Privacy Policy
Trail Rac.ing accesses Strava data only after athlete consent via OAuth and only to provide race readiness and prediction features for that same athlete.
Data accessed
- Basic activity fields from Strava (date, title, type, distance, time, elevation gain).
- Derived metrics calculated in-session for readiness and finish-time prediction.
How data is used
- Access occurs only after you authorize Trail Rac.ing using the Strava OAuth flow.
- Data is used to generate your in-app prediction outputs.
Storage model
We keep a PostgreSQL database in which the following records are held against your account identifier:
- Strava access and refresh tokens, with their expiry and your athlete ID. These are what let us fetch your training without asking you to authorize again on every analysis.
- Subscription and trial status, with your Stripe customer and subscription identifiers.
- Any race suggestions or feature notification requests you have submitted, including the email address you gave.
Equally important is what we do not keep:
- Your Strava activities are not stored. They are fetched from the Strava API for each analysis, used in memory, and discarded along with the metrics and predictions derived from them.
- Card details never reach our servers. Payment is handled entirely by Stripe.
Who we share with
We do not sell your data. We run on third-party services which, in order to work, process some of it on our behalf:
- Strava — the source of your training data, under your OAuth authorization.
- Clerk — accounts and authentication (your email address and login credentials).
- Neon — the database described above.
- Vercel — application hosting and access logs.
- Stripe — payments and subscription management.
- PostHog — product usage analytics, so we can tell what works in the app.
- Meta Platforms — ad measurement, only with your consent (see below).
Cookies and ad measurement
- Necessary cookies: your login session, the Strava token and your language choice. The app cannot work without them, so they do not depend on consent.
- Ad measurement (optional): with your consent, we use the Meta Pixel and Meta Platforms' Conversions API to measure how our Facebook and Instagram ads perform.
- What Meta receives in that case: an identifier for your account and your email address, both turned into an irreversible code (SHA-256 hash), the
_fbpand_fbccookies the Pixel creates, your IP address, your browser, and which funnel step you reached (race page visit, account creation, checkout start, trial start, subscription). We never send your Strava data, activities or predictions. - Some of these events are sent from our servers rather than your browser, so blocking cookies in the browser does not stop them. The choice recorded below does.
- Legal basis: consent (LGPD art. 7, I). Declining does not limit any Trail Rac.ing feature.
How to withdraw consent
- Ad measurement: use the "Cookies" link in the footer of any page to accept or decline at any time. Declining deletes the
_fbpand_fbccookies and stops sending events to Meta. - Strava: use the "Disconnect from Strava" button in the app. This revokes the authorization at Strava and deletes your tokens from our database.
Your rights
LGPD art. 18 entitles you, at any time and free of charge, to confirmation that we process your data, access to it, correction of anything incomplete or out of date, portability, information about who we share it with, deletion of data processed on the basis of your consent, and withdrawal of that consent.
Data protection contact and deletion requests
- To exercise any of the rights above, or to request deletion of your account and every record tied to it, write to trailracingapp@gmail.com, which is also the channel for our data protection officer.
- Write from your account email, or tell us what it is, so we can locate your records.