Privacy Policy | Ride Cave
Privacy Policy

Privacy Policy

Effective Date: January 15, 2025
Last Updated: September 14, 2026

This Privacy Policy describes how Cave Works LLC ("we," "us," or "our") collects, uses, and shares information about you when you use the Ride Cave application, website, and related services (collectively, the "Service"). Ride Cave is intellectual property owned and operated by Cave Works LLC, a Michigan limited liability company.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Privacy Policy, please do not use the Service.

1. Information We Collect

1.1 Information You Provide Directly

  • Account Information: When you create an account, we collect your email address. We automatically generate a username for your profile. You may also sign in using Google OAuth, in which case we receive your email address from Google.
  • Profile Information: You may provide fitness-related information such as your Functional Threshold Power (FTP), body weight, avatar selection, and weather location.
  • Body Composition and Nutrition Data: If you use features such as the Nutrition Guide, you may optionally provide physiological details including your height, body-fat percentage, and a body-composition goal (for example, losing fat or gaining muscle). These fields are optional and are stored with your profile under the same protections as your other fitness data. We use them only to personalize the training and nutrition estimates we show you, and we do not sell them.
  • Date of Birth: We collect your date of birth for age verification. A date of birth on your profile is required to enable real-time riding with others (presence, shared roads, and in-ride communications), and is also collected for features such as Groups. We use it to verify that you meet minimum age requirements, to apply age-appropriate privacy protections for minors, and to limit free-text in-ride chat to adults (18+). See Section 7 for how we protect this information.
  • Workout Data: If you create custom workouts, we store the workout structure, name, description, and visibility settings you choose.
  • Route Data: If you upload GPS route files (GPX, TCX, or FIT format) using the Routes feature, we store the GPS coordinates, elevation data, distance, and route metadata contained in those files. If you draw a route on the map, we store the waypoints you place and the resulting route geometry; to compute the road path between your waypoints, those coordinates are sent to our own route-calculation server, which processes them only to build your route. GPS coordinates and waypoints may reflect real-world locations you have traveled or are interested in. You control whether routes are visible only to you (private) or shared with the community (public). Public routes, including their GPS coordinates, are visible to all Ride Cave users. Deleting a route permanently removes its GPS data from our systems. We do not use route GPS data for any purpose other than providing the Routes feature.
  • AI Interactions: When you use Atlas, our AI coaching assistant, we collect the messages you send, any images you upload for workout conversion, and any training plan parameters you provide. Atlas conversations are session-based and are not stored after the session ends, unless you explicitly save content as training notes.
  • Payment Information: If you subscribe to a paid plan, payment is processed by our third-party payment processor, Stripe. We do not directly collect or store your credit card number or bank account details. Stripe may collect payment information in accordance with their own privacy policy. We receive only your subscription status and billing identifiers from Stripe.
  • Communications: If you contact us, we may retain the content of your communications.

1.2 Information Collected Automatically

  • Ride and Performance Data: When you complete workouts, we collect detailed fitness metrics including power output (watts), heart rate, cadence (RPM), speed, distance, duration, elevation, and calories burned. This includes time-series data samples recorded during your session.
  • Heart Rate and Cardiac Data: If your heart rate monitor transmits beat-to-beat (RR) interval data, we collect this data during your session. We use RR intervals to compute derived metrics including heart rate variability (HRV) statistics (RMSSD, SDNN, pNN50), premature ventricular contraction (PVC) pattern detection, and cardiac drift analysis. These derived metrics are computed locally in your browser and, for logged-in users, stored as part of your ride record.
  • Breathing and Respiratory Data: If you connect a compatible breathing sensor, we collect breathing rate, tidal volume, minute ventilation, and inhale-to-exhale ratio during your session. We use this data to compute derived metrics including breathing efficiency and ventilatory trends. These metrics are computed locally in your browser and, for logged-in users, stored as part of your ride record.
  • Device Information: We collect information about the fitness devices you connect, such as smart trainers, heart rate monitors, power meters, and breathing sensors, including device type, manufacturer, model, and connection status.
  • Usage Data: We collect information about how you interact with the Service, including pages viewed, features used, workouts started and completed, and performance milestones.
  • Log Data: Our servers automatically record information including your IP address, browser type, operating system, referring URLs, and timestamps.
  • Device Location: We do not collect your device's location. The Service never uses GPS or location services and never requests your browser's location permission. One exception exists on older Android devices (Android 11 and below), where the operating system itself requires the location permission before an app may scan for Bluetooth devices; if you grant it there, it is used only to discover your fitness sensors, and we still never read or collect your location. Coordinates that appear in Ride Cave, such as routes and avatar positions on virtual roads, describe map geography, not you. Like most websites, our servers and analytics providers receive your IP address, which can indicate an approximate region.
  • Analytics: We use Google Analytics to collect aggregated usage statistics. This may include information about your device, browser, approximate geographic location, and how you interact with the Service. We also record aggregate operational metrics about the real-time riding system (such as connection counts and timings) using Cloudflare's analytics; these are counts and timings only and do not identify individual users.

