Privacy Policy
1. Introduction and Scope
BikeFit CC (“we,” “us,” or “the Company”) provides a clear fitting engine for bicycle frames and personalized fit recommendations based on body geometry scanning (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, create an account, or use the Service, and it describes the rights available to you.
This Policy applies to visitors, prospective customers, registered users, and, where relevant, the end users of our business customers. It is designed to meet the requirements of the EU/UK General Data Protection Regulation and applicable US state privacy laws (such as the California Consumer Privacy Act, as amended by the CPRA, and comparable laws in other states).
2. Who Is Responsible for Your Data (Data Controller)
The data controller responsible for processing your personal data under this Policy is:
BikeFit CC LLC
7525 East Treasure Drive, Unit 101, North Bay Village Florida 33141 USA
Company registration number: L26000319760
Contact: privacy@bikefitcc.com
Data Protection Officer (if appointed under Art. 37 GDPR): Marco De Cuyper, reachable at privacy@bikefitcc.com.
EU representative (if the Company is established outside the EU but offers services to EU data subjects, per Art. 27 GDPR): privacy@bikefitcc.com.
3. Personal Data We Collect
3.1 Data you provide directly
Account and profile data: name, business email, job title, company name, password (stored as a salted hash).
Billing data: billing address, VAT/tax ID, payment method details (processed by our payment processor; we do not store full card numbers).
Content you submit: files, records, or other data you upload to the Service (“Customer Data”), which you control as detailed in Section 4.
Communications: messages you send via support tickets, chat, email, or forms.
3.2 Data collected automatically
Usage data: pages/features accessed, timestamps, clickstream, session duration.
Device and connection data: IP address, browser type, operating system, device identifiers.
Cookies and similar technologies: see Section 9 (Cookies).
3.3 Data from third parties
Single sign-on (SSO) or OAuth identity providers, if you choose to authenticate that way.
Publicly available business information (e.g., company registries) used for fraud prevention and account verification.
Data provided by the business customer that administers your account, where you are an end user added by an organization.
4. Our Role: Controller vs. Processor
For account administration, billing, marketing, and website operation, we act as the data controller.
For personal data that our business customers store within the Service as part of their own use of the product (“Customer Data”), we act as a data processor, and the business customer is the controller.
5. Purposes, Legal Bases, and Retention
We rely on the following legal bases under Art. 6(1) GDPR for each category of processing:
Purpose of Processing
Examples of Data Used
Legal Basis (GDPR Art. 6)
Typical Retention
Creating and administering your account
Name, business email, password hash, company name
Performance of a contract (Art. 6(1)(b))
Duration of account + 30 days
Providing and operating the Service
Account data, usage logs, content you upload
Performance of a contract (Art. 6(1)(b))
Duration of subscription
Billing and payment processing
Billing name/address, payment token (via processor), invoice history
Performance of a contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))
10 years (statutory)
Customer support
Support tickets, correspondence, account/device metadata
Performance of a contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f))
3 years after resolution
Product security & fraud prevention
IP address, device/browser fingerprint, login patterns
Legitimate interests (Art. 6(1)(f))
12–24 months
Service improvement & analytics
Aggregated/pseudonymized usage data
Legitimate interests (Art. 6(1)(f))
26 months (aggregated)
Marketing communications
Business email, name, engagement history
Consent (Art. 6(1)(a)) or Legitimate interests for existing customers (Art. 6(1)(f))
Until opt-out + 3 years suppression record
Non-essential cookies & tracking
Cookie/device identifiers
Consent (Art. 6(1)(a))
Per cookie banner settings, max 13 months
Compliance, audits & legal claims
Records relevant to the matter
Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f))
As required by law or limitation period
6. How We Share Personal Data
We do not sell personal data. We disclose personal data only in the following circumstances:
Sub-processors and service providers: hosting/infrastructure, email delivery, customer support tooling, analytics, and payment processing vendors, each bound by a data processing agreement. See our current sub-processor list:
Hubspot
Google Analytics
Supabase
Vercel
AWS
Professional advisors: auditors, insurers, and legal counsel, where necessary.
Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations.
Legal and safety reasons: to comply with a legal obligation, enforce our terms, or protect the rights, property, or safety of the Company, our users, or the public.
With your direction or consent: for example, when you connect a third-party integration.
