Privacy Policy
Last updated: 26 June 2026.
Data controller
Michael Aschauer EI, 9 rue des colonnes, 75002 Paris, France, is the data controller for personal data processed by rrrider. Contact: m [at] ash.to.
What we collect
- Account: email address, display name, and — if you sign in with Google/GitHub — the basic profile those providers return. Passwords are stored only as salted hashes (better-auth).
- Your training data: courses you create, saved rides/activities (route, time, power, heart rate, cadence), rider profile (FTP, weight, max HR) and app settings.
- Connected integrations (optional): if you connect Strava or intervals.icu, we store the credentials (tokens / API key) you provide — encrypted at rest — so we can upload your activities on your behalf. You can disconnect them at any time, and they're deleted with your account.
- Billing: handled by our payment processor Creem (merchant of record). We store only a customer reference and your subscription status — we never receive or store your card details.
- Technical: a session cookie for authentication; minimal server logs.
Why, and the legal basis (GDPR)
- Providing the Service and your account — performance of a contract.
- Processing payments and preventing fraud — contract / legal obligation.
- Transactional email (e.g. magic-link sign-in) — contract.
- Securing and improving the Service — legitimate interests.
We do not sell your personal data, and we don't run third-party advertising trackers.
Processors & sub-processors
- Creem — payments / merchant of record.
- Hetzner — application + database hosting.
Map, imagery and terrain tiles are either served from our own cache/proxy (our infrastructure) or — depending on configuration — requested directly by your browser from the upstream source (e.g. NASA/USGS, Esri/ArcGIS, or the Cesium Ion CDN). In the direct case those providers receive your IP address and the tile request as part of ordinary web serving; rrrider sends them no account data.
Cookies
We use a single first-party session cookie for authentication. No advertising or cross-site tracking cookies.
Retention & your rights
Your data is kept while your account is active. You can export (GPX/FIT) and delete your data — including deleting your account (Account → Delete account), which removes your courses, rides, settings and subscription record. Under the GDPR you have the rights of access, rectification, erasure, restriction, portability and objection. Contact m [at] ash.to. You may also lodge a complaint with the French authority, the CNIL (cnil.fr).
Data location
Data is processed in the EU/EEA where possible. Where a processor operates outside the EEA, appropriate safeguards (e.g. Standard Contractual Clauses) apply.
Changes
We'll post updates here and note the date above; material changes will be notified in-app or by email.
See also the Terms of Service and Legal Notice.