Skip to main content
Language version:English|Polski

Privacy Policy

Your privacy matters to us

Last updated: 4 September 2026
Effective: 4 September 2026

1. Introduction

Welcome to BottleChallenge ("we," "our," or "us"), a project operated by BrainGreen Foundation. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website, and related services (collectively, the "Service").

We are established in Poland, so the General Data Protection Regulation (EU) 2016/679 is the framework we build on. We apply its standard to everyone who uses the Service, wherever they live, rather than offering weaker protection outside Europe.

Where the law of your own country gives you additional or different rights, those apply too. Sections 13 and 14 describe specific rights for residents of California and Brazil. If you are in the United Kingdom, the UK GDPR gives you rights equivalent to those in section 8. If you are elsewhere and your national law gives you a right we have not listed, write to us and we will honour it.

Reading this policy does not give consent to anything. It is an explanation of what we do, not a form to agree to. Most of our processing rests on the contract between us or on a legitimate interest, as set out in section 4. Where we rely on your consent, for location or analytics, we ask for it separately, and you can withdraw it at any time without losing access to the rest of the Service.

2. Data controller

The data controller responsible for your personal data is:

BrainGreen Foundation

Operating as: BottleChallenge

Plac Konstytucji 4/17, 00-552 Warsaw, Poland

KRS: 0000964547 | NIP: 5252903313 | REGON: 521709494

Email: [email protected]

Website: BrainGreen Foundation website

You can reach the people responsible for data protection at BrainGreen Foundation at [email protected] or [email protected]. Both reach the same team and either can be used for any request under section 8.

Article 37 of the GDPR requires a formally designated Data Protection Officer only in specific cases, such as large scale monitoring. We do not currently meet those thresholds. If we do, we will designate one, notify the Polish supervisory authority and publish the contact details here.

3. Data we collect

3.1 Information you provide

  • Account: your email address, the display name you choose, and a password, which we store only as a cryptographic hash and never in readable form.
  • Optional profile details: a profile picture, a short description, a city and a phone number, if you choose to add them.
  • Contributions: photographs of refill points you upload, the details of points you add, and corrections you suggest.
  • Communications: messages you send us, support requests and problem reports.
  • Partner and public body details: for business or municipal accounts, the organisation name, address, contact person, phone, email, tax or registration number, and the terms version accepted.
  • EcoDrops and the shop: your balance, how it was earned and spent, vouchers issued to you, and any report you raise about a reward.
  • Invitations: if you invite someone or join by invitation, we record the link between the two accounts so that the bonus can be paid correctly.
  • Newsletter: if you subscribe, your email address and the IP address used to subscribe, as proof of consent.

We do not ask for your date of birth, your gender or your home address, and there is no field for them.

3.2 Information collected automatically

  • Refill records: each time you tap an NFC tag we record the single-use encrypted code the tag produces, which identifies the tag and the point, the time, and details of your device such as platform and app version. If you have granted location permission we also record the coordinates your device reported and the distance from the point. We record this whether the tap succeeds or fails, including when it is rejected for being too far away, too soon, or a suspected replay, because that record is what lets us investigate abuse.
  • Location: the app asks for your location to show nearby points and to confirm you are at the point when you tap a tag. On the map it is used on your device. On a refill record it is stored, as described above.
  • Technical and log data: IP address, browser or app version, access times and error logs. We record the IP address you registered from, the IP address on each refill record, and the IP address used for newsletter sign-up.
  • Push notification token: if you enable notifications, the token that identifies your installation, the platform, your language and your notification preferences.
  • Security and anti-abuse: when you register or reset a password on the website we send your IP address to Cloudflare for a bot check. Verification codes we email you are stored only as a hash, with a count of failed attempts.
  • Usage analytics: only if you turn analytics on. See section 9.

3.3 Information we derive

  • An inferred home city. From where you have most often recorded refills over the preceding six months, we derive a single likely home city for your account. It lets us tell a municipality how many refills in its area came from people who are mostly active there rather than visiting. Municipalities receive only the totals. They never see your identity, and this inference is never disclosed about an individual.
  • Fraud signals. We compare the time and place of consecutive refill records to detect physically impossible journeys, and we may flag an account for review as a result.
  • Team statistics. If you join a team, your refill count, streak and ranking within that team are visible to the people who manage it. Do not join a team run by your employer unless you are content with that.

3.4 Information from third parties

  • Social sign-in: if you sign in with Google or Apple, we receive your name, email address and, from Google, your profile picture. We do not currently support Facebook sign-in.
  • Donations: Stripe tells us the amount, the date, the email address you gave at checkout and the last four digits of the card. We never receive your full card number.

3.5 Sensitive data

We do not intentionally collect sensitive personal data (such as health information, religious beliefs, political opinions, sexual orientation, or biometric data). If you voluntarily provide such information, it will be processed with your explicit consent.

