Privacy Policy

Last updated: March 2026

What data we collect

When you connect your Strava account, we access:

How we use your data

We do not use your data for advertising, profiling, AI/ML training, or any purpose other than crossing detection and notifications.

Data retention

In compliance with Strava's API Agreement:

Data sharing

We do not sell, rent, or share your personal data with any third parties. Your data is only used within this application for crossing detection.

Your rights

You have the right to:

When you disconnect or revoke access, all your personal data (activities, GPS streams, crossing events, and tokens) is permanently deleted.

Security

All data is transmitted over HTTPS. OAuth tokens are encrypted at rest using Fernet symmetric encryption. We do not store your Strava password.

GDPR

If you are in the European Economic Area, we process your data based on your explicit consent when you connect your Strava account. You can withdraw consent at any time by disconnecting your account.

Cookies

We use a single session cookie to keep you logged in. We do not use tracking cookies or analytics.

Changes to this policy

We may update this policy from time to time. Significant changes will be communicated through the application.

Contact

For privacy-related questions, email support@pro-pathcrossings.app.