Privacy Policy
Velog app Privacy Policy
1. Who We Are
Velog (“Velog,” “we,” “our”) is a service for tracking cycling activities and managing equipment, available at velog.cc. This Privacy Policy explains how we process personal data when you use Velog, including data obtained through third-party APIs such as Strava and Garmin.
Data controller: Tarpes - Robert Piątkowski, Poland.
Privacy contact: robert@velog.cc
Supervisory authority (EU): President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.
2. Data We Collect
2.1. Account data
- Email address
- Password (stored in encrypted form)
- Display name and profile details (optional)
2.2. Strava and Garmin integration data
- OAuth identifiers and tokens (access and refresh tokens)
- Third-party account identifier (for example, Strava Athlete ID)
- Activity data obtained after your explicit consent (for example, activity ID, type, date and time, distance, duration, pace or speed, elevation, bike and equipment metadata, and device data). Activity files may also contain routes and location data recorded by your device. We do not request broader permissions than needed for Velog features.
2.3. Data you provide
- Bikes and components (names, types, parameters, replacement limits)
- Notes and other content you enter
2.4. Technical and operational data
- IP address and device and browser information
- Server and application logs; queue and worker logs
- Error logs and performance metrics (with personal data minimized)
Special categories of data: Activity and health data may constitute special-category personal data under the GDPR. We process such data only on the basis of your explicit consent, which you may withdraw at any time (see sections 7 and 8).
2.5. Data from Garmin
When you voluntarily connect a Garmin Connect account, Velog receives data within the permissions you accepted on Garmin’s authorization screen. Data is received through Garmin Connect Developer Program interfaces, particularly PING/PUSH notifications and FIT activity files.
Garmin data we collect
- Garmin user identifier, activity identifiers, OAuth tokens, and granted permissions;
- activity type, name, date and time, distance, duration, speed, elevation, and other activity statistics;
- data recorded in FIT files, which may include route and location, heart rate, cadence, power, and technical data about devices and sensors;
- device model and, where available, sensor identifiers, battery status or level, and hardware or software versions.
How we use and process Garmin data
We use this data only to provide the Velog features you choose: synchronizing and displaying rides, assigning them to bikes, calculating bike and component mileage, creating statistics and reports, identifying devices and sensors, and showing available battery information. Data may be combined with Strava activities and manually entered data to prevent duplicates and create aggregate statistics. Garmin does not sponsor, endorse, or guarantee results and statistics produced by Velog.
Storage and deletion of Garmin data
- Data is transmitted over HTTPS and stored on Velog infrastructure at OVH, in a PostgreSQL database and secure backups.
- Original FIT files are stored for up to 90 days for reliable processing and diagnostics, then automatically deleted.
- Processed activity, device, and sensor data, as well as technical copies of API messages, are stored while you use your account, until you delete them or request their deletion.
- Disconnecting Garmin immediately removes OAuth tokens and stops new data imports, but does not automatically delete previously imported history. You can request its deletion in the app or by emailing robert@velog.cc.
- Backups are deleted on a rotation cycle, usually within 30 days.
Third parties and artificial intelligence
Garmin data is processed by OVH as our hosting, database, and backup provider acting on our instructions. We do not sell Garmin data, share it with advertisers or other users, or send it to external AI services or models. Analytics and advertising tools do not receive Garmin activity content. Diagnostic data sent to error-monitoring providers is minimized and should not contain activity content, OAuth tokens, or FIT files.
3. Purposes and Legal Bases for Processing
- Providing and operating the Service (login, activity synchronization, bike and component management, notifications) — GDPR Article 6(1)(b), necessary for performance of a contract.
- Strava and Garmin integrations: obtaining and processing activity data only for the features you request — GDPR Article 6(1)(a), consent; for special-category data, Article 9(2)(a), explicit consent.
- Security, abuse prevention, and reliability (rate limiting, logging, backups) — GDPR Article 6(1)(f), legitimate interests.
