RideWind
Back to RideWind

Legal

Privacy Policy

Last updated: 19 August 2026

RideWind is built to help you plan a ride, not to build a profile of you. This policy explains how route and feedback data are handled.

Security at a glance

RideWind uses encrypted HTTPS connections, strict browser security headers, input validation, and rate limiting. No security measure is absolute; do not upload sensitive information in a route name, GPX file, or feedback message.

Data controller and contact

Michael Kaserer is the controller responsible for processing personal data through RideWind. You can contact us about privacy or personal-data requests at hello@ridewind.app.

Michael Kaserer
c/o Factory Works GmbH
Rheinsberger Str. 76/77
10115 Berlin, Germany

The data we handle

RideWind does not require an account to analyse a route. When you analyse a route, we process the GPX file and the route details it contains, including coordinates, elevation, route name, planned departure time, and riding speed. Route data can reveal sensitive locations; upload only routes you are comfortable processing for this purpose.

The GPX upload is used to read and prepare the route. We do not intentionally retain the original GPX file after processing. Your current route may be kept in your browser’s session storage so it remains available while that browser tab is open; it is not an account history and can be cleared by closing the session or clearing browser data.

If you sign in and explicitly save a route, we retain its normalized route details and metadata in your RideWind account until you delete that route or delete your account. We do not retain the original GPX upload. Saved routes are private to your account and are not included in a share link unless you separately create one for an analysis.

A RideWind account contains your email address, a securely hashed password credential, and session records used to keep you signed in. When you request a password reset, we create a short-lived reset record and send a reset link to your account email. We do not store your plaintext RideWind password.

If you choose to connect Komoot, we use the email address and password you enter only to authenticate with Komoot. We retain the resulting Komoot API credential encrypted in our database so your account can list and import planned tours later. We do not retain your Komoot password, original imported GPX files, or a copy of your full Komoot tour library.

If you create a share link, the route, trip settings, and forecast snapshot are stored so anyone with that link can view them. Share links are intentionally unlisted, but they are not access-controlled: treat them as public and do not share a route that reveals a location you wish to keep private. Shared snapshots expire after 30 days.

If you use the feedback form, we collect the message, optional email address, page context, and submission time so we can respond and improve the service. We also use limited request information, including IP-derived identifiers, temporarily for rate limiting and service protection. Platform hosting and observability may process technical request data such as IP address, browser details, request time, and error information to operate and secure the service.

Why and how we share data

We use route and trip data only to provide the requested analysis and sharing features. To generate forecasts, route coordinates and requested forecast times are sent to Open-Meteo. When you connect Komoot, we send the encrypted credential only from our server to Komoot to list your planned tours or download a tour you select. The map can request map tiles from its map provider. Those providers may receive technical information such as your IP address under their own privacy practices. We do not sell personal information or use route data for targeted advertising.

We use Cloudflare to host and protect RideWind, operate our D1 database, and send password-reset email. You can read the relevant provider notices at Cloudflare Privacy Policy and Komoot Privacy Policy , as well as Open-Meteo Terms and OpenFreeMap Terms information.

Your choices

Do not create a share link if you do not want others to access that ride snapshot. You can close your browser session or clear site data to remove locally stored route data. You can delete saved routes from My routes or permanently delete your account from Account. Account deletion removes your account, sessions, password credential, saved routes, and encrypted Komoot connection. To ask about, access, correct, or delete feedback you submitted, email hello@ridewind.app with enough detail to locate it. Where applicable, you may also have rights to object, restrict processing, withdraw consent, or complain to your local data-protection authority.

Security and questions

RideWind applies restrictive content, framing, referrer, and browser-permission policies. Requests are validated and rate-limited, and shared ride records expire automatically. Keep share links private and report a suspected vulnerability through the Feedback form rather than publicly disclosing it. Use hello@ridewind.app for privacy questions or data requests.