5. How we use your data

We use your personal data for the following purposes:

  • Service delivery: to provide, maintain, and improve our Service
  • Personalization: to show nearby refill stations and personalize your experience
  • Communication: to respond to your inquiries and send service-related notifications
  • Rewards program: to track the refills you record and award the corresponding EcoDrops
  • NFC verification: to verify refill visits via tag scans, prevent fraud, and accurately award EcoDrops
  • Shop & redemptions: to process reward purchases, generate voucher codes, and fulfill orders
  • Donations: to process your donation through Stripe, issue a receipt and keep the accounting record
  • Analytics: to understand how users interact with our Service and improve it
  • Safety: to detect, prevent, and address fraud, abuse, and security issues
  • Legal compliance: to comply with applicable laws and regulations
  • Marketing: with your consent, to send promotional communications about our Service

6. Data sharing & disclosure

We may share your personal data with:

6.1 The companies we actually use

These are the third parties that receive personal data when you use the Service. We keep this list current. If you would like the contractual detail for any of them, ask us.

WhoWhat they receiveWhen
Our hosting providerEverything stored in the Service, as the operator of the serversAlways
StripeYour payment details and email address, entered on Stripe's own pageOnly if you donate
CloudflareYour IP address and browser signals, for a bot checkWhen you register or reset a password on the website
Google (Firebase Analytics, Google Analytics)Screen and page views, a small number of events, an analytics identifierOnly if you turn analytics on
Google or AppleThe sign-in exchange, if you use their sign-in buttonOnly if you choose social sign-in
ExpoYour push token and the notification text, and your IP when the app checks for updatesIn the mobile app
Map tile providers (Esri, CARTO, OpenMapTiles)Your IP address and the part of the map you are viewingWhenever a map is displayed
OpenStreetMap NominatimThe place name you type into a search box, sent directly from your browser with your IP addressWhen you search for a place
Google PlacesThe venue name or coordinates being looked up. Sent by our server, not by youWhen a venue is added or edited
Our email deliveryYour email address and the message contentWhen we email you

Stripe, Google and Apple determine some of their own purposes and act as independent controllers for those. Their own privacy policies govern that part.

6.2 Business partners

Partners see counts, not people. A venue can see how many refills were recorded at it and over what period. An organisation offering rewards can see how many vouchers were issued and used. A municipality sees totals for its area. None of them receives your name, email address, phone number or the coordinates attached to your refill records, and a person who reports a problem with a reward is not identified to the partner.

6.3 Legal requirements

We disclose data only where we are compelled to by a legally binding demand under European Union or Member State law, or by a court order. A request from an authority outside the European Union is not by itself a sufficient basis: under Article 48 of the GDPR we act on it only through a mutual legal assistance treaty or an equivalent international agreement. Where the law allows, we will tell you before we disclose anything.

6.4 Business transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. You will be notified of any such change.

6.5 With your consent

We may share data for other purposes with your explicit consent.

We do not sell your personal data, and we do not share it for advertising or marketing.

7. Data retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Location shown on the mapUsed on your device, never sent to us for this purpose
Refill records, including the coordinates, IP address and device details attached to them24 months, then deleted. Deleted sooner if you delete your account
Login and verification tokensUntil they expire, then purged
Push notification tokenUntil you turn notifications off or delete your account
Newsletter subscriptionUntil you unsubscribe
Donation records5 years from the end of the year of the donation, as Polish tax law requires
Shop purchase historyDuration of account + 30 days
Support communications3 years
Legal/compliance recordsAs required by law (typically 5-7 years)

After the retention period, data is securely deleted or anonymized. You can request earlier deletion by contacting us (subject to legal retention requirements).

8. Your rights

Depending on your location, you may have the following rights:

Right to access

Request a copy of your personal data we hold

Right to rectification

Correct inaccurate or incomplete data

Right to erasure

Request deletion of your data ("right to be forgotten")

Right to restrict processing

Limit how we use your data

Right to data portability

Receive your data in a machine-readable format

Right to object

Object to processing based on legitimate interests

Right to withdraw consent

Withdraw consent at any time (won't affect prior processing)

Right to lodge a complaint

Complain to your own data protection authority, or to the Polish one, which supervises us

To exercise these rights, contact us at [email protected]. We will respond within one month. Article 12(3) of the GDPR lets us extend that by two further months for a complex or repeated request, and if we need to we will tell you within the first month and explain why.

9. Cookies & tracking technologies

We use cookies and similar technologies for:

9.1 Types of cookies

  • Essential cookies: required for the Service to function (authentication, security)
  • Functional cookies: remember your preferences (language, theme)
  • Analytics cookies: help us understand usage patterns (with consent)

9.2 Managing cookies

You can control cookies through your browser settings. Note that disabling certain cookies may affect functionality.

