Privacy Policy

Last updated: 22 July 2026. Operated by YKP BNI.

1. Scope

This Privacy Policy explains what data YKP Strava Event Service ("the Service") collects when a participant connects their Strava account to take part in a marathon event organized by YKP BNI or an authorized partner.

2. Data collected from Strava

When you authorize the Service via Strava OAuth, we receive:

  • Athlete profile: Strava athlete id, first name, last name, username, profile picture URL.
  • Activity summary: activity id, name, type (Run / VirtualRun / TrailRun), distance, moving time, elapsed time, start date, average/max speed, average/max heart rate (if shared), calories (if shared), manual/trainer flags.

We do not request or store: GPS streams, segments, gear, photos, comments, kudos, or other social data.

3. How data is used

  • Validate that an activity matches the event rules (date range, sport type, distance).
  • Compute and display the event leaderboard.
  • Show your participation status and stats to event organizers.

We do not sell, rent, or share your Strava data with third parties for advertising or analytics outside the event scope.

4. Tokens & security

Strava access tokens and refresh tokens are stored encrypted at rest (Laravel Crypt). Tokens are never exposed to any frontend, third-party site, or log file.

5. Retention

Activity records linked to a completed event are retained for the duration agreed with the event organizer (typically up to 12 months for result verification), then anonymized or deleted. You can request immediate deletion by emailing us.

6. Revoking access

You can revoke this Service's access at any time:

Upon revocation, we stop syncing further activities. Existing event results may remain visible on the event leaderboard unless you request deletion.

7. Contact

Questions or data requests: support@example.com.

This page is a draft template. The operator should adapt it to local applicable law (e.g., UU PDP in Indonesia, GDPR for EU participants) before public publication.