Privacy Policy
This policy explains what BikeViewer collects, why, who it goes to, and how you can get it back or delete it. We keep it short and specific rather than long and vague.
1. Scope
This policy covers personal information handled by BikeViewer through bikeviewer.com and the BikeViewer application. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
The short version: we collect what the product needs to work, your account details and the fits you create. We don't sell it, we don't show ads, and we don't use your fit data to train models. Payment card details never reach us.
2. What we collect
Account information
Your name, email address, password (stored only as a secure hash, never in readable form), and optionally your phone number and company name. If you sign in with Google, we receive your name, email address and profile identifier from Google.
Fit and bike data
The rider and bike information you enter: height, weight, body segment measurements, sex selection where you set one, frame and component setups, saved views, libraries, measurements and any names or notes you add.
Some of this describes your body. We treat it as your private information: it is used only to render and store your fits, it is never sold, never used for advertising, and never used to train machine-learning models. If you would rather not store it at all, you can use BikeViewer without an account: nothing is saved to our servers.
Client records (fitters and shops)
If you use client profiles, the client names, contact details and fit notes you enter are stored with your account. Those people are your clients, not ours: we hold that information on your behalf, and you are responsible for having a lawful basis to collect it and for telling them how it is used. We do not contact your clients, and we do not use their information for anything other than running the Service for you.
Uploaded logos
If you upload a company logo for branded reports, we store it with your account and reproduce it in the reports you generate. It is used for nothing else.
Subscription information
Which plan you are on, its status, and identifiers linking your account to your Stripe customer record. We never receive or store your card number. Card details are entered directly with Stripe.
Technical information
Standard server and service logs, IP address, browser and device type, pages or endpoints accessed, and timestamps, kept for security, debugging and abuse prevention.
3. Why we use it
- To provide the Service: authenticating you, saving and syncing your work, and rendering fits.
- To process subscriptions and give you access to the features you have paid for.
- To support you when you contact us, and to notify you about account, billing or security matters.
- To keep the Service secure, diagnose faults and prevent abuse.
- To understand which features are used, so we can improve them. We do this in aggregate wherever possible.
- To meet legal obligations, such as tax and financial record-keeping.
We do not use your information for advertising, and we do not sell or rent it to anyone.
4. Who we share it with
We use a small number of service providers, each handling only what they need:
- Supabase, authentication and database hosting for your account and saved work.
- Stripe, payment processing and subscription management. Stripe handles your card details under its own privacy policy.
- Vercel, website and application hosting, including standard request logs.
- Email delivery, for account, billing and security messages you have asked for or that we must send.
We may also disclose information if the law requires it, to protect our rights or someone's safety, or to a buyer in the event that the business is sold, in which case this policy continues to apply to information already collected until you are told otherwise.
5. Overseas storage
Our providers may store and process data outside Australia, including in the United States and the European Union. By using BikeViewer you agree to this transfer. We choose providers that offer recognised protections and contractual commitments about how they handle data, but overseas recipients may not be subject to the Australian Privacy Principles.
6. Share links
Share links encode the setup they describe inside the link itself. Anyone who has the link can open the fit, no account needed. Links do not include your name, email address or account details, but they do include the rider measurements of the fit being shared. Treat a share link as public.
7. Cookies and local storage
We do not use advertising or third-party tracking cookies. We use browser storage for a small number of functional things only:
- keeping you signed in (your authentication session);
- remembering your light/dark theme preference;
- remembering whether you have seen the welcome guide.
Clearing your browser storage will sign you out and reset those preferences.
8. Security
Traffic is encrypted in transit with TLS. Passwords are hashed by our authentication provider and are never stored in readable form. Database access is restricted by row-level rules so your saved work is only accessible to your account. Payment card data never touches our systems.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
9. How long we keep it
- Account and fit data, while your account is open, and deleted within 30 days of you deleting the account, except where we must keep records longer by law.
- Billing records, kept for seven years to meet Australian tax and financial record-keeping requirements.
- Technical logs, typically 30 to 90 days.
Backups are cycled on a rolling schedule, so deleted data may persist briefly in backups before being overwritten.
10. Access, correction and deletion
You can view and edit most of your information directly in the app. Beyond that, you may ask us to:
- give you a copy of the personal information we hold about you;
- correct anything inaccurate;
- delete your account and the data associated with it.
Email denis@bikeviewer.com. We will respond within 30 days. There is no charge, and we will verify your identity before acting on a request. If we cannot give you access to something, we will explain why.
11. Complaints
If you think we have mishandled your personal information, contact us first at denis@bikeviewer.com, we will investigate and respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. If you are in the EEA or UK
Where the GDPR applies to you, our legal bases are: performing our contract with you (providing the Service and processing payments), our legitimate interests (security, fault diagnosis and product improvement), and legal obligations (financial records). You have rights of access, rectification, erasure, restriction, portability and objection, and you may lodge a complaint with your local supervisory authority.
13. Children
BikeViewer is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child has given us information, email us and we will delete it.
14. Changes
We may update this policy. If a change is material, we will notify you by email or in the app. The current version is always the one published here, with the date at the top.
15. Contact
Privacy questions or requests: denis@bikeviewer.com.