LEGAL / PRIVACY
Privacy Policy
Version 1.0 · Last updated: 3 October 2026 · Governed by GDPR and German law. This policy applies to the BEATME website at beatme.fit and the associated creator and public race pages.
1. Data controller
The entity responsible for processing your personal data within the meaning of Art. 4(7) GDPR is Taras Androsiuk.
Website: https://beatme.fit
A dedicated privacy email will be published on this page and in the Impressum when it is available. Until then, use the Contact page on this website.
2. Categories of personal data we process
| Category | Data | Purpose |
|---|
| Identity & account | Email address, hashed password or Google account identifiers, display name, username, optional avatar and cover photo, bio, location, public profile styling | Registration, login, athlete profile, race pages |
| Age confirmation | Checkbox status and acceptance timestamp (we do not collect your date of birth) | Confirm you are 18+ and that you accepted these terms |
| Race & season data | Event details, targets, results, prizes you set, season titles, race photos | Core Race Page service |
| Friend predictions (Calls) | Display name, predicted finish time, optional email/contact if a prize is offered | Public leaderboard and so the creator can reach a prize winner |
| Studio data | Poster projects, export files, and the race or profile data rendered onto them | Create and download share images |
| Payments | Pack purchased, Stripe Checkout session id, grant of race credits / Studio exports. Card details are handled by Stripe, not stored by BEATME | Fulfil One race, Season pack, Studio, and related entitlements |
| Device & security | Hashed IP addresses in short-lived rate-limit records, standard request logs on the host | Abuse prevention, login limits, security |
Friends who only lock a prediction do not need a BEATME account. Creators have accounts. We record a checkbox plus timestamp for Terms, Privacy, and 18+ confirmation — we do not store your date of birth.
3. Legal bases
| Purpose | Legal basis |
|---|
| Account creation and login | Art. 6(1)(b) GDPR — contract |
| Race pages, predictions, results, Studio | Art. 6(1)(b) GDPR — contract |
| Public athlete profile and race URLs you publish | Art. 6(1)(b) GDPR — contract |
| Payments and entitlements | Art. 6(1)(b) GDPR — contract |
| 18+ confirmation | Art. 6(1)(c) and Art. 6(1)(b) GDPR |
| Security, rate limits, fraud prevention | Art. 6(1)(f) and Art. 6(1)(c) GDPR |
4. Recipients
We do not sell or rent personal data. We share it only as needed to run BEATME:
| Recipient | What and why |
|---|
| Other users and visitors | Public race pages, Calls (name + time), athlete profiles, and Studio images you publish or share |
| Supabase Inc. | Authentication, database, and file storage (processor, DPA with SCCs) |
| Vercel Inc. | Website hosting, server logs, and delivery of the app |
| Stripe, Inc. / Stripe Payments Europe | Checkout for paid packs. Stripe is an independent controller for payment data |
| Google Ireland / Google LLC | If you use Continue with Google: authentication tokens and the profile data Google shares with us |
| Law enforcement / courts | Where required by law or to protect users |
5. International transfers
Supabase, Vercel, Stripe, and Google may process data in the EEA and in other countries, including the United States. Where there is no adequacy decision, we rely on Standard Contractual Clauses (Decision 2021/914) or the supplier’s equivalent GDPR Chapter V safeguards.
Supabase DPA: https://supabase.com/dpa
Stripe privacy: https://stripe.com/privacy
Google privacy: https://policies.google.com/privacy
Vercel privacy: https://vercel.com/legal/privacy-policy
6. Retention
| Data | Period |
|---|
| Account, profile, races, Calls, Studio files, entitlements ledger | Until you delete the account |
| Legal acceptance (checkbox + timestamp + version) | Until account deletion |
| Stripe session references on the ledger | Until account deletion / as needed for accounting disputes |
| Hashed rate-limit hits | Short windows (minutes to hours) then discarded |
| Host access logs | According to the host’s default retention, used for security |
After account deletion, personal data is purged from our systems within 30 days. Anonymised totals that cannot identify you may be kept.
7. Age
BEATME is for users aged 18 or older. At registration you confirm this with the same checkbox as the Terms and Privacy Policy. We store the confirmation and timestamp only.
Accounts without that confirmation, or that we reasonably believe belong to a minor, will be closed and the data deleted.
8. Security
- TLS in transit; data at rest on Supabase Postgres and Storage
- Passwords hashed by Supabase Auth — we never store plain-text passwords
- Row Level Security so clients cannot read or change another user’s private rows
- Public race and profile content is intentionally public once you publish it
- Avatars, race photos, and Studio exports live in dedicated Storage buckets
- Payment cards stay with Stripe
9. Google sign-in
If you choose Continue with Google, Google sends us a stable account identifier and, typically, your email and name. We do not receive your Google password. You can revoke access in your Google account security settings. This does not by itself delete your BEATME account — use account deletion in BEATME for that.
10. Your rights
You may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent for optional processing, under GDPR Arts. 15–21 and 7(3). We respond within one month (Art. 12(3)), with a possible two-month extension for complex requests.
You can edit most profile fields in the app and delete your account in dashboard settings. Use the Contact page until a privacy email is published.
You may lodge a complaint with Die Landesbeauftragte für Datenschutz und Informationsfreiheit Bremen, Arndtstraße 1, 27570 Bremerhaven, Germany, or another competent EU authority.
11. Cookies and tracking
BEATME uses essential cookies and similar storage to keep you signed in (Supabase session) and, for a few minutes, to remember that you accepted the legal terms before Google sign-in. We do not run advertising pixels, third-party analytics SDKs, or cross-site trackers.
12. Changes
Material changes will be posted at https://beatme.fit/privacy with a new version date. Continued use after the effective date means you acknowledge the updated policy.
13. Governing law
This policy is governed by the laws of the Federal Republic of Germany, including the GDPR as implemented by the BDSG. Disputes that cannot be settled may be brought before the courts of Bremen, Germany, to the extent permitted by law. EU consumers may also use the courts of their country of residence.