Privacy
Last updated 17 July 2026
Who controls your data
[Controller legal entity and registered address to be supplied by Škoda legal.] Contact for privacy questions: [privacy contact address].
Information from Strava
When you connect Strava, the service receives your Strava athlete ID, name and profile picture. It can read your activity data, including activities set to Only You, because the app requests activity:read_all access. The activity information used by the app includes identifiers, activity name, start time, duration, distance, sport type, route data and whether photos are available.
Information you provide
We ask for your email address to complete registration. To enter the challenge, you choose a Strava activity and either use an available Strava photo or upload an image from your device. The image file and its association with the selected activity are stored by the service.
Photo and location data
An uploaded image may contain GPS and other metadata added by your device. The service stores coordinates for map placement. If you use a Strava photo, location information may come from the photo or its associated activity. Do not submit a photo from a location you do not want to share, such as your home.
What other participants can see
The photo layer is available to signed in, registered participants. Once an entry is approved, they can see the image, its map location, county, activity name, contributor name and upload date. When an activity identifier is available, the lightbox also provides a link to explore the route on Strava. Your email address is not displayed on the map.
Moderation
Every entry is placed in a moderation queue. Administrators can approve or reject it. Only approved entries with usable coordinates appear on the map.
Your Strava connection
Strava handles authorisation, so we never see or store your Strava password. The backend stores Strava access and refresh tokens so it can retrieve activity data. You can revoke the app's access from your Strava settings. Signing out of this site clears the local session but does not currently revoke access at Strava.
Essential cookies
The site uses essential cookies for the signed in session, basic athlete display information and short lived security state during Strava authorisation. The normal session cookies can remain for up to 30 days. The current app does not use these cookies for advertising or cross site tracking.
Why we use your data
We use the information described above to authenticate participants, complete registration, show eligible Strava activities, accept competition entries, moderate photos and display approved entries on the challenge map. [Lawful basis for each purpose to be supplied by Škoda legal.]
Service providers and transfers
Strava supplies the connected account and activity data. The application backend and image hosting infrastructure process account and photo data on behalf of the controller. [Named processors, hosting locations, international transfers and safeguards to be supplied by Škoda legal.]
How long we keep it
[Retention periods or the criteria used for account data, Strava tokens, activities, uploaded and rejected photos, moderation records and server logs to be supplied by Škoda legal.]
Your rights
[UK GDPR rights applicable to each lawful basis, including how to request access, correction, deletion, restriction, objection or portability, how to withdraw consent where relevant, and how to complain to the ICO, to be supplied by Škoda legal.]