STANDALONE MOBILE PRIVACY POLICY

NOV27 Run Club — Privacy Policy

Privacy information under Article 13 GDPR · Version 2026.09.1 · Effective 2026-09-20

Deutsch

Verantwortlicher: NOV27 — Einzelunternehmen, Bernd Alexander Stainer

Anschrift: Goldschlagstrasse 101/9, 1150 Wien, Österreich

Datenschutzkontakt: privacy@nov27.party

Telefon: +43 681 81678933

Local-First Architecture · Zero Ad-Trackers: Trainingsdaten werden primär auf deinem Gerät verarbeitet. Die App erstellt keine Werbeprofile, enthält keine Werbe-SDKs und verkauft keine Läufe. Daten verlassen die App nur für die unten beschriebenen, notwendigen technischen Dienste oder wenn du selbst Health-Export, Backup, Foto oder Teilen auswählst. Der optionale Spotify-Player auf der Website bleibt bis zu deiner ausdrücklichen Auswahl blockiert.

VERARBEITETE DATENKATEGORIEN & ZWECKE

📍 1. Präzise Standortdaten & Höhenmeter (GPS)

Während einer aktiven Aufzeichnung greift die App im Vorder- und Hintergrund auf die GPS-Schnittstelle deines Geräts zu, um Distanz, Tempo (Pace), Höhenmeter und deine Laufstrecke zu ermitteln.

• Speicherung: Im lokalen Trainingsverlauf. Die App überträgt die Laufstrecke weder an NOV27 noch an Karten-, Firebase- oder Werbeserver.

Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Erfüllung der angeforderten Telemetriefunktion).

❤️ 2. Bluetooth Low Energy Herzfrequenz (0x180D)

Standardisierte Herzfrequenzsensoren liefern Live-Puls und Trainingszonen. Messwerte werden lokal als Teil des Trainingsverlaufs gespeichert; Name und Gerätekennung des zuletzt gewählten Sensors können für die optionale Wiederverbindung lokal gespeichert werden.

Rechtsgrundlage: Art. 6 Abs. 1 lit. a und Art. 9 Abs. 2 lit. a DSGVO. Die Verarbeitung beginnt erst nach einer gesonderten, informierten Einwilligung in der App und der anschließenden Bluetooth-Berechtigung. Du kannst die Einwilligung durch Trennen des Sensors und Entzug der Bluetooth-Berechtigung mit Wirkung für die Zukunft widerrufen.

🏥 3. Android Health Connect & Apple HealthKit (Optional)

Nach deiner ausdrücklichen Auswahl schreibt die App abgeschlossene Trainings samt GPS-Laufstrecke, Herzfrequenzwerte, Distanz, je nach Plattform Geschwindigkeit und Gesamtkalorien in den Gesundheitsspeicher des Betriebssystems. Run Club liest keine bereits vorhandenen Gesundheitsdatensätze, außer soweit ein eng begrenzter Plattformvorgang technisch erforderlich ist, um zuvor von der App geschriebene Daten zu verwalten.

Rechtsgrundlage: Art. 6 Abs. 1 lit. a und Art. 9 Abs. 2 lit. a DSGVO (Nutzerseitige Berechtigungserteilung).

Berechtigungen und dort gespeicherte Kopien verwaltest oder löschst du in Apple Health bzw. Android Health Connect. Das Löschen oder Deinstallieren von Run Club entfernt diese extern gespeicherten Kopien nicht automatisch.

Gesundheits-, Fitness-, Standort- und Herzfrequenzdaten werden niemals für Werbung oder Marketing verwendet, nicht an Werbenetzwerke weitergegeben, nicht an Datenhändler verkauft und nicht an Absturzberichte angehängt.

⚙️ 4. Optionale Profildaten & Einstellungen

Alter, Gewicht, Größe, biologisches Geschlecht, Herzfrequenzzonen, Einheiten, Sprache, Audioeinstellungen, Pläne und Schuhe werden nur lokal gespeichert, um Berechnungen und die App anzupassen. Angaben sind freiwillig; ohne sie verwendet Run Club neutrale Standardwerte oder lässt die jeweilige Berechnung aus.

Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO und, soweit freiwillige Angaben Gesundheitsinformationen erkennen lassen, Art. 9 Abs. 2 lit. a DSGVO.

📷 5. Kamera, Fotos & Story Cards (Optional)

Nur wenn du die Funktion auswählst, verarbeitet Run Club ein aufgenommenes oder ausgewähltes Foto auf dem Gerät und erstellt daraus eine Story Card. Das Ergebnis wird nur auf deine Initiative in Fotos gespeichert oder über das System-Teilen-Menü an dein gewähltes Ziel übergeben.

Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (von dir angeforderte Erstellung oder Weitergabe).

📦 6. Manuelle Backups & Trainings-Exporte (Optional)

Ein vollständiges Backup-Archiv oder ein Trainings-Export wird nur auf deine Anforderung erstellt. Danach verwaltet das von dir im Datei- oder Teilen-Dialog gewählte Ziel die Kopie. Run Club kann Kopien außerhalb der App nicht automatisch löschen.

Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (von dir angeforderter Export).

☁️ 7. Automatisches Betriebssystem-Backup (Optional)

Wenn du das automatische Geräte-Backup in den Android- oder iOS-Systemeinstellungen aktiviert hast, kann das Betriebssystem dafür vorgesehene kompakte App-Daten in dein verschlüsseltes Apple- oder Google-Geräte-Backup aufnehmen. Das Wiederherstellungsset umfasst Trainingszusammenfassungen, Profil, Pläne, Schuhe, Routinen und Einstellungen. Detaillierte GPS- und Herzfrequenz-Messreihen sowie der Zustand eines unterbrochenen aktiven Laufs bleiben außerhalb des automatischen Cloud-Backups; unter Android hält dies die Sicherung außerdem innerhalb des Plattformlimits von 25 MB pro App. Das vollständige manuelle Archiv enthält diese Daten weiterhin.

NOV27 betreibt dafür keinen eigenen Cloud-Speicher, kann dein Backup nicht einsehen und kann nicht garantieren, ob oder wann das Betriebssystem es erstellt oder wiederherstellt.

Du kannst das automatische Geräte-Backup in den Android- oder iOS-Systemeinstellungen deaktivieren und vorhandene Sicherungen in deinen Apple- oder Google-Kontoeinstellungen verwalten oder löschen. Das Löschen oder Deinstallieren der App entfernt eine dort vorhandene Sicherung nicht zwingend sofort. Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO für die über die Systemeinstellung gewählte Wiederherstellungsfunktion und Art. 9 Abs. 2 lit. a DSGVO, soweit das von dir aktivierte Plattform-Backup Trainingsinformationen enthält.

🧾 8. In-App-Tipp-Kaufdaten (Optional)

Für freiwillige einmalige Tipps verarbeitet der jeweilige Store deine Zahlungsdaten. Run Club erhält Produktkennung, Store, Transaktions- oder Kaufkennung, Kaufstatus, Preis-/Währungsmetadaten und Prüfergebnis, aber keine Karten- oder Bankdaten. Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO für die Kaufabwicklung und Art. 6 Abs. 1 lit. c DSGVO für gesetzliche Abgaben- und Aufbewahrungspflichten.

EINGEBUNDENE TECHNISCHE DIENSTE

Cloudflare (Kartenzugriff & Vektor-Karten):

Beim Kaltstart kann die App über Cloudflare eine kleine statische Datei mit den aktuellen Versionsnummern und Links der rechtlichen Dokumente abrufen. Dabei verarbeitet Cloudflare die IP-Adresse und technische Anfrage-Daten; es werden keine Konto-, Lauf-, Standort- oder Herzfrequenzdaten übertragen.

