Privacy Policy for BikePrep
Last updated: September 23, 2026
This Privacy Policy applies to the BikePrep web application at https://wachsmeister.by-rousset.de and the BikePrep apps for iOS and Android (together, “BikePrep”).
1. Controller
Niklas Rousset
Firnhaberstr. 29
86159 Augsburg
Email: byrousset@gmail.com
2. Data processed by BikePrep
Depending on the features you use, BikePrep processes the following data:
- Account and sign-in data: internal user ID, name, email address, sign-in provider, sign-in and session tokens, session expiry, session IP address and user agent, and timestamps;
- Bicycle data you enter: bicycle name, odometer reading, odometer source and, where applicable, estimated weekly distance;
- Chain and maintenance data: chain name and model, chain type, lubrication interval, lifetime limits, installation and removal times, odometer readings, lubrication times, lubrication type and optional notes;
- Strava data, if you connect Strava: Strava account, bicycle and equipment data, distances, and limited activity data needed for synchronisation and the calculation of average riding distance;
- In-app notification data: related bicycle and chain, notification type, message text, read status and timestamp;
- Push delivery data, if you enable push notifications: push token or web-push endpoint and keys, and platform;
- Purchase and subscription data: internal user ID, product and entitlement, purchase, renewal, expiry, grace-period, cancellation and refund status, transaction or receipt information, store, test-environment status and a link for managing the purchase;
- Technical data: IP address, timestamps, request and response information, and technical error data;
- Internal usage metric: internal user ID and UTC calendar date on which an authenticated API request was made.
3. Provision of the website, app and API
When you access BikePrep, technically necessary connection data is processed. The IP address is required to deliver content to your device and to protect sign-in and webhook endpoints against abuse. Application logs also contain basic request, response and technical error information.
Processing necessary to provide and perform the service you request is based on Art. 6(1)(b) GDPR. Security, error analysis and the prevention of abusive access are based on Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and reliable operation of BikePrep.
For internal reach measurement, BikePrep processes the internal account ID and the calendar days on which the service is used. We use this to produce statistics about active and newly created accounts. We do not record which features are opened, user content or device data for this purpose, and we do not share the data with external analytics providers. The measurement helps us improve BikePrep according to actual demand. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is privacy-minimal measurement and improvement of our own service.
4. Hosting by IONOS
BikePrep, including the web server, API and database, is operated on a virtual server provided by IONOS SE. IONOS processes connection and content data on our behalf. We have concluded a data processing agreement with IONOS in accordance with Art. 28 GDPR.
Processing on the server booked by us takes place in Germany. Further information is available in the IONOS Privacy Policy.
5. Account and sign-in
Guest account
You can initially use BikePrep without an external sign-in account through a pseudonymous guest account. We process an internal identifier and the bicycle and maintenance data you save in order to provide the service. The legal basis is Art. 6(1)(b) GDPR.
Sign in with Google
If you choose “Sign in with Google” or link your account, a connection to Google is established. Google processes, among other things, your IP address, device and browser information and details of the sign-in operation. BikePrep receives the profile data released for sign-in, in particular a Google ID, name, email address and email verification status. Google's sign-in response may also include a profile picture, which BikePrep discards without saving or using it. Authentication data required for sign-in is also processed. The connection to Google is triggered only after you select Google sign-in.
Processing by BikePrep is necessary to perform the sign-in method you selected and to make your account available across devices (Art. 6(1)(b) GDPR). Google is responsible for its own processing. For users in the European Economic Area, the responsible entity is generally Google Ireland Limited. Details are available in the Google Privacy Policy.
You can use BikePrep as a guest instead.
Sign in with Apple
If you choose “Sign in with Apple” or link your account, a connection to Apple is established. Apple processes information about your Apple Account and the sign-in operation, as well as technical device, browser and connection data, particularly for authentication and fraud prevention. BikePrep receives a unique Apple identifier and the information you release for sign-in, particularly your name and email address. Apple may provide a private relay address instead. We also process authentication data needed for sign-in and revocation.
Processing by BikePrep is necessary to perform the selected sign-in method and make your account available across devices (Art. 6(1)(b) GDPR). Apple is responsible for its own processing. For users in the European Economic Area, the responsible entity is generally Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Details are available in the Apple Privacy Policy.
6. Purchases and RevenueCat
BikePrep Plus is available as a subscription or one-time purchase. A permanent BikePrep account is required for purchases. We use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, United States (“RevenueCat”), to display purchase options, process and restore purchases, verify entitlement to Plus and provide purchase management. RevenueCat acts as our processor under Art. 28 GDPR for this processing.
