Privacy Policy
This Privacy Policy explains how Panaride collects, uses, stores and shares information when you use the Panaride cycling app, public profile and share pages, account deletion pages, and related backend services.
Information We Collect
The exact data depends on the features you use. Panaride may process:
- account and profile information, including your sign-in identifier, email address, display name, username, avatar, language, region and profile visibility settings;
- ride and location data, including precise GPS points, route geometry, speed, altitude, accuracy, timestamps, start and finish coordinates, and reverse-geocoded addresses;
- health and fitness data when you choose to connect health features, including workouts, distance, speed, elevation, calories, heart-rate values, heart-rate zones, workout routes and device/source metadata;
- Bluetooth sensor data when you connect a heart-rate monitor or similar cycling sensor during a ride;
- photos, avatars, trip images, route photos, GPX files and other content you upload or generate in the app;
- device, diagnostics and usage data, including device identifiers, Firebase installation identifiers, FCM tokens, app version, operating system, crash logs, performance data, screen views and product events;
- public sharing data, including share tokens, public profile data, public trip/route pages, view counters and abuse-prevention signals such as IP address and User-Agent.
Sources of Personal Information
We collect personal information from the following sources:
- Directly from you — for example your email address when you sign in with a one-time email code, and information you provide when you create an account, edit your profile, upload photos or GPX files, or contact support;
- Automatically from your device and sensors — for example precise GPS location, motion/barometer-derived altitude inputs, Bluetooth heart-rate sensor readings, device identifiers, app version and diagnostics while you use the app;
- From your sign-in providers — when you use Sign in with Apple or Google sign-in, we receive the account identifier and, where you allow it, your email address and name;
- Generated by your use of the app — for example ride metrics, calculated statistics, achievements, share tokens, view counters and product usage events.
Location and Background Recording
Panaride is a cycling ride recorder. When you explicitly start a ride, the app may collect precise location in the foreground and in the background so the route, distance, speed, elevation, GPX export and ride history remain accurate while the phone is locked, minimized or in your pocket. You can stop recording in the app and can change location permissions in your device settings. Location is not used for advertising.
Health, Fitness and Sensors
Health integrations are optional. If you connect Apple Health, Google Health Connect or a Bluetooth heart-rate sensor, Panaride uses the permitted data only for cycling, fitness, import/export, statistics and related app functionality. Health and fitness data is not used for advertising and is not sold to data brokers. You can disconnect health integrations in the app or in system settings.
How We Use Information
- to create and maintain your account and sync your ride history;
- to record rides, calculate metrics, show maps, import/export workouts and create GPX files;
- to provide public profile, trip and route sharing when you choose to enable those features;
- to send service notifications and push notifications where permitted;
- to protect the service from abuse, debug issues, improve performance and understand feature usage;
- to comply with legal obligations and process account deletion requests.
No Ads and No Sale of Personal Information
Panaride does not show ads and does not use an advertising SDK. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Your location, health and fitness data is never sold to data brokers or used to build advertising profiles.
Public Sharing
If you make a profile, trip or route visible by link or publicly visible, people with the link may see the information shown on that page. This can include your display name, username, avatar, cycling metrics, route geometry, achievements, photos and view count. Panaride supports privacy settings and start/finish hiding for shared rides, but you should share only content you are comfortable making visible to others.
Service Providers and Processors
Panaride uses service providers ("processors") to operate the app. Depending on the features you use and your region, these may include:
- Hosting, database and storage — DigitalOcean (managed compute, managed PostgreSQL and object storage in a European Union region, Frankfurt, Germany). During a limited migration window (no longer than 60 days) backup and archival copies may also remain with our previous providers (Yandex Cloud, Russia; DigitalOcean, US region) and are deleted afterwards.
- Background location recording — Transistorsoft (background-geolocation SDK). It processes precise location on your device to keep the ride track accurate; it does not use your location for advertising.
- Authentication, analytics, diagnostics, configuration and push — Firebase / Google (Sign-in, Analytics, Crashlytics, Performance, Remote Config and Cloud Messaging).
- Sign-in and health platforms — Apple (Sign in with Apple, HealthKit) and Google Health Connect. The app reads or writes health data only after you grant permission.
- Maps, routing and geocoding — Mapbox (maps, static map images and reverse geocoding) and GraphHopper (route planning and geocoding).
- Push delivery — Apple Push Notification service and Firebase Cloud Messaging.
- Email — our email provider, used to send account-deletion and security emails.
Server data is primarily hosted in Germany (European Union). Data may also be processed in the United States (Google, Apple, Mapbox), the European Economic Area, Hong Kong (operator), and, during the migration window described above, Russia. Providers may act as our service providers or contractors and are permitted to use your data only to provide their services to us.
Storage and Deletion
Panaride stores account, ride, route, media and operational data for as long as needed to provide the service, maintain security, meet legal obligations and support the choices you make in the app. You can request account deletion in the app or on the web at panaride.app/account/delete. Account deletion removes the main account and associated backend records according to the deletion flow, while some logs, analytics events, backups or provider records may remain for limited operational or legal periods. Per-category retention periods are set out in the "Categories of Personal Information We Collect" table below.
Automated Decision-Making
Panaride does not use automated decision-making technology (ADMT) to make decisions that produce legal or similarly significant effects about you. Our algorithms are limited to calculating ride metrics (such as distance, speed, elevation, calories and heart-rate zones) and related statistics from the data your rides generate. We do not use this processing to profile you for advertising, eligibility, pricing or similar consequential decisions.
Security
We use reasonable technical and organizational measures to protect your information. These include encryption of data in transit (TLS), access controls and authentication for our systems, and hosting in a European Union (Frankfurt) region of our infrastructure provider. No method of transmission or storage is completely secure, so while we work to protect your information, we cannot promise absolute security.