7. International Data Transfers
Personal data may be processed in countries outside the European Economic Area (EEA), including the United States. When we transfer personal data out of the EEA/UK, we rely on one or more of the following safeguards, as applicable:
An adequacy decision by the European Commission for the destination country;
The European Commission’s Standard Contractual Clauses (SCCs), together with a transfer impact assessment and supplementary measures where needed;
The UK International Data Transfer Addendum, for transfers subject to UK GDPR;
Participation in a recognized certification framework (e.g., the EU-U.S. Data Privacy Framework), where the importer is certified.
You can request a copy of the relevant safeguard by contacting us at privacy@bikefitcc.com.
8. Data Security
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest, access controls based on least privilege, network segmentation, logging and monitoring, regular penetration testing, and employee security training. No system is completely secure, and we encourage you to use strong, unique credentials and enable multi-factor authentication where available.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR) and will notify affected individuals without undue delay where the breach is likely to result in a high risk (Art. 34 GDPR). Where we process Customer Data as a processor, we will notify the affected business customer without undue delay so they can meet their own notification obligations.
9. Cookies and Similar Technologies
We use strictly necessary cookies to operate the Service (e.g., session management, security, load balancing) without requiring consent, consistent with the ePrivacy Directive. For any non-essential cookies — analytics, preference, or advertising cookies — we request your consent through a cookie banner before they are set, and you can withdraw consent at any time via [COOKIE PREFERENCE CENTER LINK]. A full list of cookies, their purpose, and their duration is available in our Cookie Policy at [COOKIE POLICY LINK].
10. Your Data Protection Rights
If you are located in the EEA, UK, or Switzerland, you have the rights summarized below under Chapter III of the GDPR. Depending on your location, similar or additional rights may apply under local law (for example, California residents have rights to know, delete, correct, and opt out of certain sharing under the CCPA/CPRA).
Right
What it means
Access (Art. 15)
Request confirmation of whether we process your data and obtain a copy of it.
Rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data.
Erasure (Art. 17)
Ask us to delete your personal data, subject to legal retention obligations.
Restriction (Art. 18)
Ask us to limit how we use your data while a dispute is resolved.
Portability (Art. 20)
Receive your data in a structured, machine-readable format, or have it transferred directly to another controller where technically feasible.
Objection (Art. 21)
Object to processing based on legitimate interests or to direct marketing at any time.
Withdraw consent (Art. 7(3))
Withdraw previously given consent without affecting the lawfulness of processing before withdrawal.
Lodge a complaint (Art. 77)
File a complaint with your local data protection supervisory authority.
Not be subject to solely automated decisions (Art. 22)
Request human review of any decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these rights, contact us at privacy@bikefitcc.com. We will respond within one month as required by Art. 12(3) GDPR (extendable by two further months for complex requests, with notice to you). We may need to verify your identity before actioning a request. If you are an end user of one of our business customers, we may direct your request to that customer, who controls the data.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
11. Automated Decision-Making
We do not use your personal data for decisions based solely on automated processing that produce legal or similarly significant effects on you. Where such processing exists, you have the right to obtain human intervention, express your point of view, and contest the decision under Art. 22 GDPR.
12. Data Retention and Deletion
We retain personal data only for as long as necessary for the purposes described in Section 5, to comply with legal obligations, resolve disputes, and enforce agreements. Upon termination of a subscription, Customer Data is retained for 1 year to allow export or reactivation, after which it is deleted or anonymized in accordance with our data retention schedule, subject to backups which are purged on a rolling cycle.
13. Children's Privacy
The Service is intended for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.
14. US State Privacy Rights
If you are a California resident, or a resident of another state with a comprehensive privacy law (e.g., Virginia, Colorado, Connecticut, Utah), you may have the right to know what personal information we collect, request deletion or correction, opt out of the “sale” or “sharing” of personal information (we do not sell personal information), opt out of targeted advertising, and not be discriminated against for exercising these rights. Submit requests via privacy@bikefitcc.com; you may also designate an authorized agent to submit a request on your behalf.
15. Changes to This Policy
We may update this Policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We will post the updated Policy with a revised “Last updated” date and, for material changes, provide additional notice (e.g., email or in-product notification) before the changes take effect.
16. Contact Us
Questions about this Policy or our data practices can be directed to:
Email: privacy@bikefitcc.com