Draft Notice: This privacy policy is a draft pending legal review. It contains placeholder values that will be finalized before release.
Privacy Policy
Last updated: [DATE]
1. Introduction
[COMPANY NAME] (“[We/Us/Our]”) operates the Velocare mobile application (the “App”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
Contact Information:
- Company: [COMPANY NAME]
- Address: [REGISTERED ADDRESS]
- Email: [PRIVACY EMAIL]
- Data Protection Officer: [DPO NAME/EMAIL if applicable]
Legal Basis: [COMPANY REGISTRATION NUMBER, COUNTRY]
2. Information We Collect
2.1 Information You Provide Directly
Account Information:
- Email address - for account creation and communication
- Display name - for personalization within the app
- Password - stored securely (hashed, never in plain text)
Alternative Authentication:
- Sign in with Apple - We receive a unique identifier and optionally your name/email from Apple. Apple’s privacy policy applies to their authentication service.
Bike and Maintenance Data:
- Bike details (name, brand, type, purchase date/price, photos)
- Component information (types, custom labels if Pro user)
- Maintenance logs (service dates, costs, notes)
- Receipt photos (stored securely, Pro feature only)
Usage Preferences:
- Unit preferences (km/miles)
- Theme preference (light/dark/system)
- Notification preferences
2.2 Information Collected Automatically
Device Information:
- Device type and operating system version
- App version and build number
- Push notification tokens (for sending maintenance reminders)
Location Data (When In Use Only):
- Approximate location when you use the “Find Bike Shops” feature
- We do NOT track your location in the background
- You can deny location permission; shops feature will be unavailable
Usage Analytics (if enabled after you accept):
- App screens visited
- Features used
- Error logs and crash reports (via Sentry)
- No personally identifiable information in analytics
2.3 Information from Third-Party Services
Strava Integration (optional, requires your explicit consent):
- Athlete ID and profile information
- Bikes/gear from your Strava account
- Ride activities (distance, date, type, bike assignment)
- We do NOT access your private activities unless you grant
activity:read_allscope - You control this connection and can disconnect at any time
RevenueCat (Subscription Management):
- Subscription status and expiration
- Purchase history
- Anonymous customer ID
- We do NOT see your payment details (handled by Apple)
3. How We Use Your Information
We use your information for the following purposes:
3.1 Core Service Delivery
- Provide bike maintenance tracking and reminders
- Calculate component wear and Health Scores
- Send push notifications for due maintenance
- Sync ride data from Strava (if connected)
- Show nearby bike shops based on location
3.2 Account Management
- Create and authenticate your account
- Manage your subscription (Free/Pro)
- Restore purchases across devices
- Process account deletion requests
3.3 Service Improvement
- Fix bugs and crashes (via Sentry crash reports)
- Understand which features are used
- Improve app performance
- Develop new features based on usage patterns
3.4 Communication
- Send transactional emails (password reset, email confirmation)
- Send push notifications (maintenance alerts, subscription updates)
- Respond to support requests
We do NOT use your information for:
- Advertising or marketing to third parties
- Selling your data
- Cross-app tracking
- Profiling or automated decision-making
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), UK, and Switzerland, we process your personal data under the following legal bases:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Account info (email, password) | Contract | Necessary to provide the service you signed up for |
| Bike & maintenance data | Contract | Core functionality of the app |
| Location (shops feature) | Consent | You explicitly enable location permission |
| Strava integration | Consent | You explicitly connect your Strava account |
| Push notifications | Consent | You explicitly grant notification permission |
| Crash reports & analytics | Legitimate Interest | Improving app stability and performance |
| Subscription management | Contract | Managing your paid subscription |
You have the right to withdraw consent at any time where we rely on consent.
