Privacy policy
What personal data we process, why we process it, how long we retain it, and how you have it erased.
1. Controller
BRAMCO BV, a company incorporated in Belgium, is the controller for the processing described in this policy. Our particulars appear in the legal notice.
Requests concerning personal data may be addressed to bram@ridden.io.
2. Summary
- Ridden tells you when a professional race climbs a road you have ridden.
- To do so we read your Strava activities when you connect, and again when you record a new ride. We match them against our own catalog and retain the match, not the ride.
- No data sourced from Strava is stored in our database. Not routes, not times, not ride names.
- We do not disclose one user's data to another user.
- We do not use your data in any artificial intelligence system.
- We do not sell data, and we operate no advertising and no third-party tracking.
3. Categories of data processed
The following is exhaustive. Data not listed here is not held, including your name, your photograph, your postal address and your payment card details.
| Category | Purpose |
|---|---|
| Email address | Identifies the account, and is the address alerts are sent to. |
| Password verifier, where a password is set | Authentication. Stored only as a salted, memory-hard derivation, never as the password itself. |
| Strava athlete identifier, where Strava is connected | Associates your Strava athlete with your Ridden account. |
| Strava access and refresh tokens, encrypted | Permits us to read your activities. Encrypted at rest. |
| Country, time zone and language | To deliver an alert at the correct local time and to indicate the broadcaster in your territory. |
| Which catalog climbs you have ridden | Our own derived record: the climb, the date last ridden, a count, and a single Strava activity identifier used to retrieve your time at the moment an alert is composed. |
| Reminders and queued alerts | To dispatch the correct message at the correct time, once. |
| Push subscriptions for devices on which you installed Ridden | The endpoint supplied by your browser for delivery. It identifies no person. |
| Email dispatch log | Subject and outcome only, to evidence single delivery. No message body. |
| Sign-in tokens, as hashes | Single-use authentication links, stored as hashes and never as the link. |
| Ridden Pass status | Whether a pass is active and its origin. Payment is processed by Paddle and no card data reaches us. |
4. Strava data
This section addresses the four questions put by Strava's API review, in order.
What we access
With your authorisation we read your activity list and each activity's route, in order to determine which climbs in our catalog you have ridden. We request the minimum scopes necessary: your basic profile and your activities. Access to activities marked private requires a separate scope, which is disabled unless you enable it and may be disabled again at any time.
When an alert is composed we retrieve your recorded time on that single climb, use it in the message, and discard it.
What we do with it
Routes are compared against our catalog. Where a route covers a climb, we write a single derived record: that this user has ridden that climb. Route geometry, speed, heart rate and activity names are used for the comparison and then discarded.
We never use Strava data to:
- disclose anything concerning you to another user, in any form;
- train, prompt or evaluate any artificial intelligence or machine learning system;
- construct advertising profiles, or to sell or share data with any third party.
How long we keep it
No data sourced from Strava is persisted in our database. Activities are read, matched and discarded within the same processing job, which is substantially inside the seven days permitted by Strava's API terms. What is retained is our own derived record: the climb, the date, a count, and one activity identifier.
How you get rid of it
Strava may be disconnected in settings. Doing so erases our copy of your tokens, suspends alerts and terminates our access. You may equally revoke Ridden from within Strava, which notifies us and triggers the same erasure.
To erase the account and all data derived from it, write to bram@ridden.io. We complete erasure within thirty days, retaining only a hashed record that an erasure occurred, from which you cannot be identified.
5. Lawful bases
- Performance of a contract (Article 6(1)(b))
- Your account, the climb matches, reminders and alerts. Without these there is no service.
- Consent (Article 6(1)(a))
- Access to private activities, and any email that is not a service message you requested. Consent may be withdrawn as readily as it is given.
- Legitimate interests (Article 6(1)(f))
- Maintaining the security and integrity of the service, and measuring product usage. Usage measurement carries our own identifiers only and never data derived from Strava.
- Legal obligation (Article 6(1)(c))
- Retention of transaction records required by tax law. These are held by Paddle.
6. Retention
| Category | Retention period |
|---|---|
| Data sourced from Strava | Not stored. Processed within a single job and discarded. |
| Account and derived climb records | Until the account is erased. |
| Strava tokens | Until disconnection, or until Strava notifies us of revocation. |
| Sign-in tokens | Minutes to days according to type. Single use. |
| Email dispatch log | For the life of the account, then erased with it. |
| Erasure record | A hash and a date, retained as evidence of erasure. |
| Invoices | Retained by Paddle for the period required by tax law. |
7. Recipients and processors
The following process personal data on our instructions, or as independent controllers where stated. There are no others.
| Recipient | Purpose | Location |
|---|---|---|
| Railway | Application hosting and database. | United States. Transfers outside the EEA are made under the safeguards in the provider's data processing agreement, including standard contractual clauses. |
| Strava | Source of the activity data we match. Strava is an independent controller of your Strava account under its own privacy policy. | United States, under the safeguards in Strava's own terms. |
| Resend | Email delivery. | European Union, eu-west-1. |
| Paddle | Sale of the Ridden Pass. Paddle is the merchant of record and an independent controller in respect of the transaction, including payment data, which does not reach us. | United Kingdom (Paddle.com Market Ltd), the subject of a European Commission adequacy decision. |
8. Cookies
Two cookies are set, both first party: a signed session cookie that maintains your sign-in, and a cookie recording your language preference. No advertising cookie, no analytics cookie and no third-party cookie is set. Consent is accordingly not required and no banner is displayed.
9. Your rights
Under the GDPR you have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of legitimate interests. Requests may be sent to bram@ridden.io and are answered within one month.
Several of these are exercisable directly in settings: disconnecting Strava, disabling either alert, and changing your language.
You have the right to lodge a complaint with the Belgian supervisory authority, the Gegevensbeschermingsautoriteit or Autorité de protection des données, at dataprotectionauthority.be.
10. Children
The service is not directed at persons under 13, which is also Strava's minimum age. Where we are informed that an account belongs to a child under 13, it is erased.
11. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure and loss, as required by Article 32 of the GDPR. These include encryption of credentials at rest, encryption in transit, storage of authentication secrets in derived or hashed form only, segregation of secrets from the database, and restriction of administrative access.
Two properties are enforced in the application itself rather than by policy: no data sourced from Strava is written to our database, and no user's data is disclosed to another user.
Reporting a problem
Suspected vulnerabilities may be reported to bram@ridden.io, which is also the address published in our security.txt. Please describe what you found, how to reproduce it, and the impact you believe it has. We acknowledge reports within five working days.
We will not pursue action against researchers acting in good faith, which we take to mean testing only against your own account, not accessing or retaining the data of others, not degrading the service, not attempting social engineering, and allowing a reasonable period, ordinarily 90 days, before publication.
Strava, Paddle, Railway and our email provider operate their own disclosure programmes and are out of scope. Where an issue affects Ridden users, please inform us as well.
Personal data breaches
Where a personal data breach occurs, we inform the Belgian supervisory authority within 72 hours of becoming aware of it, and inform affected users where the breach is likely to result in a high risk to their rights and freedoms.
12. Changes to this policy
We may amend this policy. Where an amendment is material, we will give notice in the application or by email before it takes effect. The date above states when this version came into force.