Privacy Policy
Last updated September 28, 2026. Lap Track Racing is a beta project.
Activity files
When you load a FIT, GPX, TCX, or RaceBox CSV file, Lap Track analyzes it in your browser. The file and the resulting analysis are not uploaded to Lap Track’s servers by the ordinary file-analysis workflow. Your browser may retain local settings and temporary data until you clear them.
Private activity sharing
If you explicitly create a private share for a locally loaded activity file, Lap Track stores the file in private Cloudflare R2 object storage for the selected duration of 7, 30, or 90 days. Share metadata is stored in Cloudflare KV and includes the title, description, expiration, selected race boundaries, analysis settings, and whether autoplay was requested. An optional password is stored only as a one-way hash. The activity file and metadata are deleted when the share is deleted or expires. A private link is available to anyone who obtains it; a password adds another access check but does not make the link public or searchable.
Shared activities are reconstructed from the stored activity file when opened. Lap Track does not store precomputed lap summaries for the share. Shared views are read-only and do not give the viewer access to the sharer’s Strava account or other activities.
Strava beta integration
The optional Strava integration uses Strava OAuth to access activities you authorize. Lap Track stores the authorization token on its server so it can request the selected activity. Activity summaries may be cached in your browser for 15 minutes for Recent, 6 hours for This year, or 24 hours for an individual past year. Full activity streams are not stored in the browser cache. We do not sell activity data or use it for advertising.
You can disconnect Strava from Lap Track at any time. Disconnecting removes the server-side authorization for the current account and clears the browser’s cached Strava activity lists. Strava access can also be revoked from your Strava settings.
Analytics
Public pages load a privacy-focused analytics script hosted at analytics.henryvandenbroek.com to measure page usage. It is used for aggregate product insights and is not used to read the contents of your activity files.
Contact
For privacy questions, use the contact page.
Legal basis and rights
For the beta Strava integration, processing is based on your authorization and the operation of the requested service. Cloudflare Workers, KV, and R2 provide the hosting, session, token, share metadata, and temporary activity-file storage infrastructure. OAuth tokens are retained only while the Strava connection is active and are deleted when you disconnect or the authorization is rotated out. Share files and metadata are retained for the selected duration of up to 90 days, or until you delete the share. You may request access, correction, deletion, or clarification about personal data held for the service by using the contact page. You may also revoke Strava access from your Strava settings.