Privacy Policy
Last updated: 2026-07-07
Your privacy matters. Below, in plain language, we describe what data we collect, why, and what you can do about it.
1. Data controller
The data controller is CLICKING4YOU Marek Waluś, registered office: ul. Wincentego Witosa 64, 43-300 Bielsko-Biała, Poland, VAT ID (NIP): PL5472091113, a sole proprietorship registered in Poland. Contact: marek@pickade.cc.
2. What data we collect
- Email account: your email (required for sign-in) and password (stored as a bcrypt cryptographic hash — we never see your plaintext password).
- Profile: username, optional first name, last name, country, city, nationality, "show real name" toggle.
- Sign-in via Google (optional): if you sign in with Google we receive your Google account ID (
sub), email, email-verified flag, name, given name, family name, profile picture URL, and locale. We do not request or receive any other Google data (no Drive, Calendar, Contacts, etc.). - Sign-in via Facebook (optional): if you sign in with Facebook we receive your Facebook user ID, email and public profile (name, profile picture URL). We do not request or receive any other Meta data (no friends, posts, page admin rights, etc.).
- Sign-in via Strava (optional): if you connect Strava we receive your Strava ID, first name, last name and avatar. We do not fetch your activities, heart rate, segments or any other Strava data.
- OAuth tokens: when you sign in with or connect Google, Facebook or Strava, those services issue us access (and sometimes refresh) tokens. We store them encrypted at rest (one record per provider) so we can fetch your profile and avatar at sign-in and, where a feature you use needs it, act on your behalf at that provider; the token is refreshed automatically when it expires. We never share these tokens with third parties. They are deleted when you disconnect the provider or delete your account (see sections 5 and 6).
- Your picks: the votes you cast (which rider on which stage, when).
- Invitations from an ad (if applicable): if you left us your email address in the contact form of our Facebook ad, we receive that address and — where you provided them — your first and last name. We use them to pre-create a dormant account and email you a one-time activation link. If you don't use it within 14 days, the account is deleted automatically (see section 5). This is data you handed to us — we fetch nothing from Facebook beyond what you typed into the form yourself.
- Server logs: IP address, user agent, request path and timestamp — collected automatically for security, abuse prevention and diagnostics.
- Usage analytics: aggregate, privacy-friendly pageview statistics collected via our own self-hosted GoatCounter — the path you visit, the referring page, and coarse technical details (browser, operating system, screen size, country) derived from your request as it arrives. GoatCounter sets no cookies, stores no IP addresses, does not track you across sites and does not build any profile of you. It runs only on the production site, on our own infrastructure in the EU.
- Cookies and local storage: the strictly functional entries (login session, OAuth state for Google / Facebook / Strava) that keep sign-in working. The full list is in the table below. Separately, and only if you accept it in our cookie banner, we load the Meta (Facebook) Pixel, which sets marketing cookies and shares usage data with Meta to measure how our ads perform (see sections 7 and 8). Our own usage analytics (above) is cookieless and is unaffected by that choice.
The complete list of cookies and browser storage we use:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
pickade_strava_state | cookie (HttpOnly) | CSRF protection during sign-in / connect with Strava | ~10 minutes |
pickade_strava_link | cookie (HttpOnly) | Identifies your account while linking Strava to an existing Pickade account | ~10 minutes |
pickade_google_state | cookie (HttpOnly) | CSRF protection during sign-in with Google | ~10 minutes |
pickade_facebook_state | cookie (HttpOnly) | CSRF protection during sign-in with Facebook | ~10 minutes |
pickade_google_link | cookie (HttpOnly) | Identifies your account while linking Google to an existing Pickade account | ~10 minutes |
pickade_facebook_link | cookie (HttpOnly) | Identifies your account while linking Facebook to an existing Pickade account | ~10 minutes |
token | localStorage | Your access token (JWT) — keeps you signed in | Until you sign out |
refreshToken | localStorage | Refresh token (JWT) — silently renews your session | Until you sign out |
key | localStorage | Identifier of the signing key currently in use | Until you sign out |
pickade-consent | localStorage | Remembers your cookie-banner choice (accept / decline the Meta Pixel) | Until you clear it |
_fbp | cookie (marketing) | Meta Pixel browser identifier — set only after you accept in the cookie banner | ~90 days |
_fbc | cookie (marketing) | Meta Pixel ad-click identifier — set only when you arrive from a Facebook ad, and only after you accept | ~90 days |
The functional entries above are strictly necessary to run sign-in flows that you yourself initiate, in the meaning of ePrivacy Directive art. 5(3), so they need no consent — and our usage analytics (GoatCounter) is cookieless and stores nothing on your device. The Meta Pixel (and its _fbp / _fbc cookies) is different: it is not strictly necessary, so it loads only after you accept it in our cookie banner, and never before. You can change your decision at any time via "Cookie settings" in the footer; declining does not limit any feature.
