Datenschutzerklaerung
Last updated: June 2025
The controller responsible for data processing on this website is:
Arne Wieding
Berlin, Germany
Email: [email protected]
Milestold is a personal activity blogging platform. You can upload outdoor activities (cycling, running, swimming), add photos, and publish them as a public blog. This privacy policy explains what data we collect, why, and how we protect it.
When you sign in with Google, we receive your name and email address (Google OAuth scopes: email, profile). We store your Google user ID and OAuth tokens to maintain your session.
If you optionally connect Strava, we receive your Strava athlete ID, name, and email (scope: profile:read_all).
When you upload FIT files or import from Strava, we process and store:
Photos you upload are stored on our server. If photos contain GPS coordinates, these are stored alongside the photo. You also provide text content such as ride descriptions, blog settings, gear information, and embedded media links.
Our server automatically logs:
We use the following cookies:
We do not use any analytics, tracking, or advertising cookies.
We use Google OAuth for authentication. During sign-in, your browser connects to Google servers and your name and email are shared with us. Google's privacy policy: policies.google.com/privacy.
If you connect your Strava account, we fetch your profile and activity data from Strava's API. You can disconnect Strava at any time in your account settings. Strava's privacy policy: strava.com/legal/privacy.
We use MapTiler to display interactive maps. When you view a map, your browser loads map tiles directly from MapTiler's servers, transmitting your IP address. MapTiler's privacy policy: maptiler.com/privacy-policy.
Google (USA) and MapTiler (Switzerland) may process data outside the EU/EEA. These transfers are safeguarded by Standard Contractual Clauses (SCCs) or adequacy decisions pursuant to Art. 45 GDPR.
This website is hosted on servers provided by Hetzner Online GmbH in Germany. All user data is stored on servers located in Germany.
Under the GDPR, you have the right to:
To exercise any of these rights, contact us at [email protected].
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The competent authority for Berlin is the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit.
We do not use automated decision-making or profiling as defined by Art. 22 GDPR.
We may update this privacy policy from time to time. The current version is always available at this URL. We encourage you to review it periodically.
If you have any questions about this privacy policy or data protection, please contact us at: [email protected]