1.3 Information from Third-Party Services

If you choose to connect third-party services to your Ride Cave account, we may receive information from those services. We may add support for additional third-party services in the future. Current integrations include:

  • Strava: If you connect your Strava account, we receive your Strava athlete ID and store OAuth tokens to enable activity synchronization. We do not access your Strava activity history; we only upload activities you explicitly choose to sync from Ride Cave.
  • Intervals.icu: If you connect your Intervals.icu account, we receive your athlete ID and may access your FTP, weight, and upcoming scheduled workouts. We store OAuth tokens or API keys to enable activity synchronization and calendar integration.
  • Discord: If you link your Discord account (available for subscribers), we receive your Discord user ID and username. This is used solely for assigning subscriber roles in our Discord community. We do not access your Discord messages or server data.
  • Other Fitness Platforms: We may integrate with additional fitness platforms and services (such as Garmin Connect, TrainingPeaks, or similar services). When you connect these services, we may receive authentication tokens, user identifiers, and fitness data necessary to enable synchronization features you request.

1.4 Group and Real-Time Data

When you participate in group sessions, the following data is collected and shared in real time with other group participants:

  • Live Performance Data: Your power output, heart rate, cadence, and breathing metrics (if a breathing sensor is connected) are broadcast to other participants approximately every 500 milliseconds during group sessions.
  • Profile Information: Your username, avatar, and subscription tier are visible to other group participants.
  • Voice Audio: If you use voice chat in groups, your audio is transmitted in real time through LiveKit, a third-party voice communication provider. We do not record or store voice conversations. Audio exists only during the live session and is not retained after the session ends.
  • Session Metadata: We record group session participation, including join/leave times, session duration, and activity status, for usage tracking and service improvement.

Real-time riding with others. Signed-in users can see and be seen by other riders in real time. This is on by default, and you can turn it off at any time in settings ("Enable real-time riding with others"); turning it off stops all real-time presence traffic from your device. Ride Cave is an indoor platform: the "position" these features share is your avatar's position along the virtual route you are riding, computed from the route's stored map geometry and your in-ride distance. It is not your physical location, which we never collect. When real-time riding is on:

  • Presence: While you ride, your device sends a small status update roughly every 30 seconds: the route you are on, whether you are riding or waiting, your distance along the route rounded to the nearest 500 meters, and your avatar's map coordinates on that route, deliberately coarsened to roughly 1 kilometer of precision. Because routes are built from real-world road data, these coordinates describe the real-world geography of the route being ridden, which may be anywhere on Earth, and, like route GPS data, may reflect places you have traveled or are interested in; they do not describe where you or your trainer physically are. Presence is visible only to your mutual follows (people you follow who also follow you back). It is held in memory at the network edge for up to 90 seconds and is never written to a database; this feature keeps no history of what you rode or when.
  • Shared roads (live route positions): Riders on the same virtual route see each other's live position on that route (distance along the route, speed, and lane), relayed under an anonymous, one-time session identifier created for each ride. Your name and avatar are shown to another rider only if you are mutual follows or your profile is public; otherwise you remain anonymous to them for the entire ride. Live positions exist only in memory during the ride and are never stored. Finish and lap times are held for about 30 minutes to power that session's live leaderboard, then discarded. Sessions are limited to 120 riders.
  • In-ride communications: Riders can send curated quick-messages (such as a wave or a cowbell). Adults (18 or older, verified from the date of birth on your profile) can also send short free-text messages (up to 140 characters). Free-text messages are filtered for profanity on our servers, delivered live for a few seconds, and never stored; we keep no chat logs. Users under 18, or whose age we cannot verify, cannot send free-text messages and are never shown other riders' free-text messages. A separate setting turns off in-ride communications entirely.

