Privacy
Last updated: 3 October 2026
POPS (“More than just sport”) is a non-profit project. This page explains what personal data we process, why and on what legal basis, who we share it with, how long we keep it and what your rights are. We collect as little data as possible and do not track users.
Who is responsible for your data
The controller of your personal data is the non-profit association that runs POPS:
The association's registered name, UIC and address have not been published here yet.
We have not published an email address yet. Until we do, write to us through the notice form — it reaches the administrators and you can leave a reply address.
What we process, why and on what basis
The legal bases are those of Articles 6 and 9 of the General Data Protection Regulation (GDPR).
- Browsing the site
- The map and the pages open without an account. To limit request rates and stop abuse, the server uses your IP address in memory only and does not record it. We keep no access log of IP addresses.
- Basis: legitimate interest in keeping the site available and secure (Art. 6(1)(f)).
- Visit statistics and errors
- We use self-hosted, cookieless analytics (Umami). It records the page visited (without the parameters in its address), the referring site, the type of browser, operating system and device, the language, and an approximate country and city derived from the IP address, which is not stored. We also record the kind of some actions — for example that someone asked for directions, sent a contribution or opened a share sheet — without who did it or which facility, training, check-in or network it concerned. If an error occurs in your browser, our self-hosted GlitchTip receives the error message, the page address (which, on the map, includes the map's centre) and the browser type, with no data from your profile. We build no profiles and do not track people across sites.
- Basis: legitimate interest in knowing what is used and what is broken (Art. 6(1)(f)).
- Account and sign-in
- If you create an account: your email address (for sign-in with a one-time code), a display name, an optional city and whether you are under 18. Your date of birth, if you enter it in your profile, is used once to work out that category and is never stored. While you are signed in, we keep your browser type (user agent) with the session, but not your IP address.
- Basis: contract — the Terms of use you accept when you sign in (Art. 6(1)(b)).
- Contributions and points
- When you add or verify a facility, report its condition or upload a photo, we record the contribution with your account id in the change log, and the points in the points ledger. Facility data becomes part of the open data under the ODbL licence. Photos are published after a moderator approves them and with all metadata, including GPS, removed; a rejected or taken-down photo is deleted for good.
- Basis: contract (Art. 6(1)(b)).
- Location
- If you allow it, your browser uses your location to show the map and the nearest facilities around you; this happens in the browser itself and the coordinates are not sent to the server. When you contribute, report a problem or check in at a session, the coordinates arrive with the form; the server works out the distance to the facility and stores only that, never the coordinates themselves.
- Basis: contract and legitimate interest in protecting points and data from abuse (Art. 6(1)(b) and (f)).
- Public passport and leaderboards
- Only if you make your passport public yourself are your display name and city shown on the passport, with your badges, totals and streaks, and on the leaderboards (including “Who plays” with your number of trainings and minutes), in campaigns and in divisions. When and where you played is never published.
- Basis: consent (Art. 6(1)(a)), which you withdraw by making your passport private.
- Group sessions
- Signing up for a session, your place on the waiting list and your check-ins are stored with your account. The session organiser sees the display names of those signed up; the public page shows only how many. If you organise a session, your display name is shown on its public page.
- Basis: contract (Art. 6(1)(b)).
- Training log
- Sport, date and time, duration and, optionally, distance, elevation, facility and a note. Only you can see the log; if your passport is public, your number of trainings and minutes count towards the “Who plays” board. There are no Strava, Garmin or Apple Health connections yet, so we collect no GPS routes and no heart-rate data. If we add them, we will ask for separate explicit consent and describe here what we collect, from where and for how long.
- Basis: contract (Art. 6(1)(b)); for health data — explicit consent only (Art. 9(2)(a)).
- Emails
- We send the sign-in code, session confirmations and reminders and notices if a session is cancelled, emails about moderation decisions and — only if you subscribe — a weekly digest for your city.
- Basis: contract (Art. 6(1)(b)); for the digest — consent, which you withdraw with the unsubscribe link in every email.
- Facility problem reports
- Reports of broken equipment, missing lighting or a bad surface are anonymous — we ask for no name, email or account.
- Basis: legitimate interest in accurate facility data (Art. 6(1)(f)).
- Content notices
- The notice form records the address of the content, the kind of problem, your explanation and — only if you enter them — a name and email, so we can confirm receipt and tell you the decision. Your IP address is not recorded.
- Basis: legal obligation under Article 16 of the Digital Services Act (Regulation (EU) 2022/2065) — Art. 6(1)(c).
- Moderation and accountability
- We record which moderator took which decision and when, and for a refusal the reason, which we email to the author. When an administrator opens an account in the admin panel, that is recorded too: who, whose account and when.
