Skip to main content

Legal

Privacy Policy

Effective date: July 22, 2026

Commitr is owned and operated by Do While Software Development Services, Panabo City, Davao del Norte, Philippines. This Privacy Policy explains how we (“we”, “us”, or “our”) collect, use, store, and protect your personal information when you use Commitr for virtual runs, including Strava sign-in, challenge pass purchases, and Commitr Points rewards. It also describes your rights under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).

1. Information We Collect

1.1 Account Information

When you register, we collect:

  • Full name — displayed to other runners on leaderboards and profiles.
  • Strava profile — display name and avatar from your connected Strava account.
  • Invite and referral data— your personal invite code and, if you joined through another member's invite link, a record of which member invited you, used to credit referral rewards. For invite-only challenges, we may also store hashed challenge passcodes and related invite codes so hosts can control who joins.

1.2 Run Data

When you connect Strava, we collect:

  • Distance (km) and date of the run.
  • Strava activity identifiers and audit metadata needed for challenge verification and run review, including activity title, start time, moving and elapsed duration, average and maximum speed, per-kilometre split summaries, elevation gain, recording device, Strava activity flags (manual entry, indoor or trainer, and Strava-flagged), and a yes/no flag indicating whether the activity includes heart-rate data.

1.3 Financial Data

To process challenge pass purchases, Commitr Points (CMP) credits, pass vouchers, hosting bonds, and CMP cash-outs, we collect:

  • PayMongo payment and checkout reference IDs linked to your account (when a cash checkout is required).
  • Pass purchase amounts and CMP ledger history (progress credits, pass discounts, vouchers where applicable, hosting bond locks and returns, and cash-outs).
  • Pending CMP credit balances tied to your verified runs and challenges (amounts that may later clear into your CMP balance as shown in the Service).
  • Pass voucher records issued to you (discount type, percentage, status, and expiry), used to apply discounts at checkout.
  • Contact email — collected and verified via a confirmation link before your first CMP cash-out, used to confirm your identity for cash-out requests.
  • Cash-out destination details — the bank or e-wallet institution, account number, and account holder name you provide when cashing out CMP, shared with PayMongo to execute the transfer, together with the amount, status, and timestamps of each request.

1.4 Strava Data

If you choose to connect your Strava account, we access and store the following data from Strava via their official API:

  • Athlete profile — your Strava display name and profile photo, used to confirm your identity in run verification.
  • Strava connection data — your Strava athlete ID, OAuth access token, refresh token, and token expiry, used to keep your Strava connection active until you revoke access.
  • Activity data — activity type, distance (metres), start date and time, activity title, moving and elapsed duration, average and maximum speed, per-kilometre split summaries (split distance, duration, and average speed), elevation gain, recording device name, Strava activity flags (manual entry, indoor or trainer, and Strava-flagged), and a yes/no flag indicating whether the activity includes heart-rate data, used solely to verify that a run occurred, counts toward the challenge target, and supports review of suspicious runs.

Because Commitr requests Strava's activity read scopes, including extended activity access, private Strava runs may be available to Commitr after you authorise the connection. We use only the activity fields listed above for run verification.

We do not access, store, or use:

  • Your GPS route or map data.
  • Heart-rate, power, or other health measurements. We store only a yes/no flag indicating whether an activity has heart-rate data, never the readings themselves.
  • Strava followers, segments, kudos, or social data.
  • Your Strava email address or payment information.

How Strava data is displayed:You see your own run data in the Service. Platform administrators may view stored audit metrics from your runs (for example pace, duration, elevation, device, and activity flags) when reviewing suspicious activity; they do not receive live Strava API responses or GPS route maps from Commitr. Other participants see Commitr's own derived records on leaderboards and challenge standings (approved km totals stored in our database), not raw Strava API data. Commitr operates as a Community Application under the Strava API Agreement and displays aggregated run progress for organisational purposes.

Data minimisation and caching:We request the Strava OAuth activity read scopes used for run verification. We do not intentionally store raw Strava API response bodies beyond the processing needed to create Commitr run records.

Prohibited uses:We do not use Strava data for artificial intelligence, machine learning, analytics, customer profiling, or any purpose other than verifying your individual run activity. We do not combine Strava data with unrelated third-party data for profiling, and we do not sell, license, or transfer raw Strava data to third parties except service providers needed to operate the Service.

Strava monitoring:Please note that Strava may independently monitor and collect certain usage data related to our use of the Strava API. That data collection is governed by Strava's own Privacy Policy and API Agreement, not this policy.

Authorization:We do not access any Strava data before you explicitly authorize our application through Strava's official OAuth flow. You may revoke Commitr's Strava access at any time from Strava's connected-app settings. When you revoke access, we delete your Strava connection and the Strava-derived details stored on your runs (activity titles, times, speeds, splits, elevation, and device information). Your kilometre totals, run dates, challenge results, and finish times already earned remain for challenge integrity and financial accountability.

If you delete activity data from your Strava account, we will stop syncing that activity and may reject the corresponding Commitr run record so it no longer counts toward challenge progress. Existing derived records may be retained where needed for challenge integrity, disputes, or financial accountability.

1.5 Usage and Technical Data

We may automatically collect standard server-side technical information such as error logs, request timestamps, and the identity of API endpoints accessed.

On our public website, we use Google Analytics 4 to understand aggregate traffic and usage (for example, pages viewed and general device or browser type). Google may set cookies or use similar technologies for this purpose. Analytics is loaded in production only and is separate from Supabase session cookies used to keep you signed in.

