COOKIES
1
Without consent: one cookie that stores your decision. Any others come from the tools you switch on yourself.
LEGAL · LAST UPDATED 09.2026
In short: our own measurement uses no cookies and no identifiers; analytics and advertising tools run only with your consent. Full text below.
COOKIES
1
Without consent: one cookie that stores your decision. Any others come from the tools you switch on yourself.
IDENTIFIER
none
We never link a visit to a person or a device.
RETENTION
3 months
Aggregate usage data is deleted after three months.
Draft translation pending legal review. The Polish version is the binding one.
Dated 15 September 2026.
This Privacy Policy sets out the rules for the processing of personal data in connection with the use of the GapApp mobile application, the GapApp website, the landing page, the forms and the related functionalities and analytical or marketing tools (jointly: “GapApp”)
The controller of personal data is Łukasz Mocarski, with its registered office in Warsaw, ul. Afrykańska 5/13 - hereinafter referred to as the “Controller”, “GapApp”.
Contact in matters relating to the protection of personal data: privacy@fillthegap.app Correspondence address: Warszawa ul. Afrykańska 5/13.
Data protection officer: The Controller has not appointed a data protection officer. For all matters concerning personal data, please contact privacy@fillthegap.app.
The Policy applies in particular to:
The scope of the data depends on the way GapApp is used and on the functions that are enabled. The Controller may process the following categories of data:
GapApp does not envisage the processing of the special categories of personal data referred to in Article 9 GDPR as a necessary element of its core functionality. The user should not submit such data into fields, analytical events or advertising systems where this has not been separately designed and regulated in law.
| Purpose | Legal basis | Period |
|---|---|---|
| Creating and maintaining an account, making the GapApp functions available | Article 6(1)(b) GDPR - performance of a contract or steps taken prior to entering into it | for as long as the account exists, and thereafter for the period necessary to handle claims or legal obligations |
| Operating the user or trainer profile, publishing availability/offers, searching for and matching the parties | Article 6(1)(b) GDPR | for the period of use of the service, taking into account the retention of operational data |
| Booking or arranging a training session and handling the status of the service | Article 6(1)(b) GDPR | until the process is completed and for the period necessary for settlements and for the defence of claims |
| Contact, handling of questions and enquiries | Article 6(1)(b) GDPR - where the contact concerns a contract; or Article 6(1)(f) GDPR - the legitimate interest in conducting correspondence | until the matter is closed, and thereafter for the period justified by the possibility of pursuing or defending claims |
| Security, prevention of abuse, diagnostics and ensuring continuity of operation | Article 6(1)(f) GDPR - the legitimate interest of the Controller | for the period necessary to achieve the purpose; the detailed retention of logs is to be determined internally |
| Establishing, pursuing or defending claims | Article 6(1)(f) GDPR | until the expiry of the applicable limitation period for claims |
| Fulfilment of accounting, tax or other legal obligations | Article 6(1)(c) GDPR | for the period required by law |
| Marketing communications by e-mail/SMS/push, where the given channel is subject to a consent requirement | Article 6(1)(f) GDPR to the extent permitted by the GDPR or Article 6(1)(a) GDPR, depending on the process; in addition, the prior consent required by Article 398 of the Electronic Communications Law | until an objection to marketing is raised or consent for the given channel is withdrawn |
| Cookieless analytics through Cloudflare Web Analytics and the in-house beacon in the model described in points 8.1-8.2 | Article 6(1)(f) GDPR - the legitimate interest in analysing usability and developing the product, provided that the configuration remains cookieless and is not used to track individual persons | in-house beacon: 3 months; Cloudflare: in accordance with the configuration of the service and the agreement with the provider |
| Optional analytics requiring information to be stored on or read from the device, if implemented | Article 6(1)(a) GDPR - consent; in addition Articles 399-400 of the Electronic Communications Law | until consent is withdrawn or the lifetime of the relevant identifier/cookie expires; details in the cookie settings |
| Meta Pixel: advertising measurement, conversion attribution, campaign optimisation, remarketing and the creation of audiences | Article 6(1)(a) GDPR - consent; in addition Articles 399-400 of the Electronic Communications Law | until consent is withdrawn and in accordance with the life cycle of the identifiers used and with Meta’s rules; once consent is withdrawn the Pixel should not generate new marketing events |
| Recording and demonstrating the consents given or withdrawn | Article 6(1)(c) GDPR in conjunction with the obligation to demonstrate compliance, or Article 6(1)(f) GDPR - the interest in demonstrating compliance | for the period necessary to demonstrate compliance, taking into account the limitation periods |
Where GapApp uses the user’s location to search for trainers, training sessions or availability nearby, the location data are processed solely to the extent necessary to deliver that function. Access to the precise location of the device requires a permission granted by the user in the operating system of the device.
