Privacy Policy

Last updated: 22 July 2026

1. Who we are

RideSharp is a cycling component wear-tracking application. The data controller is RideSharp, based in Amsterdam, the Netherlands. Contact: cdiepenhorst@gmail.com.

2. What data we collect

  • Account data: email address and password (stored hashed, never in plain text).
  • Bike and component data: everything you add, including bikes, parts, builds, wishlist items, and wear settings.
  • Strava data (opt-in): when you connect Strava, we import cycling activities, including distance, time, average watts, GPS start coordinates, and activity type.
  • Performance settings: FTP (Functional Threshold Power), manually entered by the user, not retrieved from Strava.
  • Weather data: for each activity, we query Open-Meteo using the activity's start coordinates and time to determine whether it rained.
  • Technical data: log data, device and browser information.

We do not collect or process heart rate data, even where available via Strava.

3. Why we collect it

  • To provide the core service: tracking component wear against your rides.
  • To sync and retrieve your activity data from Strava.
  • To improve and maintain the service.
  • To communicate with you about your account or service changes.

4. Legal basis

  • Performance of a contract: connecting Strava is required for the core service to function, as component wear tracking depends on your activity data. Without this connection, the platform cannot deliver its primary purpose.
  • Legitimate interest: service improvement, security, fraud prevention.
  • Consent: where processing is not required for core functionality (e.g. optional communications, connecting Strava itself).

5. Age restriction

RideSharp is intended for users aged 16 and over. We do not knowingly collect data from users under 16. If you believe a user under 16 has created an account, contact us so we can remove it.

6. Third parties and data processors

  • Strava: for activity data, under Strava's own API terms and privacy policy. We only retrieve data from Strava; we do not push or write data back.
  • Supabase: our database and backend hosting provider, hosted in Frankfurt, Germany (EU).
  • Open-Meteo: we send an activity's start coordinates and time to Open-Meteo to determine rain conditions. We do not send any other account or personal data to Open-Meteo.

We have data processing agreements in place with processors where required.

7. International data transfers

Our primary database is hosted in Frankfurt, Germany, within the EU. Data does not leave the EEA unless a specific processor requires it, in which case we rely on Standard Contractual Clauses.

8. Data retention

We retain your data for as long as your account is active. Accounts inactive for 720 days are automatically deleted, along with all associated data. If you delete your account manually, all your data, including builds, activities, bikes, and settings, is deleted immediately.

9. Automated processing

RideSharp may generate wear estimates and service alerts based on your activity data. These are informational only and do not produce legal or similarly significant effects on you. No automated decision-making under Art. 22 GDPR takes place.

10. Your rights

Under GDPR, you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Request a copy of your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact cdiepenhorst@gmail.com.

11. Right to complain

If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), independently of any contact with us.

12. Cookies and local storage

RideSharp uses cookies only during the Strava connection flow:

  • strava_oauth_state: CSRF and state verification.
  • strava_backfill_months: how many months of activity history to import.
  • strava_user: HMAC-signed user ID to link the callback to your account.
  • strava_app_origin: which origin to redirect back to after authorization.

These cookies are strictly necessary to complete the Strava OAuth process, so no consent banner is required. Regular sign-in and session management do not use cookies. They rely on localStorage via the Supabase client.

13. Changes to this policy

We may update this privacy statement. Users will be notified in-app when a new version is published.

14. Contact

Questions about this policy: cdiepenhorst@gmail.com.