Privacy Policy
Effective April 17, 2026
Peloton Manager ("we", "us") helps cycling clubs organize riders, roles, and event assignments. This page explains what we collect, why, and the controls you have. If anything here is unclear, email us at privacy@pelotonmanager.com.
1. What we collect
- Strava identity. When you click "Connect with Strava" we receive your Strava athlete ID, display name, profile photo, and the access/refresh tokens needed to read your activities.
- Activity data. With your permission we read your rides (distance, duration, elevation, power, heart rate, start time) to compute rider scores, match you to events, and suggest peloton assignments.
- Club membership. The clubs you create or join, the role you hold in each, and invite links you redeem.
- Operational data. Log entries (request paths, status codes, timing), crash reports, and audit trails for security-relevant actions.
2. How we use it
- Authenticate you and keep your session signed in.
- Show you the clubs you belong to and the role you hold.
- Score rides and suggest peloton groupings inside the clubs you are a member of.
- Send operational emails (invite acceptance, security alerts). We do not send marketing email.
- Detect and respond to abuse, fraud, and security incidents.
3. How we share it
We do not sell your data. We share it only with:
- Other members of the same club. Riders in a peloton see each other's name, role, and summary ride metrics relevant to assignments.
- Infrastructure providers. Microsoft Azure (hosting, database), Strava (the source of your ride data). These providers process data on our behalf under standard data-processing terms.
- Law enforcement, only when compelled by a valid legal process.
4. Strava data specifics
Peloton Manager complies with the Strava API Agreement. We only request the OAuth scopes we need (read activities, read profile). Your Strava tokens are stored encrypted at rest. You can revoke Peloton Manager's access at any time from your Strava app settings; we honour the revocation within one hour and remove cached activity data within seven days.
5. Retention
We keep active account data for as long as you use the service. If you delete your account, or if you are inactive for 24 months, we delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate security purposes (audit logs: 12 months).
6. Your rights
You can:
- Export your data (email us for a machine-readable archive).
- Correct inaccurate data (most fields are user-editable in the app).
- Delete your account (email us; self-serve deletion ships in a later phase).
- Withdraw Strava consent at any time from Strava's app-settings page.
If you are in the UK/EEA you also have GDPR rights including the right to lodge a complaint with your data protection authority. Our UK representative for GDPR correspondence is available on request.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. We use row-level security in Postgres to isolate each club's data, and OAuth tokens are stored with an application-level encryption key. We have no direct access to your Strava password.
8. Changes
Material changes to this policy will be announced via an in-app banner at least 30 days before they take effect. Minor clarifications may be made without notice.
9. Contact
Privacy questions: privacy@pelotonmanager.com