中山市我骑软件开发工作室 (referred to as “we” or “us”) operates iRide. This policy explains how we process personal information when providing our WeChat Mini Program, official website, and related services. It also specifically describes how we connect cycling data from Intervals.icu. Please read this policy before using the relevant features.
1. Scope
This policy applies to the iRide WeChat Mini Program, the official website, and the cycling activity recording, performance analysis, data connection, and cycling sharing services that we provide directly. Services provided independently by third-party platforms are governed by their own privacy rules. When you leave iRide to authorize a third-party platform, you should also read that platform’s rules.
2. Information we process and why
| Category | Main information | Purpose |
|---|---|---|
| Account and identity | WeChat open identity identifiers, plus the nickname, profile image, region, date of birth, biography, and other profile information you choose to provide | Create and identify your account, display your profile, and protect account security |
| Cycling and sports data | Activity time, distance, route coordinates, elevation, speed, heart rate, cadence, power, device, and data-source information | Create cycling records, display routes, and calculate performance and periodic statistics |
| Third-party connection information | Third-party account identifiers, OAuth access tokens, authorization status, and synchronization results | Connect data sources after authorization, synchronize activities, and diagnose synchronization failures |
| Files and images you submit | FIT cycling files, profile images, and photos used to create cycling posters | Import activities, display your profile image, create and share cycling posters, and perform necessary content-safety checks |
| Social, sharing, and order information | Following relationships, sharing records, membership and quota purchase orders, and fulfillment records | Provide following and sharing features, and complete purchases, fulfillment, refunds, and reconciliation |
Route location data and photos that may contain faces are more sensitive. You may choose not to provide them. If you do not, route display, performance analysis, or poster features that depend on them may be unavailable, but unrelated features will not be affected.
We do not retain raw FIT file bytes, raw responses from third-party activity APIs, or raw second-by-second stream responses. We retain only the converted activity facts, source associations, and standardized sports streams.
3. Third-party cycling platform connections
We read data only after you actively choose to connect a third-party cycling platform and complete that platform’s authorization flow. We use the data within the authorized scope for iRide cycling records, route display, and performance analysis. Each third-party platform provides its services independently and applies its own privacy rules.
Intervals.icu
3.1 Authorization and access
Only when you choose to connect Intervals.icu will we take you to Intervals.icu’s authorization page. We do not collect your Intervals.icu password or personal API key. We request only the read-only ACTIVITY:READ scope and do not request write access.
3.2 Data obtained
Within the authorized scope, we obtain your Intervals.icu athlete identifier, OAuth access token, activity summaries and details, second-by-second sports streams, original source information, and device information. For second-by-second power, we use only the uncorrected original power values supplied by Intervals.icu. We filter out activities whose original source is Strava and do not import those activities again through Intervals.icu.
3.3 Purposes
We use this data only to synchronize cycling activities within your authorized scope to iRide, create your personal cycling records, display routes, analyze performance, calculate periodic statistics, and diagnose synchronization failures. We do not use the read-only authorization to modify your data in Intervals.icu.
3.4 Revocation and reauthorization
You can revoke iRide’s authorization from Intervals.icu. After we receive a revocation signal or confirm that the token is permanently invalid, we delete the access credentials and stop future synchronization. Activities and standardized streams already synchronized to iRide are not automatically deleted when authorization is revoked and remain subject to Section 4 of this policy. You can restore synchronization by authorizing again.
Other cycling platforms
Strava, Xingzhe, and other cycling platforms are independent data sources. Connection availability differs based on each platform’s authorization conditions and the availability offered by iRide. We read and process data from a platform only when the connection is available to you and you actively complete authorization, and only within the scope disclosed to you.
Revocation capabilities also differ by platform. When a platform sends us a revocation signal, or when we confirm that a token is permanently invalid, we delete the corresponding access credentials and stop future synchronization. Xingzhe currently does not send revocation notices to iRide, and iRide does not provide an active disconnect function for Xingzhe. An action taken only on Xingzhe therefore does not mean that iRide has automatically stopped processing. To delete related data, close your account or submit a deletion request using the contact email at the end of this policy.