We also set first-party cookies needed to operate the Service: a Supabase session cookie that keeps you signed in, an invite-gate cookie that remembers a valid invite while you complete sign-up, and, if you open a member's invite link, a referral attribution cookie retained for up to 7 days so we can credit referral rewards.

1.6 Notification Data

If you enable push notifications, we store your browser push subscription endpoint, encryption key, authentication secret, and user agent so we can deliver account, run, reward, and challenge updates to your device. You can unsubscribe from push notifications from your browser or device settings.

2. How We Use Your Information

We use the information we collect to:

  • Authenticate you via Strava sign-in and maintain your session.
  • Display your name and progress to other participants in runs you join.
  • Process challenge pass purchases, Commitr Points (CMP) loyalty credits, pass vouchers, and hosting bonds.
  • Process CMP cash-out requests, including verifying your contact email and executing transfers through PayMongo.
  • Credit referral rewards when a runner you invited finishes their first challenge.
  • Apply challenge reward mechanics described in our Terms of Service, including progress-based Commitr Points (CMP) credits tied to your own verified distance and pass value, and pass discount vouchers when unlock conditions are met.
  • Verify runs using associated Strava activity data.
  • Maintain purchase, pending-credit, voucher, and CMP ledger records for accountability and dispute resolution.
  • Communicate with you about your account, purchases, runs, and rewards.
  • Detect and prevent fraud, abuse, and violations of our Terms of Service.

We do not use your data for advertising, profiling for marketing purposes, or any purpose unrelated to operating virtual runs on Commitr.

3. How We Share Your Information

We do not sell your personal information. We share data only in the following limited circumstances:

  • Within your run — your name, avatar, km progress, and challenge standings are visible to other participants in runs you have joined. Run hosts can view participant progress and run settings for runs they host. Platform administrators can additionally view pass purchase records, run verification outcomes, and stored run audit details (pace, duration, elevation, device, and activity flags) when reviewing suspicious runs, fraud, or support requests.
  • Public finisher certificates — finishing a challenge issues an e-certificate with a public verification page showing your display name, the challenge name, distance, challenge dates, and your placement among finishers. Anyone with the certificate link can view it. Certificate links use unguessable codes and only circulate when you or someone you shared them with passes them on.
  • Service providers — we use Supabase (database and authentication), Google Analytics (website usage measurement), PayMongo (payment checkout and CMP cash-out transfers), Strava (activity data via OAuth), and web push providers to operate the Service. These providers process data on our behalf under their own privacy policies and security controls.
  • Legal requirements — we may disclose information if required to do so by law, court order, or to protect the rights, property, or safety of Commitr, its users, or the public.

4. Data Storage and Security

Your data is stored on Supabase-managed infrastructure. We apply Row-Level Security (RLS) policies so that each user can only access data they are authorised to see. All data is transmitted over HTTPS.

We implement security measures consistent with GDPR Article 32 (administrative, technical, organisational, and physical safeguards) for the protection of any personal data obtained through the Strava API, in addition to our obligations under the Philippine Data Privacy Act of 2012.

While we implement reasonable measures to protect your data, no system is completely secure. You are responsible for keeping your Commitr account and connected Strava account secure.

In the event of a security breach affecting Strava data obtained via the Strava API, we will notify Strava within 24 hours of becoming aware of the incident, as required by the Strava API Agreement.

5. Data Retention

We retain your personal data for as long as your account remains active. Specifically:

  • Account data (name and connected profile data) — retained for the lifetime of your account.
  • Purchase, CMP, voucher, and cash-out records — retained for financial accountability, including pending CMP credit history where applicable.
  • Strava connection and activity data— connection tokens are retained while your Strava connection is active. Approved, rejected, or reviewed run records and their stored audit fields may be retained for challenge integrity, dispute resolution, and financial accountability. If you revoke Commitr's Strava access, we stop collecting new Strava data and delete the stored Strava connection tokens when Strava sends the deauthorization event.

When you close your account, we delete or anonymise your personal information within 30 days, except where retention is required for legal or accounting purposes.

6. Your Rights (Philippine Data Privacy Act)

Under the Philippine Data Privacy Act of 2012, you have the right to:

  • Be informed — know what personal information we hold about you and how it is processed.
  • Access — request a copy of the personal information we hold about you.
  • Rectification — request correction of inaccurate or incomplete personal information.
  • Erasure — request deletion of your personal information, subject to legal retention obligations.
  • Object — object to the processing of your personal information in certain circumstances.
  • Data portability — request your data in a structured, machine-readable format.

To exercise any of these rights, contact us at support@commitr.run. We will respond within 15 business days.

7. Children's Privacy

The Service is intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with their information, please contact us immediately and we will delete it.

8. Third-Party Services

The Service may contain links to or integrate with third-party websites or services. This Privacy Policy does not apply to those third parties. We encourage you to read the privacy policies of any third-party services you use.

Where Strava data or Strava-sourced activity information is displayed in the Service, it will be accompanied by Strava attribution in accordance with the Strava API Agreement and Strava Brand Guidelines. Your use of Strava through our Service is also subject to Strava's Terms of Service and Privacy Policy.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will make reasonable efforts to notify you within the app or through available account contact channels. Continued use of the Service after any changes constitutes your acceptance of the updated policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact our Data Privacy Officer at:

Do While Software Development Services — Data Privacy Officer

Panabo City, Davao del Norte, Philippines

support@commitr.run

You may also file a complaint with the National Privacy Commission of the Philippines at www.privacy.gov.ph.