Your Rights and Our Legal Bases
Effective Date: November 2, 2023
Strava is committed to providing you with meaningful information and choices about the information you share with us. We explain how we collect, use, share, and protect your information in our Privacy Policy. We provide the same suite of privacy tools and controls to all of our members worldwide who use Strava’s websites and the related mobile applications and services (collectively, the "Services"). Strava, Inc. is the controller of your personal information. Please note that Strava, Inc. is based in the United States; when using the Services, you are sending your personal information to the United States.
Based on the laws of your residence, particular rights may be available to you. Please click on the links below to learn more about your rights and our legal bases for processing your information.
European Economic Area Member Rights
Your Rights and How to Exercise Them
If you reside in the European Economic Area ("EEA") or the United Kingdom ("UK"), you have the right to access, download, rectify, or erase your information, as well as the right to restrict and object to certain processing of your information. While some of these rights apply generally, certain rights apply only in certain limited circumstances. We describe these rights below:
Access and Portability
You can access much of your information by logging into your account. If you require additional access, please contact us at https://support.strava.com. To enforce your right to data portability, click here to download a copy of your data.
Rectify, Restrict, Limit, Delete
You can also rectify, restrict, limit or delete much of your information by logging into your account, such as to edit your profile, delete photos or videos you have posted, remove individual activities from view, or delete your account. You can delete individual activities or click here to delete your account. If you need assistance with this, please contact us at https://support.strava.com.
Object
Where we process your information based on our legitimate interests explained below, you can object to this processing in certain circumstances. In such cases, we will cease processing your information unless we have compelling legitimate grounds to continue processing or where it is needed for legal reasons.
Revoke consent
Where you have previously provided your consent, such as to permit us to process health-related data about you, you have the right to withdraw your consent to the processing of your information at any time. For example, you can withdraw your consent by updating your settings. In certain cases, we may continue to process your information after you have withdrawn consent if we have a separate legal basis to do so (e.g., to comply with a court order) or if your withdrawal of consent was limited to certain processing activities.
Complain
Should you wish to raise a concern about our use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection supervisory authority. Strava’s lead supervisory authority is the Data Protection Commission of Ireland.
Our Legal Bases for Processing Your Information
Data protection law (for example, in the EEA or Brazil) requires organizations to have legal bases to collect, use, share and otherwise process information about you. While some of your rights apply generally, certain rights only apply depending on the legal bases we rely on to process data. We explain these legal bases and your rights below.
To provide the Strava Services
As described in the Terms of Service, the core Strava Services cannot be provided, and the Terms of Service cannot be performed, without Strava processing data including for the following purposes:
- Create your account and provide you with access to the Services.
- Record your activities.
- Help you analyze your performance. For example, to compare your past efforts and analyze your training.
- Help you manage your training. For example, to set goals and use your training dashboard.
- Process your Strava subscription.
- Respond to your support requests and comments.
- To ensure the safety and security of our Services.
Since we process data you provide to us which is necessary to perform our contract with you, you have the right to port or transfer that data if you reside in the EEA or the UK.
With your consent
We ask for your permission to process your information for certain purposes and you have the right to withdraw your consent at any time. We ask for your consent to:
- Obtain your geolocation when recording GPS-based activities including to use our Beacon safety feature.
- Collect or infer health information which may include information inferred from sources such as heart rate or other indicators. We use your health information to provide helpful statistics and visualizations.
- Send you marketing communications.
- Collect and process information from third-party products and services, such as Facebook or Google, or devices and apps, such as your Garmin watch or Peloton account, which you connect to Strava.
- Access photos, location, and contacts information through your device-based settings so we can provide the services described when you enable the settings.
Legal obligation or for the establishment, exercise or defense of legal claims
We process data where we have a legal obligation to do so, for example, where we're responding to a valid and binding legal process from a law enforcement agency for certain data. See our Privacy Policy, under "Legal Requirements" for more information. We may also collect and process personal information, for example, your date of birth, to comply with regulations that require us to provide additional protections for children.
In addition, processing may be needed for us to establish, exercise or defend civil or criminal claims in connection with actual or potential litigation including to protect the Strava Services, our property or other legal rights, including those of our members, partners, or subsidiaries.
To protect vital interests
We process data where it is necessary to protect an interest which is essential to someone’s life or protect any person from serious bodily injury. This includes processing information to combat harmful conduct both on and off of our Services.
