Ridden

Privacy policy

What personal data we process, why we process it, how long we retain it, and how you have it erased.

Last updated 24 August 2026

1. Controller

BRAMCO BV, a company incorporated in Belgium, is the controller for the processing described in this policy. Our particulars appear in the legal notice.

Requests concerning personal data may be addressed to bram@ridden.io.

2. Summary

  • Ridden tells you when a professional race climbs a road you have ridden.
  • To do so we read your Strava activities when you connect, and again when you record a new ride. We match them against our own catalog and retain the match, not the ride.
  • No data sourced from Strava is stored in our database. Not routes, not times, not ride names.
  • We do not disclose one user's data to another user.
  • We do not use your data in any artificial intelligence system.
  • We do not sell data, and we operate no advertising and no third-party tracking.

3. Categories of data processed

The following is exhaustive. Data not listed here is not held, including your name, your photograph, your postal address and your payment card details.

CategoryPurpose
Email addressIdentifies the account, and is the address alerts are sent to.
Password verifier, where a password is setAuthentication. Stored only as a salted, memory-hard derivation, never as the password itself.
Strava athlete identifier, where Strava is connectedAssociates your Strava athlete with your Ridden account.
Strava access and refresh tokens, encryptedPermits us to read your activities. Encrypted at rest.
Country, time zone and languageTo deliver an alert at the correct local time and to indicate the broadcaster in your territory.
Which catalog climbs you have riddenOur own derived record: the climb, the date last ridden, a count, and a single Strava activity identifier used to retrieve your time at the moment an alert is composed.
Reminders and queued alertsTo dispatch the correct message at the correct time, once.
Push subscriptions for devices on which you installed RiddenThe endpoint supplied by your browser for delivery. It identifies no person.
Email dispatch logSubject and outcome only, to evidence single delivery. No message body.
Sign-in tokens, as hashesSingle-use authentication links, stored as hashes and never as the link.
Ridden Pass statusWhether a pass is active and its origin. Payment is processed by Paddle and no card data reaches us.

4. Strava data

This section addresses the four questions put by Strava's API review, in order.

What we access

With your authorisation we read your activity list and each activity's route, in order to determine which climbs in our catalog you have ridden. We request the minimum scopes necessary: your basic profile and your activities. Access to activities marked private requires a separate scope, which is disabled unless you enable it and may be disabled again at any time.

When an alert is composed we retrieve your recorded time on that single climb, use it in the message, and discard it.

What we do with it

Routes are compared against our catalog. Where a route covers a climb, we write a single derived record: that this user has ridden that climb. Route geometry, speed, heart rate and activity names are used for the comparison and then discarded.

We never use Strava data to:

  • disclose anything concerning you to another user, in any form;
  • train, prompt or evaluate any artificial intelligence or machine learning system;
  • construct advertising profiles, or to sell or share data with any third party.

How long we keep it

No data sourced from Strava is persisted in our database. Activities are read, matched and discarded within the same processing job, which is substantially inside the seven days permitted by Strava's API terms. What is retained is our own derived record: the climb, the date, a count, and one activity identifier.

How you get rid of it

Strava may be disconnected in settings. Doing so erases our copy of your tokens, suspends alerts and terminates our access. You may equally revoke Ridden from within Strava, which notifies us and triggers the same erasure.

To erase the account and all data derived from it, write to bram@ridden.io. We complete erasure within thirty days, retaining only a hashed record that an erasure occurred, from which you cannot be identified.

5. Lawful bases

Performance of a contract (Article 6(1)(b))
Your account, the climb matches, reminders and alerts. Without these there is no service.
Consent (Article 6(1)(a))
Access to private activities, and any email that is not a service message you requested. Consent may be withdrawn as readily as it is given.
Legitimate interests (Article 6(1)(f))
Maintaining the security and integrity of the service, and measuring product usage. Usage measurement carries our own identifiers only and never data derived from Strava.
Legal obligation (Article 6(1)(c))
Retention of transaction records required by tax law. These are held by Paddle.

6. Retention

CategoryRetention period
Data sourced from StravaNot stored. Processed within a single job and discarded.
Account and derived climb recordsUntil the account is erased.
Strava tokensUntil disconnection, or until Strava notifies us of revocation.
Sign-in tokensMinutes to days according to type. Single use.
Email dispatch logFor the life of the account, then erased with it.
Erasure recordA hash and a date, retained as evidence of erasure.
InvoicesRetained by Paddle for the period required by tax law.

7. Recipients and processors

The following process personal data on our instructions, or as independent controllers where stated. There are no others.

RecipientPurposeLocation
RailwayApplication hosting and database.United States. Transfers outside the EEA are made under the safeguards in the provider's data processing agreement, including standard contractual clauses.
StravaSource of the activity data we match. Strava is an independent controller of your Strava account under its own privacy policy.United States, under the safeguards in Strava's own terms.
ResendEmail delivery.European Union, eu-west-1.
PaddleSale of the Ridden Pass. Paddle is the merchant of record and an independent controller in respect of the transaction, including payment data, which does not reach us.United Kingdom (Paddle.com Market Ltd), the subject of a European Commission adequacy decision.

8. Cookies

Two cookies are set, both first party: a signed session cookie that maintains your sign-in, and a cookie recording your language preference. No advertising cookie, no analytics cookie and no third-party cookie is set. Consent is accordingly not required and no banner is displayed.

9. Your rights

Under the GDPR you have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of legitimate interests. Requests may be sent to bram@ridden.io and are answered within one month.

Several of these are exercisable directly in settings: disconnecting Strava, disabling either alert, and changing your language.

You have the right to lodge a complaint with the Belgian supervisory authority, the Gegevensbeschermingsautoriteit or Autorité de protection des données, at dataprotectionauthority.be.

10. Children

The service is not directed at persons under 13, which is also Strava's minimum age. Where we are informed that an account belongs to a child under 13, it is erased.

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure and loss, as required by Article 32 of the GDPR. These include encryption of credentials at rest, encryption in transit, storage of authentication secrets in derived or hashed form only, segregation of secrets from the database, and restriction of administrative access.

Two properties are enforced in the application itself rather than by policy: no data sourced from Strava is written to our database, and no user's data is disclosed to another user.

Reporting a problem

Suspected vulnerabilities may be reported to bram@ridden.io, which is also the address published in our security.txt. Please describe what you found, how to reproduce it, and the impact you believe it has. We acknowledge reports within five working days.

We will not pursue action against researchers acting in good faith, which we take to mean testing only against your own account, not accessing or retaining the data of others, not degrading the service, not attempting social engineering, and allowing a reasonable period, ordinarily 90 days, before publication.

Strava, Paddle, Railway and our email provider operate their own disclosure programmes and are out of scope. Where an issue affects Ridden users, please inform us as well.

Personal data breaches

Where a personal data breach occurs, we inform the Belgian supervisory authority within 72 hours of becoming aware of it, and inform affected users where the breach is likely to result in a high risk to their rights and freedoms.

12. Changes to this policy

We may amend this policy. Where an amendment is material, we will give notice in the application or by email before it takes effect. The date above states when this version came into force.