Privacy Policy
Introduction
Paced ("we", "our", "us") operates the Paced platform — a cycling training app where you log your rides, track your fitness, follow a training plan, and view personalised stats and coaching insights. Paced offers a free tier and optional paid subscriptions (see our Terms of Service).
This policy explains what personal data we collect, why, how we use it, who we share it with, and your rights under the UK GDPR, the EU GDPR, and other applicable data protection law. For the purposes of that law, Paced is the data controller of your personal data.
By creating a Paced account and using the platform, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the platform.
Who we are
Paced is an independent product built and operated by a sole developer, available at ridepaced.com. You can review, edit, export the substance of, and permanently delete your account and associated data at any time from your account settings within the app. For any question about this policy or your data, send us a message through our contact form.
Visitors to our website
We do not run advertising networks, marketing trackers, analytics platforms, or cross-site tracking on our marketing website. If you browse the site without signing up, we do not build a profile of you.
We do count page views in aggregate: when a page (on this website, in the signup flow, or inside the app) is opened, a per-day counter for that page goes up by one. Nothing is attached to that count — no identifier, no IP address, no cookie, no device information — so it can never describe you, only how many. We use these totals solely to understand which pages are useful and where new riders lose interest.
Our public pages do load web fonts from a third-party content delivery network (Google Fonts). When your browser fetches those assets, your IP address is necessarily visible to that provider as part of delivering the file. We do not send them any account or ride data, and we do not use these requests to identify or track you.
Data we collect
We collect the following categories of data, most of it only because you choose to enter it:
1. Account & profile data
- Identity: the name and email address you provide at sign-up, and your authentication credentials (managed and encrypted by Firebase Authentication — we never see your password).
- Preferences & settings: distance units, display mode, theme, notification preferences, onboarding progress, and the timestamp at which you accepted our Terms.
- Cycling profile: details you add to personalise your training — such as your bikes, cycling goals, and functional threshold power (FTP) and its history.
2. Ride & training data
When you log a ride or build your training, we store what you enter and the figures we calculate from it, which may include: distance, duration, elevation, route name, ride type, date, notes, cadence, and — where you provide them — power (including average/normalised power, training-stress and intensity figures) and heart rate. From this we compute personal statistics, records, power curves, training zones, training load, and fitness/fatigue/form trends (CTL · ATL · TSB) and related estimates.
3. Fitness & health-related data
If you choose to use the relevant features, you may enter health-related measurements such as body weight, body-fat percentage, resting heart rate, and maximum heart rate, and your rides may include heart-rate data. If you use the injuries feature, we also store the injury and soreness entries you log — the body area, side, severity, dates, your notes, and your check-in responses — solely to power the injury-awareness features you are using (such as adjusting training guidance while an issue is active). Under data protection law some of this may qualify as a special category (health) data. We process it only with your explicit consent, given when you choose to enter it, and solely to power the training features you are using. You can withdraw that consent at any time by deleting the data or your account. We never use this data for advertising and never sell it.
4. Community & social data
Paced includes optional communities, challenges, and badges. If you join or create a community, information you contribute — such as your display name and the ride/training statistics and activity you choose to share within that community — is visible to other members of that community. This sharing happens only because you choose to take part; if you don't join a community, none of your data is shown to other users.
5. Billing & subscription data
If you buy a paid subscription, payment is handled by our payment processor, Stripe. Stripe collects and processes your payment details (such as card information) directly — Paced never receives or stores your full card number. We store the subscription information we need to give you access: your tier, subscription status, trial and renewal dates, cancellation state, and the customer/subscription identifiers Stripe returns to us.
6. Referral data
If you use our referral programme, we store your referral code, which accounts were attributed to your referrals, and the status of any rewards earned or redeemed.
7. Connected services (optional)
If you choose to connect a third-party service such as Strava, we receive the profile details and activities you authorise it to share (including private activities, where you grant that permission) and import them as rides on your account, along with the secure connection tokens needed to keep the link alive. You can disconnect at any time in Settings — this revokes Paced's access on the provider's side and deletes our copy of the tokens; rides already imported remain yours in Paced. Deleting your account also revokes and deletes the connection. The provider processes your data under its own privacy policy.
8. Technical, usage & security data
- Request data: IP address (used transiently for rate limiting, security, and abuse prevention — not retained as part of your profile), plus browser and device type.
- Country: when you open the app we record which country the request came from, and store that two-letter country code on your account. Our hosting provider determines it at the network edge and passes us only the country — we never receive, process or store your IP address in order to work it out, and we do not record anything more precise: no region, no city, no postcode, no coordinates. We use it for one thing: to know which countries Paced is used in, so we can prioritise units, languages, currencies and support hours. It is never used for advertising, never shared, and it is deleted with the rest of your account.
- Usage data: to understand whether Paced is genuinely useful and keep improving it, we record when your account uses the app — a count of app opens, when you were last active, and which days you used it (we keep at most your 400 most recent active days). From this we derive simple activity summaries (for example whether an account is regularly active, occasional, or inactive, and an activity calendar), which the operator can see for support, service-statistics and product decisions — never for advertising, and never shared with anyone else. Aggregate business figures (such as total revenue per day) are also snapshotted over time; these contain no personal data.
- Security logs: limited access and event logs kept for a short period to protect the service.
- Device tokens: if you enable notifications, the push token needed to deliver them.
How we use your data
- To provide the service: store your rides, calculate your stats and records, run your training plan, and show your dashboard.