Carrying out a task in the public interest
Where laid down by EU law or the law in an EU Member State, we may process your data to perform processing in the public interest. This may include protecting against harm and undertaking research for social good. You have the right to object to, and seek restriction of, our processing of your personal information when we process data using this legal basis.
In furtherance of legitimate interests
We process your information for our legitimate interests, and those of third parties, while applying appropriate safeguards that protect your privacy, rights and interests. We do this to:
- Market the Services, activities on Strava and other commercial products or services. For example, our partners may pay us to promote their challenges, products, or services on Strava. This is one of the ways we are able to provide the Services on a sustainable basis.
- Maintain our business by conducting research and continuously improving the Services so as to offer innovative and customized offerings to our members and partners.
- Convert your information into aggregated form for use by us and our partners. Our partners may use this information to improve transportation infrastructure, such as with Strava Metro, or for other commercial purposes including developing useful insights. We also aggregate information to generate community-powered features like our Global Heatmap, Points of Interest, and Start Points.
- Keep the Services safe and secure by using information to prevent or detect violations of our Terms of Service or Community Standards, fraud or abuse, and other harmful or illegal conduct. We may also share information with third parties, including law enforcement agencies for this purpose.
- Promote the Services, including email and in-product marketing campaigns to inform you about our Services.
- Enable you to find new ways to interact by using the Services. For example, to compete on segments, participate in clubs, challenges, or events, follow other athletes, and use features that help athletes interact with one another, such as group activities or flyby.
- Enable you to contribute to and access community-powered insights. For example, sharing points of interest or public photos from specific routes to provide insights to other users about those places.
- Enable you to visualize your activities in new ways. For example, by creating personal heatmaps or using your training log.
- Customize the Services for you. We may suggest segments, routes/trails, challenges, points of interests, or clubs that may interest you, athletes that you may want to follow, or new features that you may want to try. We rely on our legitimate interest in retaining members when ensuring that we offer new opportunities, such as showing routes or segments of interest to our community, and we may use location information when suggesting such opportunities.
Brazil Member Rights
If you reside in Brazil, you have rights under the Lei Geral de Proteção de Dados ("LGPD"), including the right to access, rectify, download or erase your information, as well as the right to restrict and object to certain processing of your information. You can find more information about how to exercise these rights in the section above entitled European Economic Area Member Rights.
The LGPD requires us to have legal bases to collect, use, share and otherwise process information about you. You can find a description of the legal bases we rely on by reviewing the above section entitled Our Legal Bases for Processing Your Information.
If you have questions about your rights, you may contact us at DPO@strava.com.
Germany Member Rights
If you reside in Germany, you have a right to report content that you believe is unlawful under the Network Enforcement Act ("NetzDG"). To submit a report, please email netzdg@strava.com.
Please note that Strava separately maintains Community Standards that prohibit certain types of content, including hate speech. You can report content which you believe violates our Community Standards by using our reporting or flagging tools in our app or on our website, or by visiting the Strava Support Center.
Japan Member Rights
If you reside in Japan, you may have additional rights under Japan’s Act on the Protection of Personal Information (“APPI”). Please note that when using the Services, you are sending personal information into the United States. Your personal information may also be transferred to Strava’s offices, subsidiaries, or service providers, which may be located outside the United States, including in the EEA or the UK.
Both the UK and the EU have been designated by Japan’s Personal Information Protection Commission (“PPC”) as having adequate data protection standards to those in Japan. The PPC has also published summaries of the United States’ and California’s personal information protection systems, which are linked below (available in Japanese only):
U.S. State Member Rights
If you are a resident of certain U.S. states, such as California, Colorado, Connecticut, Virginia, or Utah, you may have additional rights under your corresponding state laws (“State Privacy Laws”). Only you or someone legally authorized to act on your behalf may make a request related to your personal information. Below, we provide a general description of your rights under these State Privacy Laws and additional disclosures about your personal information.
Your Rights and How to Exercise Them
Rights to know about the personal information we collect and share
State Privacy Laws give you the right to request that we disclose the specific pieces of personal information we have collected about you, which we do after we receive and validate your request.
You have the right to make a free request two times in any 12-month period. We will make the disclosure no later than 45 days of receiving your request, unless we request an extension. In the event that we reasonably need a 45-day extension, we will notify you of the extension within the initial 45-day period.
You may request the disclosures described above by clicking here to download a copy of your data.
