The German version is authoritative
This page is a translation of German legal obligations (§ 5 DDG, GDPR and § 312j BGB among others), not an adaptation to the law of other countries. In case of doubt the German wording applies. Questions? Write to support@bikecare.app.
Protecting your data matters to us. This app is "offline first" – your data lives primarily on your device and is stored in your personal cloud so you can use it across devices. We show no ad banners, embed no advertising networks and sell no data. The part recommendation links to shops partly via commission links – marked as such and at no extra cost to you (see section 13). To improve the app we collect pseudonymous usage statistics, which you can object to at any time in the settings (see section 10). On our public marketing pages we additionally use web analytics only with your consent (see section 10).
Tobias Meixner, c/o Online-Impressum #7711, Europaring 90, 53757 Sankt Augustin, Germany.
Email: support@bikecare.app
For sign-in we store your email address, your optional name and your password exclusively as a cryptographic hash (PBKDF2) – never in plain text. Purpose: sign-in and cross-device storage. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
Alternatively you can use "Sign in with Apple" or "Sign in with Google". In that case we receive a unique user identifier from Apple or Google and – if you agree – your email address, in order to create or match your account. With "Sign in with Apple" you can choose whether your real address or an anonymous forwarding address ("…@privaterelay.appleid.com") is transmitted. Legal basis: performance of a contract or pre-contractual measure (Art. 6 (1) (b) GDPR). Apple (Apple Distribution International Ltd., Ireland) and Google (Google Ireland Ltd.) operate their respective sign-in service as independent controllers; their own privacy notices apply additionally (Apple: apple.com/legal/privacy/data/en/sign-in-with-apple). You can disconnect the link at any time in the settings.
The data you enter is stored in your personal cloud so that it stays available on all of your devices. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
If you actively connect Strava, we process and store Strava access tokens as well as retrieved activity data (e. g. distance, duration, route, elevation, bike assignment). Where your Strava activities contain them, this also includes heart rate and power data (watts/kilojoules). Heart rate data is health data within the meaning of Art. 9 GDPR. We process it exclusively to show you your rides, statistics and records – there is no further evaluation, no scoring and no disclosure; it is never shared in the community.
Legal basis: your explicit consent, which you give when connecting your Strava account (Art. 6 (1) (a) and Art. 9 (2) (a) GDPR). You can withdraw that consent at any time with effect for the future by choosing "Disconnect Strava" in the settings – rides already imported stay in your account and can be removed there individually or completely by deleting your account.
If you enable reminders, we store your device push subscription in order to send you maintenance reminders. Depending on the device, delivery runs through a different service:
Only the technical token and the content of the reminder are transmitted (e. g. "Chain due soon"). Legal basis: consent (Art. 6 (1) (a) GDPR). You can withdraw it at any time via "Disable notifications" in the settings.
For the weather tip on the overview, approximate coordinates are transmitted to Open-Meteo (open-meteo.com) – only if you allow location access. For imported rides the start location, rounded to roughly one kilometre, is additionally queried together with the ride date in order to detect wet rides and add the temperature; you can switch that off in the Strava settings. No account or identity data is sent. Nothing is stored at Open-Meteo; the result ("wet", temperature) is then part of your ride. Legal basis: consent / legitimate interest (Art. 6 (1) (a)/(f) GDPR).
If you enable sharing, friends and groups you are connected with can see exclusively aggregated figures (e. g. kilometres, elevation, streak, badges, records) and your display name – never costs, locations or individual rides. Legal basis: consent (Art. 6 (1) (a) GDPR). Withdrawal: switch sharing off or leave the connection/group.
If you request a new password, we send an email containing a time-limited link via our service provider Resend. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
For offline use the app stores your content locally (IndexedDB/localStorage). This storage is technically necessary to operate the app (Art. 6 (1) (b) GDPR, § 25 (2) TDDDG) and does not serve advertising purposes. For the pseudonymous usage statistics and the device identifier used for them, see section 10.
a) In the app (iOS/Android app as well as the logged-in web app): to understand which functions are used and to improve the app, we collect pseudonymous usage statistics via Google Analytics 4 / Firebase (Google Ireland Ltd., Dublin). Events such as "bike created", "reminder enabled" or "AI report generated" are recorded together with technical context (platform, app version) and a random app instance identifier. We transmit no advertising ID (no IDFA; on iOS there is therefore no ATT "app tracking" dialog), we do no profiling for advertising purposes, show no ad banners and sell no data. The statistics are not linked to the commission links of the part recommendation (section 13): we do not learn who clicked what or who bought what. Legal basis: our legitimate interest in improving the app in line with actual demand (Art. 6 (1) (f) GDPR). You can object to the usage statistics at any time – under Settings → Data → "Anonymous usage statistics"; after that no analytics events are collected any more.