1.5 Guest Mode

You may use certain features of the Service without creating an account ("Guest Mode"). In Guest Mode, your data is stored locally in your browser using Local Storage and IndexedDB. This data is not transmitted to our servers and remains solely on your device. Clearing your browser data will permanently delete this information.

1.6 Garmin Connect Data

This section describes specifically how data obtained through Garmin Connect is collected, used, processed, stored, and shared. It applies only if you choose to connect your Garmin account.

  • What we collect: When you connect Garmin, we receive your Garmin user identifier and OAuth access tokens. If you enable ride import, Garmin notifies us when you complete a cycling activity on a Garmin device, and we download that activity's summary and FIT file to import your performance data (power, heart rate, cadence, speed, and similar metrics such as distance, duration, elevation, calories, normalized power, and timestamps). We do not retain the GPS/location track from imported activity files.
  • How we use it: We use Garmin activity data to import your rides into your Ride Cave history and to compute fitness analytics (such as normalized power, training load/TSS, training zones, energy-system and strain metrics, and peak power). If you use our training features, structured workouts and training plans you create in Ride Cave are sent to your Garmin Connect calendar and compatible Garmin devices at your request.
  • How we process and store it: FIT files are processed on our servers to compute the metrics above, and the results are stored as part of your ride history record. Your Garmin OAuth tokens are stored server-side in an isolated, access-restricted table; they are never exposed to other users or written to your public profile.
  • Third-party and AI processing: Garmin data is stored on our infrastructure providers, Supabase and Cloudflare. If you use Atlas, our AI coaching assistant, or our AI training-analysis features, your training history — which may include activities imported from Garmin — is processed by our AI provider, Anthropic, to generate coaching and analysis. We do not permit Anthropic to use this data to train its models. If you also connect other platforms such as Strava or Intervals.icu, activities you choose to sync — which may include Garmin-sourced rides — are shared with those platforms according to your instructions. We do not sell Garmin data or share it for advertising.
  • Retention and revocation: You can disconnect Garmin at any time in your Ride Cave settings, or revoke access from your Garmin account. When you disconnect or revoke access, we delete your stored Garmin OAuth tokens. Activities already imported into your history remain until you delete them individually or delete your account.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process and store your workout data and fitness metrics
  • Compute derived health and fitness analytics from your sensor data, including heart rate variability, PVC pattern detection, breathing efficiency, cardiac drift, and energy system metrics
  • Display your performance history, personal records, and aggregate statistics
  • Generate personalized training and nutrition estimates, such as fueling targets, from the profile, activity, and body-composition data you provide
  • Enable features such as leaderboards, public profiles, and user discovery (where you opt in)
  • Facilitate synchronization with third-party fitness platforms you connect
  • Enable real-time group sessions, including live performance data sharing and voice communication
  • Enable real-time riding with others, including presence sharing with your mutual follows, live positions on shared routes, and in-ride communications
  • Enable coaching, including a coach's access to and permitted edits of an athlete's training data at the athlete's request
  • Filter and moderate in-ride chat and enforce its age restrictions
  • Power AI features including Atlas coaching, workout generation, training plan creation, and training analysis
  • Verify age eligibility, restrict free-text chat to adults, and apply appropriate privacy protections for minors
  • Process subscription payments and manage your account tier
  • Analyze usage patterns to improve the Service and develop new features
  • Diagnose technical issues, including trainer device compatibility problems
  • Communicate with you about the Service, including updates and support
  • Protect against fraud, abuse, and unauthorized access
  • Comply with legal obligations

3. How We Share Your Information

3.1 We Do Not Sell Your Personal Data

We do not sell, rent, or trade your personal information or fitness data to third parties for their marketing purposes.

