Back to home

Privacy policy

Last updated: September 26, 2026

BikeCheck is a small personal project: I built it to track wear on my own bikes, then opened it to other cyclists. This page explains, as plainly as I can, what data the site uses, why, who it is shared with, and how to have it deleted.

The French version of this page is the reference version.

In short

  • I only use the data needed to make BikeCheck work.
  • No ads, no audience analytics, no third-party trackers.
  • Your data is never sold, rented or handed over to anyone.
  • You can delete everything yourself, at any time, from the settings.

Who is responsible for your data?

The data controller is Nina Boulton, a private individual who publishes the BikeCheck site on a non-professional basis. For any question about your data: ninaboulton@icloud.com.

There is no Data Protection Officer (DPO): one isn't required for a project of this size, and I answer directly.

What data is used?

When you sign in with Strava, then as you use BikeCheck:

  • Your Strava profile: athlete ID, first and last name, profile picture URL.
  • Your Strava sign-in tokens (access and refresh) and their expiry date, used to fetch your rides.
  • Your bike rides imported from Strava: activity ID, name, date, distance, moving time, “indoor” flag (home trainer) and the bike used. No GPS track, heart rate or power data.
  • Your bikes registered on Strava (name and ID), to attach each ride to the right bike.
  • What you enter yourself: bikes, components, maintenance and costs, reminders, ride conditions (dry, rain…), notes.
  • Your email address, only if you choose to add it (Strava doesn't share it).
  • Your settings: language, theme, currency, home trainer type, alert preferences.
  • If you turn on notifications: the subscription address provided by your browser, its encryption keys and the browser/device type.
  • The history of alerts sent (which component, which level, by email or notification, when), so you never get the same alert twice.

If you write to me through the contact form: your email, your name if you give it, the category, subject and message. Your IP address is not stored as such: only a keyed hash (HMAC with a secret key) is kept, solely to limit abusive sending.

Like any website, the host also records technical logs (IP address, browser, requested pages) to run and secure the service.

When an error occurs, a technical report goes to my error-monitoring tool (Sentry): the error message and details, the page or address involved, browser and operating system — without cookies, authentication headers or URL parameters, which are removed before sending. Nothing records your screen or your clicks (no “session replay”).

Why, and on what legal basis?

  • Running the service (account, Strava sync, wear calculation, reminders, showing your data): performance of the contract, i.e. the terms of use you accept by creating your account (GDPR Article 6(1)(b)).
  • Securing the site and preventing abuse (sign-in session, protection of the Strava sign-in, rate limiting of contact messages, technical logs, error monitoring, database backups): legitimate interest in protecting the service and its users (Article 6(1)(f)).
  • Sending you wear alerts by email or notification, your maintenance reminders when they fall due (by notification, or by email when no device is subscribed), and the Monday weekly recap email (your km for the week, parts to watch, care and reminders due): your consent, given by adding your email or turning on notifications, and which you can withdraw at any time in the settings (email alerts also cover maintenance reminders); the recap can be turned off on its own (Article 6(1)(a)).
  • Answering your messages: legitimate interest in replying and following up on requests (Article 6(1)(f)).

No automated decision with legal effects on you is ever made. Wear figures are simple estimates to help you look after your bike.

Cookies and local storage

BikeCheck only uses strictly necessary cookies, which don't require consent:

  • bc_session: keeps you signed in. Lifetime: 7 days.
  • bc_oauth_state: protects the Strava sign-in against hijacking. Lifetime: 10 minutes.

The site also saves your language and currency in your browser's local storage so it can show them straight away. This information doesn't leave your device this way.

There are no advertising cookies, no analytics and no social media buttons. Your profile picture is displayed from Strava's servers.

Who else processes your data?

Nobody but me accesses your data, apart from the technical providers the service can't run without, acting on my behalf:

  • Vercel Inc. (United States): hosting of the site and the server.
  • Supabase: database, hosted in the European Union (Ireland region).
  • Resend (United States): sending emails (alerts, maintenance reminders, weekly recap, welcome email, contact messages).
  • Functional Software, Inc., the company behind Sentry (United States): error monitoring. Reports (technical error details, request information without cookies, authentication headers or URL parameters, no session replay) are stored in the European Union (Germany region).
  • GitHub, Inc. (United States): storage of the nightly database backups, encrypted before they are sent (GitHub can't read them) and kept for 30 days.
  • Browser push services (Apple, Google, Mozilla…), if you turn on notifications: they deliver the notification to your device. Its content is end-to-end encrypted.

Strava, Inc. (United States) is where your rides come from: BikeCheck fetches your data from Strava with your permission, but sends nothing back. BikeCheck is not affiliated with Strava.

Your data is never sold or used for advertising.

Transfers outside the European Union

Some providers (Vercel, Resend, Sentry, GitHub) and Strava are based in the United States. These transfers rely on the safeguards provided by the GDPR: certification under the EU–US Data Privacy Framework where the company participates, and/or the European Commission's standard contractual clauses.

How long?

  • Account data (profile, bikes, components, maintenance, reminders, rides, settings, notification subscriptions, alert history): as long as your account exists. When you delete your account (Settings → Delete my account), everything is erased from the database.
  • Data from Strava: if you revoke BikeCheck's access from your Strava account, the data imported from Strava is deleted from the database as soon as Strava confirms it, and at the latest 25 days after access was lost if you don't reconnect.
  • Backups: the database is backed up every night, and each encrypted backup is kept for 30 days. After you delete your account or revoke Strava access, your data may therefore remain in these backups for up to 30 days before being overwritten. They are only used to restore the service after a failure.
  • Error reports (Sentry): 90 days at most.
  • Contact messages: 12 months after they were sent.
  • Cookies: 7 days for the session, 10 minutes for the Strava sign-in.
  • Host technical logs: a short period set by the host.

Security

The site is served over HTTPS only, the session is a cookie JavaScript can't read, database access is restricted to the server, every record is tied to your account so no one else can see it, and backups are encrypted (AES-256) before they leave the database. No system is flawless: if an incident affected your data, I would let you know and report it to the CNIL (the French data protection authority) as the law requires.

Your rights

You have the following rights over your data at any time:

  • access: know what data I hold about you and get a copy;
  • rectification: correct inaccurate data (most of it can be edited directly in the app);
  • erasure: delete your account yourself from the settings, or ask me to;
  • portability: download all your data as a machine-readable JSON file with the “Export my data” button in the settings (or on request by email);
  • objection and restriction: object to processing based on legitimate interest, or ask for it to be paused;
  • withdrawing consent: turn off email alerts, the weekly recap or notifications in the settings;
  • post-mortem instructions: decide what happens to your data after your death (French data protection law).

To exercise these rights, write to me at ninaboulton@icloud.com or use the contact form. I reply within one month at most. I may ask you to confirm the account is yours, for example by writing from the email address saved in your settings.

If you feel your rights aren't respected, you can lodge a complaint with the CNIL: cnil.fr, or with the data protection authority of your own country.

Changes

This page may change along with the service. The last update date is shown at the top. If something important changes (a new provider, a new use of your data), I'll let you know in the app, or by email if you've added one.