Privacy Policy
Last updated: April 2026
This Privacy Policy explains how Tempo Gigante ("we", "our", "the service") collects, uses, and protects information about you when you use the platform.
1. Data We Collect
When you use GPX XC Analyse we collect:
• Account information — email address and password hash, managed by Supabase Auth.
• GPX tracks — the .gpx files you upload, including GPS coordinates, timestamps, and elevation data recorded during your activities.
• Derived data — speed profiles, lap times, and elevation grades computed from your GPX files and stored in our database.
• Official results — timing results you or an administrator enter for competitions.
• Strava tokens — if you connect your Strava account, we store OAuth access and refresh tokens in your user profile so we can import your activity list on your behalf.
• Usage data — standard server logs (IP address, browser agent, request timestamps) retained for up to 30 days for security and debugging.
2. How We Use Your Data
We use the data we collect to:
• Provide and improve the analysis features (speed charts, lap detection, comparison tools).
• Associate your GPX uploads with your user account and the selected competition.
• Render your activity data in performance dashboards and PDF reports.
• Import activities from Strava when you explicitly trigger an import.
• Detect and prevent abusive or fraudulent use of the service.
We do not sell your personal data to third parties, use it for advertising, or share it with anyone outside the scope described here.
3. Strava Integration
If you connect your Strava account:
• You will be redirected to Strava's OAuth authorisation page. We never see your Strava password.
• We receive read-only access to your activity list (scope: `activity:read`).
• Your Strava access and refresh tokens are stored encrypted in your user profile row and used solely to fetch your activity catalogue for import.
• You can disconnect Strava at any time from your profile page; this revokes and deletes the stored tokens.
• We comply with the Strava API Agreement and only access data within the granted scope.
4. Data Retention
• GPX files are stored on the server for processing and kept until you or an administrator deletes the associated run.
• Derived data points (speed, elevation per metre interval) are stored in the database and linked to your run record.
• Account data is retained for the lifetime of your account. You may request deletion at any time.
• Server logs are purged automatically after 30 days.
5. Your Rights
Depending on your jurisdiction you may have the right to:
• Access — request a copy of the personal data we hold about you.
• Correction — ask us to correct inaccurate data.
• Deletion — ask us to delete your account and associated data.
• Portability — receive your data in a machine-readable format.
To exercise any of these rights, contact us at the address below.
6. Security
We use Supabase's hosted PostgreSQL with row-level security policies, JWT-based authentication, and HTTPS for all data in transit. No system is completely secure; if you discover a vulnerability, please disclose it responsibly by contacting us directly.
7. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the service after changes are posted constitutes acceptance of the new policy.
8. Contact
If you have questions or requests regarding this Privacy Policy, please open an issue in the project repository or contact the administrator of the competition you are participating in.