0,00  0

Basket

No products in the basket.

EST. 2024
0,00  0

Basket

No products in the basket.

Privacy policy

Effective date: 25 April 2026
Last updated: 25 April 2026
Controller: ARDECCI, ardecci.com

PLAIN LANGUAGE SUMMARY

We collect only what we need to run the club and its services. We don't sell your data, we don't run ads, and we don't share your information with third parties except where necessary to deliver the services described below (payment processing, Strava integration, map rendering). You can request deletion of your data at any time.

01 Who we are

ARDECCI is a cycling club based in Slovenia, operating at ardecci.com. We are the data controller for all personal data collected through this website and its associated services.

For data protection enquiries, contact us at: info@ardecci.com

This policy applies to all visitors, registered users, and members of ardecci.com, regardless of membership tier.

02 What data we collect

The data we collect depends on how you interact with the site. Below is a full breakdown.

 

Data type What it includes When collected
Account data Name, email address, username, password (hashed) On registration
Membership data Membership tier, purchase date, expiry date On membership purchase
Order data Billing name, address, email, order history, payment status On purchase via WooCommerce
Strava credentials OAuth access token, refresh token, token expiry, Strava athlete ID, first name, last name When you connect your Strava account
Activity data Activity name, distance, sport type, date, GPS route (polyline), altitude stream, athlete name Via Strava webhook when you log an activity
Location data Your device's current GPS coordinates Only when you use "Near me" — not stored
GPX file data Route coordinates, elevation points When you upload a GPX file — processed in-browser, not stored on our server
Technical data IP address, browser type, referring URL, pages visited Automatically on site visit (server logs)
Cookie data Session identifiers, login persistence, Strava connection state On login and Strava OAuth completion

You may choose to prevent this website from aggregating and analyzing the actions you take here. Doing so will protect your privacy, but will also prevent the owner from learning from your actions and creating a better experience for you and other users.

03 How we use your data

The data we collect depends on how you interact with the site. Below is a full breakdown.

Purpose Data used
Creating and managing your account Name, email, password
Processing membership purchases Order data, billing address, payment status
Displaying the club activity feed Activity name, athlete name, distance, sport type, date
Route overlay on the café map Strava route polyline, altitude stream
Determining café proximity to your route Route polyline — compared against café coordinates, not stored
"Near me" café sorting Device GPS — used in-browser only, never transmitted to our server
Enforcing membership tier access Membership tier, expiry date
Sending transactional emails Email address, order details
Security and fraud prevention IP address, login attempts
Legal compliance Order records, billing data

WHAT WE DO NOT DO

We do not sell your personal data to any third party. We do not use your data for advertising or profiling. We do not use your Strava activity data for any purpose other than displaying it on ardecci.com as described above.

04 Legal basis for processing

Under GDPR (General Data Protection Regulation), we are required to identify a legal basis for each type of data processing. We rely on the following:

Processing activity Legal basis
Account creation and management Contract — necessary to provide the service you registered for
Membership and order processing Contract — necessary to fulfil your purchase
Strava OAuth connection and activity processing Consent — you explicitly authorise this by connecting your Strava account
Displaying your activity on the club feed Consent — granted via Strava OAuth authorisation
Retaining order records Legal obligation — required for tax and accounting purposes
Security logging (IP addresses) Legitimate interest — protecting the integrity of the service
Transactional emails Contract — necessary to communicate order and membership status

05 Strava integration

Connecting your Strava account is optional and available to Espresso and Doppio members. When you connect, the following happens:

  • You are redirected to Strava's authorisation page, where you grant ardecci.com permission to access your activity data
  • Strava returns an OAuth access token, refresh token, and your basic profile (first name, last name, athlete ID)
  • These credentials are stored securely in our WordPress database and used solely to fetch your activity data
  • When you log an activity on Strava, Strava sends a webhook notification to our server
  • We use your stored token to fetch the activity details and store a summary (name, distance, sport type, date, route polyline, altitude data) locally
  • Your activity may appear in the club activity feed visible to other logged-in members
  • The route polyline and altitude data are used to render the elevation profile and café proximity overlay on the map

WITHDRAWING STRAVA CONSENT

You can disconnect your Strava account at any time from your profile page. Disconnecting removes your stored tokens from our system. You can also revoke access directly in your Strava account under Settings → My Apps. Once disconnected, no new activity data will be collected. Previously stored activities will be retained for 30 days before being permanently deleted, unless you request immediate deletion.

We access Strava data under Strava's API Agreement. Strava is an independent data controller for data held on their platform — their privacy policy applies to data you share with Strava directly.

06 Café map & location data

The café map is publicly accessible without login. The following applies to location-related features:

  • "Near me" button: Your device's GPS coordinates are requested via your browser's Geolocation API. These coordinates are used only to sort the café list by proximity and are never transmitted to our server or stored anywhere
  • GPX file upload: GPX files you upload are processed entirely within your browser. The route data is never sent to or stored on our server
  • Strava route overlay: Route data loaded from your Strava activities is fetched from our server (where it was stored after the webhook event) and rendered locally in your browser. No additional location data is collected at this point
  • Map tiles: The map is rendered using MapTiler, which serves vector map tiles. MapTiler may log tile requests including your IP address. See section 9 for details

07 Membership & payments

Memberships are processed through WooCommerce. Payment transactions are handled by our payment processor — we do not store full card details on our servers at any point.

We retain the following order data for legal and accounting compliance:

  • Billing name and address
  • Email address
  • Order total and product purchased
  • Payment status and transaction reference
  • Date of purchase

This data is retained for a minimum of 7 years as required by Slovenian and EU accounting regulations, even if you delete your account.

