data
    1. Storage Period. We store your Data as long as you are a registered user of the Products. Beyond that, we only store Data, if it is legally necessary (because of warranty, limitation or retention periods) or otherwise required.

    2. Account Deletion. If you decide to delete your account, all Data we have about you will be deleted, with the following exceptions:

      • Any details made public by you (e.g. routes, comments on other registered users’ sport activities, will be anonymized, i.e. it will be made clear that such details were provided by a deleted user).
      • Any Data required for Runtastic’s performance of contractual obligations or compliance with statutory retention obligations shall not be deleted, but minimized to the necessary extent.

      A deletion request does not affect Data, if the storage is legally necessary, for example for accounting purposes.

  7. Which Rights You Have
    1. Exercise your Rights. To exercise your rights defined in sections 7.2 to 7.8, please send a request via email to the Email Address or via mail to our postal address.

    2. Revocation of Consent. You can revoke your consent – in those cases where consent for processing is necessary – for future data processing at any time. However, this does not affect the lawfulness of Data processing based on the consent before the revocation. In certain cases, we may continue to process your information after you have withdrawn consent, if we have another legal basis to do so or if your withdrawal of consent was limited to certain processing activities.

    3. Right of Access. You have the right to obtain (i) confirmation as to whether or not your Data is being processed by us and, if so, (ii) more specific information on the Data. The more specific information concerns, among other things, processing purposes, categories of Data, potential recipients, or the duration of storage.

    4. Right to Rectification. You have the right to obtain the rectification of inaccurate Data concerning you from us. In case the Data processed by us is not correct, we will rectify these without undue delay and inform you of this rectification. Please note that (i) you can rectify much of your information in the settings and (ii) it is not technically possible for us to rectify all kinds of data in our Product.

    5. Right to Erasure. You have the right to delete Data we store about you. Should you decide to do so, please go to your account settings on the Website and delete your account there. If you are unable to do this, please contact us via the Email Address. As a safety measure, we will send you an email in order for you to confirm this deletion. We will delete your Data after this confirmation. Please note that your phone may still have Data stored on it after deletion of your account.

    6. Right to Restriction of Processing. You have the right to obtain a restriction of processing of your Data from us in the following cases:

      • you make an inquiry pursuant para. 7.4, if you so request;
      • you are of the opinion that the processing of your Data is unlawful, but are opposed to an erasure of Data;
      • you still require the Data for the establishment, exercise or defense of legal claims; or
      • you have objected to the processing pursuant para. 7.8.
    7. Right to Data Portability. You have the right to (i) receive a copy of your Data in a structured, commonly used and machine-readable format and (ii) transmit those Data to another controller without hindrance from us. You can download a copy of your Data in your account settings on the Website.

    8. Right to Object. You have the right to object at any time to the processing of Data for which our legitimate interests are the legal basis, including profiling based on those provisions. You also have the right to object to processing of Data for direct marketing purposes.

    9. Right to File a Complaint. You have the right to file a complaint with your local supervisory authority, if you think that the processing of Data infringes applicable law.

  8. Further Important Information
    1. Legal Bases. Data protection laws regulate that we are only allowed to collect and process your Data, if we have lawful bases for processing. The lawfulness of processing of Data stems from:

      • your (explicit) consent in cases where you have given (explicit) consent to the processing;
      • the necessity for the performance of your user contract, e.g. where Data is needed for a satisfactory use of the Product; or
      • legitimate interests pursued by Runtastic or a third party, e.g. our use of cookies, plug-ins, or targeted advertising.

        Our legitimate interests include protecting you, Runtastic, or others from security threats or fraud, complying with all applicable laws, managing and improving our business (e.g. customer service, reporting) including possible corporate transactions (e.g. M&A), enabling users to share their and connect via their fitness experiences, and express all fitness and health-related opinions.
    2. Security Measures. We are committed to protecting your Data and implement appropriate technical and organizational security measures to protect it against any unauthorized or unlawful processing and against any accidental loss, destruction, or damage. Those security measures are constantly revised to comply with the latest technological developments.

  9. Changes to the Privacy Policy
    1. General. Runtastic may change this Privacy Policy.

    2. Material Changes. If we make material changes to it, we will provide notice directly in our Products, or by other means (e.g. via email), to offer you the opportunity to review the changes before they become effective. Material changes could, for example, include further tracking, profiling, and analytics services. Should your consent be necessary, we will ask for it before the changes become effective. If you object to any changes, you may need to close your account as it might not function properly.

    3. Last Updated. This Privacy Policy was last modified on 21 May, 2018.