← Back to Streekly

Legal

Privacy Policy

Last updated: 25 August 2026 · Slovenská verzia

This policy explains how streekly s. r. o. collects and processes personal data across the Streekly mobile app, this website and the partner portal. We act as the data controller and process personal data in line with the EU General Data Protection Regulation (GDPR) and Slovak data-protection law.

Controller. streekly s. r. o., Karpatské námestie 7770/10A, 831 06 Bratislava – mestská časť Rača, Slovak Republic · IČO: 57 812 667 · registered in the Commercial Register, section Sro, insert no. 202888/B.
Privacy contact: support@streekly.com. We are not required to appoint a Data Protection Officer.

Venue operators should also read the Partner Privacy Policy, which covers company and venue data.

1. What we collect

  • Account data — email, username, display name, password (stored only as a hash), and two-factor settings if you enable them.
  • Profile data — avatar configuration, home city, sports you follow and your privacy preferences.
  • Check-in data — the venue, date and time of each visit, and your device's location and its accuracy at the moment you check in.
  • Progress data — streaks, XP, levels, badges, groups, friends and rewards you earn.
  • Technical data — log data, device and app version, push notification token, and security events needed to run and protect the Service.

2. Location — and your consent to it

Location is central to how Streekly works: it is how we decide whether a check-in is genuine. By granting the location permission and using check-in, you consent to us collecting and processing your device's location for that purpose.

Specifically, you agree that we may:

  • read your coordinates and their reported accuracy at the moment you check in, and compare them against the venue's location and check-in radius to decide whether the check-in is accepted;
  • read your location periodically while a check-in session is running, including while the app is in the background or the screen is locked, so we can confirm you stayed and detect when you leave and end the session;
  • process signals that indicate falsified location — such as mocked or simulated location flags, implausible accuracy, or impossible travel speed between check-ins — to detect and prevent cheating, as described in section 3;
  • retain the location recorded with a check-in as part of that visit's record, so a flagged visit can be reviewed and disputed.

We do not track your location for advertising, we do not build a movement profile of you outside check-ins and running sessions, and we do not sell location data to anyone.

Withdrawing it. You can revoke the location permission at any time in your device settings, and refuse or stop background location separately. Withdrawal takes effect from that point and does not affect processing already carried out. Without location, check-ins that depend on it cannot be verified and will not be accepted — this is a functional consequence, not a penalty.

3. How we use it & legal bases

  • To provide the Service — create your account, record visits, streaks, XP, levels, badges and rewards — performance of a contract (Art. 6(1)(b) GDPR).
  • To verify a check-in is genuine — matching your location against the venue, validating the venue QR code, and monitoring the session while it runs — performance of a contract, and your consent to location access (Art. 6(1)(a) and (b)).
  • To detect and prevent cheating and fraud — automated scoring of location accuracy, mocked-location signals and travel speed, flagging and reviewing suspicious check-ins, and enforcing the fair-play rules in our Terms — legitimate interest (Art. 6(1)(f)) in keeping streaks, rewards and leaderboards honest for everyone and protecting our partners from fraudulent reward claims.
  • To run social features — friends, groups, leaderboards and friend activity — performance of a contract, governed by the visibility choices described in section 4.
  • To send service emails — verification codes, password resets, security alerts — contract / legitimate interest.
  • To send notifications and summaries — push notifications and weekly or monthly recaps — based on your preference, adjustable in Settings.
  • To keep the Service secure — two-factor authentication, rate limiting, audit logging, abuse prevention — legitimate interest.
  • To meet legal obligations — accounting, tax and responding to lawful requests — legal obligation (Art. 6(1)(c)).

Where we rely on legitimate interest, we have weighed that interest against your rights and concluded it does not override them. You can object at any time — see section 9.

Automated decision-making. Our anti-fraud checks score check-ins automatically and may flag one so it does not immediately count towards your streak or rewards. Flagged check-ins are available for human review, and you can dispute one from the Disputed check-ins screen in the app. We do not use your data for profiling or automated decisions producing legal effects beyond this.

4. What other people can see — and what you agree to

Streekly is a social product: friends, groups and leaderboards only work if some of your activity is visible to other people. By using these features you agree that the following may be shown to others.

  • Your friends may see that you are currently checked in and at which venue, your recent check-in activity, your streaks, XP, level, badges and shared group progress. Friend activity notifications may tell your friends when you check in.
  • Other users may see your display name, username, avatar, level and streak — for example on leaderboards and in group standings, subject to your settings.
  • Groups you join show your contribution and progress to the other members of that group.
  • Venues you visit see that you visited, your visit statistics and customer tier at that venue, and — when you claim a reward — that you earned and redeemed it. Venue staff see what is needed to hand a reward over.