MEMBERSHIP EXPIRY

All memberships are annual. When a membership expires, your account automatically reverts to the free Ristretto tier. No automatic renewal occurs — you must actively renew. You will receive an email reminder before expiry.

08 Cookies

We use the following cookies. We do not use advertising cookies or third-party tracking cookies.

Cookie name Purpose Duration Type
wordpress_logged_in_* Maintains your login session Session / 14 days if "Remember Me" selected Strictly necessary
wordpress_sec_* Security token for authenticated requests Session Strictly necessary
wp-settings-* Stores your WordPress display preferences 1 year Functional
woocommerce_cart_hash Tracks cart contents for session continuity Session Strictly necessary
woocommerce_items_in_cart Indicates whether cart contains items Session Strictly necessary
ardecci_strava_athlete Stores your Strava athlete ID to show connect/disconnect state on the map page 1 year Functional

Strictly necessary cookies are required for the site to function and cannot be disabled. Functional cookies can be cleared via your browser settings at any time, though this may affect certain features such as the Strava connect button state.

We do not use Google Analytics, Facebook Pixel, or any other third-party analytics or advertising trackers.

09 Third-party services

We use a small number of third-party services to deliver ardecci.com. Each is listed below with a link to their privacy policy.

Service Purpose Data shared Privacy policy
Strava Activity data via OAuth and webhooks OAuth tokens, activity IDs strava.com/legal/privacy
MapTiler Vector map tile rendering IP address (tile requests) maptiler.com/privacy-policy
OpenStreetMap Map data underlying all map tiles None directly osmfoundation.org
WooCommerce / Automattic E-commerce and order processing Order and billing data automattic.com/privacy
WooPayments Secure card payment handling Payment details (not stored by us) Provided at checkout
Neoserv Server infrastructure Server logs including IP addresses Provided on request
Google Fonts Typography (Cormorant Garamond, DM Sans) IP address on font file request policies.google.com/privacy

All third-party processors we use are either based in the EU/EEA or operate under standard contractual clauses (SCCs) approved by the European Commission, ensuring adequate protection for any data transferred outside the EU.

10 Data retention

Data type Retention period Reason
Account data Until account deletion, or 2 years of inactivity Service provision
Strava tokens Until disconnected or account deleted Service provision
Strava activity data Up to 5 most recent activities stored at any time; older entries overwritten automatically Club activity feed display
Strava activity data after disconnect 30 days, then deleted permanently Grace period for reconnection
Order and billing records 7 years minimum Legal/accounting obligation
Membership tier and expiry Duration of membership + 1 year Dispute resolution
Server logs (IP addresses) 30 days Security monitoring
"Near me" location Not stored — browser only N/A
GPX file data Not stored — browser only N/A

11 Data sharing

We do not sell, rent, or trade your personal data. We share data only in the following circumstances:

  • Service providers: We share data with third-party processors listed in section 9 solely to deliver the services described in this policy
  • Legal requirements: We may disclose data if required by law, court order, or regulatory authority
  • Business transfer: In the unlikely event of a merger or acquisition, your data may be transferred as part of that transaction. You will be notified in advance
  • Club activity feed: Your first name and activity details (name, distance, sport type, date) are visible to other logged-in members of ardecci.com as part of the club feed. This is part of the service you consent to when connecting your Strava account

12 Your rights

Under GDPR, you have the following rights regarding your personal data. To exercise any of them, contact us at info@ardecci.com.

Right What it means
Right of access You can request a copy of all personal data we hold about you
Right to rectification You can correct inaccurate data. Most account data can be updated directly in your profile
Right to erasure You can request deletion of your personal data. We will comply except where we are legally required to retain certain records (e.g. order data)
Right to restriction You can ask us to pause processing your data in certain circumstances, for example while a dispute is resolved
Right to data portability You can request your data in a structured, machine-readable format
Right to object You can object to processing based on legitimate interest. You can withdraw Strava consent at any time by disconnecting your account
Right to withdraw consent Where processing is based on consent (Strava integration), you can withdraw consent at any time without affecting prior processing
Rights related to automated decisions We do not make automated decisions that significantly affect you

We will respond to all requests within 30 days. If we are unable to fulfil a request, we will explain why.

13 Data security

We take appropriate technical and organisational measures to protect your personal data, including:

  • All data is transmitted over HTTPS (TLS encryption)
  • Passwords are hashed using WordPress's bcrypt-based hashing — we cannot see your password
  • Strava OAuth tokens are stored in the WordPress database and accessible only to administrators
  • Payment card data is never stored on our servers — all card processing is handled by our PCI-compliant payment processor
  • Access to the server and database is restricted to authorised personnel only
  • Server software is kept up to date with security patches
  • In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.

14 Changes to this policy

We may update this policy from time to time to reflect changes in our services, legal requirements, or data practices. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify registered users by email if the changes materially affect how we use their data
  • Where required by law, seek fresh consent
  • Continued use of ardecci.com after changes are published constitutes acceptance of the updated policy. If you disagree with changes, you may request account deletion.

15 Contact & complaints

For any questions, requests, or concerns about how we handle your personal data, contact us directly at:

Email: info@ardecci.com
Website: ardecci.com
Country: Slovenia, European Union

If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the Slovenian supervisory authority:

Information Commissioner of the Republic of Slovenia
(Informacijski pooblaščenec)
Website: ip-rs.si
Email: gp.ip@ip-rs.si
Phone: +386 1 230 97 30

You also have the right to lodge a complaint with the supervisory authority in your country of residence if it differs from Slovenia.

© Ardecci - Est. 2024.
Born in Slovenia. Dressed in Italian.