MARS.RRRIDER

Privacy Policy

Last updated: 26 June 2026.

Data controller

Michael Aschauer EI, 9 rue des colonnes, 75002 Paris, France, is the data controller for personal data processed by rrrider. Contact: m [at] ash.to.

What we collect

  • Account: email address, display name, and — if you sign in with Google/GitHub — the basic profile those providers return. Passwords are stored only as salted hashes (better-auth).
  • Your training data: courses you create, saved rides/activities (route, time, power, heart rate, cadence), rider profile (FTP, weight, max HR) and app settings.
  • Connected integrations (optional): if you connect Strava or intervals.icu, we store the credentials (tokens / API key) you provide — encrypted at rest — so we can upload your activities on your behalf. You can disconnect them at any time, and they're deleted with your account.
  • Billing: handled by our payment processor Creem (merchant of record). We store only a customer reference and your subscription status — we never receive or store your card details.
  • Technical: a session cookie for authentication; minimal server logs.

Why, and the legal basis (GDPR)

  • Providing the Service and your account — performance of a contract.
  • Processing payments and preventing fraud — contract / legal obligation.
  • Transactional email (e.g. magic-link sign-in) — contract.
  • Securing and improving the Service — legitimate interests.

We do not sell your personal data, and we don't run third-party advertising trackers.

Processors & sub-processors

  • Creem — payments / merchant of record.
  • Hetzner — application + database hosting.

Map, imagery and terrain tiles are either served from our own cache/proxy (our infrastructure) or — depending on configuration — requested directly by your browser from the upstream source (e.g. NASA/USGS, Esri/ArcGIS, or the Cesium Ion CDN). In the direct case those providers receive your IP address and the tile request as part of ordinary web serving; rrrider sends them no account data.

Cookies

We use a single first-party session cookie for authentication. No advertising or cross-site tracking cookies.

Retention & your rights

Your data is kept while your account is active. You can export (GPX/FIT) and delete your data — including deleting your account (Account → Delete account), which removes your courses, rides, settings and subscription record. Under the GDPR you have the rights of access, rectification, erasure, restriction, portability and objection. Contact m [at] ash.to. You may also lodge a complaint with the French authority, the CNIL (cnil.fr).

Data location

Data is processed in the EU/EEA where possible. Where a processor operates outside the EEA, appropriate safeguards (e.g. Standard Contractual Clauses) apply.

Changes

We'll post updates here and note the date above; material changes will be notified in-app or by email.

See also the Terms of Service and Legal Notice.

TermsPrivacyLegal notice← Home
Contact | Terms | Privacy | Legal notice