Privacy Policy
This Privacy Policy explains what information LDPWorkshop collects, how it is used, and what rights you have over your data. LDPWorkshop is operated by Next4 Enterprises LLC, a limited liability company. If you have questions, contact ldpworkshop.com@gmail.com.
1. What we collect
Account information
When you sign up, we collect your email address, a username, and a display name. You may optionally provide a birth year, location country, city, disciplines, and social profile links.
Gear and activity data
Everything you enter into the app - parts, setups, ride logs, snapshots, feel ratings, wishlist items, and competition history - is stored and associated with your account.
Photos
Photos you upload are stored securely. GPS and EXIF metadata are stripped from images before storage.
Activity data from Strava
If you connect your Strava account, we import your ride history including distance, date, activity type, and speed metrics. We store the access token required to perform this sync. We do not access your Strava data beyond what is needed to import ride information.
Usage data
We collect information about how you use the app including page views, feature interactions, and session data. This is collected via PostHog, a product analytics tool. This data is used to improve the product. It is not sold.
Technical data
We log standard server data including IP addresses, browser type, and device type for security and debugging purposes.
2. How we use your data
We use the data we collect to:
- Operate the app and provide the features you use
- Attribute ride mileage to your parts and setups
- Send transactional emails such as account confirmation, password reset, and welcome messages
- Monitor for errors and fix bugs
- Understand how the product is being used and improve it
- Enforce the Terms of Service
We do not sell your data. We do not use your data for advertising.
3. What we share
We share data with the following third-party services to operate the product:
Supabase
Database, authentication, and file storage. Your data is stored on Supabase infrastructure.
Vercel
Hosting and content delivery.
PostHog
Product analytics. Usage events and session data are sent to PostHog.
Strava
If you connect your account, we exchange data with Strava via their API under their terms.
Resend
Transactional email delivery. Your email address is used to send account-related messages.
Stripe
Payment processing (when paid plans launch). If you subscribe to a paid plan, payment data is handled directly by Stripe. We do not store card numbers.
We do not share your data with any other third parties except where required by law.
4. Public content
LDPWorkshop allows you to make certain content public. Specifically:
- Your profile page at ldpworkshop.com/[username] if you set your profile visibility to public
- Setup pages you choose to make public
Public content is visible to anyone, including people without an account. You can change the visibility of your profile and setups at any time in your settings.
5. Data retention
We retain your data for as long as your account is active. If you delete your account, your personal data is removed within 30 days. Some anonymised usage data may be retained for product analytics purposes.
Parts, setups, and snapshots use soft deletion - they are marked as retired or archived rather than permanently deleted immediately. Hard deletion of your account removes all associated data.
6. Your rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion of your account and associated data
- Export your data
- Withdraw consent for optional data processing at any time
To exercise any of these rights, contact ldpworkshop.com@gmail.com. We will respond within 30 days.
If you are in the European Union or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR including the right to lodge a complaint with your local supervisory authority. Our lawful basis for processing your data is:
- Contract - processing necessary to provide the service you signed up for
- Legitimate interests - analytics and security monitoring
- Consent - optional features such as Strava connection
7. Cookies and tracking
LDPWorkshop uses cookies and similar technologies for:
- Authentication (keeping you logged in)
- Product analytics via PostHog
We do not use advertising cookies. You can disable cookies in your browser settings, but doing so may prevent the app from functioning correctly.
8. Children
LDPWorkshop is not directed at children under the age of 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact ldpworkshop.com@gmail.com and we will delete it.
9. Security
We use industry-standard security practices including encrypted connections (HTTPS), server-side authentication checks on all data operations, row-level security policies on the database, and EXIF stripping on uploaded photos. No method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
10. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice in the app. Continued use of the service after changes are posted constitutes acceptance of the updated policy.
11. Contact
Questions about this policy: ldpworkshop.com@gmail.com
LDPWorkshop is operated by Next4 Enterprises LLC, a limited liability company.