Production model of location handling: [TO BE COMPLETED: precise / approximate / entered manually; whether the location is stored and for how long].
Disabling access to location may limit the functions that depend on position, but it should not prevent the use of functions that do not require location, provided that the product architecture allows this.
GapApp may send push notifications, in particular concerning available slots, offers, bookings, status changes or other events connected with the use of the service. For the technical handling of notifications, a device token or another technical identifier required by the notification system may be processed.
The user may at any time disable push notifications in the system settings of the device or - where the function is made available - in the GapApp settings.
Push infrastructure provider: [TO BE COMPLETED: e.g. Apple Push Notification Service / Firebase Cloud Messaging / other].
Commercial information, including direct marketing, is sent using telecommunications terminal equipment or automated calling systems after obtaining the prior consent required by Article 398 of the Electronic Communications Law, where the given means of communication is subject to that provision.
Marketing consent concerning a communication channel is separate from consent to optional cookies and tracking technologies. The absence of consent to the Meta Pixel or to marketing cookies may not in itself deprive the user of access to the core GapApp functions that do not require such technologies.
Every consent is voluntary. It may be withdrawn at any time, without affecting the lawfulness of the processing carried out before its withdrawal. Withdrawing consent should be as easy as giving it.
Where data are processed for the purposes of direct marketing on the basis of the legitimate interest of the Controller, the data subject has the right to object at any time. Following an effective objection, the data will no longer be used by the Controller for direct marketing.
GapApp uses Cloudflare Web Analytics in order to obtain aggregate information about the way the site is used, about its performance and about traffic. In the model declared by the provider, the service can operate without cookies and without localStorage for the individual tracking of users. The actual configuration deployed in GapApp should be verified before this Policy is published.
The legal basis for processing in such a cookieless model is Article 6(1)(f) GDPR - the legitimate interest of the Controller in analysing the operation of the site and improving it. If the configuration is changed in a way that requires access to information on the user’s device or a persistent identifier, the tool must be brought under a consent mechanism.
Provider: Cloudflare, Inc. / the relevant Cloudflare contracting entity. [TO BE COMPLETED: the relevant entity, DPA, data location and transfers].
GapApp may use an in-house analytical mechanism (a beacon) to assess the way the site is used. In the model described below it measures in particular:
Where the in-house beacon does not use cookies, localStorage, fingerprinting or persistent user or device identifiers, and does not link events to a GapApp account, it may be used on the basis of Article 6(1)(f) GDPR. The raw data from that mechanism are stored for 3 months and are then deleted or retained solely in the form of statistics that do not allow a person to be identified.
Once consent to marketing technologies has been obtained, GapApp may run the Meta Pixel - a tool of Meta Platforms Ireland Limited (“Meta”) used, among other things, to measure the effectiveness of advertisements, to attribute conversions, to optimise campaigns, to create audiences, for remarketing and to display advertisements better matched to the user’s activity.
The Meta Pixel may process, among other things, information about the page displayed and the URL, the entry source, the time of the event, the type of event performed, the IP address, browser and device data, cookie identifiers or identifiers of similar technologies (e.g. _fbp and, in certain cases, _fbc) as well as information about interactions and conversions transmitted by the Pixel configuration.
