Privacy Policy
Last updated: 14 September 2026
BOB Ultracycling: delete your account and data
1. Controller
The controller responsible for processing personal data on this website and in the BOB 600 services is:
myITsolutions GmbH
Gatower Straße 197a
D-13595 Berlin
Germany
Represented by: Sven Fröbel, Managing Director
Email: Show email address
Website: myitsolutions.de
2. General Information
We process personal data only to the extent necessary for operating the website, providing app functions, notifying users about the launch of BOB 600, managing participation, support, security and the technical improvement of the offer.
The legal bases arise in particular from Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interests).
3. Hosting and Technical Provision
Our website, app backend and database are operated on servers in Germany. We currently use hosting infrastructure from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
When the website is accessed, the server processes technically necessary data, for example IP address, date and time of access, requested URL, transferred data volume, HTTP status, browser and operating system information and referrer information, insofar as these are transmitted by the browser.
The purpose is delivery of the website, system stability and security, and error analysis. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in secure and reliable operation of the website.
4. Cookies and Device Access
The public website does not use tracking cookies for reach measurement and does not use cross-site tracking. We do not store a permanent visitor ID in the browser for website statistics and do not create advertising profiles.
If technically necessary app or admin functions later require local storage or session technology, this will be used only to the extent required for the requested function. There is no further use for advertising or profiling.
5. Cookieless Statistics
We want to understand whether BOB 600 is found and used. For this purpose, we use our own data-minimised statistics without tracking cookies and without a permanent browser-side identifier.
In particular, we record:
- page views and requested paths,
- time of access,
- page language,
- referrer, if transmitted by the browser,
- UTM parameters from campaign links,
- rough device category such as mobile or desktop,
- rough browser information,
- clicks on central elements such as app preview, leaderboard or notification.
We do not store complete IP addresses for statistics and do not create personal advertising profiles. Evaluation is aggregated in order to assess reach, technical function and interest in the offer. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in improving, measuring and developing BOB 600 according to demand.
If your browser sends a Do Not Track or Global Privacy Control signal, this client-side statistics function is not executed.
6. Notification List
If you would like to be notified when BOB 600 launches or registration opens, we process your email address and technical proof of your consent.
In particular, we store:
- email address,
- normalised email address to avoid duplicate entries,
- source of the form,
- subscription status,
- consent text,
- time of consent.
The purpose is notification about the launch, the opening of registration and directly related information about BOB 600. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future, for example by email to Show email address. After withdrawal, we delete or block your email address for this purpose, unless statutory retention obligations apply.
7. Rider Account and App Use
A rider account may be required for later use of the BOB 600 app. We process data necessary for the account, login, participation, result determination and support.
Depending on use, this may include:
- rider name, alias or username,
- email address,
- password in hashed form,
- optional profile data such as first name, last name, telephone number or address, if provided by you,
- optional emergency or assistance contact, in particular email address,
- internal rider ID or rider code,
- technical session data.
The legal basis is Art. 6(1)(b) GDPR where processing is necessary to provide the account and app functions. For voluntary additional information, Art. 6(1)(a) GDPR may apply.
8. Checkpoints, Location Data and Track Proof
BOB 600 uses QR checkpoints to document start, intermediate points and finish in a traceable way. When a checkpoint is scanned, the checkpoint, time and GPS location for this scan may be processed.
If you voluntarily activate live tracking, location pings may be processed during an active attempt and displayed in the admin area or via a live link shared by you. Live tracking is not required to visit the website.
After finishing, track proof may be required. You may normally submit one or more original activity files in FIT, TCX or GPX format with activity timestamps. In addition to route and time, such raw files may contain device, sensor or performance data. For the automated pre-check, we retain only the necessary route and time characteristics and, where available, the manufacturer and model of the recording device. Raw files are stored privately and encrypted.
Before acceptance, files are checked for malware, file type and technical usability. Track analysis may also form the basis for result verification, plausibility checks and achievements. In particular, route, times, speed, stop or movement patterns and contextual information derived from external sources, such as weather or daylight conditions, may be taken into account. Authorised personnel may retrieve a raw file for a manual review in individual cases; this retrieval is logged. Raw tracks are not transferred to OpenAI or other AI providers.
