GPX is verbose XML and has no place for extras such as heart rate unless an extension is used. CSV is plain text that every spreadsheet, database and script can read. GPX is at home in GPS tracks, routes and waypoints; CSV is the usual choice for moving tabular data between systems.
Every format is read into plain GeoJSON features and written out from there, so coordinates, names and properties carry over wherever the target has a place for them. XML that declares custom entities is refused, and GPX files are parsed without touching the network. Each point, and each vertex of a line, becomes one row with name, lat and lon columns, plus elevation and time when the data has them. Areas cannot be written as rows, so a file with polygons is refused. Text that starts with =, +, - or @ is escaped so a spreadsheet does not run it as a formula.