Paced Paced
Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseDPASubprocessorsSecurity & Trust
Back to app
Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseDPASubprocessorsSecurity & Trust

Documents

Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseDPASubprocessorsSecurity & Trust

Data Processing Addendum

Effective: 22 July 2026 Last updated: 22 July 2026

Overview

When you use Paced, we process the account, training, and billing data connected to your use of the service. In this context:

  • You are the data subject — the data relates to you and the training you record.
  • Paced is the data controller, and engages the sub-processors listed below to store and process that data on our behalf.

This Data Processing Addendum ("DPA") summarises what we process, why, and the technical and organisational measures we apply. It forms part of our Terms of Service and should be read with our Privacy Policy.

Data we process

Account & profile data

  • Name and email address used to create and sign in to your account.
  • Authentication data managed by Firebase Authentication.
  • Preferences and settings, and your cycling profile (bikes, goals, FTP and its history).

Ride & training data

  • Ride distance, duration, elevation, route name, ride type, date, cadence, and notes.
  • Where provided: power and heart-rate data, and figures derived from them (training load, zones, records, power curves, fitness/fatigue/form trends and estimates).

Fitness & health-related data (special category)

  • Optional measurements you choose to enter, such as body weight, body-fat percentage, resting heart rate, and maximum heart rate, plus heart-rate data within rides.
  • Some of this may constitute special-category (health) data under Article 9 of the UK/EU GDPR. We process it only on the basis of your explicit consent (given when you enter it), solely to power the training features you use, and never for advertising or resale. You may withdraw consent by deleting the data or your account.

Community & referral data

  • Community membership, and the display name and activity you choose to share within communities you join.
  • Referral code, attributions, and reward status.

Billing data

  • Subscription tier, status, trial/renewal dates, and Stripe customer/subscription identifiers. Payment card details are collected and processed by Stripe directly; Paced does not receive or store full card numbers.

Technical data

  • IP addresses used transiently for rate limiting and security, plus browser/device type and short-lived security logs.
  • Push notification tokens, if you enable notifications.

Processing purposes

Paced processes your data to:

  • Authenticate you and maintain your account and subscription.
  • Store the training you record and display it back to you.
  • Calculate your statistics, records, and personalised insights.
  • Operate community and referral features you choose to use.
  • Maintain service integrity, security, and abuse prevention.

We will not use this data for advertising, third-party profiling, or sale to third parties, and we do not carry out automated decision-making producing legal or similarly significant effects about you.

Technical and organisational measures

  • HTTPS/TLS encryption for all data in transit; encryption at rest by Google Cloud (AES-256).
  • Cloud Firestore data isolation — your data is stored under account-scoped paths and is not accessible by other users.
  • Firebase Authentication and server-side verification of every API request.
  • Role-based access controls limiting internal access to user data.
  • Rate limiting and request-origin checks to protect against abuse.

Sub-processors

We engage the following sub-processors:

  • Google Firebase / Google Cloud — authentication and database (Cloud Firestore).
  • Vercel — serverless hosting and compute.
  • Stripe — payment processing and subscription management for paid plans.

See our Subprocessors page for the current list and details. We will notify you of intended changes by updating that page, and you may object to a new sub-processor within 30 days of notification.

Retention and deletion

  • Account, profile & fitness data: retained for the duration of your account.
  • Ride & training data: retained until you delete it or close your account.
  • Billing records: retained as required for tax, accounting, and legal obligations.

On account deletion, remaining data is removed from our active systems within 30 days, subject to legal retention obligations. You can permanently delete your account and associated data at any time from your account settings.

Data subject requests

You may exercise your data rights (such as access, correction, erasure, restriction, portability, objection, and withdrawal of consent) at any time — largely self-service in the app, or via the support form. We will respond within a reasonable timeframe and at no additional charge, subject to legal exceptions.

International transfers

Where our sub-processors process data internationally, transfers are covered by the UK/EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other recognised mechanisms, together with the applicable provider data-processing agreements.

Contact

You can manage and delete your data from your account settings. For data requests or questions, send us a message through our contact form.