Cheerlify
← Back to home

Privacy Policy

Last updated: 14 September 2026

This policy explains what personal data Cheerlify collects, why, on what legal basis, who it is shared with, and the rights you have over it. We aim to collect as little as the service needs.

1. Who we are (the controller)

The controller of the personal data described here is Machan Félix egyéni vállalkozó, e-mail: [email protected]. Cheerlify is the brand name of this service, operated from Hungary.

We have not appointed a data protection officer (not required at our size); for any privacy question or request write to the e-mail above.

2. What we collect

Runner account data: your e-mail address, display name, a hashed password (never the password itself) — or, with Sign in with Apple / Google, the identifier and e-mail those providers give us — plus any profile details, avatar and race settings you add, and the version of these terms you accepted and when.

Race data: the GPX routes you upload and, while a race is active, location updates (GPS coordinates and timestamps) used to show your progress, pace and ETA, and the derived recap.

Follower data: the display name a follower types when joining, the cheers they record (voice or video — this is a recording of their voice and, for video, their face), chat messages, claps, and — only if they choose to share it — a one-off location pin. Followers have no account; we do not ask for their name or e-mail.

Payment data: purchases are made through Apple App Store or Google Play in-app purchase. We receive a signed confirmation with the product, price band, currency and a store transaction id. We never receive or store card details.

Technical data: the IP address and basic request details of failed requests (for security and debugging), push-notification tokens if you turn notifications on, and the crash/error reports described under Sentry below (with personal data stripped).

3. Why we use it and our legal basis

To provide the service you ask for — creating and running races, live tracking, delivering cheers, recaps and notifications you enable (GDPR Art. 6(1)(b), performance of a contract; for followers, our legitimate interest in delivering the cheer they chose to send, Art. 6(1)(f)).

To take payment for credits and upgrades and to keep the accounting records the law requires (Art. 6(1)(b) and 6(1)(c)).

To keep the service working, secure and free of abuse — rate limiting, error logs, moderation (Art. 6(1)(f), legitimate interests).

To send you the transactional e-mails the service needs (verification code, password reset, invites). We do not send marketing e-mail unless you explicitly signed up for launch news, which you can leave with one click.

4. Who we share it with (processors and recipients)

We use these service providers, who process data only on our instructions:

Cloudflare, Inc. — CDN, DNS, TLS, DDoS protection, the tunnel in front of the server (all traffic passes through it) (EU / USA (EU-US Data Privacy Framework + SCCs)).

Resend, Inc. — transactional e-mail (verification codes, password reset, invites) (EU (eu-west-1) / USA).

Functional Software, Inc. (Sentry) — error monitoring — personal-data sending is switched off (no IP, no headers, no user data) (EU / USA).

Apple Inc. / Apple Distribution International Ltd. — App Store, in-app purchase, Sign in with Apple, push notifications (APNs) (EU (Ireland) / USA).

Google Ireland Ltd. / Google LLC — Google Play, in-app purchase, Google Sign-In, push notifications (FCM, Android) (EU (Ireland) / USA).

OpenFreeMap (Zsolt Ero, Hungary) — OpenStreetMap data — map tiles — your browser / the app fetches the map directly from them (IP address) (EU).

Followers who hold the race link (and, for a private race, the access code) can see the runner's live position, name, avatar and the cheer timeline for that race. The runner sees who sent each cheer (the display name). Nothing is public: there is no search, directory or public profile.

We do not sell personal data and do not use advertising trackers. We disclose data to authorities only where the law obliges us to.

5. International transfers

Our servers are in Hungary. Some providers above (Cloudflare, Sentry, Apple, Google, Resend) may process data in the United States; those transfers rely on the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.

6. Location data

Location is collected only while a race is active and the runner is sharing it (the app asks for background location permission so tracking continues with the screen locked), and only for that race. It is shown to the race's followers and kept as part of the race recap. A follower's location pin is optional and can be removed by the follower at any time.

7. Retention

Account data is kept while your account exists. Race data, cheers, chat and recaps are kept while the runner's account exists so you and your followers can revisit them; a race the runner deletes is removed with its cheers and media.

Anonymous (no-account) races and their cheers are removed by our periodic cleanup no later than 12 months after the race.

Purchase records are kept for as long as Hungarian accounting and tax law requires (currently 8 years); these contain the transaction, not your race data.

Failed-request logs are kept for up to 90 days. Push tokens are removed when you turn notifications off or the store reports them invalid.

8. Your rights

Under the GDPR you can request access to, correction or deletion of your data, restriction of or objection to processing, and portability, and withdraw consent where we rely on it. Runners can delete their account in the app (Profile → Account) or via cheerlify.com/delete-account; followers can ask us to delete a cheer or message by e-mail.

To exercise any right write to [email protected]. We answer within one month. You can also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa u. 9–11., naih.hu) or with your local supervisory authority, and you may seek a judicial remedy.

9. Cookies and local storage

The website sets no tracking or advertising cookies, so it shows no cookie banner. Your browser's local storage keeps your language, the races you have joined and your sign-in token (runners); the admin interface and the built-in admin use a session cookie that is strictly necessary. Fonts and scripts are served from our own domain.

10. Security

Traffic is encrypted in transit (TLS via Cloudflare), passwords are stored hashed, uploaded media is stored under unguessable names, access is rate-limited, and the origin server is reachable only through an authenticated tunnel. No system is perfectly secure; if a breach affects your data we will notify the authority and, where required, you, within the statutory deadlines.

11. Children and changes

Cheerlify is not directed at children under 16 and we do not knowingly create accounts for them.

We may update this policy; the date above shows the current version, and we will give reasonable notice of material changes (in the app and on this page).