- To generate Paced AI and coaching insights — personalised reads, daily focus, ride breakdowns and projections derived from your own training data (see Paced AI and automated insights).
- To manage your account, subscription, trials, renewals, and referral rewards.
- To operate optional community features you choose to join.
- To keep the service secure, prevent abuse, and diagnose errors.
- To provide customer support and investigate problems: authorised personnel (currently the operator) can access your account data, including through an audited in-app support view that shows the service exactly as you see it. Every such access is recorded in an audit log, is used only for support, troubleshooting, security and service-quality purposes, and does not alter your data, one-time prompts, engagement records or earned rewards.
- To send you service and (if enabled) coaching notifications.
- To comply with our legal and regulatory obligations.
Paced AI and automated insights
Paced generates personalised training insights and coaching from the data on your own account. These insights are computed from your numbers to help you understand your training — they are informational only, are not medical, professional, or safety-critical advice, and no specific outcome is guaranteed. Paced does not carry out automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 of the GDPR.
Today these insights are generated by Paced's own coaching engine, running on our servers — your data is not sent to any external AI provider. If we ever introduce one to help power these features, it will be listed on our Subprocessors page (with at least 30 days' advance notice) before any data flows to it, it will be governed by this policy, and your health-related data will only ever be used to serve features you have chosen to use.
Legal bases for processing
| Purpose | Legal basis |
|---|---|
| Providing the core service (rides, stats, plan, insights) | Performance of a contract |
| Account management and authentication | Performance of a contract |
| Processing health-related fitness data you enter | Your explicit consent |
| Community features you choose to join | Your consent |
| Taking payment and managing subscriptions | Performance of a contract; legal obligation (tax/accounting) |
| Referral programme | Performance of a contract / legitimate interests |
| Notifications you enable | Your consent |
| Security, fraud prevention, and service integrity | Legitimate interests |
| Recording which country your account uses Paced from, to decide which units, languages, currencies and support hours to build | Legitimate interests |
| Responding to support requests | Contract performance / legitimate interests |
| Compliance with legal obligations | Legal obligation |
How we share your data
We do not sell your personal data and we do not share it for advertising. We share data only with the following parties, and only as needed to run the service:
- Google Firebase / Google Cloud: authentication, database (Cloud Firestore), and related infrastructure. Processes your account, profile, ride, fitness, community, and referral data on our behalf.
- Vercel: hosting and serverless compute. Processes request data on our behalf.
- Stripe: payment processing and subscription management for paid plans. Processes your billing data as an independent controller/processor under its own terms.
- Strava (only if you connect it): when you choose to link your Strava account, we request the profile and activity data you authorise there, and Strava learns that you use Paced. Strava acts as an independent controller under its own privacy policy; disconnecting (or deleting your account) revokes Paced's access.
- Other members of a community you join: for the display name and activity you choose to share there.
- Legal authorities: where required by law, court order, or to protect the rights, property, or safety of Paced, our users, or others.
- A successor: if Paced is involved in a merger, acquisition, or sale of assets, your data may transfer to the successor under the protections of this policy.
A full, current list of our subprocessors is on our Subprocessors page.
International data transfers
Our subprocessors (Google, Vercel, Stripe) may process data outside your country, including in the United States. Where they do, they rely on the UK/EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other recognised transfer mechanisms and applicable data-processing agreements, designed to give your data an adequate level of protection wherever it is processed.
Data retention
| Data type | Retention period |
|---|---|
| Account, profile & fitness data | Duration of your account; deleted within 30 days of account deletion |
| Ride & training data | Until you delete it, or until you close your account |
| Billing records | As required for tax, accounting, and legal obligations (typically up to 6 years) |
| Support communications | 2 years, or deleted with your account if sooner |
| Usage data (app-open history) | Your 400 most recent active days, plus overall counters; deleted with your account |
| Country of use | The latest country only — each app open overwrites it, so no history is built; deleted with your account |
| Security and access logs | Up to 90 days (support-access audit entries are kept longer for accountability, with your email removed on account deletion) |
Your rights
Depending on where you live, you may have the following rights over your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: delete your data, subject to legal retention obligations.
- Restriction: limit how we process your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where we rely on consent (including for health-related and community data), withdraw it at any time without affecting prior processing.
You can exercise most of these rights directly in the app: edit your profile in settings, add/edit/remove rides and measurements from your dashboard, manage your subscription through the billing portal, and permanently delete your account and all associated data at any time. Deleting your account erases your data from our active systems within 30 days, subject to the retention periods above. You also have the right to complain to your local data protection authority (in the UK, the Information Commissioner's Office).
Cookies and local storage
We use only a minimal set of strictly necessary cookies and browser storage — to keep you signed in, secure the service, and remember basic preferences such as your theme and units. We do not use advertising, marketing, or third-party tracking cookies. See our Cookie Policy for details.
Security
We implement technical and organisational measures to protect your data, including HTTPS/TLS encryption in transit, encryption at rest by Google Cloud, Firebase Authentication, account-scoped data isolation, and server-side verification of every request. See our Security & Trust page for details.
No transmission or storage system is ever completely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.
Age and children's privacy
Paced is intended for adults and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we will delete it.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the app. Continued use of the platform after changes take effect constitutes acceptance of the revised policy.
Contact
You can manage and permanently delete your data at any time from your account settings. To make a data request or ask about this policy, send us a message through our contact form.