Privacy Policy
Last Updated: March 12, 2025
1. Who We Are
Rally ("we", "our", "us") is committed to protecting and respecting your privacy. This policy explains how we handle your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Rally is a sports activity matching application registered in the United Kingdom. We are registered with the Information Commissioner's Office (ICO) and act as a data controller for the personal information you provide to us.
2. Information We Collect
We collect and process the following personal data:
- Account Information: Name, email address, password (encrypted)
- Profile Information: Profile picture, bio, location, sports preferences
- Activity Data: Sports activities, participation history, scheduling preferences
- Usage Information: App interactions, activity patterns, communication logs
- Device Information: Device type, IP address, operating system
- Location Data: GPS location (with your consent)
- Communications with other users
3. Legal Basis for Processing
We process your data under the following legal bases:
- Contract: Processing necessary for our contract with you
- Consent: Where you have explicitly agreed to the processing
- Legitimate Interests: To improve our services and ensure platform safety
- Legal Obligation: To comply with UK law
4. How We Use Your Information
Your information is used to:
- Provide and personalize our services
- Match you with suitable activity partners
- Maintain your Rally Score
- Ensure platform safety and prevent misuse
- Send important updates about our service
- Improve our app and services
- Communicate with you about our services
5. Data Sharing
We share your data with:
- Other users (only information you choose to make public)
- Service providers (e.g., hosting, analytics)
- Law enforcement (when legally required)
All our third-party service providers are required to take appropriate security measures to protect your personal data in line with UK GDPR requirements.
6. Data Retention
We retain your personal data for as long as necessary to provide our services or to comply with legal obligations. Specifically:
- Account information: While your account is active plus 2 years
- Communication records: 2 years from last interaction
- Technical logs: 90 days
- Marketing preferences: Until you withdraw consent
You can request deletion of your account at any time through the app settings.
7. Your Rights
Under UK data protection law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request erasure of your data
- Object to processing
- Request data portability
- Withdraw consent
To exercise these rights, contact our Data Protection Officer.
8. Facial Verification
Our facial verification system processes biometric data to verify user identity:
- Purpose: To enhance platform safety and prevent impersonation
- Processing: Comparison of profile photo with verification selfie
- Storage: Verification selfies are immediately deleted after processing
- Legal Basis: Explicit consent (you can choose not to use this feature)
- Data Protection: All facial verification data is processed with enhanced security measures
- Your Rights: You can withdraw consent for facial verification at any time
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage.
10. International Transfers
We use Supabase, a US-based company, as our data storage provider. This means your personal data may be transferred to and stored in the United States. We ensure these transfers are conducted in accordance with UK data protection law through appropriate safeguards, including:
- Standard contractual clauses approved by the UK Information Commissioner's Office
- Regular security and privacy compliance audits
- UK International Data Transfer Agreements
- Adequacy decisions by the UK Information Commissioner's Office
We carefully assess all international data transfers to ensure your privacy rights are protected in accordance with UK GDPR standards.
11. Cookies and Similar Technologies
We use cookies to enhance your experience on our website. Cookies are only set on the rallyapp.co.uk domain. We use the following types of cookies:
Necessary Cookies
These cookies are essential for the website to function properly. They enable basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Analytics Cookies
These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. This helps us improve our website's performance and user experience.
Marketing Cookies
These cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user.
Managing Cookies
You can control and/or delete cookies as you wish. You can delete all cookies that are already on your computer and you can set most browsers to prevent them from being placed. However, if you do this, you may have to manually adjust some preferences every time you visit a site and some services and functionalities may not work.
You can manage your cookie preferences at any time by clicking the "Cookie Preferences" button in the cookie banner at the bottom of the page.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes via:
- Displaying a notice on our website
- Sending an email to registered users
- Requiring renewed consent where necessary
Contact Us
For privacy-related concerns:
Data Protection Officer
Echelon Ventures LTD
123 Example Street
London, EC1A 1BB
United Kingdom
Email: support@rallyapp.co.uk
For information about your data rights or to submit a data request, please visit our Data Rights page.
Need help with the Rally app? Visit our Support page.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).