Privacy
Effective date: 2026-08-11
Data from Strava
With your authorization, RouteStamp receives profile name and avatar, activity summaries, and activity location fields needed to resolve country and supported region. We request read and activity:read by default. You may explicitly choose activity:read_all, which includes “Only You” activities and privacy-zone data.
Purpose and retention
We use this data only to display your private RouteStamp. It is a transient cache: RouteStamp revalidates it from Strava by the six-day target and never displays it after seven days without successful revalidation. Failed refreshes hide the data until a refresh succeeds. Expired records are purged by the protected worker.
Coordinates and security
Coordinates are processed transiently on the server for country/region resolution and immediately discarded. They are not persisted, logged, returned to the browser, or disclosed to other RouteStamp users. OAuth tokens are encrypted before storage and kept server-side. Vercel hosts the application; Supabase provides server-side database storage. Processing locations: Vercel: iad1 — Washington, D.C., USA Supabase: ap-northeast-1 (Tokyo)
What we do not do
We do not sell Strava Data, use it for advertising, AI, analytics reuse, product-improvement analytics, or disclosure to other RouteStamp users. We do not create public RouteStamp pages or public maps from Strava Data.
Your choices
RouteStamp displays your current, successfully revalidated cache in the private app. To export your Strava data, use Strava’s own tools. You can withdraw consent by disconnecting. Disconnect & Delete Strava Data revokes access, deletes local Strava and derived data, clears the session, and shows a durable written confirmation ID and timestamp. Strava-side deletion and revocation are handled through Strava’s revoke endpoint and deauthorization webhooks. You may also use Strava’s own connected-app settings and privacy controls.
Strava statements
Strava may monitor and collect Usage Data relating to API access and may use Usage Data for any business purpose, including API or platform enhancements, support, and compliance. Strava’s own privacy practices are described in its Privacy Policy.
Policy reference: Strava API Policy effective June 1, 2026.
RouteStamp is independently operated by Harold Choo.