Die App tauscht außerdem ein kurzlebiges Firebase-App-Check-Token über einen Cloudflare Worker gegen eine technische Karten-Zugangskennung und lädt danach Vektorkarten über verschlüsseltes HTTPS aus Cloudflare R2. Cloudflare Workers, KV, WAF und R2 verarbeiten dabei IP-Adresse, technische Anfrage-Daten, das App-Check-Token beim Austausch und die Zugangskennung bei Kartenanfragen. Laufstrecke und Herzfrequenz werden dabei nicht übertragen.

Zweck und Rechtsgrundlage sind sichere Kartenauslieferung und Missbrauchsschutz gemäß Art. 6 Abs. 1 lit. f DSGVO. Verarbeitung kann über Cloudflares globales Edge-Netz erfolgen; Speicherdauer richtet sich nach den konfigurierten Service- und Sicherheitslogs.

Cloudflare Datenschutzerklärung

Firebase Crashlytics (optionale Absturzdiagnose):

Anbieter sind Google Ireland Limited und Google LLC. Die Übermittlung ist ausgeschaltet, bis du sie nach der Information in der App ausdrücklich aktivierst. Verarbeitet werden technische Absturzinformationen: Stacktraces, Crashlytics-, Firebase-Installations- und Sitzungskennungen, Zeitpunkt, App-Version, Gerätemodell, Betriebssystem und technischer Gerätezustand. Diese Berichte sind nicht anonym.

NOV27 hängt keine Routen, Standort- oder Herzfrequenzwerte, Trainingsnotizen, Nutzerkennungen oder benutzerdefinierten Logs an und entfernt Fehlermeldungstexte aus Dart-Berichten. Native Absturzberichte können standardmäßige Exception-Klassen und -Meldungen enthalten. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO). Google verarbeitet Crashlytics global und bewahrt Absturztraces samt zugehörigen Kennungen 90 Tage auf, bevor die Löschung beginnt.

Du kannst deine Einwilligung jederzeit unter Einstellungen → Datenschutz → „Absturzberichte teilen“ mit Wirkung für die Zukunft widerrufen. Dabei löscht die App auch noch nicht gesendete Berichte vom Gerät.

Firebase Datenschutz und Sicherheit

Firebase App Check (Schutz der Karteninfrastruktur):

Die App nutzt Firebase App Check mit Apple App Attest bzw. Google Play Integrity, um echte App- und Geräteanfragen zu bestätigen und den Kartendienst vor Missbrauch zu schützen. Dabei werden Attestierungsdaten an den jeweiligen Anbieter übermittelt und kurzlebige App-Check-Tokens erzeugt. Firebase speichert das Attestierungsmaterial nicht; die Anbieter verarbeiten es nach ihren eigenen Bedingungen.

Rechtsgrundlage ist unser berechtigtes Interesse an der Absicherung der Karteninfrastruktur (Art. 6 Abs. 1 lit. f DSGVO). Es werden dabei keine Laufstrecken oder Herzfrequenzdaten an Firebase übermittelt.

Apple-/Google-Geräte-Backup:

Wenn das automatische Geräte-Backup in deinen Android- oder iOS-Systemeinstellungen aktiv ist, kann die systemeigene Sicherung die dafür vorgesehenen kompakten Run-Club-Dateien erfassen. Apple bzw. Google betreibt den Dienst nach deinen Konto- und Geräteeinstellungen. Die Plattform kann technische Sicherungsmetadaten und die verschlüsselten App-Dateien verarbeiten; NOV27 erhält keinen Zugriff auf den Inhalt des Geräte-Backups.

Apple App Store / Google Play (In-App-Käufe):

Der jeweilige Store zeigt und verarbeitet den freiwilligen einmaligen Tipp nach seinen Zahlungs- und Datenschutzbedingungen. NOV27 erhält nur die zur Bestätigung, Betrugsvermeidung und gesetzlich erforderlichen Abrechnung nötigen Transaktionsdaten, nicht deine Zahlungsinstrumentdaten.