5. Data Sharing and Disclosure
5.1 Service Providers We Use
We share data with these third-party services to operate the app:
Supabase (Database & Backend):
- Stores all your account and bike data
- Location: [US/EU - SPECIFY]
- Privacy Policy: https://supabase.com/privacy
- Data Processing Agreement: In place
Strava (Ride Sync):
- Only if you connect your account
- We fetch your rides and bikes
- Privacy Policy: https://www.strava.com/legal/privacy
- You control access via Strava settings
RevenueCat (Subscriptions):
- Manages Pro subscription status
- Receives anonymous identifiers only
- Privacy Policy: https://www.revenuecat.com/privacy
- GDPR compliant
Google Places API (Bike Shops):
- Location sent to find nearby shops
- Google’s privacy policy applies
- Privacy Policy: https://policies.google.com/privacy
Sentry (Crash Reporting):
- Receives error logs and crash data
- No PII included (email/name removed)
- Privacy Policy: https://sentry.io/privacy/
- GDPR compliant
Expo Push Notification Service:
- Delivers push notifications via APNs
- Privacy Policy: https://expo.dev/privacy
Apple (Authentication & Payments):
- Sign in with Apple (if you choose)
- In-app purchase processing
- Privacy Policy: https://www.apple.com/legal/privacy/
5.2 We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5.3 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to:
- Protect our legal rights
- Enforce our Terms of Service
- Protect user safety
- Prevent fraud or abuse
6. Data Retention
We retain your data for as long as your account is active, plus:
| Data Type | Retention Period |
|---|---|
| Account data | While account exists + 30 days after deletion |
| Bike & maintenance data | While account exists, deleted on account deletion |
| Receipt photos | While account exists, deleted on account deletion |
| Crash logs | 90 days (Sentry default) |
| Backup data | 30 days (Supabase automated backups) |
After account deletion:
- All data is permanently removed within 30 days
- Strava access is revoked
- Push tokens are deleted
- Storage (photos) is purged
7. Your Rights (GDPR & CCPA)
7.1 European Users (GDPR)
You have the following rights:
Right to Access:
- Request a copy of your personal data
- Email [PRIVACY EMAIL] to request
Right to Rectification:
- Correct inaccurate data via app settings
- Or contact us for assistance
Right to Erasure (“Right to be Forgotten”):
- Delete your account via Settings → Privacy → Delete Account
- All data is removed within 30 days
Right to Data Portability:
- Export your maintenance data
- Contact [PRIVACY EMAIL] for export in JSON format
Right to Object:
- Object to processing based on legitimate interest
- Opt out of analytics (currently not collecting)
Right to Restrict Processing:
- Request temporary restriction
- Contact [PRIVACY EMAIL]
Right to Withdraw Consent:
- Disconnect Strava at any time (Settings → Strava)
- Disable notifications (Settings → Notifications)
- Revoke location permission (iOS Settings)
Right to Lodge a Complaint:
- Contact your local data protection authority
- [EU LIST: https://edpb.europa.eu/about-edpb/about-edpb/members_en]
7.2 California Users (CCPA)
California residents have additional rights:
- Know what personal information is collected
- Know if personal information is sold or disclosed (we don’t sell)
- Opt-out of sale (not applicable - we don’t sell)
- Request deletion
- Non-discrimination for exercising rights
To exercise these rights, email [PRIVACY EMAIL] with subject “California Privacy Request”.
8. Data Security
We implement appropriate technical and organizational measures:
Technical Measures:
- All data transmitted via HTTPS/TLS encryption
- Passwords hashed using industry-standard algorithms
- Row-level security on all database tables
- Receipt photos in private storage buckets (signed URLs, 5-min expiry)
- Push tokens stored securely, scoped to user
Organizational Measures:
- Supabase service role key never exposed to client
- API secrets (Strava, Google Places) kept server-side only
- Regular security reviews
- Limited employee access to production data
Despite our efforts, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
9. Children’s Privacy
Velocare is not intended for users under 16 (or 13 in some jurisdictions). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us immediately at [PRIVACY EMAIL] and we will delete it.
10. International Data Transfers
For EEA/UK Users:
- Your data may be transferred to and processed in [US/EU - SPECIFY]
- Supabase provides standard contractual clauses (SCCs) for GDPR compliance
- We ensure appropriate safeguards are in place
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the “Last Updated” date
- Sending an email notification
- Displaying an in-app notice
Your continued use after changes constitutes acceptance of the updated policy.
12. Cookie Policy
The App does not use cookies (as it’s a native mobile app, not a website). We use:
- Local storage for app settings
- AsyncStorage for session tokens
- No web cookies or tracking pixels
13. Contact Us
For questions, concerns, or to exercise your rights:
Email: [PRIVACY EMAIL]
Mail: [COMPANY NAME], [REGISTERED ADDRESS]
Response Time: We aim to respond within 30 days (GDPR requirement)
For urgent matters regarding your data, mark your email “URGENT - Data Protection Request”.
14. App Store Privacy Labels
Data Collected and Linked to You:
- Contact Info (email address)
- User Content (bike data, maintenance logs, photos)
- Identifiers (user ID, device ID for push notifications)
- Location (when using bike shops feature)
Data Collected but Not Linked to You:
- Crash logs and diagnostics (anonymized)
Data Not Collected:
- Financial Info (handled by Apple)
- Browsing History
- Search History
- Contacts
- Health & Fitness Data
- Sensitive Info
© 2026 [COMPANY NAME]. All rights reserved.