Privacy Policy
Last updated: March 10, 2026
1. Data Controller
The data controller is WattLab, reachable at: info@wattlab.it.
2. Data Collected
We collect the following data:
- Registration data: email, name (optional), authentication method (email/password or Google).
- Athlete data: body weight, bike weight, W/kg ratio, number of laps entered by the user.
- GPX files: uploaded course files containing latitude, longitude and elevation data.
- Third-party platform data: weight and FTP imported from Strava (only when authorized by the user).
- Usage data: number of calculations performed, subscription plan, calculation history.
- Payment data: handled entirely by Stripe. We do not store credit card numbers.
- Feedback: messages, ratings and types submitted through the in-app feedback form.
3. Legal Basis and Purposes
- Contract performance: data is necessary to provide the pacing calculation and nutrition service.
- Consent: for third-party platform integration (Strava, Garmin), the user grants explicit consent via OAuth.
- Legitimate interest: to improve the service, analyze anonymized usage patterns and prevent abuse.
4. Third-Party Services
- Firebase (Google): authentication, database, hosting, cloud functions. Data hosted in Europe (eur3 / europe-west1).
- Stripe: payment and subscription management. PCI DSS Level 1 compliant.
- Strava API: athlete data import, only with explicit OAuth authorization.
5. Data Retention
Personal data is retained for the duration of the account. Calculation history follows plan limits (Free: no history, Base: last 30, Pro: unlimited). Archived GPX files (Pro only) are deleted when the account is cancelled. Payment data is managed by Stripe according to their privacy policy.
6. User Rights (GDPR)
Under the GDPR, you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data ("right to be forgotten").
- Portability: receive your data in a structured, readable format.
- Objection: object to processing on legitimate grounds.
- Withdraw consent: revoke consent for third-party platform integration at any time.
To exercise these rights, contact us at info@wattlab.it. You can delete your account from the Profile page.
7. Cookies and Tracking Technologies
WattLab uses the following categories of cookies:
- Essential cookies: required for the service to function, including Firebase authentication and session management. These cookies cannot be disabled.
- Analytics cookies (optional): we use Google Analytics 4 (GA4) to analyze in aggregate and anonymous form how users interact with the application. Analytics cookies are activated only after the user's explicit consent via the cookie banner shown on first visit. No personal data is shared with third parties for advertising purposes.
You can change your cookie preferences at any time by clicking "Cookie Settings" in the site footer. We do not use profiling or marketing cookies.
8. Security
Data is protected with encryption in transit (HTTPS/TLS) and at rest (Firebase). Data access is governed by Firestore Security Rules that prevent unauthorized access. Calculations are performed server-side via Cloud Functions to prevent client-side manipulation.
9. Data Transfers
Data is hosted on Firebase servers in Europe (Firestore: eur3, Cloud Functions: europe-west1, Belgium). Any transfers to third countries (e.g. Google services) are covered by Google's Standard Contractual Clauses (SCC).
10. Changes to This Policy
We reserve the right to update this Privacy Policy. Changes will be published on this page with the date of last update. You will be informed of any material changes via email.
11. Contact
For any questions about privacy, contact us at info@wattlab.it.