Your Choices
- change or revoke device permissions for location, Bluetooth, health, photos, camera and notifications;
- change profile, statistics and sharing visibility settings in the app;
- disconnect health integrations and delete imported health data where the app provides that control;
- delete your account through the app or web deletion flow;
- contact us to request access, correction, deletion or clarification.
Your California Privacy Rights
This section applies to residents of California and describes your rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). It supplements the rest of this policy.
Notice at Collection — Categories of Personal Information We Collect
The table below maps the information we collect to the statutory CCPA categories, and states the business purpose and retention period for each category. We collect these categories from the sources described in "Sources of Personal Information" above.
| CCPA category | Examples of what we collect | Business purpose | Retention |
|---|---|---|---|
| Identifiers | Sign-in identifier, backend user ID, email address, display name, username, device identifiers, Firebase installation/analytics identifiers, FCM token. | Create and maintain your account, authenticate you, sync your data, deliver push notifications, prevent abuse. | Account, profile and FCM/notification tokens are kept while your account is active and are deleted when you delete your account. |
| Internet or other electronic network activity | App interactions, screen views, ride lifecycle and share/route/profile events, crash logs, performance and diagnostics data. | Operate, secure, debug and improve the app; understand feature usage. | Our own product analytics events (stored on our servers and linked to your account) currently have no fixed limit (we plan to introduce one) and are deleted or de-identified when you delete your account. Third-party analytics and crash data (Firebase) are retained per the provider's periods. Backend routing/diagnostics logs (IP address plus user ID) currently have no fixed limit; we plan to introduce one. |
| Geolocation data (precise) | Precise GPS points, start and finish coordinates, route geometry, speed, heading, accuracy, altitude and reverse-geocoded addresses from your rides. | Record rides, calculate metrics, show maps, import/export GPX, provide navigation and sharing when you enable it. | Ride and route data is kept while your account is active and is deleted when you delete your account. Map-coverage tile caches are kept for up to 365 days. |
| Biometric / health information (sensitive) | Workouts, distance, speed, elevation, calories, heart-rate values, heart-rate zones and source metadata when you connect Apple Health, Google Health Connect or a Bluetooth heart-rate sensor. | Provide cycling, fitness, import/export and statistics functionality you request. | Kept while your account is active and deleted when you delete your account; you can also disconnect or delete imported health data in the app at any time. |
| Audio / visual information | Avatars, trip images, route photos and poster images you upload or generate. | Display your profile, rides, routes and shared content that you choose to create. | Kept while your account is active and deleted when you delete your account. |
| Commercial information / inferences | We do not sell products through the app and do not build advertising or marketing profiles. We generate only ride-derived metrics and statistics (for example calories and heart-rate zones) shown back to you. | Show you your own ride statistics and achievements. Not used to profile you for advertising or consequential decisions. | These metrics are stored as part of your ride and account data and are deleted when you delete your account. |
In addition to the periods above: database backups are retained for up to 7 days; notification-delivery history is kept for audit purposes, with the personal association removed when you delete your account. Where a category currently has no fixed limit, we keep it only as long as needed for the stated purpose and plan to set explicit limits.
Sensitive Personal Information
Precise geolocation and health/fitness data are treated as Sensitive Personal Information (SPI) under the CCPA/CPRA. We use SPI only to provide the service you request — recording and showing your rides, metrics, maps and health features. We do not use SPI to infer characteristics about you, and we do not use it for any purpose beyond those permitted for providing the requested service. Because of this, the CCPA/CPRA does not require us to offer a separate "Limit the Use of My Sensitive Personal Information" link, and we do not provide one. If we ever use SPI for a secondary purpose that triggers this requirement, we will provide that link and update this policy.
Your Rights
If you are a California resident, you have the right to:
- Know / Access — request the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it;
- Delete — request deletion of personal information we have collected from you, subject to legal exceptions;
- Correct — request correction of inaccurate personal information;
- Opt out of the sale or sharing of your personal information (see below — we do not sell or share it);
- Limit the use of your Sensitive Personal Information (see above — not applicable, as we use SPI only to provide the requested service);
- Non-discrimination — you will not receive discriminatory treatment for exercising any of these rights.
How to Submit a Request
You can submit a request using either of these methods:
- email us at info@panaridesport.com; or
- use the in-app privacy controls and the account deletion flow, in the app or on the web at panaride.app/account/delete.
We will acknowledge your request within 10 business days and respond within 45 calendar days. If we need more time, we may extend the period by up to another 45 days and will let you know. We will act on a valid opt-out request within 15 business days. We may need to verify your identity before completing certain requests, and an authorized agent may submit a request on your behalf with proof of authorization.
Do Not Sell or Share; Global Privacy Control
We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. Because we do not sell or share your personal information, no opt-out of sale or sharing is required. Some browsers or extensions send a Global Privacy Control (GPC) signal; since we do not sell or share personal information, there is no sale or sharing to opt out of, and receiving a GPC signal does not change how we handle your data. If our practices ever change, we will honor GPC signals as an opt-out preference and update this policy.
Non-Discrimination
We will not discriminate against you for exercising any of your California privacy rights. We will not deny you our services, charge you a different price, or provide you a different level or quality of service because you exercised your rights.
Children
Panaride is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you are under the age of majority in your jurisdiction, use Panaride only with permission from a parent or guardian. If you believe a child under 13 has provided us personal information, contact us at info@panaridesport.com and we will delete it.
Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" at the top of this page. If we make a material change, we will provide additional notice in the app or by other appropriate means before the change takes effect. Your continued use of Panaride after an update becomes effective means you accept the updated policy.
Contact
For privacy questions or data requests, contact us at info@panaridesport.com.