Weather context is derived locally on our servers from publicly accessible radar grids and station observations supplied by the German Meteorological Service (Deutscher Wetterdienst). Source files are retrieved without track coordinates, account data or participation data; no location data is transmitted to a weather provider.
A Strava activity link is accepted only as a manually handled support exception. We store the link and the necessary reason, but do not retrieve the Strava page automatically.
The legal basis is Art. 6(1)(b) GDPR insofar as these data are necessary for participation, classification and result verification. Voluntary live tracking is additionally based on your active decision to enable that function.
9. Support, Assistance and Emergency Contact
If you use support, assistance or route-disruption reports, we process the content you submit, time, request status, affected route, attempt, rider account and, where applicable, location data if you transmit them.
The assistance/location-send function does not replace an emergency call. In case of danger to life or limb, the official emergency numbers 112 or 110 must be used immediately. Through BOB 600, we can only try to make contact or inform a stored assistance contact.
The legal basis is Art. 6(1)(b) GDPR for support related to app use and Art. 6(1)(f) GDPR for security, abuse prevention and error handling.
If you allow notifications in the installed Android app, we register the app installation with Firebase Cloud Messaging for important route updates. For this purpose, we process a random technical device identifier, language, app version, delivery status and registration or delivery timestamps. The device identifier is stored encrypted in our system and removed when you sign out. The lock-screen message contains no location, disruption description or performance data. The legal basis is Art. 6(1)(b) GDPR for the safe performance of participation; you can also disable display at any time in Android settings.
10. Leaderboards, Results and Achievements
If you participate in BOB 600, result data may be displayed in leaderboards, DNF lists or achievement overviews. This includes in particular rider name or alias, route, season, finish/DNF status, time, rough performance data and unlocked achievements.
We recommend not using your real name as a public rider name if you do not want your name to appear in public lists. The display is based on the participation rules and the result presentation required for the challenge, Art. 6(1)(b) GDPR.
11. Start Fee and Payment Processing
A start or organisation fee may be charged for participation in BOB 600. Payment is processed through the external payment service provider Stripe: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Depending on the selected payment method and technical processing, Stripe may involve further Stripe entities, payment service providers, banks, card schemes or technical service providers.
When you start a payment, we transmit to Stripe the information required for the payment process, in particular amount, currency, payment purpose, technical payment references, an internal user or payment ID and, where applicable, email address or billing data, insofar as this is required for checkout, payment confirmation, receipts, fraud prevention, support or statutory records. We do not process full card numbers ourselves; these are processed directly by Stripe or the payment providers involved.
In our system, we store in particular payment status, amount, currency, payment purpose, internal user and payment references, Stripe references, test or live mode, timestamps, refund and dispute status as well as support and accounting notes. For individual refunds, we also store the relevant Stripe reference, amount, currency, status and associated event timestamps.
To document the conclusion of the contract, we store the versions of the participation terms and the declaration requesting early performance that were accepted during checkout. This includes document versions and checksums, the declaration text shown, the confirmed checkboxes, the time of acceptance and the associated user, payment and checkout references. These records are not used for advertising.
If you use the electronic withdrawal function, we store your name, the associated payment and attempt references, your account email address, the submission channel, the exact wording of the declaration, receipt and processing timestamps, and the status of the refund review. Contract confirmations and withdrawal receipts are documented in a protected delivery outbox with recipient address, message content, content checksum, delivery status, retry count and, where applicable, a technical message ID. These data are used exclusively for contract performance, delivery and evidence.
The processing is based on Art. 6(1)(b) GDPR insofar as it is necessary for participation, conclusion of the contract, payment processing and refunds. Art. 6(1)(c) GDPR applies to statutory documentation and retention obligations. Fraud prevention, security, traceability and support are based on Art. 6(1)(f) GDPR.
Stripe processes personal data partly as an independent controller, for example for fraud prevention, compliance with regulatory obligations, processing of payment methods and improvement of payment services. Stripe may also process data in countries outside the European Union or the European Economic Area, in particular in the United States. According to Stripe, such transfers are based on appropriate transfer mechanisms such as standard contractual clauses, the Data Privacy Framework or supplementary data protection agreements. Further information is available in Stripe's privacy policy: stripe.com/privacy.
