Privacy Policy
This Privacy Policy describes how Trailo collects, uses, and protects the data you provide to us, particularly when using the Strava connection.
1. Data Collection
We collect information when you use our site, notably via cookies (managed by our partner Cookiebot) and when importing files or connecting to third-party services.
2. Use of Strava Data
Trailo offers the possibility to connect to your Strava account to import your activities. This process is designed to be as minimally intrusive as possible and to scrupulously respect your privacy.
a. Requested Permissions
When connecting, we only request the following permissions (scopes) via the secure OAuth protocol:
- read : General permission to read your public profile.
- activity:read_all : Permission to read your activities (metadata and data streams) to allow you to select them.
These permissions are read-only. Trailo does not have permission to modify, comment on, or delete your Strava activities.
b. Processing Workflow
The processing of your Strava data follows a strict and transparent workflow:
- Selection: You view the list of your recent activities (retrieved from Strava and displayed on your browser, without being stored on our server).
- GPX Generation: When you select an activity, our server contacts the Strava API to retrieve the data streams (latitude, longitude, altitude) for this specific activity.
- Creation of Temporary File: A GPX file is generated in memory from these streams, then temporarily saved on our server while the 3D generation is launched.
- 3D Generation: This temporary GPX file is used by our script to calculate the relief and generate the 3D models.
- Immediate Deletion: Once the generation task is complete (whether successful or failed), the temporary GPX file we created is immediately and automatically deleted from our server.
3. Data Storage and Sharing
Trailo does not store, retain, or archive any of your GPX activity data. The GPX file exists only for the time necessary to generate the 3D model, which is a few seconds to a few minutes.
Strava authentication tokens (access_token, refresh_token) are securely stored in your session (session cookie) and are only used to communicate with the Strava API. They expire and are destroyed when your session ends.
We do not share, sell, or analyze your activity data for purposes other than generating your personalized 3D model. The athlete ID (athlete_id) is used solely for authentication and is not stored.
4. Security
We take appropriate security measures to protect against unauthorized access or modification of your data. All communications with the Strava API and our server are encrypted via HTTPS.
5. Cookies
Our site uses cookies. Your consent management is handled via the Cookiebot platform. You can modify your preferences at any time via the cookie management panel.
6. Your Rights
In accordance with the GDPR, you have the right to access, rectify, and delete your personal data. Since we do not store your activity data, this right applies primarily to contact information you might provide us through other means. You can also revoke Trailo's access at any time from your Strava account settings.
7. Policy Amendments
These conditions may be modified at any time. It is the user's responsibility to consult them regularly.
8. Contact
For any questions regarding this privacy policy, you can contact us at the address [email protected].