RestOrTrain

Privacy Policy for RestOrTrain

Last updated: July 17, 2025

1. Introduction

Welcome to RestOrTrain. We are committed to protecting your privacy. This Privacy Policy explains how RestOrTrain ("we," "our," or "us") collects, uses, and protects your information when you use our service.

RestOrTrain is the data controller responsible for your information under the General Data Protection Regulation (GDPR).

2. Information We Collect

We collect the following types of information to provide and improve our service:

Account Information:

  • Username and password to secure your account.
  • Email address for communication and account recovery.
  • Manually provided profile information, such as weight and gender, for analysis accuracy.

Health and Activity Data:

  • Cycling activity files (e.g., .fit files) you upload.
  • Data extracted from these files, including power, heart rate, speed, and GPS coordinates.
  • Processed data and performance metrics derived from your activities.

Technical Information:

  • Log data, such as your IP address, browser type, and access times, for security and service functionality.
  • Information on how you interact with our features to help us improve the application.

3. How We Use Your Information

Your data is used exclusively to:

  • Provide, operate, and maintain our service.
  • Analyze your performance data to generate personalized insights and training recommendations.
  • Secure your account and protect our service from fraud and misuse.
  • Communicate with you regarding your account or service updates.
  • Improve our existing features and develop new ones.
  • Comply with our legal obligations.

4. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Performance of a Contract: To fulfill our service agreement with you. This includes processing your account and activity data to provide the performance analysis you signed up for.
  • Legitimate Interests: For purposes such as improving our service, ensuring security, and performing analytics, provided these interests do not override your fundamental rights and freedoms.

5. Data Sharing and Third-Party Services

We do not sell your personal information. Your personal data and activity information is private to you and is not shared with other users or made available through any social features, leaderboards, or community mechanisms. We only share data in the following limited circumstances:

  • With Your Consent: If you give us explicit permission to share your information.
  • For Legal Reasons: If required by law, court order, or governmental request.
  • Service Providers: With trusted vendors who perform services on our behalf (e.g., cloud hosting) under strict confidentiality agreements.
  • AI-Powered Analysis: To provide advanced insights, we send your cycling activity data to third-party AI services like OpenAI or Google Gemini. This data does not include personally identifiable information (PII) such as your name or email address. We process this data exclusively via enterprise APIs that contractually prohibit the third party from using your data to train their models. RestOrTrain does NOT use your data to train AI models and does NOT allow third parties to use your data for training purposes.

6. Data Security

We implement robust technical and organizational measures to protect your data, including data encryption in transit and at rest, regular security assessments, and strict access controls.

7. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, we will permanently delete your personal information and activity data from our production systems within a reasonable timeframe, unless we are required by law to retain it for a longer period.

8. Your Rights Under GDPR

As a user, you have the following rights regarding your personal data:

  • Right of Access: To request a copy of the information we hold about you.
  • Right to Rectification: To correct any inaccurate or incomplete data.
  • Right to Erasure ('Right to be Forgotten'): To request the deletion of your data.
  • Right to Data Portability: To receive your data in a machine-readable format and transfer it.
  • Right to Object: To object to our processing of your data based on legitimate interests.

To exercise these rights, please contact us at contact@restortrain.com. You also have the right to lodge a complaint with a supervisory authority, such as the Polish Data Protection Office, the Prezes Urzędu Ochrony Danych Osobowych (UODO).

9. Cookies and Tracking Technologies

We use only essential first-party cookies necessary for the basic functionality of our service, such as keeping you logged in. We do not use cookies for advertising, marketing, or third-party tracking.

10. Children's Privacy

Our service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have, we will take steps to delete that information promptly.

11. Changes to This Privacy Policy

We may update this policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Data Controller: RestOrTrain
Email: contact@restortrain.com
Address: Sarego 18, 31-047 Kraków, Poland