12. Email Communication
If you contact us by email or we write to you in connection with BOB 600, we process your email address, message content and technical communication data. The purpose is handling your request or carrying out the relevant function. This also includes contract confirmations and receipts for an electronic withdrawal.
We use Hornetsecurity as mail provider for the technical provision and protection of our email communication. In particular, email addresses, message content, technical sending and receiving data as well as security and filter information may be processed. Where Hornetsecurity processes personal data on our behalf, this is done on the basis of a data processing agreement.
13. Recipients and Processors
Within myITsolutions GmbH, only persons who need access for operation, support, administration or development receive access to data. External recipients may be hosting, email, maintenance, IT or payment service providers where this is required for operation.
For Android system notifications, we use Firebase Cloud Messaging provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google receives the technical device identifier, the neutral notification content and technical delivery data. Google may involve other group companies and infrastructure outside the EU or EEA. Google describes processing and international transfers at Firebase Privacy and Security.
Data are not disclosed for advertising purposes.
14. Storage Period
We store personal data only for as long as required for the respective purposes or as long as statutory retention obligations exist.
- Notification data are stored until withdrawal or until the purpose no longer applies.
- Push device identifiers are stored until sign-out, account deletion or technical invalidation.
- Account and participation data are stored for the duration of account use and required proof periods.
- Payment, withdrawal, refund, delivery and contract evidence data are stored for processing, delivery, proof, support and the applicable statutory retention periods. Deleting an account does not prematurely remove records that must be retained.
- Support data are stored while the request is being processed and subsequently for appropriate documentation periods.
- Live-tracking data are processed only for the active function and a short technical follow-up period.
- Track drafts that have not been submitted are cleared after seven days. Submitted track evidence is kept for classification review, complaints and necessary evidence periods; raw files and derived personal data are then deleted or anonymised unless legal obligations or claims require otherwise.
- Aggregated statistical data may be stored for longer as long as they no longer relate to a person.
15. Your Rights
Under the GDPR, you have in particular the following rights:
- access to the personal data processed,
- rectification of inaccurate data,
- erasure of your data,
- restriction of processing,
- data portability,
- objection to processing based on legitimate interests,
- withdrawal of consent with effect for the future.
To exercise your rights, you can contact Show email address.
BOB Ultracycling: delete your account and data
You can request deletion of your BOB 600 account and associated personal data from myITsolutions GmbH without installing or signing in to the app.
- Email datenschutz@bob-600.de with the subject “BOB Ultracycling – Delete account”.
- Include your account email address or rider ID. Preferably send the request from your registered email address. Tell us if you no longer have access to it.
- We verify the account assignment and confirm processing. If necessary, we agree on suitable proof of account ownership with you. Do not send passwords, sign-in codes or payment details.
Alternatively, use Profile → Delete account in the app, confirming with your password and “DELETE”. Uninstalling the app alone does not delete your account.
What is removed and what is retained?
- When account deletion is executed, personal profile and sign-in data are removed or replaced with technical placeholders, sessions are revoked and live shares are ended.
- After a technical follow-up period of seven days, the daily cleanup removes associated live positions, precise scan positions, personal support content, route-report photos and track evidence. Encrypted track files are subsequently removed by a separate deletion job.
- Pseudonymised result, checkpoint and achievement records may remain for classification and abuse prevention. Pseudonymisation is not complete anonymity. Your deletion request also includes a review of whether these records are still needed.
- Payment, invoice and contract records are retained where statutory obligations or the handling of claims require this. When processing your request, we explain any remaining data, the reason and the applicable retention period.
- Existing backup copies expire no later than 90 days after their respective backup date. Deletions must be reapplied when restoring a backup.
Account deletion and contract withdrawal are separate processes. You can declare a withdrawal using our public withdrawal form (German). That form is not a prerequisite for requesting account deletion.
16. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. In particular, the Berlin Commissioner for Data Protection and Freedom of Information may be competent.
17. Changes to This Privacy Policy
We update this privacy policy when functions, technical implementation or legal requirements change. The current version is available on this website.