Privacy Policy

Last updated: 15 September 2026

VirtualRide processes the data needed to run accounts, subscriptions, and Street View rides. This page lists what we store, why, how long, and how you can delete it.

Who we are

Operator: VirtualRide. Contact: hello@virtualride.app or Support.

What we collect and store

On our servers (Cloudflare D1) we may store:

On your device we may store:

What we do not store

We do not store a recording of your ride, trainer power, cadence, speed, or a GPS track. Bluetooth trainer data is read on your device and used to pace Street View. It is not uploaded. Street View and map requests go from your browser or the iOS app to Google; we do not host or keep Street View imagery. In-memory prefetch of upcoming panoramas exists only while you ride and is not written to disk.

Why we use the data

Email, password hash, and session tokens authenticate you. Stripe and Apple / RevenueCat identifiers take payment and enforce the paywall. Email tokens confirm the address. Funnel events and referral rows help us understand checkout and pay affiliates. Legal basis for accounts and paid access is contract performance (GDPR Art. 6(1)(b)). Funnel and referral records are legitimate interests in operating the service (Art. 6(1)(f)).

Who else sees data

Stripe processes web payments. Apple processes iOS in-app purchases. RevenueCat receives a purchaser identifier so we can unlock the ride after an App Store purchase. Google receives map and Street View requests from your browser or app (including IP address) under Google’s privacy policy. Hosting and the database run on Cloudflare. We do not sell personal data.

Cookies and similar

vr is an HttpOnly session cookie. vr_ref remembers an affiliate code. They are not used for advertising. The iOS app may also keep a session token on device. You can end a session with Log out.

Retention

Account rows stay while the account exists. Sessions expire after 30 days of idle time or when you log out. Email tokens expire after 24 hours. Funnel and referral rows stay for accounting and abuse prevention until you delete the account or ask us to erase them. After you delete the account we remove the user row, sessions, email tokens, funnel events, and referral rows tied to that email.

Your rights and deletion

You can delete the account from the logged-in Ride screen (Delete account). You must confirm your password. That erases the personal data listed above from our database.

Deleting the account does not cancel an App Store subscription. Cancel that in Settings → Apple ID → Subscriptions or you may still be charged. A web (Stripe) subscription is set to stop renewing when you delete the account.

If you are in the EEA/UK you may also access or correct your data, object to legitimate interests processing, and complain to a supervisory authority (in Finland: the Office of the Data Protection Ombudsman). Email hello@virtualride.app if you cannot use the in-app delete flow.

Children

VirtualRide is for people 18 or older. We do not knowingly create accounts for children.

Contact

Support or hello@virtualride.app.