Right of deletion
You have the right to request that we delete your personal information, subject to certain exceptions. After we receive and validate your request, we will delete your personal information, as well as direct our service providers to delete your personal information, unless an exception applies.
You can delete individual activities or click here to delete your account.
Right to non-discrimination
You have the right not to receive discriminatory treatment for the exercise of your privacy rights under State Privacy Laws.
We will not discriminate against you for exercising any of your State Privacy Law rights.
Right to opt out of personal information sales or shares
We have never sold your personal information for monetary value, and we still don’t. However, under certain privacy laws, some non-monetary sharing of personal information with third parties – for example to provide you with targeted advertising for Strava on other platforms – may be considered a “sale” or “share.”
Strava does not “sell” or “share” your personal information for analytics or to serve you with targeted advertising on other platforms unless you accept non-essential cookies using our cookie banner.
You have the right to direct us to not “sell” or “share” your personal information. We do not “sell” or “share” the personal information of users we know are under 16 years old. If you opted into receiving our targeted advertising using our cookie banner, you may opt out of targeted advertising by (1) clicking the “Do Not Share My Personal Information” link in the footer below and following the instructions; (2) clicking in our app on the “Personal Information Sharing” link in your Privacy Controls and following the instructions; or (3) setting your cookie preferences to deny non-essential cookies. More information on your opt out options is provided here.
Once you make an opt-out request, we will wait at least 12 months before asking you if you want to re-opt into “sales” or “shares” of your personal information.
Right to correct inaccurate personal information
You have the right to direct us to correct inaccurate information that we maintain about you. You can do so by contacting us using the information provided in the “How to contact us” section below.
Right to limit the use and disclosure of sensitive information
You have the right to direct us to only use your sensitive information, such as precise geolocation data or health data, for limited purposes, such as providing you with the services you requested.
We obtain your express consent before processing your sensitive information and only use it to provide the Services, in accordance with your privacy settings.
Additional Disclosures About Your Personal Information
Categories of information we collect and disclose for a business purpose
We collect the following categories of personal information from you in connection with the Services. In addition, during the past 12 months, we have disclosed these categories of personal information to Service Providers for the following business purposes:
Category of Personal Information | Category of Service Provider(s) | |
---|---|---|
Identifiers, such as your real name, athlete ID, Internet Protocol address, email address, and other similar identifiers. | Advertising and communications Subsidiaries Analytics Data hosting and pipeline Search Site performance and debugging Support Surveys Trust and Safety |
|
Personal information categories, such as: | Physical characteristics such as height or weight, as indicated by you | Analytics Data hosting and pipeline |
Payment information | Payment processors | |
Categories of protected classifications, such as: | Gender, as identified by you | Advertising and communications Analytics Data hosting and pipeline Surveys |
Age, as identified by you | Advertising and communications Analytics Data hosting and pipeline Surveys |
|
Commercial information, such as the record of purchase of your Strava subscription | Advertising and communications Data hosting and pipeline Payment processors Subsidiaries Surveys |
|
Biometric information, such as your exercise data | Advertising and communications Analytics Data hosting and pipeline Subsidiaries |
|
Internet or other electronic network activity information, such as session logs | Analytics Data hosting and pipeline |
|
Geolocation data, such as the physical location, direction and speed of your recorded activity | Advertising and communications Analytics Data hosting and pipeline Subsidiaries |
|
Electronic, visual, or similar information, such as photos | Data hosting and pipeline Support |
|
Inferences drawn from any of the above information to create a profile reflecting your preferences, characteristics, behavior, abilities, and aptitudes, such as Relative Effort | Analytics Data hosting and pipeline |
According to State Privacy Laws, personal information does not generally include:
- Publicly available information from government records
- De-identified or aggregated consumer information.
Other disclosures about your personal information
Our Privacy Policy covers additional disclosures about your personal information that State Privacy Laws require we provide to you. Learn more about the sources from which we collect your personal information, the business or commercial purposes for which we collect your personal information, and the categories of third parties with whom we share your personal information.
Changes to This Information
We reserve the right to modify this information at any time. Please review it occasionally. If Strava makes changes to this information, the updated page will be posted on the Services in a timely manner.
How to contact us
Questions or comments about this information, your rights or our disclosures, or requests to appeal a decision made regarding your privacy rights may be submitted by mail or email using the contact information or via https://support.strava.com.
Strava, Inc.
208 Utah Street
San Francisco, CA 94103
USA
Attn: Legal
DPO@strava.com
© 2023 Strava