When the purchase function is available in the installed app, the RevenueCat SDK contacts RevenueCat for a signed-in permanent account. RevenueCat receives BikePrep's opaque internal user ID and technical information such as device type, operating system, app and SDK version, IP address and time of access. When you view an offer, make or restore a purchase, RevenueCat also processes the selected product and offering, store, purchase history, transaction status, Apple receipt or Google purchase token, purchase and expiry times, cancellation, grace-period and refund status, and the resulting entitlement. If web billing is offered, RevenueCat and the payment service used for checkout also process the information required for payment. BikePrep does not receive full card or bank-account details.
We send RevenueCat the internal BikePrep user ID so that purchases can be assigned to your account across devices and platforms. We do not send your name, email address, Strava data, bicycle data or maintenance history to RevenueCat, and we do not enable RevenueCat advertising or attribution integrations. RevenueCat does not receive data from guest accounts through the purchase integration.
The BikePrep server stores only the verified Plus status, any expiry time, the time of the last verification, the purchase-management URL and the free-plan allowances needed to enforce the plan. It verifies current status with RevenueCat and receives purchase lifecycle webhooks. Client-side information alone is not used to authorise paid features.
This processing is necessary to present the purchase requested by you, conclude and perform the Plus contract, restore purchases, prevent duplicate or fraudulent entitlements and provide paid features (Art. 6(1)(b) GDPR).
Payments in the iOS or Android app are concluded through Apple App Store or Google Play. Apple or Google processes the payment and store-account data under its own responsibility and privacy policy. Cancel subscriptions through the store or Customer Center. Deleting a BikePrep account does not itself cancel a store subscription.
Further information is available in RevenueCat's Privacy Policy and Data Processing Addendum.
7. Bicycles, chains and maintenance
We process the bicycle, chain, distance and maintenance data you enter to calculate odometer readings, lubrication and lifetime status, display your history and notify you when maintenance is due. Optional notes are stored as entered. Please do not enter special categories of personal data, such as health data, in the notes field.
The legal basis is Art. 6(1)(b) GDPR. The relevant tracking or reminder feature cannot be provided without fields marked as required. Optional fields may be left empty.
8. Optional Strava connection
You may voluntarily connect your Strava account to synchronise bicycle distance and calculate average riding distance.
BikePrep processes the Strava data listed in section 2. Activity data is retrieved for calculation purposes but is not stored as a complete activity history in the BikePrep database. BikePrep does not request routes, locations or heart-rate data.
The legal basis is your consent under Art. 6(1)(a) GDPR. You may disconnect Strava in BikePrep at any time. This deletes the local connection, stored Strava tokens and gear links; distance and maintenance data previously synchronised into BikePrep remains part of your BikePrep account. To revoke the authorisation at Strava as well, remove BikePrep from “My Apps” in your Strava settings.
When connecting and synchronising, data is transferred to Strava Ireland Limited. Strava processes data under its own responsibility. Details are available in the Strava Privacy Policy.
9. Notifications
In-app notifications
BikePrep may store maintenance notices in your account and display them in the app or web application. For this purpose, we process the related bicycle and chain, notification type, message, read status and timestamp. The legal basis is Art. 6(1)(b) GDPR.
Push notifications
Push notifications are optional and are sent only after you enable them and grant permission in your operating system or browser. A device-specific push token or browser-push endpoint, the platform and message text are processed. The message may contain a bicycle or chain name chosen by you and may be visible on the lock screen.
On Android, delivery is handled by Google's Firebase Cloud Messaging; on iOS, by the Apple Push Notification Service. Web push uses the push service associated with your browser. These services receive the relevant token or endpoint, technical connection data and the content of the push message.
The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw it at any time with future effect in BikePrep and in your system or browser settings. Disabling notifications does not affect other functions.
Further information is available from Google/Firebase and Apple.
10. Cookies and local storage
The web application uses only technically necessary authentication information, in particular a session cookie, to keep you signed in and associate requests with your account. Storage is necessary to provide the digital service expressly requested by you under section 25(2)(2) TDDDG; the related processing of personal data is based on Art. 6(1)(b) GDPR. BikePrep does not use advertising or tracking cookies and does not embed general-purpose external analytics or advertising services. Purchase processing by RevenueCat is described in section 6; its web SDK is configured not to collect UTM parameters or optional SDK analytics events. The internal server-side usage measurement described in section 3 sets no additional cookies and does not access local device storage.
