Privacy policy

Who we are

Triglog is the data controller for the personal data described here. Contact us at support@triglog.com or via the support page.

What we collect, and why

Most account and activity data comes from Strava, with your permission. We request a single scope, activity:read_all, and no other. Your summit corrections and pack details are supplied directly by you.

We do not collect your email address, and Strava does not give it to us. We do not use analytics or advertising cookies. The only cookies set are a signed session cookie that keeps you logged in and a short-lived cookie protecting the login flow against cross-site request forgery.

Legal basis

We process this data to perform the service you asked for (UK GDPR Article 6(1)(b), contract). Health-adjacent data such as heart rate is processed on the basis of your explicit consent, given when you grant activity access on Strava’s permission screen and withdrawable at any time by disconnecting.

Who can see your data

Only you. Triglog has no public profiles, no leaderboards, no following, public exports, and no cross-user aggregation. Strava data from one athlete is never shown to another.

Where it is stored, and who processes it

Strava may monitor and collect data about Triglog’s API use and may use that information for internal or external business purposes, including service improvements, developer support and compliance. Strava handles that information under Strava’s privacy policy. That is outside our control.

How long we keep it

Your data is retained while your account exists and your Strava connection is active, because the product is a permanent logbook of your climbing history. It is deleted immediately when you disconnect or delete your account — see below.

Triglog subscribes to Strava’s change notifications, so your copy here follows what you do there. If you delete an activity on Strava, or change it to “Only You”, it is removed from Triglog too; renames and sport-type changes are applied. If you revoke Triglog from Strava’s own settings, the deauthorisation notification causes everything we hold for you to be deleted automatically.

If Triglog is discontinued, or if our access to the Strava API ends, all Strava data will be deleted and users notified.

Deleting your data

You are in control, and neither option requires contacting us:

Both happen immediately, not on a schedule, and both finish by showing you written confirmation of exactly what was removed. Neither touches anything on Strava: your activities stay there untouched.

You can also revoke Triglog from My Apps in your Strava settings. If you do, Strava notifies Triglog and your imported and derived data is deleted automatically.

Your rights

You have the right to access, correct, export, restrict and erase your personal data, and to withdraw consent. Your logbook already shows everything we hold in readable form, and the deletion options above exercise erasure directly. For anything else — including a machine-readable export — contact us via the support page. You can also obtain a free export of your original Strava data from Strava’s bulk export tool. You may also complain to the UK Information Commissioner’s Office.

Security

Strava tokens are encrypted at rest. Session cookies are signed, HTTP-only and, in production, secure and same-site. All traffic is served over HTTPS. No third party is given access to your activity data.

Changes

If this policy changes materially we will update the date above and note the change on the support page.