HeatmapsterConnect with Strava

Privacy Policy

Last updated: 9 August 2026

Heatmapster turns your Strava activities into a printable poster. Doing that means handling data about where and when you exercise, which is sensitive. This page explains exactly what is collected, why, how long it is kept, and how to get rid of it.

Who is responsible for your data

The data controller is Jakob Hamilton. For any privacy question or to exercise the rights below, contact [email protected].

What we collect

When you connect Strava, we receive and store:

  • Your Strava profile basics — athlete ID, first and last name, and profile picture URL. Used to identify your account and to put your name on the poster if you choose to include it.
  • Your activities — for each run or ride: name, sport type, distance, moving time, elevation gain, start date, start coordinates, and the route line (“polyline”). The route line is a record of where you physically travelled. This is the data the heatmap is drawn from.
  • Strava access tokens — needed to fetch your activities. Stored encrypted (AES-256-GCM) and never shown to anyone, including us.
  • Order records which posters you generated, when, and the settings you chose (map position, theme, caption).

We request read-only access to Strava. We cannot post, edit or delete anything on your Strava account.

What we do not collect

  • No payment data, and no email address. This service is free, so there is no payment step and nothing to collect from one. Strava does not disclose your email address to us, and we do not ask for it.
  • No advertising or analytics trackers. There are no third-party analytics, advertising pixels, or cross-site tracking cookies on this site.
  • No selling or sharing. Your data is never sold, rented, or shared for anyone else’s marketing.

Why we are allowed to use it (legal bases)

  • Performance of a contract (GDPR Art. 6(1)(b)) — importing your activities, rendering your poster and delivering the file. You asked us to make a poster; we cannot do it without this data.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure and preventing abuse, e.g. basic rate limiting.

Because we rely on contract rather than consent, withdrawing Strava access at any time stops all future processing — see below.

Cookies

One cookie: an encrypted session cookie that remembers which Strava athlete you are and carries a CSRF token. It is strictly necessary for the service to function, so no cookie consent banner is required for it. There are no analytics or advertising cookies.

Who else processes your data

These providers act as processors or independent controllers on our behalf:

  • Strava — source of your activity data, under your Strava account and their privacy policy.
  • Mapbox — renders the map used in your printed poster. Mapbox receives the map coordinates of your chosen crop, but not your identity or your activity data.
  • OpenFreeMap and Photon — supply the on-screen preview map and the place search. Your browser contacts them for map tiles; search queries are proxied through our server so your IP is not sent to Photon.
  • Our hosting provider — operates the servers and database.

Some of these are based in the United States. Transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses.

How long we keep it

Data is deleted automatically on this schedule:

  • Unfinished poster selections 30 days.
  • Imported activities, if you never generated a poster 90 days.
  • Imported activities, if you have generated a poster 365 days, so making another one doesn’t require re-importing.
  • Your generated PDF365 days after it is generated, then deleted. Download and keep your file; we are not a storage service.
  • Dormant accounts (no orders, no activity) — 730 days, then the whole record including tokens is erased.

Your rights

If you are in the EU/EEA or the UK, you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To use any of them, email [email protected] from the address on your Strava account, or include your Strava athlete ID. We respond within one month.

You can also stop all processing yourself at any time by revoking Heatmapster’s access in your Strava connected-apps settings. After that we can no longer fetch anything, and your stored data ages out on the schedule above — or email us and we will delete it immediately.

If you think we have handled your data badly, you may complain to your national data protection authority. In Sweden that is IMY.

California residents

We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. California residents may request access to or deletion of their personal information using the same contact address above, and will not be discriminated against for doing so.

Security

Traffic is served over HTTPS. Strava tokens are encrypted at rest with AES-256-GCM. Session cookies are encrypted, HTTP-only and same-site. Administrative access is restricted and does not expose customer route data — staff can see order records, but the backoffice does not display your activity names or GPS traces.

Children

This service is not directed at children under 16 and we do not knowingly collect their data. Strava’s own terms set a minimum age for holding an account.

Changes

If this policy changes materially we will update the date at the top. Continuing to use the service after a change means the updated policy applies.