b) On our public marketing pages (home page, features, pricing, FAQ, login etc.) we use – only with your consent given via the cookie banner – Google Tag Manager and Google Analytics 4 (Google Ireland Ltd., Dublin) in order to understand how our website is used (e. g. page views, where visitors come from, clicks on "Start for free"). Without consent no analytics cookies are set and no data is transmitted to Google (Google Consent Mode v2, default: denied). We manage consent via the consent tool CookieScript; you can withdraw or adjust it at any time via "Cookie settings" in the footer. Legal basis: consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG).
c) Server-side conversion measurement. In addition our server transmits certain events directly (server to server, Google Measurement Protocol) to Google Analytics 4: sign-in and registration, purchase and subscription events (including transaction ID and order value), subscription cancellation and reactivation as well as account deletion. The transmission is pseudonymous, based on the GA4 client ID, and happens only if you have not objected to analytics (in-app statistics active, section a) or have consented on the web (section b) – if you switch the statistics off, the client ID is removed and no such events are sent any more. Purpose: conversion measurement (sign-ups, purchases). Legal basis: legitimate interest (Art. 6 (1) (f) GDPR) or consent on the web ((a)).
Google processes the analytics data as our processor. Transfers to the USA are based on EU standard contractual clauses and the EU-US Data Privacy Framework. Retention in Google Analytics: 14 months at most.
For paid Pro subscriptions we use the payment service provider Stripe (in the EEA: Stripe Payments Europe, Ltd., Dublin, Ireland). Payment and billing data is processed (e. g. name, email, payment method, invoice and subscription data). Full card details are processed exclusively by Stripe – they are not held on our servers. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR) and fraud prevention ((f)). Transfers to the USA are based on EU standard contractual clauses and the EU-US Data Privacy Framework. Stripe's privacy policy: stripe.com/privacy.
If you use the AI functions, the inputs and bike data required for them are transmitted to our AI service providers – exclusively in order to provide the respective function (Art. 6 (1) (b) GDPR):
Both process data in the USA (EU standard contractual clauses). Please do not enter particularly sensitive data into the AI functions – it is not needed there.
The part recommendation suggests suitable spare parts and links to them in online shops. Some of these links are commission links (affiliate links) of the networks ADCELL (Firstlead GmbH, Rosenstr. 17, 10178 Berlin, Germany) and AWIN (AWIN AG, Eichhornstr. 3, 10785 Berlin, Germany). If you buy something after clicking one, we receive a commission from the shop. The price does not change for you. These links are marked as advertising in the app.
When you click such a link, the network forwards you to the shop and sets a cookie or identifier in order to attribute the purchase to our recommendation. This processing happens only after your click and within the responsibility of the respective network or shop – as long as you do not click, nothing is transmitted to them. From the networks we receive only aggregated billing data, no personal details about your order (no names, no addresses, no baskets linked to a person). The legal basis for embedding the links is our legitimate interest in financing the free function (Art. 6 (1) (f) GDPR); for the processing after the click the networks and shops are independent controllers. Their privacy notices apply (adcell.de/datenschutz, awin.com/de/rechtliches).
The selection of products depends solely on how well they fit your bike – not on the size of the commission. Where we find no suitable part at a partner shop, we link to other shops without any commission. Price and availability information comes from the merchants' product data and is updated daily; the price in the shop at the time of your order always prevails. The recommendations are non-binding suggestions – please check compatibility before buying.
Where data is transferred to the USA, this happens on the basis of appropriate safeguards: Cloudflare, Stripe, Google and Apple are certified under the EU-US Data Privacy Framework; with the other US providers (Anthropic, Perplexity, Resend, Strava) there are EU standard contractual clauses (SCC) in place.
We store your data for as long as your account exists. On account deletion (possible in the app at any time) your data including all community entries is removed completely. Short-lived security data deletes itself automatically: password reset links after 60 minutes, email confirmation codes after 30 minutes, login sessions after 180 days at the latest. Invoice and payment data for Pro subscriptions is kept by us and by Stripe for up to 10 years for tax and commercial law reasons (§ 147 AO).
You have the right to information, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent you have given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority – the one responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany; you may also contact the authority where you live. There is no automated decision-making.
Please send requests to support@bikecare.app.
Our service is aimed at people who are at least 18 years old. By registering you confirm that you have reached this minimum age. We do not knowingly collect data from children.
Last updated: 7 July 2026
BikeCare · Tobias Meixner · support@bikecare.app