Privacy policy
Protecting your personal data matters to us. This policy explains what data clubrides.eu processes when you use it, for what purpose, and on what legal basis.
Data controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Timo Lohmann
Albert-Lüke-Str. 72a
48282 Emsdetten
Deutschland
[email protected]
Hosting and server log files
The application runs on a rented server from Hetzner Online GmbH in their Nuremberg data centre in Germany. Uploaded files and the database backups are stored separately in Amazon S3 object storage (Amazon Web Services) in the Stockholm region, Sweden — both within the EU. On every request the server logs technically necessary access data: the time of the request, the path called, the HTTP status code, the processing time and the requesting IP address. These logs serve system security, error analysis and stable operation (Art. 6(1)(f) GDPR); they are not kept permanently but rotated continuously and overwritten automatically in the process.
Content delivery network (Cloudflare)
All requests to clubrides.eu pass through Cloudflare as a content delivery network and protection against overload and attacks. This means your browser's encrypted connection first terminates at Cloudflare, which then forwards the request to our server over its own encrypted connection. In doing so, Cloudflare inevitably processes your IP address and the technical characteristics of the request, and keeps its own short-lived logs about it. The provider is Cloudflare Germany GmbH and Cloudflare, Inc.; appropriate safeguards are in place for any transfer to the USA (including EU standard contractual clauses), and a data processing agreement exists. The legal basis is our legitimate interest in secure, available and fast operation (Art. 6(1)(f) GDPR).
Cookies
clubrides.eu uses only strictly necessary cookies: one stores your session after login, another can optionally keep you signed in for up to two weeks ("Remember me"). The legal basis is Art. 6(1)(b) GDPR (contract performance) or Art. 6(1)(f) GDPR (legitimate interest in a working login). No analytics, tracking, or advertising cookies are used — cookie consent is therefore not required.
Usage statistics
To understand how clubrides.eu is used and to spot errors or load spikes, our servers log which page or action was called on every page view — together with the user account for logged-in users, and without any account reference for visitors who are not signed in. Browser type, operating system, device type, referrer and a truncated IP address are also recorded: the last segment is set to zero before storing, so no full address reference arises. No additional cookies are set for this, no form input is logged and no location lookup is performed. Requests originating from sign-in, password reset, the personal calendar links and the connection callbacks of external services are deliberately not recorded, as those carry a personal security token in the address. The evaluation happens solely internally for the operators of clubrides.eu and is not visible to other club members. The legal basis is our legitimate interest in comprehensible and secure operation (Art. 6(1)(f) GDPR); when you delete your account the personal reference of these entries is removed while the entries themselves remain in anonymised form.
Registration and user account
Using clubrides.eu requires a user account. This involves processing your name, email address, and a password you choose (stored encrypted), plus your role within your club. You can optionally upload a profile picture. Alternatively, you can sign in via Strava — in that case we store only an identifier for your Strava account plus the name and email address Strava provides, never your Strava credentials or access tokens. The legal basis is performance of the usage agreement (Art. 6(1)(b) GDPR).
Signing in with Google
You can sign in with your Google account as an alternative. Doing so transmits your IP address to Google (Google Ireland Limited), and Google sends us an identifier for your Google account, your name, your email address and whether Google has verified that address. We never learn your Google password and we access no other data in your Google account. The legal basis is performance of the usage agreement (Art. 6(1)(b) GDPR); signing in with Google is optional, and registering with an email address and password is equally available.
Content you create yourself
Within your club you can create content that is visible to other members — and, for public rides, to guests or visitors who are not signed in: rides you create, sign-ups and withdrawals, routes you add together with the uploaded GPX file, comments and reactions, route reviews, news posts including attachments, and bulletin board listings (which have their own section below). This processing enables the core function of clubrides.eu, coordinating rides together (Art. 6(1)(b) GDPR).
Chat messages
Every ride has a chat. It is visible only to that chat's members — registered participants plus anyone who has explicitly joined the chat — not to your whole club. Message text, emoji reactions, and the time you joined (shown as a system notice in the thread) are stored for as long as the ride or your user account exists. Whether and when you've read a message, and any mute setting, are visible only to you, not to other chat members. Please note: messages in this chat are visible to all its members — don't share sensitive personal data here. The legal basis is performance of the usage agreement (Art. 6(1)(b) GDPR).
Club channel
In addition to per-ride chats, your club can enable a club-wide channel. It's visible to all members, guides, and admins, but not to guests. Message text and emoji reactions are stored for as long as the club or your user account exists. Whether and when you've read a message, and any mute setting, are visible only to you. Please note: messages in this channel are visible to all its members — don't share sensitive personal data here. The legal basis is performance of the usage agreement (Art. 6(1)(b) GDPR).
Direct messages
Members can message each other directly within their club, provided your club has enabled this feature; it is not available to guests. A conversation exists between exactly two people and separately per club — it is visible to those two only, not to admins and not to the club. Message text is stored encrypted in our database; attached images and emoji reactions are stored like other content for as long as the conversation or your account exists. Whether and when you read a message, and any mute setting, are visible to you alone. The legal basis is performance of the usage contract (Art. 6(1)(b) GDPR).