We do not currently act on the "Do Not Track" header or the Global Privacy Control signal, because our analytics are already switched off until you consent, so there is nothing for such a signal to turn off. If you take no action, no analytics cookie is set.

9.3 Third-party analytics

We may use analytics services that collect anonymized data. These services have their own privacy policies governing their use of data.

For the complete list of cookies, their purposes, and how to manage your preferences, please see our Cookie Policy.

10. Children's privacy

The Service is for people aged 16 and over. We do not knowingly collect personal data from anyone younger.

We do not ask your age or verify it when you register. We rely on the confirmation you give when you accept the Terms of Service. If we learn that an account belongs to someone under 16, we close it and delete the personal data.

If you believe we have collected data from a child, please contact us immediately at [email protected], and we will promptly delete such information.

Parents and guardians: if you believe a child has given us personal information, contact us and we will delete it. We do not operate a service directed at children under 13, so the United States Children's Online Privacy Protection Act does not apply to us, and we make no claim to comply with its notice and verifiable parental consent procedures.

11. Data security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit: all traffic between your device and our servers uses TLS
  • Password and code storage: passwords and email verification codes are stored only as cryptographic hashes, never in readable form
  • Access controls: strict access controls and authentication for staff
  • Review: we review the security of the Service as we develop it, and we act on reports from security researchers
  • Incident response: procedures to detect, report, and respond to breaches
  • Least privilege: only the small number of people who operate the Service can reach production data, and access is individually accounted for

While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but commit to notifying you of any breach as required by law.

12. International data transfers

Our servers are in the European Union, and the core of the Service, including your account and your refill records, stays there.

Some of the companies in section 6.1 are established in the United States or process data there. That applies in particular to Google, Apple, Stripe, Cloudflare and Expo. For those transfers we rely on one of the following, in this order:

  • The EU-US Data Privacy Framework. Where the recipient is certified under the Framework, the European Commission's adequacy decision of 10 July 2023 covers the transfer. Google, Apple and Cloudflare are certified.
  • Standard Contractual Clauses. Where the recipient is not certified, or for the parts of a service the certification does not cover, we rely on the Commission's Standard Contractual Clauses of 4 June 2021, together with an assessment of the risk in the destination country and any additional measures it calls for.

For transfers out of the United Kingdom we use the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses.

You can ask us for a copy of the safeguards that apply to a particular transfer by writing to [email protected].

Two of these happen directly from your device rather than through our servers: the map tiles you load and the place searches you type. Those requests carry your IP address to the provider. If that matters to you, you can browse the map without searching, and the mobile app lets you skip the location permission entirely.

13. California privacy rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the CCPA/CPRA:

Your rights

  • Right to know: what personal information we collect, use, and disclose
  • Right to delete: request deletion of your personal information
  • Right to correct: correct inaccurate personal information
  • Right to opt-out: opt-out of the sale/sharing of personal information
  • Right to non-discrimination: we won't discriminate against you for exercising your rights
  • Right to limit: limit use of sensitive personal information

Categories of information

In the past 12 months, we have collected the following categories of personal information:

  • Identifiers (name, email, username)
  • Internet activity (usage data, device information)
  • Geolocation data (with consent)
  • Inferences drawn from the above

Notice: We do NOT sell or share your personal information for cross-context behavioral advertising purposes.

To exercise your California rights, contact us at [email protected] . We accept requests by email, and you may appoint an authorised agent to make one for you. We do not operate a telephone line for privacy requests, because we are a small volunteer organisation and email is the channel we can answer reliably.

We are a Polish non-profit and do not currently meet the revenue or volume thresholds that make the California Consumer Privacy Act apply to a business. The rights in this section are therefore granted as a matter of policy rather than obligation, and we will honour them on that basis.

14. Brazil privacy rights (LGPD)

If you are a resident of Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD):

  • Confirmation of data processing
  • Access to your data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary data
  • Data portability
  • Deletion of data processed with consent
  • Information about sharing with third parties
  • Information about the possibility of denying consent
  • Revocation of consent

To exercise your LGPD rights, contact our data protection team at [email protected].

15. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new policy on this page with an updated "Last Updated" date
  • Sending you an email notification (for significant changes)
  • Displaying a prominent notice in our app or website

We encourage you to review this policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.

16. Contact us

If you have questions, concerns, or requests regarding this Privacy Policy or your data:

Data protection contact

[email protected]

BrainGreen Foundation

Plac Konstytucji 4/17, 00-552 Warsaw, Poland

KRS: 0000964547 | NIP: 5252903313

[email protected]
BrainGreen Foundation website

EU and EEA residents: you may complain to the data protection authority where you live, where you work, or where the alleged infringement happened. Because we are established in Poland, you may also complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland. A list of all EU authorities is at edpb.europa.eu.

UK Residents: You can contact the Information Commissioner's Office (ICO) at ico.org.uk.