If the Controller enables Advanced Matching or other matching mechanisms that use contact data, Meta may also receive matching data (e.g. an e-mail address or a telephone number) in a technically secured/hashed form. [TO BE COMPLETED BEFORE PUBLICATION: whether Advanced Matching is enabled; which fields are transmitted]. Special categories of data and the content of form fields that are not necessary for the agreed advertising purpose must not be sent to Meta.
The Meta Pixel is run only after the user’s consent to marketing technologies has been obtained. The basis for the processing of data by the Controller in this respect is Article 6(1)(a) GDPR, and access to information on the user’s device or the storing of information on it takes place under Articles 399-400 of the Electronic Communications Law.
To the extent that the Controller and Meta jointly determine the purposes and means of collecting event data through the Meta Pixel and of transmitting them to Meta, they may act as joint controllers within the meaning of Article 26 GDPR. The scope of responsibility is governed by Meta’s business tools terms and by the applicable Controller Addendum. As regards Meta’s further processing of the data after it receives them, Meta may act as a separate controller in accordance with its own terms and policies.
Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland [VERIFY THE CURRENT CONTRACTING ADDRESS IN THE META ACCOUNT BEFORE PUBLICATION]. Meta’s privacy information: https://www.facebook.com/privacy/policy. Business tools terms: https://www.facebook.com/legal/technology_terms. Controller Addendum: https://www.facebook.com/legal/controller_addendum.
If GapApp deploys additional tools, for example Google Analytics, Google Ads, the TikTok Pixel, the LinkedIn Insight Tag or other tracking technologies, they should not be run solely on the basis of a general provision in this Policy. Before they are run, the list of providers, the purposes, the scope of the data, the legal basis, the retention and the transfers must be completed and the consent CMP/banner configured accordingly.
GapApp may use cookies, localStorage, SDKs, pixels, tags and other technologies that make it possible to store information on the user’s device or to gain access to information already stored on the device.
The technologies are divided into the following categories:
The first layer of the banner/CMP should offer the user at least: “Accept all”, “Reject optional” and “Settings”. Optional categories may not be pre-ticked. The user should be able to change their choice at any time through an easily accessible “Cookie settings” link or an equivalent mechanism.
A failure to respond to the banner is not consent. Until consent is obtained, optional technologies - in particular the Meta Pixel - should not load code, set identifiers or send events to an external provider.
Once consent has been withdrawn, the Controller stops running the technologies covered by the withdrawn consent. Where it is technically possible and remains within the Controller’s control, the relevant identifiers should be deleted or expired. The withdrawal of consent does not operate retroactively and does not mean that data lawfully transmitted earlier to a separate or joint controller are automatically deleted.
An up-to-date list of production cookies and technologies should be published in the CMP or in a cookie table covering at least: the name, the provider, the category, the purpose, the lifetime and information on whether it is a first-party or a third-party cookie. For the Meta Pixel, the presence of the _fbp and _fbc identifiers and their actual lifetime in the production configuration must be verified as a minimum.
Data may be disclosed to entities supporting the Controller in operating GapApp, solely to the extent needed for the performance of their tasks, in particular:
List of the main production providers: [TO BE COMPLETED: NAME - ROLE - PURPOSE - COUNTRY/EEA - TRANSFER BASIS - LINK TO THE TERMS/DPA].
To the extent necessary to match a user with a trainer, to present an offer, to accept a booking or to deliver an agreed training session, certain profile and transaction data may be visible to the other party. The scope of the data should be limited to the information necessary for the given functionality.
Scope of the data visible before and after acceptance/booking: [TO BE COMPLETED].
If, after receiving the data, the trainer uses them independently for their own purposes going beyond the GapApp functions, the trainer’s legal status and obligations towards the user require a separate assessment. Data obtained within the platform should not be treated as a freely available marketing database for trainers.
Some technology providers may process data outside the European Economic Area. Where such a transfer of personal data takes place, the Controller applies or verifies the mechanisms provided for in Chapter V GDPR, in particular an adequacy decision, standard contractual clauses and - where necessary - supplementary safeguards.