4. Retention and deletion
- OAuth credentials: retained only while the connection remains active; deleted when we receive a platform revocation signal, confirm that the token is permanently invalid, or the account is closed.
- Activities and standardized sports streams: retained on an ongoing basis, without a fixed expiry date, to continue providing cycling records and analysis; deleted when the related activity is deleted through existing product mechanisms or when you close your account. A second-by-second stream rejected during collision deduplication is deleted immediately.
- User-uploaded photos: used temporarily only while generating a cycling poster, with the original photo deleted after generation. A public poster is accessible for 10 days by default, while its generation record is retained for 90 days by default. Account closure or another earlier deletion event takes precedence, and cleanup across systems and object storage is completed using the eventual-consistency process described in this section.
- Financial records: orders, transaction records, settlements, reconciliation records, support cases, refunds, and similar records are retained for at least three years as required by law. After account closure, their direct link to your natural-person identity is removed, and the closed account no longer receives membership benefits or remaining quota.
- Content-safety and necessary audit records: retained only to the extent needed to meet security and compliance obligations; identifiable links to the natural person are removed after account closure.
Account closure takes effect once confirmed and cannot be reversed. We then delete or irreversibly erase identity profiles, social relationships, third-party connections and credentials, activities and route streams, performance and statistical data, user photos, posters, and other account data. Financial and audit records that must be retained by law are kept under the rules above and de-identified. Cleanup across systems and object storage proceeds using eventual consistency and is considered complete only after all cleanup succeeds.
5. Third-party processing
We do not sell personal information. We use only the following third-party processing capabilities, and only as needed for the corresponding purpose:
| Third-party capability | Information and purpose |
|---|---|
| Tencent Cloud Object Storage | Hosts profile images, QR codes, user photos, generated posters, and standardized sports-stream files |
| Tencent Maps | Provides geocoding and reverse geocoding to convert places and route information into readable location descriptions |
| Volcengine Ark (Doubao) | Processes photos or signed image addresses actively submitted by users for visual understanding and image generation, and generates poster captions from cycling metrics |
| WeChat content security | Performs content-safety checks on relevant images |
6. Public display and sharing
A public profile displays only information suitable for public distribution and allowed by product rules or your privacy settings. After you actively create and share a cycling poster or sharing link, anyone with the link may be able to view the relevant content. Whether a route is displayed depends on your route privacy settings. Do not upload or share another person’s information unless you are authorized to do so. If a photo contains another person, obtain their consent first.
7. Security
We use access controls, least-privilege permissions, log redaction, object-access restrictions, and incident-response measures to protect personal information. Third-party OAuth tokens are never returned to the Mini Program in plain text or written to plain-text logs. If a security incident may affect personal rights and interests, we will take remedial and notification measures as required by law.
8. Your rights
- You can edit your profile in the Mini Program and use privacy and display settings to manage the visibility of route, power, height, weight, FTP, gender, and other information.
- If the relevant platform provides an OAuth revocation option, you can revoke authorization on that platform. The handling after we actually receive a revocation signal or confirm that the token is permanently invalid is described in Section 3.
- You can request account closure under “Settings — Account & Security” in the Mini Program. If unsettled funds or benefit matters prevent closure, we will explain the reason and how to resolve it.
- You can use the contact email below to request access, copies, correction, deletion, or an explanation of this policy. To protect account security, we may first need to verify your identity.
We will respond within three business days after receiving your email. If your request concerns information that we must retain by law, we will explain why it cannot be deleted immediately and how it will be handled.
9. Children
A child under 14 should use the service and provide personal information only with the consent and guidance of a parent or guardian. A guardian who believes that we have processed information about a child under their guardianship can contact us using the email below.
10. Contact us and policy updates
Personal information processor: 中山市我骑软件开发工作室
Email: support@mail.iridesports.cn
You can use this email for privacy-rights requests, feedback, and reports of infringement or inappropriate content. We may update this policy when our services, legal requirements, or processing practices change. If a material change occurs, we will provide notice in an appropriate manner as required by law.