OPTIONALER SPOTIFY-PLAYER AUF DER RUN-CLUB-WEBSITE

Der Spotify-Player wird nicht automatisch geladen. Erst wenn du „Spotify-Player laden“ auswählst, baut dein Browser eine direkte Verbindung zu Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden auf. Ohne diesen Klick findet keine Verbindung zu Spotify statt.

Spotify erhält dabei insbesondere deine IP-Adresse, die aufgerufene URL und Referrer-Informationen sowie Browser-, Geräte-, Nutzungs- und Wiedergabedaten. Spotify und beteiligte Dritte können Cookies oder ähnliche Technologien setzen oder auslesen. Zweck ist die Wiedergabe der ausgewählten Playlist; Rechtsgrundlage ist deine Einwilligung gemäß Art. 6 Abs. 1 lit. a DSGVO und den anwendbaren ePrivacy-Regeln.

NOV27 speichert deine Auswahl nicht; nach einem Neuladen bleibt der Player wieder blockiert. Bereits von Spotify gespeicherte Daten oder Cookies verwaltest du über deine Browser- bzw. Spotify-Einstellungen. Weitere Informationen: Spotify-Datenschutzerklärung und Spotify-Cookie-Richtlinie.

SPEICHERDAUER, LÖSCHUNG & ERFORDERLICHKEIT

Lokale Trainings- und Einstellungsdaten bleiben gespeichert, bis du den jeweiligen Eintrag löschst, App-Daten zurücksetzt oder die App deinstallierst. Manuelle Exportdateien, automatische Geräte-Backups und an Apple Health oder Android Health Connect übertragene Kopien musst du am jeweiligen Speicherort separat löschen. Transaktions- und Abrechnungsdaten bleiben für die jeweils geltenden gesetzlichen Aufbewahrungsfristen gespeichert.

Crashlytics-Daten werden nach Googles aktueller Aufbewahrungsregel grundsätzlich 90 Tage gespeichert, bevor die Löschung beginnt. Cloudflare verarbeitet technische Logs nach der jeweils konfigurierten Sicherheits- und Serviceaufbewahrung.

GPS ist für die Aufzeichnung einer Laufstrecke erforderlich. Bluetooth-Herzfrequenz, Profildaten, Health-Export, Fotos, Teilen, Backups und Crashberichte sind freiwillig; wenn du sie nicht freigibst, bleibt die jeweilige Zusatzfunktion aus.

Es findet keine ausschließlich automatisierte Entscheidung mit rechtlicher oder ähnlich erheblicher Wirkung und kein Werbe-Profiling statt.

DEINE RECHTE (DSGVO)

Dir stehen nach Maßgabe der gesetzlichen Voraussetzungen die Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch zu. Eine erteilte Einwilligung kannst du jederzeit mit Wirkung für die Zukunft widerrufen. Du kannst dich bei der Österreichischen Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb.gv.at, oder einer sonst zuständigen Aufsichtsbehörde beschweren.

Google-, Apple- und Cloudflare-Dienste können Daten außerhalb des EWR verarbeiten. Dafür gelten die jeweils anwendbaren Angemessenheitsbeschlüsse, Standardvertragsklauseln und ergänzenden Schutzmaßnahmen der Anbieter. Informationen oder eine Kopie der einschlägigen Garantien kannst du über den Datenschutzkontakt anfordern.

Datenschutz-Kontakt: privacy@nov27.party

English

Controller: NOV27 — Sole Proprietorship, Bernd Alexander Stainer

Address: Goldschlagstrasse 101/9, 1150 Wien, Österreich

Privacy contact: privacy@nov27.party

Phone: +43 681 81678933

Local first. No advertising trackers. Workout data is processed primarily on your device. The app creates no advertising profile, contains no advertising SDK, and does not sell runs. Data leaves the app only for the necessary technical services described below or when you choose a Health export, backup, photo, or share action. The optional Spotify website player remains blocked until you choose to load it.

