Privacy Policy

Effective date: July 26, 2026

Operator: Panaride Sport Limited, Room 5003, 5/F YAU LEE CENTRE, 45 HOI YUEN ROAD, KWUN TONG, Hong Kong.

This Privacy Policy explains how Panaride collects, uses, stores and shares information when you use the Panaride cycling app, public profile and share pages, account deletion pages, and related backend services.

Information We Collect

The exact data depends on the features you use. Panaride may process:

Sources of Personal Information

We collect personal information from the following sources:

Location and Background Recording

Panaride is a cycling ride recorder. When you explicitly start a ride, the app may collect precise location in the foreground and in the background so the route, distance, speed, elevation, GPX export and ride history remain accurate while the phone is locked, minimized or in your pocket. You can stop recording in the app and can change location permissions in your device settings. Location is not used for advertising.

Health, Fitness and Sensors

Health integrations are optional. If you connect Apple Health, Google Health Connect or a Bluetooth heart-rate sensor, Panaride uses the permitted data only for cycling, fitness, import/export, statistics and related app functionality. Health and fitness data is not used for advertising and is not sold to data brokers. You can disconnect health integrations in the app or in system settings.

How We Use Information

No Ads and No Sale of Personal Information

Panaride does not show ads and does not use an advertising SDK. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Your location, health and fitness data is never sold to data brokers or used to build advertising profiles.

Public Sharing

If you make a profile, trip or route visible by link or publicly visible, people with the link may see the information shown on that page. This can include your display name, username, avatar, cycling metrics, route geometry, achievements, photos and view count. Panaride supports privacy settings and start/finish hiding for shared rides, but you should share only content you are comfortable making visible to others.

Service Providers and Processors

Panaride uses service providers ("processors") to operate the app. Depending on the features you use and your region, these may include:

Server data is primarily hosted in Germany (European Union). Data may also be processed in the United States (Google, Apple, Mapbox), the European Economic Area, Hong Kong (operator), and, during the migration window described above, Russia. Providers may act as our service providers or contractors and are permitted to use your data only to provide their services to us.

Storage and Deletion

Panaride stores account, ride, route, media and operational data for as long as needed to provide the service, maintain security, meet legal obligations and support the choices you make in the app. You can request account deletion in the app or on the web at panaride.app/account/delete. Account deletion removes the main account and associated backend records according to the deletion flow, while some logs, analytics events, backups or provider records may remain for limited operational or legal periods. Per-category retention periods are set out in the "Categories of Personal Information We Collect" table below.

Automated Decision-Making

Panaride does not use automated decision-making technology (ADMT) to make decisions that produce legal or similarly significant effects about you. Our algorithms are limited to calculating ride metrics (such as distance, speed, elevation, calories and heart-rate zones) and related statistics from the data your rides generate. We do not use this processing to profile you for advertising, eligibility, pricing or similar consequential decisions.

Security

We use reasonable technical and organizational measures to protect your information. These include encryption of data in transit (TLS), access controls and authentication for our systems, and hosting in a European Union (Frankfurt) region of our infrastructure provider. No method of transmission or storage is completely secure, so while we work to protect your information, we cannot promise absolute security.

Your Choices

Your California Privacy Rights

This section applies to residents of California and describes your rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). It supplements the rest of this policy.

Notice at Collection — Categories of Personal Information We Collect

The table below maps the information we collect to the statutory CCPA categories, and states the business purpose and retention period for each category. We collect these categories from the sources described in "Sources of Personal Information" above.