3.2 Information Shared Through Your Choices and Settings

  • Real-Time Presence: If real-time riding is enabled (it is on by default; you can turn it off at any time in settings), your riding status, current route, and your avatar's coarse position along that route are shared with your mutual follows while you ride. These are coordinates on the virtual route's map geometry, deliberately coarsened, and are not your physical location. Nobody other than your mutual follows can see your presence, and blocking a user permanently prevents them from seeing it.
  • Shared Roads: Riders on the same virtual route see your avatar's live position, speed, and lane during the ride. You appear to them anonymously unless you are mutual follows or your profile is public.
  • Public Profiles: If you enable a public profile, the information you choose to share — including your username, avatar, fitness statistics (FTP, watts per kilogram, ride count, total energy), ride history, custom workouts, starred workouts, and track records — becomes visible to other authenticated users. You control which categories are visible through granular privacy settings. Users under 18 are automatically restricted to private profiles.
  • Follow Relationships: If your profile is public, the list of users you follow may be visible to other users.
  • Group Sessions: When you join a group, your username, avatar, subscription tier, and live performance data are shared with other group participants for the duration of the session.
  • Third-Party Services: When you connect services like Strava or Intervals.icu, we share workout data with those services according to your instructions.

3.3 Coaching

Ride Cave lets one adult user act as a coach for another adult user (the "athlete"), with the athlete's consent. A coach is another Ride Cave user; a coach is not Cave Works, is not our employee or agent, and is not one of our service providers. Coaching is available only to users 18 or older, verified from the date of birth on each account.

A coaching relationship starts only when one person requests it and the other accepts. There is one active coach per athlete. Either party can end it at any time, which immediately cuts off the coach's access; blocking the other person also ends it.

While the relationship is active, a coach can see the following about an athlete they coach:

  • Training-load summaries and history.
  • Training plans, including planned-versus-completed adherence.
  • Training physiology, including FTP, body weight, W', peak power, lactate threshold heart rate (LTHR), maximum heart rate, and sex.
  • Recent rides as summaries and, on request, the full detail of an individual ride, including the performance streams such as power, heart rate, and cadence recorded during that ride.
  • Analytics reports the coach generates about the athlete using our Data Lab, which are computed on our own infrastructure and are not sent to our AI provider.
  • Because accepting a coach makes the two of you mutual followers, the athlete's profile and ride history the way any mutual follower can see them, even if the profile is otherwise private, subject to the athlete's own ride-history and record visibility settings.

We do not share location data with coaches. Rides in Ride Cave are ridden on virtual routes ("eRoutes") on an indoor trainer; we do not record where you physically are during a ride, and any route coordinates present in a ride's data are removed before a coach can view that ride.

We never share the following with a coach: your email address, date of birth, billing identifiers, or Discord ID.

A coach on a paid plan also has write access: from within the athlete's account, the coach can edit the athlete's training numbers (such as FTP and weight) and create, edit, activate, deactivate, and delete the athlete's training plans. These changes are recorded in a coach activity log on the athlete's account. A coach can also keep private notes and generate reports about the athlete.

We enable this sharing solely to let a coach the athlete has chosen provide coaching. We do not use coaching data for advertising, and we do not sell it.

Ending or revoking the coaching relationship, or blocking the other person, immediately stops the coach's access and removes the mutual-follow visibility. A coach's own notes and reports about the athlete are the coach's record and are retained after the relationship ends, until the coach deletes them or deletes their account; the athlete's own data follows the athlete's own retention and deletion choices.

