Effective [date] · Last updated [date]
Draft · not yet reviewed
The Lines Project (linesproject.com) is run by Singletrack Media, LLC, 1090 S Wadsworth Blvd, Unit C #3325, Lakewood, CO 80226, USA (“we”, “us”). We decide what happens to the data described here, which makes us its “controller” under European and UK law.
Questions about this policy or your data go to privacy@linesproject.com. For anything else, contact support@linesproject.com.
When you make an account: your email address (it’s also your username), a password (stored only as a salted hash we can’t reverse), your name if you give one, and your settings, such as units, email choices and a home town if you enter one.
From Strava, if you connect it: your activities’ GPS tracks and timestamps, titles, descriptions, dates, types, distances, elevation, the device that recorded them, and their photos and videos along with the photo locations Strava supplies. We ask for activity:read_all, so this includes activities you’ve set to private or “Only You”. We also keep your Strava athlete ID and the access tokens Strava gives us.
From Ride with GPS, if you connect it: the same kinds of information about your trips, and its access tokens.
From files you upload: whatever is in the GPX, FIT or TCX files or Strava export you give us.
A GPS track shows exactly where you went, including where it starts and finishes, which for many people is home. We draw your tracks in full on your own map. Privacy settings on Strava or Ride with GPS control what other people see there; they don’t hide your own tracks from you, so they don’t hide them from us.
When you pay (once subscriptions open): see Payments below. We never see your card.
When you use the site: our servers log each request, including your IP address, browser type, the page asked for and the time, which we use to keep the site working and secure (for example, locking out repeated wrong passwords). We keep these logs for up to 90 days. If something breaks, an error report goes to Sentry (see below); it doesn’t include your IP address, name or email.
When you write to us: your message and address.
One thing: activity notes, which are on by default. From the moment you connect Strava or Ride with GPS, we add a line to the description of each new activity saying what it added to your map — new miles, the size and rank of the web it landed in, whether it joined two webs — followed by a link to linesproject.com. For example:
Strava and Ride with GPS each have their own switch, on the Sync page and in Settings, and turning one off stops the next note. On Strava, notes need a separate permission (activity:write). We ask for it when you connect, and you can untick it on Strava’s own consent screen; without it, nothing is written to Strava. Ride with GPS has a single permission that covers both reading and writing, so there the switch is the only way to stop notes. We read the current description immediately before writing, so whatever you or another app put there stays. Each note is written once and we don’t come back to change it. Switching notes off doesn’t remove notes already written — you can edit or delete those yourself on Strava or Ride with GPS.
This is the one part of The Lines Project other people can see, because a description is as visible as the activity it’s on. We never create or delete an activity, and never change its title, photos, route or privacy setting.
We don’t sell your personal information, and we don’t “share” it for cross-context behavioral advertising as California law defines that. We run no ads, use no advertising trackers, don’t give your data to data brokers, and don’t use it to train AI or machine-learning models.
Our team. Authorized personnel of Singletrack Media, LLC can access account and activity data when it’s needed to support you, fix a problem, or keep the service secure.
The companies we use. Each gets only what its job needs and may use it only to do that job for us, except where noted:
Because we have to. We’ll disclose information when the law requires it, or when we believe in good faith it’s needed to protect someone’s safety or our rights. If The Lines Project is sold or merged, your data would move with it under this policy, and we’d tell you first.
Nobody else. No other user of The Lines Project can see your map, tracks or stats.
When subscriptions open, they’re sold through Link, LLC, Stripe’s merchant of record, and processed by Stripe. Your card details go to Stripe and never to us. Link and Stripe act as their own controllers for the payment data they hold, under their own privacy policies (Stripe, Link). Your receipts, and your card statement, will name Link. We keep only what we need to know whether your account is subscribed — the subscription’s status and dates and Stripe’s identifiers for it.
Your browser also remembers some map preferences, like your chosen background map, in its own local storage; that never leaves your device.
We use Google Analytics to count visits to our pages. It sends Google the address and title of each page you open. For a page about one of your activities, that includes the activity’s title. For a page about a gap, the address includes the gap’s approximate location. Google also receives your IP address, as any website you load does. We never send Google your name, email address or tracks. You can block Google Analytics with Google’s opt-out add-on or any tracker blocker, and the site works the same.
[⚠️ If you use GA for visitors in the EEA or UK, the analytics cookies need consent first: add a consent banner and replace this paragraph with how to change your choice.]
We email you to confirm your address, reset a password, tell you when your map is ready, and about your subscription. If you want them, we also email when a build adds new miles and a weekly digest; those two have an unsubscribe link and a switch in Settings. We don’t send marketing. Amazon SES delivers our mail. If a message bounces or is marked as spam, we record that and stop sending to that address.
Everything travels over HTTPS. Passwords are stored only as salted hashes, access to our servers is limited to key-based login, and your map files are served only to your own signed-in session. No system is perfectly secure; if a breach affects your personal information, we’ll tell you as the law requires.
Anyone can, from Settings:
Depending on where you live — including the EEA, the UK, California and several other US states — you may also have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict how we use it, and to withdraw consent at any time. Email privacy@linesproject.com and we’ll answer within 30 days. We may need to confirm it’s you. We won’t treat you differently for using any of these rights. If you’re in the EEA or UK and unhappy with our answer, you can complain to your data protection authority.
Our servers are in the United States, and so are most of the companies above. If you use The Lines Project from outside the US, your information is transferred to and stored in the US, where privacy law may differ from yours. We transfer it because that’s where the service runs; where European or UK law requires more, the companies we use rely on Standard Contractual Clauses or the EU–US Data Privacy Framework.
The Lines Project isn’t for anyone under 16, and we don’t knowingly collect their information. If you think a child has an account, tell us and we’ll delete it.
If we change this policy in a way that matters, we’ll email you before it takes effect and update the date at the top. Older versions are available on request.
Singletrack Media, LLC · 1090 S Wadsworth Blvd, Unit C #3325, Lakewood, CO 80226, USA · privacy@linesproject.com