Legal
PRIVACY POLICY
Last updated: 2026-06-28
1. Who we are
JoyVelo ("we", "us", "our") operates the website joyvelo.com and related services. We're reachable at privacy@joyvelo.com.
2. What data we collect
- Account data: email, display name, and avatar URL when you sign in (Google OAuth, email link, or other Supabase-supported provider).
- Training data: FIT files, power / HR / cadence samples, routes, and notes that you choose to upload or sync (Strava, Polar, Whoop, Fitbit, or manual upload).
- Fitting reports: measurements, screening results, and equipment configurations you save in JoyFit.
- Newsletter: email address and signup metadata (referrer, IP for spam prevention).
- Usage: anonymized page views via Vercel Analytics and Speed Insights. We do not use third-party tracking cookies.
3. Why we collect it
- To deliver the service you signed up for (training sync, FIT export, route library).
- To remember your preferences across devices when you're signed in.
- To send the newsletter you opted into (and nothing else).
- To improve the site via aggregated, non-identifying analytics.
4. Where your data lives
Data is stored on Supabase (auth, profiles, activities, reports) and on Vercel Edge Network. Our primary database region is the United States. We may move regions in the future; we'll update this page before doing so.
5. Cookies
We use a single strictly-necessary cookie for Supabase auth session. We do not use advertising cookies. If you sign in with Google, Google may set its own cookies governed by their privacy policy. The cookie banner on your first visit lets you reject non-essential cookies (we don't currently have any beyond the auth cookie, but the banner is required for GDPR-compliant future expansion).
6. Your rights (GDPR / CCPA)
You can at any time:
- Access: ask what data we hold about you.
- Export: download all your training data as FIT / GPX / JSON.
- Correct: update profile fields in /account.
- Delete: request full account deletion via the link in /account or by emailing privacy@joyvelo.com.
- Opt out of newsletter: every email has an unsubscribe link.
We respond to verified requests within 30 days, in line with GDPR Art. 12.
7. Children
JoyVelo is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has signed up, contact us and we'll delete the account within 7 days.
8. Security
We use TLS everywhere, Supabase Row-Level Security on all tables, and OAuth via Supabase Auth. We never store your raw OAuth access tokens in cookies — they're held server-side in the profiles table and never exposed to the client.
9. Changes to this policy
We'll bump the "Last updated" date and post a short summary of changes in the /news feed.
10. Contact
Data Protection Officer: privacy@joyvelo.com. EU residents may also contact our representative via the same address.