3. Why we collect it (legal basis)
- Service performance (GDPR art. 6(1)(b)) — we cannot run an account without an email and password (or an OAuth identity). On the same basis, as a step taken at your request before entering a contract, we create an account and send an activation link when you leave us your address in the form of our ad. Any marketing consent is separate and never pre-ticked.
- Legitimate interest (GDPR art. 6(1)(f)) — server logs for security, abuse prevention and diagnostics; error reports for keeping the service stable; aggregate, cookieless usage analytics to understand how the service is used and improve it; and promoting the service using your public username (never your first or last name) together with your in-service results and achievements, e.g. in social media posts. You can object to this use at any time by writing to marek@pickade.cc.
- Consent (GDPR art. 6(1)(a)) — when you choose to connect Google, Facebook or Strava, and, separately, when you accept the Meta (Facebook) Pixel in our cookie banner (see sections 2 and 7). You can withdraw either consent at any time — disconnect the provider in your account settings (or delete the account), and change your Meta Pixel choice via "Cookie settings" in the footer. Withdrawal takes effect going forward.
4. How we use Google, Facebook and Strava data — and what we will not do
We use information received from Google, Meta (Facebook) and Strava solely to:
- create and authenticate your Pickade account,
- display your name and avatar on your Pickade profile and on rankings.
We will never:
- sell or rent this data to anyone,
- use it for advertising or ad targeting,
- use it to train, improve or evaluate any AI / machine-learning model,
- transfer it to data brokers or analytics platforms,
- use it for any purpose not directly tied to running Pickade.
This section is about the account data we receive when you sign in with Google, Meta (Facebook) or Strava. The optional Meta Pixel described in sections 2, 7 and 8 is a separate, consent-based advertising-measurement tool — we never feed your social-login account data into it.
Pickade's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How long we keep it
- Account data (email, profile, OAuth identifiers, tokens, avatar URLs, your picks): for as long as your account is active. After you request deletion we keep the data for a 30-day grace period in case you change your mind, and then permanently erase all personally identifiable data — email, password hash, OAuth identifiers (Google, Facebook, Strava), tokens, avatar URLs, names, country, city. Your historical picks are kept anonymously in rankings (as "Anonymous player"); they cannot be tied back to you.
- Accounts from an unused invitation: if we pre-created an account from an address you left in our ad and you don't activate it within 14 days of the link being sent, the account — together with any first and last name you gave — is deleted automatically and permanently. The invitation record itself (the email address only) is kept for up to a further 90 days, then deleted too.
- Server logs (IP, user agent, request path): up to 90 days. Logs are stored separately from your account and rotate independently of account deletion — they exist for security and abuse-prevention purposes.
- Usage analytics: GoatCounter stores only aggregate, non-identifying pageview counts (no IP, no cookies), so it holds nothing that can be traced back to you; we keep these aggregate statistics for as long as they remain useful for understanding the service.
- Operational backups: encrypted database snapshots may keep your data for up to 30 days after your account is deleted before they are themselves rotated out.
6. How to delete your account
You can delete your Pickade account at any time. The detailed step-by-step procedure (including how to disconnect Google, Facebook or Strava and what gets erased) is described on our Data Deletion page. If you cannot use the in-app flow, write to marek@pickade.cc from the email tied to your account and we will process the request within 30 days.
