Logo
HikeBike
Transparency and GDPR compliance

Privacy Policy

Your data stays under your control

Last updated : August 3, 2026

Preamble: our commitment

  • No targeted advertising and no ad tracking.
  • We do not sell or rent your personal data.
  • Data is hosted in Europe (OVH + Cloudflare R2 WEUR region).
  • We apply GDPR-level standards to all users.
  • You can control your data and consent settings from your account.

Data controller

  • HikeBike (sole proprietor - Andy Dabek).
  • Address: 3 rue Claude Monet, 62800 Lievin, France.
  • Privacy contact: support@hikebike.app.

1. Data we collect

  • Account: email, username, hashed password, subscription status.
  • Routes: planned and recorded routes, segments, favorites, waypoints, stats (distance, elevation, time).
  • Location: GPS positions and route history needed for navigation and sync.
  • Location is used only when required for navigation features and can be disabled at any time in device settings.
  • Sensors (optional): heart rate, cadence, power when you enable sensors and provide explicit consent.
  • Sensor data can be considered health data under GDPR Article 9.
  • You can withdraw consent at any time from app settings.
  • Content: photos and media points you choose to add.
  • Support: message content, exchange dates and resolution status needed to process your request.
  • Technical data: IP address, security logs, session tokens, local preferences and caches.

2. How we use data

  • Create and secure your account.
  • Plan, navigate and record routes.
  • Match segments and compute performance stats.
  • Display local weather and alerts (if enabled).
  • Provide community features (shared routes and media).
  • Provide support, prevent abuse and secure the service.

3. Legal basis and retention

  • Contract performance: account, routes, navigation, synchronization.
  • Consent: sensor data (health/activity).
  • Legal obligation: invoicing and accounting obligations.
  • Legitimate interest: security, logging and abuse prevention.
  • Retention: while the account is active, then deleted on request or account deletion.
  • Support messaging: an inactive request is closed no later than after 90 days; a closed conversation is automatically deleted no later than 12 months after closure.
  • You can immediately delete a closed conversation from the messaging interface. Deleting your account also deletes its associated support history.
  • Deleted accounts: main data is deleted within 6 months, subject to legal and technical constraints.
  • Technical and security logs are retained up to 12 months.
  • Billing data is retained for the legal retention period.

4. Your rights

  • Access, correction and deletion of your data.
  • Data export (JSON) from account settings.
  • Data portability and restriction rights.
  • Withdraw sensor consent at any time from the app.
  • Delete your account at any time from the app.
  • Lodge a complaint with your data protection authority.

5. Providers, data sources and sharing

  • OVH (database and API hosting) - Europe.
  • Cloudflare R2 (image storage) - WEUR region.
  • Mapbox (maps, geocoding, static images).
  • OpenWeatherMap (weather).
  • Stripe (payments).
  • Zimbra/SMTP (transactional emails).
  • No commercial data sharing.

6. Security and incidents

  • Appropriate technical and organizational safeguards (encryption in transit, access control, logging).
  • Support message content is encrypted in the database, and moderator access to unread requests and moderator actions are logged.
  • If a data breach occurs, we notify affected users and competent authorities as required by law.

7. International transfers

  • Some providers may process data outside the EU (for example Stripe, Mapbox, OpenWeatherMap).
  • Such transfers rely on appropriate safeguards (for example Standard Contractual Clauses).
  • We limit transfers to what is strictly necessary to provide the service.

8. Payments and billing

  • Payments are processed exclusively by Stripe (PCI-DSS certified provider).
  • We do not store bank card details.
  • We only receive identifiers and status information required to activate subscriptions.

9. Cookies and local storage

  • Technical cookies only (session/authentication).
  • No third-party advertising or analytics cookies.
  • Cookies are configured with HttpOnly, SameSite=Lax, and Secure in production (HTTPS).
  • Tokens are never stored in localStorage.
  • Local storage is used for preferences, route/POI caches and images.
  • No ad tracking.

10. Minors

  • The service is intended for users who have reached the minimum legal age to consent to personal data processing under applicable law (for example, 15 in France).
  • If you are below that minimum age, you must obtain permission from your parent or legal guardian before using the service.
  • By using the service, you represent that you meet these age requirements or have the required authorization.

11. Contact

  • To exercise your rights or ask a question: support@hikebike.app
  • Privacy contact: support@hikebike.app (or via the website contact page).
  • We respond within 30 days.
This policy follows GDPR (EU) 2016/679 and applicable privacy laws.

For all users: we apply high privacy and security standards.

If translations differ, the French version prevails.