Information We Collect
- Name, address, contact number, email, and emergency contact details during registration.
- Payment and transaction details (processed securely through our payment partners).
- If you connect Strava (optional): athlete profile information returned by Strava during OAuth authorization (such as Strava athlete ID, username, name, sex, city/state/country, profile photo URLs, weight, premium status, follower/friend counts, and measurement preference), and activity data we sync from Strava for your rides (such as activity ID, name, type/sport, distance, elevation, speed, moving/elapsed time, start time, location fields, map summary polyline, calories/watts where provided, device/gear identifiers, and related activity metadata used for tracking).
How We Use Information
- To manage event participation and communication.
- To send updates, ride information, and promotional messages (with your consent).
- Strava-connected data is used to sync your rides on an ongoing basis (including scheduled sync), calculate challenge progress and rider statistics, maintain your rider activity history, and show challenge leaderboards and related rankings on Royal Riders.
- We do not sell, trade, or rent your personal information to others.
Strava Authorization & Consent
- Connecting Strava is optional and requires you to be logged in to your Royal Riders rider account.
- You authorize Royal Riders through Strava’s OAuth consent screen. We request the Strava scope
activity:read_all so we can read your activities for challenge tracking.
- Data is collected from Strava only after you approve that authorization, via Strava’s OAuth token exchange and subsequent authenticated Strava API requests.
- You can withdraw Strava access at any time from your rider dashboard using Disconnect Strava, or by revoking the app in your Strava account settings. Disconnecting stops future sync and clears our stored Strava access/refresh tokens after we attempt to revoke authorization with Strava.
Storage & Security of Strava Data
- Strava access and refresh tokens are stored in our database encrypted at rest (application-level encryption). Encryption keys are kept in server configuration and are not exposed in this policy or to end users.
- Synced athlete and activity records are stored in our application database for the purposes described above.
- We follow industry standards to protect your data from unauthorized access. However, no online platform can guarantee 100% security.
Data Retention (Strava)
- While your Strava account remains connected, we retain synced athlete/activity data needed for daily tracking, challenges, statistics, and your rider history.
- If you disconnect Strava, we clear stored Strava tokens and mark the connection as disconnected so sync stops. Previously synced activity history and challenge-related results (such as statistics, leaderboard entries, and certificates derived from that history) remain in our systems unless you request deletion as described below.
Access to Your Data
- You can view your Strava connection status, synced activities, challenge progress, and related rider information in your Royal Riders rider account (for example, dashboard and activities areas).
- You can manage Strava authorization for this application in your Strava account as well.
Data Deletion Requests
- Disconnecting Strava alone does not automatically delete previously synced activity history or challenge results.
- To request deletion of Strava-related data we hold about you (or other personal data), email royalriders2911@gmail.com from the email associated with your rider account, and describe what you want deleted.
- We will process verified requests and send written confirmation when deletion has been completed.
Third-Party Sharing & Strava
- We use Strava as a third-party service to authenticate you and retrieve the athlete/activity data you authorize. Strava processes data under Strava’s own terms and privacy policy.
- We do not sell Strava data. Challenge leaderboards and public challenge pages may display rider names and challenge statistics derived from synced activity data to other participants and visitors of those pages.
- This Privacy Policy does not modify or supersede the Strava Privacy Policy. If there is a conflict regarding Strava’s handling of data on Strava’s platform, Strava’s Privacy Policy controls for that data.
- For developer/API rules applicable to our use of Strava’s API, see the Strava API Agreement and Strava API Policy (as published by Strava).
Data Security
- We follow industry standards to protect your data from unauthorized access.
- However, no online platform can guarantee 100% security.
Cookies
- Our website may use cookies to enhance your user experience.
Your Consent
- By using our website and registering, you consent to our Privacy Policy.
- By connecting Strava, you additionally consent to the Strava-related collection and uses described in this policy, subject to Strava’s authorization screen and Strava’s policies.
Contact
For any privacy concerns, contact us at:
royalriders2911@gmail.com