Your control. You choose what to share in Settings → Privacy, you choose who your friends are and can remove them at any time, and you can leave a group or delete your account. Withdrawing visibility applies going forward; it does not retract what people have already seen. Adding someone as a friend is what makes your check-in location visible to them, so only add people you are comfortable sharing that with.

5. Service providers

We use providers who process data on our behalf under appropriate agreements:

  • Hosting & database — Hetzner Online GmbH, Finland (EU).
  • Email delivery — Google Workspace.
  • Push notifications — Expo, together with Apple (APNs) and Google (FCM).
  • Map tiles — OpenFreeMap.
  • Bot protection — Cloudflare Turnstile, on the partner portal's sign-in and registration forms.

We do not sell your personal data to anyone.

6. Bot protection (Cloudflare Turnstile)

We use Cloudflare Turnstile to tell real people apart from automated sign-up and sign-in attempts on the partner portal. It runs in invisible mode: there is normally nothing for you to click, and it does not use cookies to track you across sites.

To make that judgement Turnstile collects technical signals from your browser — such as your IP address, user agent, and characteristics of the browser environment. Cloudflare processes this data as described in the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy. Our legal basis is our legitimate interest in keeping the Service secure from abuse.

6b. Venues as separate controllers

When you check in at a partner venue or claim one of its rewards, that venue receives the data described in section 4. The venue decides for itself how it then uses that data within its own business (for example, its own customer records), and to that extent acts as an independent controller under its own privacy notice — we are not responsible for what it does with that data outside Streekly. If you want to exercise your rights against a venue directly, contact the venue; we will help you reach them if needed.

7. International transfers

We keep processing within the EU/EEA where we can. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. How long we keep it

  • Account, profile and progress data — for as long as your account exists.
  • Check-in and location records — for as long as your account exists, since they underpin your streaks, visit history and any reward you claim.
  • Anti-fraud signals and flagged check-in reviews — kept while your account exists and for up to 12 months after a flag, so a dispute can be reviewed and repeat abuse detected.
  • Security and audit logs — normally up to 12 months.
  • Records we must keep by law — for the retention period the relevant law requires.

When you delete your account we remove or anonymise your personal data within a reasonable period — normally within 30 days — except where we must keep certain records to meet legal obligations or to establish, exercise or defend legal claims. Data that has been aggregated or anonymised so it can no longer identify you may be kept.

9. Your rights

Under the GDPR you have the right to:

  • access the data we hold about you and receive a copy;
  • correct inaccurate or incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict processing, or object to processing based on our legitimate interests — including our anti-fraud checks;
  • data portability — receive your data in a structured, machine-readable format;
  • withdraw consent at any time, including the location consent in section 2, without affecting processing already carried out.

You can do most of this yourself: edit your profile, adjust privacy and notification settings, export your data or delete your account, all from Settings. For anything else, email support@streekly.com. We respond within one month, as the GDPR requires; we may ask you to confirm your identity first.

If you are unhappy with how we handle your data you have the right to lodge a complaint with the Slovak supervisory authority — Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava (dataprotection.gov.sk) — or with the supervisory authority where you live or work.

Providing your data. Account data is needed to create and operate your account; without it we cannot provide the Service. Location is needed to verify check-ins; without it, check-ins that depend on it cannot be accepted.

10. Security

We protect your data with encrypted transport (HTTPS), hashed passwords, encrypted two-factor secrets, access controls and audit logging. No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.

11. Younger users

Streekly is a general-audience service and we do not verify age at sign-up. If you are a parent or guardian and would like an account removed, or the data held about it deleted, email support@streekly.com and we will take care of it.

12. Cookies

See our Cookie Policy. In short: this website sets no cookies, the partner portal uses one strictly necessary sign-in cookie, and the mobile app uses none.

13. Changes

We reserve the right to update this policy at any time — for example when we add or change features, engage a new service provider, improve our security and anti-fraud measures, or to reflect changes in law or regulatory guidance. The current version always applies and is published here with its “last updated” date.

If a change is material we will notify you in the app or by email before it takes effect. Where a change requires your consent under data-protection law, we will ask for it rather than rely on notice alone.

14. Contact

For any privacy question or request, email support@streekly.com, or write to streekly s. r. o., Karpatské námestie 7770/10A, 831 06 Bratislava – mestská časť Rača, Slovak Republic (IČO: 57 812 667).

Governing language. This document is published in Slovak and English. In the event of any discrepancy between the language versions, the Slovak version prevails.
© 2026 streekly s. r. o. · Terms · Cookies