In the mobile app, session credentials and an optional push token are stored in protected device storage. The browser uses information required for a web-push subscription you activate. This storage is necessary for the respective sign-in or notification feature requested by you.
11. Product and affiliate links
BikePrep may display links to external shops. Merely displaying a link does not transfer account, bicycle or maintenance data to the shop. When you open a link, your browser or operating system connects directly to the relevant shop. The shop processes, under its own responsibility, technical data such as your IP address, device or browser information, time and destination address. A link may contain an affiliate identifier through which BikePrep can receive a commission after a purchase; this identifier identifies the source of the link, not your BikePrep account. The privacy policy of the respective shop applies.
12. Recipients and international transfers
Personal data is disclosed only to parties that need it for the purposes described above. These include:
- IONOS as hosting processor;
- Google for Google sign-in selected by you and for Android push;
- Apple for Apple sign-in selected by you and for iOS push;
- your browser's push service for web push;
- Strava when you establish a Strava connection;
- RevenueCat as processor for purchase offers, purchase verification, entitlements and purchase management;
- Apple App Store, Google Play or the applicable web-payment service for a purchase you initiate;
- public authorities or other bodies where disclosure is required by law.
Processing by Google, Apple, Strava, RevenueCat, payment services and individual browser-push services may take place outside the European Economic Area, in particular in the United States. Depending on the recipient and processing operation, transfers are based on an adequacy decision under Art. 45 GDPR, including the EU-US Data Privacy Framework for certified recipients, or appropriate safeguards under Art. 46 GDPR, in particular the European Commission's Standard Contractual Clauses. You may request information and a copy of the applicable safeguards using the contact address in section 1. Further information is available in the provider privacy policies linked above. RevenueCat is based in the United States and uses subprocessors there. Restricted transfers of data processed by RevenueCat on our behalf are covered by the European Commission's Standard Contractual Clauses (controller-to-processor module) incorporated into RevenueCat's Data Processing Addendum.
13. Retention and deletion
We retain data only for as long as it is needed for the relevant purpose or a legal obligation requires further storage:
- Sessions: A session is valid for up to 180 days. Its expiry may be extended while you continue to use BikePrep. Expired session records are deleted daily once their expiry is more than seven days in the past, and no later than when the account is deleted.
- Account, bicycle, chain and maintenance data: until you delete individual content or your account, or the service is discontinued. Data required by law may be retained in restricted form until the relevant obligation expires.
- Apple sign-in data and tokens: until you delete your BikePrep account. On account deletion, we revoke the Apple authorisation where the required token is available and delete the locally stored sign-in data.
- Strava connection data: until you disconnect Strava or delete your BikePrep account. Technical synchronisation records are deleted daily once they are more than 90 days old.
- Purchase data: BikePrep's local status and entitlement record is retained until your account is deleted. When you delete the account, BikePrep sends an authenticated deletion request for the associated customer to RevenueCat; RevenueCat queues this deletion asynchronously. RevenueCat may retain data in backups or where legally required under its processing terms. Apple, Google and payment providers retain their own transaction records according to their legal obligations and policies. Account deletion does not cancel an active subscription.
- Push tokens and web-push endpoints: until you disable notifications, delete your account or the delivery service reports the token as invalid.
- In-app notifications: deleted daily once they are more than twelve months old, and no later than when the account or related bicycle is deleted.
- Security and error logs: ordinary server logs are deleted automatically after no more than 14 days. Extracts required to investigate a specific security incident may be stored separately only for as long as necessary for the investigation and resulting measures.
- Daily usage metrics: deleted daily once they are more than 400 days old, and no later than when the account is deleted.
- Unused guest accounts: guest accounts without stored bicycles or linked services are deleted after one month. Other guest accounts remain until the stored content or account is deleted.
- Backups: Daily database backups created by us are deleted automatically after 30 days.
You can delete your account in the app's account settings or at https://wachsmeister.by-rousset.de/delete-account. This deletes the account and its bicycles, chains, maintenance data, connections, local purchase status and notification settings from the production database and requests deletion of the associated RevenueCat customer record. Mandatory legal retention obligations remain unaffected.
14. Your rights
Where the legal requirements are met, you have the right to:
- access your personal data (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR), and
- object to processing based on legitimate interests (Art. 21 GDPR).
You may withdraw consent at any time with future effect. Withdrawal does not affect the lawfulness of processing carried out before it.
To exercise your rights, contact the address provided in section 1. Where necessary, we may request additional information to verify your identity and protect other accounts.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).