Privacy Policy

This Privacy Policy describes how Trailo collects, uses, and protects the data you provide to us, particularly when using the Strava connection.

1. Data Collection

We collect information when you use our site, notably via cookies (managed by our partner Cookiebot) and when importing files or connecting to third-party services.

2. Use of Strava Data

Trailo offers the possibility to connect to your Strava account to import your activities. This process is designed to be as minimally intrusive as possible and to scrupulously respect your privacy.

a. Requested Permissions

When connecting, we only request the following permissions (scopes) via the secure OAuth protocol:

These permissions are read-only. Trailo does not have permission to modify, comment on, or delete your Strava activities.

b. Processing Workflow

The processing of your Strava data follows a strict and transparent workflow:

  1. Selection: You view the list of your recent activities (retrieved from Strava and displayed on your browser, without being stored on our server).
  2. GPX Generation: When you select an activity, our server contacts the Strava API to retrieve the data streams (latitude, longitude, altitude) for this specific activity.
  3. Creation of Temporary File: A GPX file is generated in memory from these streams, then temporarily saved on our server while the 3D generation is launched.
  4. 3D Generation: This temporary GPX file is used by our script to calculate the relief and generate the 3D models.
  5. Immediate Deletion: Once the generation task is complete (whether successful or failed), the temporary GPX file we created is immediately and automatically deleted from our server.

3. Data Storage and Sharing

Trailo does not store, retain, or archive any of your GPX activity data. The GPX file exists only for the time necessary to generate the 3D model, which is a few seconds to a few minutes.

Strava authentication tokens (access_token, refresh_token) are securely stored in your session (session cookie) and are only used to communicate with the Strava API. They expire and are destroyed when your session ends.

We do not share, sell, or analyze your activity data for purposes other than generating your personalized 3D model. The athlete ID (athlete_id) is used solely for authentication and is not stored.

4. Security

We take appropriate security measures to protect against unauthorized access or modification of your data. All communications with the Strava API and our server are encrypted via HTTPS.

5. Cookies

Our site uses cookies. Your consent management is handled via the Cookiebot platform. You can modify your preferences at any time via the cookie management panel.

6. Your Rights

In accordance with the GDPR, you have the right to access, rectify, and delete your personal data. Since we do not store your activity data, this right applies primarily to contact information you might provide us through other means. You can also revoke Trailo's access at any time from your Strava account settings.

7. Policy Amendments

These conditions may be modified at any time. It is the user's responsibility to consult them regularly.

8. Contact

For any questions regarding this privacy policy, you can contact us at the address [email protected].