Privacy Policy

Last updated: March 13, 2026

Overview

Trail Hits LLC ("we", "our", or "us") respects your privacy. This policy explains how we collect, use, and protect your information when you use the Trail Hits mobile app and website. Trail Hits LLC is the data controller responsible for your personal data.

Contact: support@trailhits.com

Information We Collect

Account Information

  • Email address (for account creation and communication)
  • Phone number (when provided by a bike shop during service check-in, for service notifications)

Bike and Component Data

  • Bike names and types you create
  • Component information (type, brand, model)
  • Maintenance records and service history
  • Setup diary entries (PSI, pressure, notes)

Ride Data

  • GPS coordinates and elevation data
  • Ride duration, distance, and conditions
  • Bike-specific ride characteristics (e.g., assist mode for eBikes)
  • Data synced from connected services (Strava, Ride with GPS, Apple Health, Garmin Connect)

Device Information

  • Device type and operating system version
  • App version
  • Anonymous usage analytics
  • Device diagnostics (collected automatically when submitting bug reports)

How We Use Your Information

  • Provide maintenance tracking and service recommendations
  • Send maintenance reminders and service alerts
  • Sync data across your devices
  • Process bug reports and respond to support requests
  • Improve the app based on anonymous usage patterns

Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

DataLegal Basis
Account data (email)Contract performance — necessary to provide the service (Art. 6(1)(b))
Bike, component, and ride dataContract performance — core functionality of the app (Art. 6(1)(b))
Connected services (Strava, Garmin, etc.)Consent — you choose to connect each service (Art. 6(1)(a))
Analytics (Google Analytics)Consent — only collected when you accept analytics cookies (Art. 6(1)(a))
SMS notificationsConsent — provided verbally at shop check-in (Art. 6(1)(a))
Payment dataContract performance — required to process subscriptions (Art. 6(1)(b))
Error monitoring (Sentry)Legitimate interest — maintaining service reliability (Art. 6(1)(f))
Bug reports and diagnosticsConsent — submitted at your discretion (Art. 6(1)(a))

Third-Party Services and Sub-Processors

Trail Hits uses the following third-party services to operate. These services may process your data on our behalf:

  • Supabase: Secure database, authentication, and serverless functions (hosted on AWS, US)
  • Vercel: Website and web app hosting (US)
  • Stripe: Payment processing for web subscriptions (US)
  • Apple App Store: iOS payment processing and subscription management
  • Google Play: Android payment processing and subscription management
  • Google Analytics: Website analytics — only with your consent (US)
  • Sentry: Error monitoring and crash reporting (US)
  • 99 Spokes: Bike catalog and specification data (US)
  • Twilio: SMS/text message delivery for service notifications (US)
  • GitHub: Bug report processing (US)
  • Strava: Ride sync — connected at your discretion (US)
  • Ride with GPS: Ride sync — connected at your discretion (US)
  • Apple Health: Ride sync — connected at your discretion (on-device)
  • Garmin Connect: Ride sync — connected at your discretion (US)

International Data Transfers

Trail Hits LLC is based in the United States. If you are located in the EEA, UK, or Switzerland, your personal data is transferred to and processed in the United States through our sub-processors listed above.

These transfers are protected by appropriate safeguards, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs) where applicable. By using Trail Hits, you acknowledge that your data will be processed in the United States.

Data Storage and Security

Your data is stored securely using Supabase, which provides enterprise-grade security including encryption at rest and in transit. We use row-level security to ensure users can only access their own data.

Data Sharing

We do not sell your personal information. We only share data in these limited circumstances:

  • With service providers who help operate the app (hosting, payment processing, analytics)
  • With authorized Trail Hits staff for customer support and operational purposes
  • When required by law or to comply with legal process
  • With your explicit consent

Cookies and Tracking

We use cookies and similar technologies on our website and web app. Analytics cookies are only set with your consent. For full details on the cookies we use, how to manage them, and your choices, see our Cookie Policy.

SMS/Text Messaging

Phone Number Collection

Your phone number may be collected by a Trail Hits partner bike shop when you check in your bike for service. The shop enters your phone number into the Trail Hits platform to enable service-related text message notifications.

How We Use SMS

Text messages are used for transactional service notifications only. We do not send marketing or promotional messages via SMS. Messages you may receive include:

  • Service estimates and repair quotes
  • Work order status updates
  • Pickup notifications when your bike is ready

Consent

Consent to receive text messages from Trail Hits on behalf of a partner shop may be obtained in the following ways:

  • Verbal opt-in: By providing your phone number to a shop at check-in, you verbally consent to receive service-related texts.
  • Text message opt-in: When a shop adds your phone number to the Trail Hits platform, you may receive a one-time opt-in invitation via text message. Replying YES to that message confirms your consent to receive service notifications from that shop.
  • Written consent: Consent may be collected via a written form or web-based consent flow at the shop.

Consent is specific to the individual shop — consenting at one shop does not authorize messages from another. You will not receive service notifications until you have opted in.

Opting Out

You can opt out of text messages at any time by replying STOP to any message. After opting out, you will receive a confirmation message and no further texts will be sent. You can also contact support@trailhits.com to request removal.

Message Frequency and Rates

Message frequency varies based on your bike service activity, typically 1–3 messages per service visit. Message and data rates may apply. Contact your mobile carrier for details about your messaging plan.

Phone Number Retention

Your phone number is retained as part of your customer record with the shop. If you opt out of SMS, your phone number is retained but no further messages are sent. To request deletion of your phone number, contact support@trailhits.com.

Your Rights

You have the right to:

  • Access your personal data
  • Export your data in a portable format (right to data portability)
  • Correct inaccurate personal data (right to rectification)
  • Delete your account and all associated data (right to erasure)
  • Restrict processing of your data in certain circumstances
  • Object to processing based on legitimate interest
  • Withdraw consent at any time for consent-based processing (e.g., analytics, connected services)
  • Disconnect third-party services at any time through the app

To exercise any of these rights, use the account settings in the app or email support@trailhits.com. We will respond within 30 days.

Right to Complain

If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed unlawfully. A list of EU supervisory authorities is available at edpb.europa.eu.

Data Retention

  • Active accounts: Data is retained as long as your account is active.
  • Deleted accounts: All personal data is permanently removed within 30 days of account deletion.
  • Analytics data: Google Analytics retains data for 14 months (GA4 default).
  • Payment records: Transaction records are retained for 7 years as required by tax and accounting regulations.
  • SMS records: Message logs are retained for 90 days for delivery verification, then deleted.

Automated Decision-Making

Trail Hits uses algorithms to calculate component wear (strain scores), predict service intervals, and suggest suspension tuning adjustments. These calculations are informational tools to assist your bike maintenance — they do not produce decisions with legal or similarly significant effects. You should always inspect your bike regularly and consult a qualified mechanic for safety-critical components.

Children's Privacy

Trail Hits is not intended for children under 13. In the EEA, users must be at least 16 years old (or the minimum age set by their member state) to create an account without parental consent. We do not knowingly collect personal information from children below these age thresholds.

Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of Trail Hits after changes are posted constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy, your data, or want to exercise your rights, contact us at:

support@trailhits.com

Trail Hits LLC · Bend, Oregon, United States