Last updated: 15 September 2026
VirtualRide processes the data needed to run accounts, subscriptions, and Street View rides. This page lists what we store, why, how long, and how you can delete it.
Operator: VirtualRide. Contact: hello@virtualride.app or Support.
On our servers (Cloudflare D1) we may store:
vr, and on the iOS app a session token in on-device storage so you stay signed in.rc_app_user_id) and subscription status.email_submit and purchase).On your device we may store:
vr_ref (HttpOnly) if you used an affiliate link.We do not store a recording of your ride, trainer power, cadence, speed, or a GPS track. Bluetooth trainer data is read on your device and used to pace Street View. It is not uploaded. Street View and map requests go from your browser or the iOS app to Google; we do not host or keep Street View imagery. In-memory prefetch of upcoming panoramas exists only while you ride and is not written to disk.
Email, password hash, and session tokens authenticate you. Stripe and Apple / RevenueCat identifiers take payment and enforce the paywall. Email tokens confirm the address. Funnel events and referral rows help us understand checkout and pay affiliates. Legal basis for accounts and paid access is contract performance (GDPR Art. 6(1)(b)). Funnel and referral records are legitimate interests in operating the service (Art. 6(1)(f)).
Stripe processes web payments. Apple processes iOS in-app purchases. RevenueCat receives a purchaser identifier so we can unlock the ride after an App Store purchase. Google receives map and Street View requests from your browser or app (including IP address) under Google’s privacy policy. Hosting and the database run on Cloudflare. We do not sell personal data.
vr is an HttpOnly session cookie. vr_ref remembers an affiliate
code. They are not used for advertising. The iOS app may also keep a session token on
device. You can end a session with Log out.
Account rows stay while the account exists. Sessions expire after 30 days of idle time or when you log out. Email tokens expire after 24 hours. Funnel and referral rows stay for accounting and abuse prevention until you delete the account or ask us to erase them. After you delete the account we remove the user row, sessions, email tokens, funnel events, and referral rows tied to that email.
You can delete the account from the logged-in Ride screen (Delete account). You must confirm your password. That erases the personal data listed above from our database.
Deleting the account does not cancel an App Store subscription. Cancel that in Settings → Apple ID → Subscriptions or you may still be charged. A web (Stripe) subscription is set to stop renewing when you delete the account.
If you are in the EEA/UK you may also access or correct your data, object to legitimate interests processing, and complain to a supervisory authority (in Finland: the Office of the Data Protection Ombudsman). Email hello@virtualride.app if you cannot use the in-app delete flow.
VirtualRide is for people 18 or older. We do not knowingly create accounts for children.