Privacy notice
What VeloWatt Pro stores about you, why, where, for how long, and what you can do about it. This notice applies to this website today, and to the app and the account service from the date they become available.
Last updated: 16 September 2026
1. Who is responsible
The controller under the GDPR is: VeloWatt UG (haftungsbeschränkt) Hoher Weg 3, 26605 Aurich Germany Represented by: Niels Meereboer, Managing Director Email: support@ridevelowatt.com
For anything about your data, write to support@ridevelowatt.com.
2. What this notice covers
This website (ridevelowatt.com), the account service the app and the account pages talk to (api.ridevelowatt.com), the VeloWatt Pro app, and riding together with other people.
3. This website
The website sets no cookies, runs no analytics and loads nothing from other companies: fonts and images come from this server. Your browser remembers whether you chose the light or dark theme, on your device only.
The server receives the technical data every web request carries (address, time, page, browser) to answer it, and keeps no access log of it.
4. Your account
To use VeloWatt Pro you sign in with your email address and a one-time code we send to it. We store your address, the name you ride under, the machines you are signed in on and when each was last seen, and a record of which version of the terms you accepted and when -- and, when you subscribed, that you asked for the subscription to start straight away. Legal basis: the contract with you (Art. 6(1)(b) GDPR).
The account page in your browser holds one cookie, which keeps you signed in. It is necessary for the page to work and is not used for anything else.
5. Trial, subscription and payment
The trial lasts 14 days and needs no card. So that it is used once per person, we keep a keyed fingerprint of the address (not the address itself) for up to two years. Legal basis: our legitimate interest in the trial not being repeated (Art. 6(1)(f) GDPR).
Subscriptions are sold and charged by Stripe as the reseller (merchant of record). Stripe receives your payment details and billing address directly and processes them under its own responsibility; we never see your card. From Stripe we receive a customer reference, the state of your subscription and which periods are paid for.
Invoices and the records behind them are kept for as long as tax and commercial law requires, which in Germany is up to ten years. That obligation is independent of your account: deleting the account does not delete an invoice we are required to keep.
6. Rides, workouts and your profile
**Backups are off until you turn them on.** A finished ride stays on your machine. Nothing about your riding is kept on our servers unless you ask for it, in the app or on the account page.
When you do ask, finished rides are kept so they are not lost with a machine: time, position in the virtual world, speed, power, cadence and, if you use a sensor, heart rate. Your workouts are kept the same way. You can download all of it from the account page.
Heart rate is health data (Art. 9 GDPR), and the only basis for keeping it is your explicit consent (Art. 9(2)(a) GDPR), which is what that switch is. We record when you gave it and when you took it back. The service refuses to store a ride without it.
You can withdraw at any time by turning backups off, which stops new backups, and the effect of what happened before stays lawful. Deleting what was already kept is a separate button beside it, so that turning a switch off cannot destroy a season of riding by accident.
Your rider profile, your appearance and the language you read are synced whether or not backups are on: that is what another machine and the riders in your room need, and it is not training data.
7. Riding with others
In a shared world, the riders in your room see the name you ride under and your position and speed while you ride. The relay that carries this keeps nothing after the ride; its logs keep a shortened network address for 14 days to keep the service safe.
8. Strava and intervals.icu
Only if you connect them. We then store the access they grant (encrypted), and send the rides you finish, or the workouts you plan, to that service. Disconnecting, or deleting your account, revokes it.
9. Emails
We write to you only when something has happened to your account: a failed payment, a cancellation and its confirmation, a trial about to end, a deleted account. There is no newsletter and no marketing email.
10. Who processes data for us
Each works on our instructions under a data processing agreement. The list below is the one in use; if it changes, this notice changes with it.
- Akamai Technologies (Linode), servers in Frankfurt, Germany: the website, the account service and the relay.
- Supabase, database and sign-in in the EU (Frankfurt).
- Mailgun (Sinch), sending emails from the EU region.
- Cloudflare, storage for ride backups, downloads and database backups (R2), and delivery of the app's installers.
- Stripe, as the reseller of subscriptions (see section 5).
11. How long we keep it
- Your account and everything in it: until you delete the account.
- Rides and workouts kept here: while backups are on, and until you erase them or delete the account. Turning backups off stops new ones.
- Database backups: up to 30 days, with monthly copies up to 12 months.
- The trial fingerprint: up to two years.
- A cancellation you send us: up to three years, to show it arrived.
- Server logs of the account service and the relay: up to 14 days. The relay's keep only a shortened network address.
- Records of what was done with your account (terms accepted, access granted by support, a cancellation reviewed): while the account exists, and for up to three years after it is deleted.
- Invoices and tax records: as long as tax and commercial law requires, up to ten years.
12. Your rights
You may ask for access, correction, deletion, restriction and a copy of your data, and object to processing based on legitimate interest. Export and deletion are buttons on the account page (https://api.ridevelowatt.com/account); anything else, write to us.
You may complain to a supervisory authority; ours is the Data Protection Commissioner of Lower Saxony (Die Landesbeauftragte für den Datenschutz Niedersachsen), Prinzenstraße 5, 30159 Hannover, https://www.lfd.niedersachsen.de.