CCPA category Examples of what we collect Business purpose Retention
Identifiers Sign-in identifier, backend user ID, email address, display name, username, device identifiers, Firebase installation/analytics identifiers, FCM token. Create and maintain your account, authenticate you, sync your data, deliver push notifications, prevent abuse. Account, profile and FCM/notification tokens are kept while your account is active and are deleted when you delete your account.
Internet or other electronic network activity App interactions, screen views, ride lifecycle and share/route/profile events, crash logs, performance and diagnostics data. Operate, secure, debug and improve the app; understand feature usage. Our own product analytics events (stored on our servers and linked to your account) currently have no fixed limit (we plan to introduce one) and are deleted or de-identified when you delete your account. Third-party analytics and crash data (Firebase) are retained per the provider's periods. Backend routing/diagnostics logs (IP address plus user ID) currently have no fixed limit; we plan to introduce one.
Geolocation data (precise) Precise GPS points, start and finish coordinates, route geometry, speed, heading, accuracy, altitude and reverse-geocoded addresses from your rides. Record rides, calculate metrics, show maps, import/export GPX, provide navigation and sharing when you enable it. Ride and route data is kept while your account is active and is deleted when you delete your account. Map-coverage tile caches are kept for up to 365 days.
Biometric / health information (sensitive) Workouts, distance, speed, elevation, calories, heart-rate values, heart-rate zones and source metadata when you connect Apple Health, Google Health Connect or a Bluetooth heart-rate sensor. Provide cycling, fitness, import/export and statistics functionality you request. Kept while your account is active and deleted when you delete your account; you can also disconnect or delete imported health data in the app at any time.
Audio / visual information Avatars, trip images, route photos and poster images you upload or generate. Display your profile, rides, routes and shared content that you choose to create. Kept while your account is active and deleted when you delete your account.
Commercial information / inferences We do not sell products through the app and do not build advertising or marketing profiles. We generate only ride-derived metrics and statistics (for example calories and heart-rate zones) shown back to you. Show you your own ride statistics and achievements. Not used to profile you for advertising or consequential decisions. These metrics are stored as part of your ride and account data and are deleted when you delete your account.

In addition to the periods above: database backups are retained for up to 7 days; notification-delivery history is kept for audit purposes, with the personal association removed when you delete your account. Where a category currently has no fixed limit, we keep it only as long as needed for the stated purpose and plan to set explicit limits.

Sensitive Personal Information

Precise geolocation and health/fitness data are treated as Sensitive Personal Information (SPI) under the CCPA/CPRA. We use SPI only to provide the service you request — recording and showing your rides, metrics, maps and health features. We do not use SPI to infer characteristics about you, and we do not use it for any purpose beyond those permitted for providing the requested service. Because of this, the CCPA/CPRA does not require us to offer a separate "Limit the Use of My Sensitive Personal Information" link, and we do not provide one. If we ever use SPI for a secondary purpose that triggers this requirement, we will provide that link and update this policy.

Your Rights

If you are a California resident, you have the right to:

How to Submit a Request

You can submit a request using either of these methods:

We will acknowledge your request within 10 business days and respond within 45 calendar days. If we need more time, we may extend the period by up to another 45 days and will let you know. We will act on a valid opt-out request within 15 business days. We may need to verify your identity before completing certain requests, and an authorized agent may submit a request on your behalf with proof of authorization.

Do Not Sell or Share; Global Privacy Control

We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. Because we do not sell or share your personal information, no opt-out of sale or sharing is required. Some browsers or extensions send a Global Privacy Control (GPC) signal; since we do not sell or share personal information, there is no sale or sharing to opt out of, and receiving a GPC signal does not change how we handle your data. If our practices ever change, we will honor GPC signals as an opt-out preference and update this policy.

Non-Discrimination

We will not discriminate against you for exercising any of your California privacy rights. We will not deny you our services, charge you a different price, or provide you a different level or quality of service because you exercised your rights.

Children

Panaride is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you are under the age of majority in your jurisdiction, use Panaride only with permission from a parent or guardian. If you believe a child under 13 has provided us personal information, contact us at info@panaridesport.com and we will delete it.

Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" at the top of this page. If we make a material change, we will provide additional notice in the app or by other appropriate means before the change takes effect. Your continued use of Panaride after an update becomes effective means you accept the updated policy.

Contact

For privacy questions or data requests, contact us at info@panaridesport.com.