Images and files
Uploaded images and files — profile picture, club logo, ride cover images, news post attachments, images in chats and direct messages, and images attached to bulletin board listings — are likewise stored via Amazon Web Services (server location Stockholm, Sweden). Photos are downscaled on your own device before upload; embedded camera metadata (such as the GPS coordinates of where a photo was taken) is discarded in the process and never reaches our servers.
Database backups
To guard against data loss, the system creates a full backup of the database every hour and stores it — transmitted encrypted — in a separate Amazon S3 bucket in Stockholm, Sweden. A backup therefore contains all the account data and content named in this policy. The application's credentials only permit writing new backups, not reading or deleting existing ones — restoring is deliberately a manual act by the operator. The legal basis is our legitimate interest in resilient operation (Art. 6(1)(f) GDPR).
Bulletin board
Your club can use a bulletin board on which members post their own listings (title, price, description, images). This content comes solely from the members themselves; we do not review it up front. clubrides.eu is neither the seller nor a broker and never becomes a party to any deal made there — purchase, payment and handover happen exclusively between the members, without our involvement, and we accept no liability for them. A listing is only visible to members and guests of that club, never publicly; a draft is visible to its seller alone. We also store when you last opened the bulletin board, purely to mark new listings for you; nobody but you sees this. Contact runs through the app's direct messages (see below). Listings and their images are stored until the seller deletes them, and are removed together with the account or the club. You can report unlawful content to us at [email protected]; we will remove it after review. The legal basis is performance of the usage contract (Art. 6(1)(b) GDPR).
Wahoo connection
If you connect your Wahoo account to upload routes directly to Wahoo Connect, we store the required OAuth access and refresh tokens encrypted. This connection is optional and can be disconnected again at any time in settings (Art. 6(1)(a) GDPR, consent).
Garmin connection
If you connect your Garmin account to upload routes directly to Garmin Connect, we store an encrypted session token for that purpose. We never store your Garmin password itself. This connection is optional and can be disconnected again at any time in settings (Art. 6(1)(a) GDPR, consent).
Calendar subscription link
Every user account gets an individual, secret access token for the personal calendar subscription link (.ics). This link lets you subscribe to the rides visible to you in an external calendar app without signing in again. Treat this link as confidential — you can revoke and regenerate it at any time in settings.
Push notifications
If you enable browser notifications, we store a push address issued by your browser vendor plus two encryption keys per device or browser — encrypted in our database. Delivery itself runs through your browser vendor's push service (e.g. Google, Mozilla, or Apple), which sees technical delivery information but not the message content (end-to-end encrypted). In the native iOS app, push notifications instead run through Apple's Apple Push Notification service (APNs); for this we store a device identifier. For new chat messages, the notification — both on the web and in the app — includes a short excerpt of the message text as a preview; unlike browser push, delivery via APNs is not end-to-end encrypted, so Apple can technically access this excerpt. Transfer to Apple in the US relies on appropriate safeguards (including EU standard contractual clauses). This feature is optional and can be revoked at any time in settings, via mute in a chat, and in your browser or device (Art. 6(1)(a) GDPR, consent).
Email delivery
For system emails (e.g. registration confirmation, invitations, password reset, ride notifications) we use the email provider Mailjet (Mailjet SAS, part of the Sinch group), unless your club has configured its own email server. This involves processing your email address and the respective message content. The legal basis is performance of the usage agreement (Art. 6(1)(b) GDPR); a data processing agreement is in place with Mailjet.
Error tracking
To detect and fix technical errors we use Sentry with EU data residency (stored in Frankfurt am Main, Germany). When a technical error occurs, the requested address and a technical error context (e.g. a stack trace) are transmitted. IP addresses, cookies and form contents are deliberately not sent along; known sensitive field names such as passwords or access tokens are additionally filtered out automatically. In individual cases we deliberately transmit technical identifiers (such as the database ID of an account, a club or a listing) in order to be able to attribute an error at all — names, email addresses, message contents, push addresses and device tokens are never included. The legal basis is our legitimate interest in reliable, error-free operation (Art. 6(1)(f) GDPR).
Embedded third-party content
Some pages embed content from the following external providers. Loading it necessarily transmits your IP address to that provider — their own privacy notices apply in addition to this one:
- Google Fonts (Google Ireland Limited): the "Manrope" typeface is loaded directly from Google's servers (fonts.googleapis.com, fonts.gstatic.com).
- Font Awesome icons are loaded via Cloudflare's content delivery network (cdnjs.cloudflare.com).
- If a ride has a Komoot link, its detail page embeds a route preview from Komoot (komoot.de) via iframe.
- If a ride has a Strava link, the official Strava embed widget is loaded (strava-embeds.com).
- Route maps are rendered with the Leaflet library; your browser loads the map tiles directly from OpenStreetMap's servers.
- For a ride's weather forecast, our servers — not your browser — query the Open-Meteo weather service for the ride's start coordinates and time. No personal data is transmitted in the process.
Retention period
We store your data for as long as your user account exists. After you delete your account or upon request, your data is deleted unless legal retention obligations require otherwise.
Your rights
As a data subject, you have the following rights:
- Access to the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR) — you can delete your account yourself in your profile settings, or contact us by email
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
Right to complain
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement.
Encryption
The connection to clubrides.eu is encrypted throughout via TLS/SSL, indicated by the padlock icon in your browser.