7. Who we share data with
- AWS (Amazon Web Services EMEA SARL) — our hosting provider. Servers run in the EU (Frankfurt region). AWS acts as a "processor" under GDPR.
- AWS SES — used to send transactional and notification email (sign-up verification, password reset, and — unless you turn them off in settings — ranking-result notifications, vote reminders, trophy awards and new-follower alerts). Operated by AWS as a processor.
- Google — only if you choose to sign in with Google. Google acts as an independent controller for the data it holds about you and as a sub-processor for the OAuth-flow data it sends to us.
- Meta (Facebook) — only if you choose to sign in with Facebook. Same model as above.
- Strava — only if you connect Strava. Same model as above.
- Self-hosted analytics: our usage analytics runs on self-hosted GoatCounter on our own AWS infrastructure (EU) — no Google Analytics or other third-party analytics provider receives that pageview data.
- Meta (Facebook) Pixel — only with your consent: if you accept it in our cookie banner, Meta Platforms Ireland Ltd receives pixel data — the pages you visit on Pickade, the
_fbp/_fbccookie identifiers, your IP address and browser information — so we can measure how our ads perform. For this collection and transmission we and Meta act as joint controllers (CJEU C-40/17, Fashion ID) under Meta's Business Tools terms. We do not send Meta your email, name or other account data. Meta processes this data under its own Privacy Policy; you can manage your ad preferences at facebook.com/adpreferences. If you decline (or never accept), no pixel data is ever sent; you can withdraw at any time via "Cookie settings" in the footer. - We do not sell your data and do not share it with third parties (e.g. data brokers, ad networks) for their own marketing. We may, however, use your public username (never your first or last name) together with your results in our own Pickade promotional materials, including social media — see section 3. You can object to this at any time.
- We may share data with public authorities if required by law (e.g. court order or law-enforcement request that meets the legal bar).
8. International transfers
Your account data is hosted in the EU (AWS Frankfurt). However, when you sign in via Google or Facebook, when — if you consent — the Meta Pixel shares ad-measurement data, and when AWS SES delivers email, your data may be processed in the United States by Google LLC, Meta Platforms Inc. or Amazon. These transfers rely on the EU-U.S. Data Privacy Framework (where the recipient is certified) and on Standard Contractual Clauses (SCCs) approved by the European Commission as a fallback. You can request a copy of the relevant transfer mechanisms by writing to marek@pickade.cc.
9. Your rights
Under GDPR you have the right to:
- access your data,
- rectify inaccurate data,
- have your data erased ("right to be forgotten"),
- restrict processing,
- data portability,
- object to processing based on legitimate interest,
- withdraw consent (where consent was the basis — e.g. for Google, Facebook or Strava, or for the Meta Pixel via "Cookie settings" in the footer, which stops it and deletes its cookies going forward),
- file a complaint with your local Data Protection Authority (in Poland: uodo.gov.pl).
Most of these rights you can exercise yourself from your account settings. For anything else write to marek@pickade.cc — we reply within 30 days.
10. Minimum age
Pickade is intended for users aged 16 or older. By creating an account you confirm that you are at least 16 years old. If we learn that an account was created by a younger user we will delete it.
11. Security
Passwords are stored as bcrypt cryptographic hashes. Connections to the app go over HTTPS. Auth tokens are cryptographically signed (JWT). OAuth access and refresh tokens issued by Google, Facebook or Strava are stored encrypted at rest (AES-based Fernet encryption, with a key derived from our server secret), never in plaintext, and never shared with third parties. Our own session tokens are cryptographically signed JWTs stored in your browser's localStorage. Access to production systems is restricted and logged. Application error reports are stored on our own infrastructure (in the same EU region as the rest of the service), and our error-reporting SDK is configured to strip IP addresses, cookies and request bodies before events leave the application. No system is 100% bulletproof — if you spot something suspicious, please tell us at marek@pickade.cc with a subject starting with "[SECURITY]".
12. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the service and, where the change affects how we process your data, we will ask you to review and re-confirm your acceptance before continuing to use Pickade. The current version is always available on this page, with the date of the last update.