Privacy Policy of the climbAlot Application entered into force on 01.12.2025. The document is available both in the application and on climbalot.com, and its purpose is to transparently explain how we process user data.
1. Data Controller
The controller of personal data is the Climbing Development Support Foundation "Wspinka", ul. Wincentego Pola 66a, 33-300 Nowy Sącz, KRS: 0000331588, NIP: 7343380796.
2. Scope of Processed Data
- Registration data: first name, last name, gender, e-mail address, password.
- Optional data: sex, locality.
- External login data: information gathered when authenticating via Google, Facebook, or Apple.
- Location data: GPS used to search for objects, driving and approach.
- Activity data: saved objects, user statistics, behavior in the app.
- Payment data: donations for public benefit causes handled by external operators (e.g. Tpay, Apple Pay, Google Pay).
- Technical data: IP address, device type, operating system.
The Application accesses selected device functions (GPS, storage, camera) only to the extent necessary to implement functionality, after the user gives consent; consent can be withdrawn in device settings.
When logging in through Google, Facebook or Apple, we do not store passwords or authentication data — their processing takes place in accordance with the policies of those providers.
3. Purposes of Data Processing
- Enable use of the application and its features.
- Personalize content and account settings.
- Handle payments related to donations.
- Ensure security and prevent abuse.
- Statistical and analytical purposes.
- Fulfill legal obligations imposed on the Controller.
4. Legal Basis for Processing
- User consent (Art. 6(1)(a) GDPR).
- Necessity to perform a contract (Art. 6(1)(b) GDPR).
- Legal obligations of the Controller (Art. 6(1)(c) GDPR).
- Legally justified interests of the Controller (Art. 6(1)(f) GDPR).
5. Data Sharing
- Data is shared with entities supporting the app (payment operators, IT service providers).
- We do not transfer data to third countries, unless this results from using external provider services (e.g. Google, Apple).
- Data is not sold or shared for marketing purposes.
- Data is stored on EEA servers; in case of transfer outside the EEA we apply compliance mechanisms (standard contractual clauses).
6. Data Retention
We store data for the period of app use, and also as long as required by law or until the user withdraws consent.
7. User Rights
- Access to own data.
- Correction, deletion or restriction of processing.
- Data portability.
- Objection to processing.
- Withdrawal of consent at any time.
- Filing a complaint with the President of UODO.
A request to delete an account or data can be sent to: kontakt@climbalot.com.
8. Data Security
The Controller applies technical and organizational measures ensuring confidentiality and integrity of data, including connection encryption and system security.
9. Cookies and Tracking Technologies
The Application may use cookies and similar technologies for analytical and personalization purposes; the user can manage their use in device or browser settings.
10. Contact
For matters related to personal data protection, please contact: kontakt@climbalot.com.