- Basis: legal obligation under Article 17 of the Digital Services Act and legitimate interest in every decision and every access being checkable (Art. 6(1)(c) and (f)).
- Calendar and open-data keys
- If you create them: a personal address through which your calendar follows the sessions you signed up for, and an open-data API key, of which we keep only a fingerprint (hash) — the key itself is not stored.
- Basis: contract (Art. 6(1)(b)).
Who receives data
We do not sell data and do not use it for advertising. We share it only with the following recipients, and only as far as needed:
- Hetzner Online GmbH (Germany) — hosting. The server and the database are in a data centre in Finland (EU).
- Cloudflare, Inc. (USA) — network protection and delivery. Every visit to the site passes through Cloudflare’s network on its way to our server, so Cloudflare processes your IP address and the requests themselves (including which pages you open) to deliver the site and protect it from attacks, and keeps technical logs of this for a limited time under its own terms. It keeps copies only of the site’s design files, fonts and icons, which are the same for everyone — never of pages, photos or anything about you.
- Google (Gmail) — sending our emails. The emails, including your address and their content, pass through Google, and a copy stays in the “Sent” folder of our mailbox until we delete it. Deleting your account does not remove it automatically — write to us if you want it deleted.
- Backblaze, Inc. — storing encrypted off-server backups, only once that service is switched on.
- People at POPS: a session organiser sees the display names of those signed up; ambassadors (volunteer moderators for their municipality) see the contributions and facility reports there; administrators can use the admin panel, and every time they open an account it is recorded.
- External services you choose. The default map is served entirely from our own server, but if you pick an external map layer (CyclOSM, Thunderforest Transport, Tracestrack Topo), your browser loads tiles directly from that provider, and the “Directions” button opens Waze or Google Maps at the facility. They see your IP address, as they would if you visited their site.
- Ads and partner logos on the site receive no data about you: they are shown the same to everyone, and we count neither their views nor their clicks.
Transfers outside the EU
Your data is stored in the EU. It can leave the EU through Cloudflare, whose network every visit to the site passes through, and through our email provider, Google; both also process data in the United States under the EU-U.S. Data Privacy Framework. It can also leave the EU through the external services you choose yourself. If we switch on backups at Backblaze, we will keep them in an EU data centre.
How long we keep data
- Your account — until you delete it. You can delete it yourself from My profile: the profile, email, sessions, points, sign-ups and check-ins, training log and subscriptions go at once, and your contributions stay in the shared data anonymously, as “former user”.
- Sign-in codes — 10 minutes; then they expire and are deleted automatically.
- Sign-in sessions, with the browser type — until you sign out or 30 days after your last visit.
- The change log of facility data and the moderation decisions — with no time limit, because the history of the open data must stay traceable; once your account is deleted, those records are no longer linked to you.
- The name and email in a content notice — up to 180 days after the decision on it; the notice itself and the decision are kept as a record.
- Records of administrators opening accounts — with no time limit, so that every such access can be checked.
- Error reports in GlitchTip — up to 90 days.
- Backups — of the database for up to 14 days on the server, and of the database and uploaded photos for about 8 weeks off it, once that is switched on. A deleted account or photo disappears from them as the copies expire.
Your rights
You have the right to access your data and receive a copy, to rectification, to erasure, to restriction of processing, to data portability and to object to processing based on legitimate interest. You can withdraw consent at any time, without affecting the lawfulness of processing before that.
You can do much of this yourself from My profile: change your name and city, make your passport private, unsubscribe from the digest and delete your account.
For anything else — for example a copy of your data — write to the address under “Who is responsible for your data” or on the Contact page. We reply within one month.
You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (www.cpdp.bg).
Cookies and data in your browser
We use no analytics or advertising cookies, and the site sets no language cookie. When you sign in, your browser keeps a session cookie (up to 30 days) and a short-lived signed cookie (5 minutes) so we do not have to look the session up on every request. They are strictly necessary for signing in and are deleted when you sign out.
So that the map works offline, your browser caches the app's files and icons, an offline page and the map tiles you viewed last. They contain no data about you and you can clear them in your browser settings.
Minors
We have not set a minimum age for an account. Your date of birth, if you enter it, is used once to note whether you are under 18 and is not stored; at present that flag restricts nothing. Our age policy is under review and we will update this page when it is adopted.
Automated decisions
We take no decisions based solely on automated processing. Automated checks can only prompt moderators; every moderation decision is taken by a person.
Where facility data comes from
Facility data is based on OpenStreetMap (ODbL) and the base map on Protomaps. Community contributions are published as part of the shared open data.
Changes
When we change this page, we update the date at its top.