University of Strathclyde Sport

Privacy Notice

Strath Steps — University of Strathclyde Sport

Last updated: July 2026  ·  Next review: June 2027

1. Who we are

Strath Steps is a step-tracking and leaderboard web application operated by the University of Strathclyde Sport department. The University of Strathclyde is the data controller for all personal data processed through this application. If you have questions about how your data is handled, contact us at stepcount@strath.ac.uk or the University's Information Governance Unit at dataprotection@strath.ac.uk.

2. What data we collect

  • Account information — your email address and display name
  • Step and activity data — daily step counts and logged activities you submit manually
  • Fitness device data — step counts synced from connected services (Google Health / Fitbit, Garmin, Strava) where you choose to connect them
  • Team membership — which team you belong to, if any
  • Profile preferences — whether you appear anonymously on the leaderboard, your daily step goal
  • Usage data — pages visited and timestamps, used only for aggregate analytics
  • OAuth tokens — access and refresh tokens for any connected fitness service, stored securely and never shared

3. Lawful basis for processing

We process your personal data on the following legal bases under UK GDPR:

  • Consent — account creation, step and activity logging, and connecting fitness devices. You provided explicit consent at registration and can withdraw it at any time by deleting your account.
  • Legitimate interest — displaying aggregated leaderboard totals and reporting challenge participation and completion rates. The University of Strathclyde has a legitimate interest in running staff and student wellness challenges and measuring their impact. This processing is limited to aggregate data and does not override your individual rights.

Step counts and fitness activity data may constitute health-related data under UK GDPR. Where this is the case, we rely on your explicit consent as the basis for processing this special category data.

4. Why we use your data

  • To operate your account and display your step progress
  • To show leaderboard rankings — either under your display name or anonymously
  • To track participation and progress in step challenges
  • To award badges based on cumulative step totals
  • To sync step data automatically from connected fitness devices
  • To provide aggregate analytics to university staff about overall challenge engagement
  • To identify and fix bugs and errors in the application (via Sentry error monitoring)

5. Data retention

We retain your personal data for as long as your account remains active. Your data will be automatically deleted from the database after 7 years.

When you delete your account, all personal data associated with it is permanently removed, including your profile, step logs, activity logs, team membership, connected device tokens, and badge records. Deletion is immediate and irreversible. No personal data is retained after account deletion — including no anonymised or aggregated individual records.

Aggregate, non-identifiable analytics data (such as total page view counts) may be retained beyond account deletion as it contains no personal data.

For a detailed breakdown of retention periods by data category, see our Data Retention Policy.

6. Third-party processors

We use the following third-party services to operate Strath Steps. Each acts as a data processor under our instruction:

Supabase

Database, authentication, and real-time infrastructure. All personal data at rest is stored exclusively in Supabase's EU (Ireland) infrastructure (eu-west-1). Supabase is GDPR-compliant and provides Standard Contractual Clauses for data transfers.

Vercel

Application hosting and global edge network for performance. Vercel hosts the application layer only — it processes request data transiently to serve pages but does not store personal data at rest. The database remains exclusively in Supabase's EU infrastructure.

Sentry

Error monitoring and bug tracking. Sentry may capture session context and anonymised error data (stack traces, browser type, page URL at the time of an error) to help us identify and fix bugs. No intentional personal data is sent to Sentry. Session Replay is disabled. Sentry is SOC 2 Type II certified and GDPR-compliant.

Google Health API (Fitbit / Pixel Watch)

If you choose to connect a Fitbit device or Google Pixel Watch, step data is retrieved from Google's Health API with your explicit consent. OAuth tokens are stored securely and only used to sync your step data.

Strava (pending)

If you choose to connect Strava, activity data will be retrieved with your explicit consent. This integration is not yet available.

Garmin (pending)

If you choose to connect a Garmin device, step data will be retrieved with your explicit consent. This integration is not yet available.

7. Data storage and security

All personal data is stored in Supabase's EU (Ireland) infrastructure. Data in transit is encrypted using TLS. Data at rest is encrypted using AES-256. Access to your data is enforced at the database level using Row Level Security — no user can access another user's personal data.

OAuth tokens for connected fitness services are stored in a secured, access-controlled table and are never exposed to the browser or to other users.

8. Your rights

Under UK GDPR you have the following rights regarding your personal data:

  • Right of access — you can view your data at any time within the app
  • Right to rectification — you can update your display name and profile settings at any time
  • Right to erasure — you can permanently delete your account and all associated data from your profile settings
  • Right to data portability — you can download all your personal data in JSON format from your profile settings at any time
  • Right to restrict processing — you can contact us to request that we pause processing of your data while a complaint or query is being resolved
  • Right to object — where processing is based on legitimate interest (leaderboard display and aggregate reporting), you have the right to object. Contact us and we will review your request
  • Automated decision-making — we do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you. Badge awards and leaderboard rankings are automated but have no consequential effect beyond the application

To exercise any of these rights, contact us at stepcount@strath.ac.uk or submit a formal data subject request to dataprotection@strath.ac.uk.

9. Complaints

If you believe your personal data is being handled unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the opportunity to address your concerns directly before you contact the ICO — please reach out to us first at dataprotection@strath.ac.uk.

10. Changes to this notice

This privacy notice will be reviewed annually, with the next review due in June 2027. If we make material changes to how we process your personal data, we will inform you via the app before the changes take effect. Continued use of Strath Steps after notification of material changes constitutes acceptance of the updated notice.

Strath Steps is operated by the University of Strathclyde Sport department. University of Strathclyde, 16 Richmond Street, Glasgow, G1 1XQ. For data protection queries: dataprotection@strath.ac.uk