Privacy Policy
Last updated: 23 September 2026
This policy explains what RidePals collects, why, and who can see it. It was written from what the app actually does today, not from a template.
What this covers
The RidePals app and this website. RidePals is for adults — 18 or over — and we do not knowingly collect information from anyone younger. If what we collect changes, this page changes with it.
Your account
When you sign up we store your name, your email address and your profile photo: the one your provider supplies, if it does, or one you upload. You can create an account with an email and password, with Google, or with Apple. If you use “Sign in with Apple” and choose to hide your email, we receive the private relay address Apple generates and that is the only address we hold. We also store the preferences you set on your profile, such as your discipline and your country, and what you do in the app so that it works: which rides you join, who you save as a Pal, who you block or report, and when you accepted the terms.
Your emergency contact
You can save the name and phone number of a person to contact in an emergency. The contact's name and number are information about someone else, so please only add them with that person's permission.
Who can see it
Every rider who has joined the same ride as you — not only that ride's host — and only while the ride is active. Once it is finished or cancelled it stops being readable. It is never public, never shown to anyone who has not joined your ride, and is not used for any other purpose. Someone you have blocked cannot see yours, and you cannot see theirs.
Every view is logged: we record who viewed it, whose it was, which ride, and when. Platform administrators can review that log.
So that it still opens after a crash with no signal, the app copies the emergency details of everyone on a ride onto the phones of the other riders on that ride. That copy sits in the app's own storage on their device, and we cannot reach into it to erase it. It is cleared the next time they open that ride's rider list after the ride has ended, and it goes when they uninstall the app.
The person you add is not a user of the app and cannot be notified by us, which is why we ask you to add them only if they agreed to it.
You can change or remove it at any time from your profile, and it is deleted along with your account.
Rides and clubs you create
When you create a ride or a club we store what you write: the title, description, date, meetup point and any images you upload, such as a club logo or banner. This is visible to other people using RidePals, and public rides and clubs can also be seen on this website without signing in. The public map publishes only an approximate area for the meetup point. The exception is the ride link a participant shares: anyone with that link sees the exact meetup point and who is going, without needing an account. If you attach a route file to a ride, we store that route and show it to the riders who joined; route files are not public and are not published on this website.
Strava, if you choose to verify
Linking Strava is optional to use RidePals, but it is the only thing that grants the “Verified” badge, and you need to be verified to create a ride or a club. If you only join rides, you never need to link anything. If you do, we read your profile and recent activities once, to count how many cycling rides you have in the previous six months, and we keep only the result: your Strava id and username, and whether you cleared the bar. We revoke the permission immediately afterwards. We do not store your Strava tokens, we do not keep your activities, and we have no ongoing access to your account.
Notifications
If you turn on notifications we store your device's notification identifier, whether it is iOS or Android, and the app's language, so we can tell you what is happening on your rides. It is deleted along with your account.
Your location: used for a moment, never kept
The app asks for your location only while you are using it — never in the background — and uses it in three ways: to centre the map where you are; to find rides within 10 km for Near Me, which sends your coordinates to our server for that one search; and, when you create a club, to suggest your city, which sends them once to Google to look it up. We do not save your location or share it for any other purpose. If you decline the permission the map still works — it opens on the national view.
The permissions you will see on the store
The app's Google Play listing names the permissions the package declares, and there are more of them than the app's features use. Only two are ours: location, to centre the map and find rides near you. The rest are added by the libraries the app includes — notifications, the map, the image picker, the secure storage that keeps you signed in. We removed the ones with no feature behind them: RidePals does not ask for the camera, the microphone, or permission to draw over other apps. We do not take photos, we do not record audio, and we do not read your biometrics. Android will ask you at the moment we need the ones we do use, and you can say no.
This website
If you write to us through the contact form we store your message, your email address, your name if you choose to give one, and the IP address the message was sent from. The IP is kept to limit abuse of the form. Beyond that, this site asks nothing of you to browse it.
Who else processes this data
We do not sell your data and we do not share it with advertisers. The services we use to make RidePals work are:
- Supabase — our database, sign-in, and image storage. Its servers are in the United States.
- Amazon Web Services — hosts this website, in the United States.
- Expo — delivers notifications to your device.
- Resend — sends the account emails — confirming your address, resetting your password — and emails us the notification when someone uses the contact form.
- Google — Google sign-in if you choose it, the map on Android, and place search inside the app — what you type when searching for a meetup point is sent to Google to fetch the suggestions. When you create a club, your location is sent to Google once to suggest your city.
- Apple — “Sign in with Apple” if you choose it, and the map on iOS.
- Strava — only if you choose to verify, and only that once.
- OpenStreetMap — supplies the map imagery on this website, so their server receives the IP address of anyone who visits it.
Cookies and analytics
This site uses no tracking cookies and no analytics tools, and the app ships no advertising or tracking SDK. There is no cookie banner because there is nothing to consent to.
How to delete your account
You can delete your account at any time from your profile in the app, without writing to us or asking permission. Doing so deletes:
- your profile, your name and your photo;
- your emergency contact;
- any route files you attached to rides you hosted;
- the log of who viewed your emergency contact;
- your devices' notification identifiers;
- the rides you hosted and the clubs you own, along with their sign-ups.
No longer have the app, or can't open it? Ask us to delete your RidePals account through the contact form on this site, writing from the email address on the account so we can confirm it is yours. We delete the same data listed above.
Images you uploaded for a club or as a profile photo are deleted along with your account. Copies already downloaded to a device, or briefly held in our content cache, may persist for a short time. The same is true of the emergency details copied onto the phones of riders you rode with, described above.
Changes to this policy
This policy may change. The current version is always at this URL, and the date shown above is when it was last updated.
Contact
Questions about your data, or want something deleted? Get in touch through the contact form on this site.