In connection with the use of Meta’s services, data may be processed by Meta Platforms Ireland Limited and by other Meta entities or infrastructure, including outside the EEA. The detailed bases for the transfers should be verified against the current Meta terms and the account configuration at the time this Policy is published.
Production / transfers outside the EEA: [TO BE COMPLETED AFTER THE PROVIDER AUDIT, INCLUDING META AND CLOUDFLARE].
Data are stored for no longer than is necessary for the purpose for which they were collected. The specific periods follow from the nature of the service, the legal basis, the legal obligations of the Controller and the need for protection against claims. Once the applicable period has elapsed, the data are deleted, anonymised or their processing is restricted, where the law so requires.
Data from the in-house behaviour beacon in the model described in point 8.2 are stored for 3 months. The lifetime of individual cookies and identifiers, including Meta’s tools, should be indicated in the current CMP panel/cookie table. Withdrawing consent alone blocks future optional processing by GapApp, but does not automatically result in the deletion of data already held by a separate or joint controller; in such a case the rules on exercising rights set out in point 14 apply.
On the terms set out in the GDPR, the data subject may have the right to:
Consents to cookies and optional technologies may be changed through [LINK / “COOKIE SETTINGS” BUTTON]. Requests concerning rights against the Controller may be addressed to: [GDPR E-MAIL]. As regards the processes covered by joint controllership with Meta, rights may be exercised against either joint controller in accordance with the GDPR and with the applicable Meta arrangement.
Providing the data required to create an account or to use a specific functionality is voluntary, but it may be necessary in order to enter into and perform a contract for the provision of GapApp services. A failure to provide the data marked as required may make it impossible to create an account, to make a booking or to use a given function.
Giving consent to electronic marketing, to analytical or marketing cookies, to the Meta Pixel or to other optional technologies is not a condition of using the core GapApp functions that do not require such technologies.
GapApp may use search parameters, location, availability or other operational data to sort results and to match offers. [TO BE COMPLETED: the actual recommendation model].
Once consent to marketing technologies has been given, Meta may use the event data from the Meta Pixel to create audiences, to measure advertisements, to optimise campaigns and to personalise advertisements in accordance with its own rules. Such activities may include marketing profiling.
Production status: [TO BE COMPLETED - recommended wording, if consistent with the actual operation: “GapApp does not take decisions in relation to users that produce legal effects concerning them or similarly significantly affect them based solely on automated processing within the meaning of Article 22 GDPR.”].
The Controller applies technical and organisational measures appropriate to the risk associated with the processing of data, taking into account the nature, scope, context and purposes of the processing. They include in particular access control, the principle of least privilege, transmission safeguards, system updates, backups or recovery mechanisms, incident monitoring and periodic access reviews - as appropriate to the infrastructure used.
The deployment of advertising tools should respect the principles of privacy by design and privacy by default. The events sent to external platforms should be limited to the necessary minimum and should not contain special categories of data, the content of free-text form fields or other information going beyond the documented purpose.
Minimum age of a GapApp user: 18 years.
If the service is to be made available to minors, the Controller should, before launching the function, verify the rules on entering into contracts, on consents, on behavioural advertising and on the processing of children’s data, and adjust the age verification mechanisms and the configuration of the advertising tools accordingly.
The Policy may be updated in the event of changes to GapApp functionality, to technologies, to providers, to the ways in which data are processed or to the law. The current version will be available in the application and/or on the GapApp website. Where the changes are significant for users, the Controller may also inform them through the application, by e-mail or through another appropriate channel.
Where a change concerns the purpose or the scope of processing based on consent, an earlier consent must not be extended automatically. Where necessary, the user’s consent must be obtained again.
Date of the last update: [PUBLICATION DATE].
The document has been prepared taking into account in particular: Regulation (EU) 2016/679 (GDPR), the Act of 10 May 2018 on the protection of personal data and the Act of 12 July 2024 - Electronic Communications Law, in particular Articles 398-400. As regards Meta technologies, the current Meta terms on business tools and joint controllership must additionally be applied. Before publication, the content must be confronted with the actual production deployment, since the correctness of the policy depends, among other things, on the tags, events, CMP configuration and data transfers that are actually in use.