DATA, PURPOSES & LEGAL BASES

1. Precise location and elevation

During an active workout, foreground and background GPS determine route, distance, pace, and elevation. The route is stored in local workout history and is not sent to NOV27, map, Firebase, or advertising servers. Legal basis: Article 6(1)(b) GDPR for the requested workout-recording service.

2. Bluetooth heart rate

Standard Bluetooth heart-rate sensors provide live heart rate and zone guidance. Values are stored locally as part of workout history; the last selected sensor name and device identifier may be retained locally for optional reconnection.

Legal basis: Articles 6(1)(a) and 9(2)(a) GDPR. Processing begins only after separate informed consent in the app followed by the operating-system Bluetooth permission. Disconnect the sensor and revoke Bluetooth permission to withdraw consent for future processing.

3. Apple Health and Android Health Connect (optional)

After your explicit choice, the app writes completed workouts and their GPS routes, heart-rate samples, distance, platform-supported speed, and total calories to the operating system’s health store. Run Club does not read existing health-store records except where a narrowly scoped platform operation is technically required to manage data previously written by the app. Legal basis: Articles 6(1)(a) and 9(2)(a) GDPR.

Manage or delete permissions and stored copies in Apple Health or Android Health Connect. Deleting or uninstalling Run Club does not automatically remove copies stored there.

Health, fitness, location, and heart-rate data is never used for advertising or marketing, shared with advertising networks, sold to data brokers, or attached to crash reports.

4. Optional fitness profile and settings

Age, weight, height, biological sex, heart-rate zones, units, language, audio preferences, plans, and shoes are stored locally to personalise calculations and the app. These details are optional; without them, Run Club uses neutral defaults or omits the relevant calculation. Legal basis: Article 6(1)(b) GDPR and, where an optional value reveals health information, Article 9(2)(a) GDPR.

5. Camera, photos, and story cards (optional)

Only when you choose the feature, Run Club processes a captured or selected photo on the device and creates a story card. The result is saved to Photos or handed to a destination through the operating-system share sheet only at your initiative. Legal basis: Article 6(1)(b) GDPR for the creation or sharing action you requested.

6. Manual backups and workout exports (optional)

A complete backup archive or workout export is created only when you request it. The destination selected through the file or share interface then controls that copy. Run Club cannot automatically delete copies outside the app. Legal basis: Article 6(1)(b) GDPR for the requested export.

7. Automatic operating-system backup (optional)

If automatic device backup is enabled in your Android or iOS system settings, the operating system may include eligible compact app data in your encrypted Apple or Google device backup. The recovery set contains workout summaries, profile, plans, shoes, routines, and settings. Detailed GPS and heart-rate sample streams and interrupted active-run state stay outside automatic cloud backup; on Android this also keeps the backup within the platform's 25 MB per-app limit. The complete manual archive continues to include that data.

NOV27 does not operate the cloud storage, cannot inspect your backup, and cannot guarantee whether or when the operating system creates or restores it.

You can disable automatic device backup in Android or iOS system settings and manage or delete existing backups in Apple or Google account settings. Deleting or uninstalling the app does not necessarily remove a stored backup immediately. Legal basis: Article 6(1)(b) GDPR for the recovery function selected through operating-system settings and Article 9(2)(a) GDPR where the user-enabled platform backup contains workout information.

8. In-app tip purchase data (optional)

For voluntary one-time tips, the relevant store processes your payment details. Run Club receives the product identifier, store, transaction or purchase identifier, purchase status, price/currency metadata, and verification result, but no card or bank details. Legal basis: Article 6(1)(b) GDPR for purchase processing and Article 6(1)(c) GDPR for statutory tax and record-keeping obligations.

TECHNICAL SERVICES

Cloudflare — map access and vector maps

On a cold launch, the app may retrieve a small static file through Cloudflare containing the current version numbers and links for the legal documents. Cloudflare then processes the IP address and technical request data; no account, workout, location, or heart-rate data is sent.