3.4 Service Providers

We share information with third-party service providers who perform services on our behalf, including:

  • Supabase: Cloud hosting, database, authentication, and serverless functions
  • Cloudflare: Content delivery network (CDN), DNS, web hosting infrastructure, and the real-time edge network that powers riding with others. All traffic to the Service passes through Cloudflare's network. Presence updates, live in-ride position data (your avatar's position on the virtual route), and in-ride chat are processed in ephemeral memory on Cloudflare's edge infrastructure as described in Section 1.4, and aggregate operational metrics are recorded with Cloudflare's analytics.
  • OVH: Infrastructure hosting for our own route-calculation server. When you draw a route, the waypoint coordinates you place are sent to this server solely to compute the road path between them.
  • Stripe: Payment processing for subscriptions. Stripe receives payment details you provide directly to them during checkout.
  • Google Analytics: Aggregated usage analytics and traffic analysis
  • LiveKit: Real-time voice communication in group sessions. LiveKit processes audio data only during live sessions; audio is not recorded or stored.
  • Anthropic: AI model provider powering Atlas coaching features. When you use Atlas, your messages and any uploaded images are processed by Anthropic's AI models. Anthropic's use of this data is governed by their data usage policies. We do not permit Anthropic to use your data for model training.

These providers are contractually obligated to use your information only to provide services to us and in accordance with this Privacy Policy and applicable data protection laws.

3.5 Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process, such as a court order, subpoena, or government request. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

3.6 Business Transfers

If Cave Works LLC is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service of any change in ownership or uses of your personal information.

3.7 Map Services Your Browser Contacts Directly

Some map features load data directly from independent, community-operated services rather than through our servers. When a request goes to these services, they receive the request itself and, where your browser makes the request directly, your IP address, under their own privacy policies. They are not our service providers and are not under contract with us:

  • OpenFreeMap: Map tiles for the interactive map are fetched by your browser directly from OpenFreeMap, a community tile host. OpenFreeMap receives your IP address and, implicitly, the map areas you view.
  • Nominatim (OpenStreetMap Foundation): When you search for a place on the map ("fly to a location"), or when we look up a human-readable name for a generated route's start point, the search text or coordinates are sent to Nominatim, the OpenStreetMap Foundation's geocoding service.

We send these services only what is needed to answer the request, never your name, email address, or account identifiers.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you the Service. Specific retention periods include:

  • Workout history and fitness data: Retained indefinitely to enable features like personal records, historical analysis, and trend tracking, unless you request deletion.
  • Atlas conversations: Chat messages exist only during your active session and are cleared when you end or reset the session. Cached training analysis is refreshed after each new workout. Content you explicitly save as training notes is retained until you delete it.
  • Group session data: Session metadata (participation, timestamps) is retained for usage tracking. Real-time performance data and voice audio are not stored after the session ends.
  • Real-time riding data: Presence updates (route, riding status, coarse progress, and your avatar's coarsened position on the virtual route) live in ephemeral edge memory for up to 90 seconds and are never written to a database. Live route positions are never stored at all. Finish and lap times are held for about 30 minutes to power the session's live leaderboard, then discarded. In-ride chat messages are delivered live and are never stored anywhere; we keep no chat logs and cannot retrieve past messages. This feature is designed so that almost nothing about your ride with others is retained, and none of it involves your physical location, which we never collect.
  • Payment records: Subscription and billing records are retained as required for accounting and legal purposes.

If you request account deletion, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal, accounting, or other legitimate business purposes.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using HTTPS/TLS
  • Row-level security policies ensuring users can only access their own data
  • Secure OAuth 2.0 with PKCE for third-party service connections
  • Server-side storage of sensitive authentication tokens in isolated tables with restricted access
  • Database-level enforcement of privacy controls (e.g., automatic private profiles for minors)
  • A security-definer view layer that prevents direct access to sensitive profile fields

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

6. Your Rights and Choices

6.1 Account Information

You may update or correct your profile information at any time by accessing your account settings within the Service.

6.2 Profile Visibility

You control the visibility of your profile through privacy settings. You can toggle your profile between public and private, and independently control the visibility of your ride history, starred workouts, custom workouts, and track records. Users under 18 are automatically restricted to private profiles and cannot override this setting.

6.3 Data Export

You may export your workout data in standard fitness file formats (TCX, FIT) at any time through the Service.

6.4 Third-Party Connections

You may disconnect third-party services (such as Strava, Intervals.icu, or Discord) at any time through your account settings or through the third-party service directly. Disconnecting a service revokes our access to that service but does not delete data previously synchronized.

