Privacy Policy
Last updated: May 2026 (platform profile data disclosure; Strava integration live; 48-hour deletion guarantee)
WaxTrack ("we", "us", "our") is a chain wax interval tracking service for cyclists. This policy explains what data we collect, how we use it, and your rights regarding it.
1. What data we collect
- Account data: your email address and a hashed password when you register.
- Platform credentials: your Intervals.icu or Strava API credentials or OAuth tokens, stored encrypted using AES-256-GCM encryption.
- Platform profile data: your display name and the athlete ID assigned to you by your connected training platform, fetched once when you connect. We use these to label your profile inside the app (e.g. in the top bar) so you can see which platform account is connected. We do not fetch or store profile photos, email addresses, or other profile details from the platform.
- Activity data: cycling activity records (date, distance, bike used) synced from your connected training platform.
- Chain data: bikes, chains, wax logs, and settings you create within the app.
- Connection data: the IP address you used to sign up and the IP address and timestamp of your most recent login. At signup, the IP is also used for an approximate geographic lookup (country, region, city) which is stored alongside your account.
2. How we use your data
- To provide the WaxTrack service — syncing your rides and tracking wax intervals.
- To authenticate you and keep your account secure.
- To monitor signup activity for abuse prevention and to understand where our users are based (using the connection data described above).
- We do not sell, share, or use your data for advertising or marketing purposes.
- We do not share your data with any third parties beyond what is necessary to operate the service (e.g. our hosting provider).
3. Data storage and security
Your data is stored on servers hosted by Railway. Platform credentials (API keys and OAuth tokens) are encrypted at rest before storage. Passwords are hashed using bcrypt and never stored in plain text.
4. Data retention
Your data is retained for as long as your account is active. You may delete your account and all associated data at any time from Settings → Account → Delete account in the app. Deletion is immediate and permanent — once confirmed, your account, profiles, bikes, chains, wax logs and synced activity history are removed and cannot be recovered.
If you are unable to use the in-app deletion flow, deletion requests sent to [email protected] will be actioned within 48 hours of receipt. The same 48-hour window applies if you disconnect a third-party platform (such as Strava) from your account: any data associated with that platform connection is removed within 48 hours of the disconnection request.
5. Your rights
You have the right to:
- Access the data we hold about you (use the in-app backup export in Settings).
- Request correction of inaccurate data.
- Delete your account and all associated data (use Settings → Account → Delete account).
- Withdraw consent for data processing at any time by deleting your account.
For anything you can't do directly in the app, contact us at [email protected].
6. Cookies
WaxTrack uses a single session cookie to keep you logged in. No advertising or tracking cookies are used.
7. Third-party services
WaxTrack integrates with Intervals.icu and Strava. Your use of those platforms is governed by their respective privacy policies. We only request the minimum access needed to sync your activity and gear data, and to identify which platform account is connected (display name and athlete ID).
To approximate the geographic region of new signups, we send your IP address to ipapi.co at registration time and store the resulting country, region, and city alongside your account. This lookup happens once per signup; we do not send your IP to ipapi.co on subsequent visits or logins.
8. Changes to this policy
We may update this policy from time to time. Significant changes will be communicated via the app. The "last updated" date at the top of this page will always reflect the most recent revision.
9. Contact
Questions about this policy? Email us at [email protected].