The app also exchanges a short-lived Firebase App Check token through a Cloudflare Worker for a technical map credential, then downloads vector maps over encrypted HTTPS from Cloudflare R2. Cloudflare Workers, KV, WAF, and R2 process the IP address, technical request data, the App Check token during exchange, and the credential on map requests. No workout route or heart-rate data is sent.

Purpose and legal basis: secure map delivery and abuse prevention under Article 6(1)(f) GDPR. Processing may use Cloudflare’s global edge network; retention follows the configured service and security logs.

Cloudflare Privacy Policy

Firebase Crashlytics — optional crash diagnostics

Google Ireland Limited and Google LLC process crash stack traces; Crashlytics, Firebase installation, and session identifiers; timestamps; app version; device model, operating-system version, and technical device state. Upload remains disabled until you make an informed opt-in choice. These reports are not anonymous. NOV27 does not attach routes, location, heart rate, workout notes, user identifiers, or custom logs, and strips exception-message text from Dart reports. Native crash reports may contain standard exception classes and messages.

The legal basis is your consent under Article 6(1)(a) GDPR. Google processes Crashlytics globally and retains crash traces and associated identifiers for 90 days before deletion begins.

Withdraw consent for future uploads at any time under Settings → Privacy → “Share crash reports”. Disabling also deletes unsent reports from the device.

Firebase privacy and security

Firebase App Check — map-service protection

Firebase App Check uses Apple App Attest or Google Play Integrity to attest legitimate app and device requests and protect map infrastructure from abuse. Attestation material is sent to the relevant provider and short-lived App Check tokens are created. Firebase does not retain the attestation material; providers process it under their own terms. Legal basis: our legitimate interest in service security under Article 6(1)(f) GDPR. No route or heart-rate data is sent to Firebase for this purpose.

Apple / Google device backup

If automatic device backup is active in your Android or iOS system settings, the operating-system backup may collect the compact Run Club files designated for that purpose. Apple or Google operates the service according to your account and device settings. The platform may process technical backup metadata and encrypted app files; NOV27 has no access to the content of the device backup.

Apple App Store / Google Play — in-app purchases

The relevant store displays and processes the voluntary one-time tip under its payment and privacy terms. NOV27 receives only transaction data needed for confirmation, fraud prevention, and legally required accounting, not your payment-instrument details.

OPTIONAL SPOTIFY PLAYER ON THE RUN CLUB WEBSITE

The Spotify player does not load automatically. Only after you select “Load Spotify player” does your browser connect directly to Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden. No connection to Spotify is made before that click.

Spotify then receives data including your IP address, the requested URL and referrer information, and browser, device, usage, and playback data. Spotify and participating third parties may set or read cookies or similar technologies. The purpose is to play the selected playlist; the legal basis is your consent under Article 6(1)(a) GDPR and applicable ePrivacy rules.

NOV27 does not save your choice; after reloading the page the player is blocked again. Manage data or cookies already stored by Spotify through your browser or Spotify settings. For more information, see the Spotify Privacy Policy and Spotify Cookie Policy.

RETENTION & YOUR RIGHTS

Local workouts and settings remain until you delete the relevant item, reset app data, or uninstall the app. Delete manual export files, automatic device backups, and copies sent to Apple Health or Android Health Connect separately at their destination. Transaction and accounting records remain for the applicable statutory retention periods. Crashlytics generally retains crash data for 90 days before deletion begins; Cloudflare technical-log retention follows the configured security and service settings.

GPS is required to record a route. Bluetooth heart rate, profile details, Health export, photos, sharing, backups, and crash reports are optional; refusing them only disables the relevant optional feature. The app performs no solely automated decision with legal or similarly significant effect and no advertising profiling.

Subject to the legal conditions, you have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent for future processing. You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at, or another competent supervisory authority.

Google, Apple, and Cloudflare services may process data outside the EEA under the provider’s applicable adequacy decisions, Standard Contractual Clauses, and supplementary safeguards. Request information or a copy of the relevant safeguards through the privacy contact.

Privacy contact: privacy@nov27.party