- Error monitoring and debugging (for example, Sentry) — GDPR Article 6(1)(f), legitimate interests, with data minimization and masking.
- Compliance with legal obligations — GDPR Article 6(1)(c).
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Where We Obtain Data
- Directly from you (account creation and use of the Service).
- From third-party APIs (such as Strava and Garmin) only after authorization (OAuth).
- Automatically from your device (technical data) when you use the Service.
5. Recipients and Processors
The following process data on our behalf under data-processing agreements and with appropriate safeguards:
- Hosting and database: OVH, including PostgreSQL storage and backups.
We do not sell personal data or share it with advertisers.
International transfers: If we transfer data outside the EEA/UK, we use appropriate safeguards (such as standard contractual clauses or adequacy decisions). Details are available on request.
6. Retention Periods
- Account data: while the account is active and for up to 30 days after its deletion for operational purposes, unless a longer period is required by law.
- OAuth tokens: deleted promptly after disconnecting the integration or deleting the account.
- Activity, equipment, and component data: until you delete it or delete the account; disconnecting an integration alone does not automatically delete previously imported history.
- Server and application logs: usually for up to 90 days.
- Backups: usually for up to 30 days in rotation.
We may retain minimal information to demonstrate compliance or handle claims where required by law.
7. Your Rights (GDPR)
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (where applicable). Where processing is based on consent, you may withdraw it at any time.
To exercise your rights, email us at robert@velog.cc. We will respond within one month at the latest and may ask you to confirm your identity. You also have the right to lodge a complaint with UODO.
8. Consent and Revocation (Strava/Garmin)
- You grant access to Strava/Garmin data through OAuth screens showing the requested permissions.
- To revoke access:
- In Velog: disconnect the integration (this deletes tokens and stops synchronization); you can also delete imported activities.
- In your Strava/Garmin account: revoke Velog’s access.
- After consent is withdrawn, we do not process new data. You can request deletion of historical data in the app or by email.
9. Security
We use appropriate technical and organizational measures: HTTPS/TLS in transit, hashed passwords, least-privilege access, secure secret management, access controls, queue isolation, regular updates and backups, monitoring and alerts, and incident-response procedures. If a breach may pose a risk to your rights, we will notify you and the supervisory authority when required by law.
10. Children
The Service is not directed at children under 16 and we do not knowingly process their data. If you believe a child has provided us with data, contact us so that we can delete it.
11. Changes to This Policy
We may update this Policy. We will publish the new version with its current effective date and notify you of material changes in the app or by email. Any planned change to the rules governing Garmin data will be submitted to the Garmin Connect Developer Program team before implementation and requires its prior written approval.
12. Contact
- Email: robert@velog.cc
13. Cookies and Similar Technologies
Velog uses cookies and similar technologies (such as localStorage) to provide essential features (login, security, and basic settings). In addition, only with your consent, we use Google Analytics 4 to understand how the Service is used and improve the product.
13.1. Categories
- Essential — required for the Service to work properly (authentication, session maintenance, security). These cookies are always active and do not require consent.
- Analytics (optional) — Google Analytics 4. Enabled only if you consent through the cookie banner.
13.2. Consent, Customization, and Withdrawal
On your first visit, we display a cookie banner with Accept all, Customize, and Decline buttons. Under Customize, you can enable or disable only the Analytics category. The Essential category is always active and cannot be changed. You can change your choice at any time using the “Ustawienia cookies” (Cookie settings) link in the site’s Polish-language footer. This opens the customization panel, where you can select Save preferences.
13.3. Consent Mode
We use Google Consent Mode v2. Analytics defaults to denied before you give consent, so no analytics data is stored in identifiable cookies. After you accept, the setting changes to granted and GA4 records visits and events. Changes made under Cookie settings take effect immediately.
13.4. Additional Information
- You can also manage cookies in your browser settings (block or delete them).
- For more about GA4 and privacy, see Google’s Privacy Policy and Google Analytics documentation.