This Privacy Policy describes how your personal information is collected, used, and shared when you visit or use Athlete-IQ. By using our Service, you agree to the collection and use of information in accordance with this policy.
Athlete-IQ is a UK-based business. We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our service is directed at individual consumers in the United Kingdom. We are the data controller in respect of the personal data we collect and process as described in this policy.
Information We Collect
We collect information necessary to provide and improve our service, as described below. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Account Information
- Email address and name for account creation and communication
- Password (hashed; we do not store plain-text passwords)
- Profile preferences, settings, and physiological inputs (e.g. threshold pace, max HR) you provide for zone calculations
Training and Activity Data
- Training data you enter manually (e.g. distance, duration, pace, elevation)
- Activity data we receive from Strava when you connect your account (e.g. activities, routes, heart rate, pace, timestamps). This is governed by Strava's terms and your authorisation.
- Workout segments, goals, race information, and progress tracking you create or we derive to provide dashboards and analytics
Usage and Technical Data
- Log data (e.g. IP address, browser type, pages visited, timestamps) for security, debugging, and service operation
- Anonymised or aggregated analytics to improve the product (where we do not identify you)
- Cookies and similar technologies as described in the Cookies section below
How We Use Your Data
Athlete-IQ uses the collected data for various purposes:
To provide and maintain the Service, sync and analyse your training data, and personalise your experience.
To notify you about changes to our Service, new features, or to provide customer support.
To provide insights and analytics and to improve the Service (including anonymised or aggregated analysis).
To monitor usage, detect and prevent abuse, and address technical and security issues.
Data Security
Encrypted & Secure
We use industry-standard SSL encryption to protect your data during transmission. Your sensitive health metrics are stored in secured databases with restricted access.
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
Your Data Rights
Depending on your location, you may have the following rights regarding your personal data:
- The right to access: you can request a copy of the personal data we hold about you.
- The right to rectification: you can have inaccurate or incomplete data corrected.
- The right to erasure: you can request deletion of your personal data, subject to legal or contractual exceptions.
- The right to restrict processing: you can ask us to limit how we use your data in certain circumstances.
- The right to data portability: where applicable, you can receive your data in a structured, machine-readable format.
- The right to object: you can object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Complaint: you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection (ico.org.uk).
Children's Privacy
Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us.
Data Retention
We retain your personal data only for as long as necessary to provide the service and as set out in this policy. Account and profile data are kept until you delete your account or ask us to delete your data. Activity and training data (including data synced from Strava) are retained for the same period; when you disconnect Strava or delete your account, we will delete or anonymise such data in line with our internal procedures (e.g. within 30 days from account deletion, subject to backup and legal retention requirements). We may retain certain data where required by law (e.g. tax, legal claims) or for legitimate purposes such as security and fraud prevention for a limited period after account closure.
Contact Our Data Officer
If you have any questions about this Privacy Policy, please contact us:
Your privacy matters
We are committed to transparency. If you have any concerns about how your data is handled, please don't hesitate to reach out.
Privacy FAQ
Can I download my data?
Yes. You can request a copy of your personal and training data (data export). Contact us using the details in the Contact section. We will provide the data in a portable format where feasible and within the timeframes required by applicable law.
Do you sell my data to advertisers?
No. We do not sell your personal or training data to advertisers or any third parties. Our business model is based on providing tools and services to users, not selling user data.
How long do you keep my data?
We keep your data while your account is active and as needed to provide the service. After you delete your account, we remove or anonymise your personal data within our retention window (e.g. 30 days), except where we must retain it for legal or legitimate operational reasons (e.g. backups, fraud prevention).
What if I disconnect Strava?
When you disconnect Strava, we stop receiving new activity data from Strava. You can request deletion of activity data we have already received; we will process that in line with our retention and deletion procedures.
Is my payment info safe?
If we offer paid features, we do not store your full credit card details. Payments are processed by trusted payment providers (e.g. Stripe) that are certified to handle card data securely. We receive only the information needed to manage your subscription (e.g. last four digits, expiry).