TCX is a fitness-specific format that plain GPS and map tools do not understand. CSV is plain text that every spreadsheet, database and script can read. TCX is at home in workouts with laps, heart rate and cadence; CSV is the usual choice for moving tabular data between systems.
Every format is read into plain GeoJSON features and written out from there, so coordinates, names and properties carry over wherever the target has a place for them. XML that declares custom entities is refused, and TCX files are parsed without touching the network. Each point, and each vertex of a line, becomes one row with name, lat and lon columns, plus elevation and time when the data has them. Areas cannot be written as rows, so a file with polygons is refused. Text that starts with =, +, - or @ is escaped so a spreadsheet does not run it as a formula.