Privacy Policy

Last updated: July 6, 2026

BikeDialed (“we”, “us”) is a free, non-commercial bicycle build configuration and weight tracking tool available at bikedialed.com (the “Service”), operated by an individual (the “Operator”). The Service shows no advertising and sells nothing. This policy explains what data we collect, why, and what rights you have.

1. Data We Collect

Account data (registered users)

  • Email address — used to sign you in, verify your account, and send account-related email (verification, password reset). Never used for marketing without separate consent.
  • Name — display name shown on your profile and public builds.
  • Password — stored only as a bcrypt hash. We never store or see your plaintext password.
  • Email verification status and timestamps (account created, last updated).

Sign in with Google (OAuth)

If you sign in with Google, we receive your name, email address, and profile picture from Google and link them to your BikeDialed account. We do not receive your Google password and we request no other Google data. Google's own privacy policy (https://policies.google.com/privacy) governs their side of the sign-in.

Content you create

  • Bike builds — component selections, custom components (names, weights, prices), personal notes, target weight/budget, build names and descriptions.
  • Sharing state — whether a build is public and its share link. Public builds (including your display name) are visible to anyone; private builds are visible only to you.
  • Social actions — likes and saves on public builds.
  • CSV imports — the contents of build files you upload are stored as build data.

Automatically collected data

  • Server logs — our hosting provider records standard request metadata (IP address, user agent, timestamps) for security and operations.
  • Page analytics — we use Vercel Web Analytics to count page views and referrers in aggregate. It is cookieless, sets no identifiers, and does not track you across other websites. We do not run advertising trackers, and we do not use Google Analytics or similar profiling tools.

2. Cookies and Local Storage

  • Session cookie — an encrypted JWT session cookie keeps you signed in for up to 30 days. It is strictly necessary for authentication; deleting it signs you out.
  • CSRF/auth cookies — set by the authentication layer to protect sign-in.
  • Guest build draft (localStorage) — if you configure a bike without an account, your draft is saved in your browser's localStorage on your device (key bikedialed:guest-build-draft). It is not transmitted to our servers until you sign in and save the build. Drafts expire automatically after 30 days and can be removed at any time by clearing your browser storage.

We do not use advertising cookies and we do not sell or share personal data for advertising.

3. How We Use Data

  • Provide the Service: store and display your builds, calculate weights and prices.
  • Authenticate you and keep your account secure.
  • Send transactional email (verification, password reset) via our email provider.
  • Maintain, debug, and protect the Service (logs, abuse prevention).

We do not sell personal data. We do not use your data to train AI models.

4. Service Providers (Processors)

We share data only with providers needed to run the Service:

ProviderPurposeData involved
VercelHosting, server infrastructure, and cookieless page analyticsRequest logs, application data in transit, aggregated page views
Neon (PostgreSQL)Data storageAccount and build data
ResendTransactional email deliveryEmail address, email content
GoogleOptional OAuth sign-inOAuth profile (name, email, picture)

5. Data Retention

  • Account and build data are kept while your account exists.
  • Guest drafts live only in your browser and expire after 30 days.
  • Server logs are retained per our hosting provider's standard rotation.
  • When you delete your account, your data is permanently deleted (see below).

6. Your Rights

Depending on your location (e.g. GDPR, UK GDPR, CCPA), you may have the right to access, correct, export, delete, or object to processing of your personal data.

  • Access & export — your builds can be exported to CSV from within the Service.
  • Correction — name and password can be changed on your Profile page.
  • Deletion — you can permanently delete your account and all associated data yourself at Profile → Delete Account (/account/delete). This removes your builds, custom components, notes, and profile, and cannot be undone.
  • For anything else, contact us (Section 9) and we will respond within 30 days.

7. Security

Passwords are hashed with bcrypt; sessions use signed, encrypted JWT cookies; all traffic is served over HTTPS. No method of storage is 100% secure, but we follow industry-standard practices and limit data collection to what the Service needs.

8. Children

The Service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

9. Contact

Questions or privacy requests: contact@bikedialed.com

10. Changes to This Policy

We will post any changes on this page and update the “Last updated” date. For material changes affecting registered users, we will notify you by email or an in-product notice before they take effect.