Privacy Policy

Effective April 17, 2026

Peloton Manager ("we", "us") helps cycling clubs organize riders, roles, and event assignments. This page explains what we collect, why, and the controls you have. If anything here is unclear, email us at privacy@pelotonmanager.com.

1. What we collect

2. How we use it

3. How we share it

We do not sell your data. We share it only with:

4. Strava data specifics

Peloton Manager complies with the Strava API Agreement. We only request the OAuth scopes we need (read activities, read profile). Your Strava tokens are stored encrypted at rest. You can revoke Peloton Manager's access at any time from your Strava app settings; we honour the revocation within one hour and remove cached activity data within seven days.

5. Retention

We keep active account data for as long as you use the service. If you delete your account, or if you are inactive for 24 months, we delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate security purposes (audit logs: 12 months).

6. Your rights

You can:

If you are in the UK/EEA you also have GDPR rights including the right to lodge a complaint with your data protection authority. Our UK representative for GDPR correspondence is available on request.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest. We use row-level security in Postgres to isolate each club's data, and OAuth tokens are stored with an application-level encryption key. We have no direct access to your Strava password.

8. Changes

Material changes to this policy will be announced via an in-app banner at least 30 days before they take effect. Minor clarifications may be made without notice.

9. Contact

Privacy questions: privacy@pelotonmanager.com