Privacy Policy

Datenschutzerklaerung

Last updated: June 2025

1. Controller

The controller responsible for data processing on this website is:

Arne Wieding
Berlin, Germany
Email: [email protected]

2. Overview

Milestold is a personal activity blogging platform. You can upload outdoor activities (cycling, running, swimming), add photos, and publish them as a public blog. This privacy policy explains what data we collect, why, and how we protect it.

3. Data We Collect

3.1 Account Data

When you sign in with Google, we receive your name and email address (Google OAuth scopes: email, profile). We store your Google user ID and OAuth tokens to maintain your session.

If you optionally connect Strava, we receive your Strava athlete ID, name, and email (scope: profile:read_all).

3.2 Activity Data

When you upload FIT files or import from Strava, we process and store:

  • Route data (GPS coordinates, polylines)
  • Performance metrics (distance, elevation, speed, duration)
  • Biometric data (heart rate and power streams, if present in the file)
  • Activity metadata (name, description, date, activity type)

3.3 Photos and Content

Photos you upload are stored on our server. If photos contain GPS coordinates, these are stored alongside the photo. You also provide text content such as ride descriptions, blog settings, gear information, and embedded media links.

3.4 Automatically Collected Data

Our server automatically logs:

  • IP address
  • Browser type and version
  • Operating system
  • Referrer URL
  • Date and time of access

4. Cookies

We use the following cookies:

  • cycling_session — Session cookie for authentication. HttpOnly, secure, 30-day duration.
  • milestold_visitor — Anonymous visitor identifier used for the ride "like" feature. HttpOnly, secure, 365-day duration. This cookie does not contain personally identifiable information.
  • oauth_state — Temporary cookie for OAuth CSRF protection. HttpOnly, 10-minute duration. Deleted after login.

We do not use any analytics, tracking, or advertising cookies.

5. Legal Basis (Art. 6 GDPR)

  • Art. 6(1)(b) — Contract performance: Processing your account and activity data is necessary to provide the service you signed up for.
  • Art. 6(1)(a) — Consent: Connecting third-party services (Google, Strava) and publishing content publicly is based on your explicit consent.
  • Art. 6(1)(f) — Legitimate interest: Server log files and the anonymous visitor cookie serve our legitimate interest in ensuring security and basic functionality of the website.

6. Third-Party Services

6.1 Google OAuth

We use Google OAuth for authentication. During sign-in, your browser connects to Google servers and your name and email are shared with us. Google's privacy policy: policies.google.com/privacy.

6.2 Strava (optional)

If you connect your Strava account, we fetch your profile and activity data from Strava's API. You can disconnect Strava at any time in your account settings. Strava's privacy policy: strava.com/legal/privacy.

6.3 MapTiler

We use MapTiler to display interactive maps. When you view a map, your browser loads map tiles directly from MapTiler's servers, transmitting your IP address. MapTiler's privacy policy: maptiler.com/privacy-policy.

7. Data Transfer to Third Countries

Google (USA) and MapTiler (Switzerland) may process data outside the EU/EEA. These transfers are safeguarded by Standard Contractual Clauses (SCCs) or adequacy decisions pursuant to Art. 45 GDPR.

8. Hosting

This website is hosted on servers provided by Hetzner Online GmbH in Germany. All user data is stored on servers located in Germany.

9. Data Retention

  • Session data: 30 days (automatically deleted after expiry)
  • Visitor cookie: 365 days
  • Account and activity data: stored until you delete your account
  • Server log files: retained as per hosting provider's standard retention period

10. Your Rights

Under the GDPR, you have the right to:

  • Access (Art. 15) — request a copy of your personal data
  • Rectification (Art. 16) — correct inaccurate data
  • Erasure (Art. 17) — request deletion of your data
  • Restriction (Art. 18) — restrict processing of your data
  • Data portability (Art. 20) — receive your data in a portable format
  • Objection (Art. 21) — object to processing based on legitimate interest
  • Withdraw consent (Art. 7(3)) — withdraw consent at any time

To exercise any of these rights, contact us at [email protected].

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The competent authority for Berlin is the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit.

11. No Automated Decision-Making

We do not use automated decision-making or profiling as defined by Art. 22 GDPR.

12. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at this URL. We encourage you to review it periodically.

13. Contact

If you have any questions about this privacy policy or data protection, please contact us at: [email protected]