Rider information
Strava Data Use & Rider Privacy
DirtRacer uses rider-authorised Strava data only to calculate that rider’s result for a named, in-person event.
Why DirtRacer connects to Strava
A rider chooses a DirtRacer event, selects a category and connects their own Strava account through OAuth. DirtRacer then checks the configured event window and stages to calculate that rider’s private event result.
What data DirtRacer uses
- Rider name and Strava athlete identifier returned during OAuth
- OAuth access and refresh tokens required to process the rider’s event activity
- Activity and segment-effort data needed to match configured event stages
- Segment effort times within the named event window
- The event category selected by the rider
- Consent records required to demonstrate the rider’s choices
OAuth permissions
DirtRacer requests the narrower read,activity:read scope by default. This allows processing of activities visible to Everyone or Followers.
A rider may separately choose to include activities marked “Only You”. Only then does DirtRacer request activity:read_all. Private-activity access is optional and is not required when the event activity is otherwise visible through the narrower scope.
Who can see the result
Each connected rider can view only their own Strava-derived result through a private rider session. DirtRacer does not display Strava-derived rider names, stage times, total times or rankings on a public leaderboard or participant-to-participant.
Multi-rider organiser access, exports and organiser distribution of consolidated results remain disabled unless Strava approves that exact workflow in writing.
What DirtRacer does not do
- Does not scrape Strava pages, segments, clubs or leaderboards
- Does not access riders who have not connected their own Strava account
- Does not display one rider’s Strava-derived data to another rider
- Does not sell, license or use Strava data for advertising
- Does not use Strava data for AI or machine-learning training
- Does not use Strava data for unrelated marketing
- Does not expose full private activity details beyond event timing needs
Retention
Raw cached activity and segment-effort payloads are automatically redacted after the event retention window. DirtRacer keeps only the minimum information required for the rider’s private event result while the entry remains active, subject to deletion, deauthorisation and Strava’s requirements.
Disconnecting, withdrawal and deletion
- Disconnect DirtRacer from the Applications section of your Strava account to revoke future access.
- Submit the Strava data request form to request access, correction, withdrawal or deletion.
- DirtRacer records the request and provides a reference number.
- DirtRacer support verifies the request, completes the required action and sends written confirmation to the supplied email address.
You can also contact dirtracermtb@gmail.com.
Activity deletion or privacy changes
DirtRacer’s Strava webhook removes cached event data when Strava reports deauthorisation or deletion of an activity. Privacy updates are treated conservatively: affected cached effort and result records are removed and must be rebuilt only if the rider remains authorised and the activity is still accessible under the approved scope.
Access to your information
Use the data request form to ask what DirtRacer holds about your connection and event entry. DirtRacer support may request limited information to verify that the request belongs to the connected athlete.
DirtRacer is not affiliated with or endorsed by Strava. See the Privacy Policy for the broader platform privacy terms.