6.5 Account Deletion

You may request deletion of your account and all associated personal data by contacting us at https://ridecave.com/contact. Upon receiving a valid deletion request, we will delete your account and personal data within 30 days, subject to any legal retention requirements.

6.6 Analytics Opt-Out

You may opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

6.7 Real-Time Riding Controls

Real-time riding with others is on by default for signed-in users. You can turn it off at any time in settings, which stops all presence and live in-ride position sharing from your device. In-ride communications (quick-messages and chat) have their own toggle and can be turned off independently. You can also block another user at any time; blocking removes the follow relationship in both directions, so a blocked user can never see your presence.

7. Children's Privacy and Age Restrictions

7.1 Minimum Age

The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child under 13 has provided us with personal information, please contact us at https://ridecave.com/contact, and we will take steps to delete such information.

7.2 Protections for Users Ages 13–17

We apply additional privacy protections for users between the ages of 13 and 17:

  • Private profiles enforced: Minor users' profiles are automatically set to private and cannot be made public. Other users cannot view their ride history, fitness statistics, custom workouts, or other profile data beyond username and avatar.
  • Limited data exposure: Minors' data does not appear in user search results or public profile views.
  • Age-gated features: Features involving real-time interaction with other users, including real-time riding, Groups, and voice chat, require a verified date of birth. Users under 13 are blocked from these features entirely. Coaching between users is available only to users 18 years of age or older.
  • Chat protections: Users under 18 cannot send free-text messages in in-ride chat and are never shown free-text messages sent by other riders; they can use only the curated quick-messages we provide. If we cannot verify a user's age, we apply the same restrictions. Because minors' profiles can never be public, a minor riding on a shared road appears anonymous to every other rider except the minor's own mutual follows.

7.3 Date of Birth

We collect date of birth solely for age verification and applying appropriate privacy protections. Your date of birth is stored securely, is never displayed on your public profile, and is never shared with other users or third parties except as required by law.

8. International Data Transfers

Your information may be transferred to, stored, and processed in the United States or other countries where our service providers maintain facilities. By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules than your country.

9. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation. These rights include:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You may request correction of inaccurate or incomplete personal data.
  • Right to Erasure: You may request deletion of your personal data, subject to legal retention requirements.
  • Right to Restrict Processing: You may request that we limit how we use your personal data in certain circumstances.
  • Right to Data Portability: You may request your personal data in a structured, machine-readable format. You can also export your workout data in standard fitness file formats (TCX, FIT) directly through the Service.
  • Right to Object: You may object to processing of your personal data for certain purposes, including direct marketing.

We process your personal data on the following legal bases: (a) your consent; (b) performance of a contract (providing the Service); (c) our legitimate interests (improving the Service, preventing fraud); and (d) compliance with legal obligations.

Health Data: Certain data we collect and process — including heart rate variability, RR intervals, PVC detection results, breathing rate, tidal volume, and minute ventilation — may constitute "data concerning health" under Article 9 of the GDPR. We process this data based on your explicit consent, which you provide by voluntarily connecting health sensors to the Service and using health analytics features. You may withdraw consent at any time by disconnecting your sensors, at which point we will no longer collect new health data. Previously stored health data can be deleted by requesting account deletion.

Presence and In-Ride Position Data: If real-time riding with others is enabled (it is on by default; you can turn it off at any time in settings), we process your riding status, current route, and your avatar's position along the virtual route in ephemeral memory, to show your presence to your mutual follows and your live position to riders on the same route. This is activity data about your use of the Service: it describes where your avatar is on a virtual route, not where you are, and we never collect your device's location. We rely on our legitimate interest in providing the social riding features of the Service, balanced by the safeguards described in Section 1.4: coarsened route coordinates, visibility limited to mutual follows or riders on the same route, retention of at most 90 seconds in memory, no database storage, and a one-step opt-out. You may object to or stop this processing at any time by turning the setting off.

To exercise any of these rights, please contact us at https://ridecave.com/contact. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.

10. California Privacy Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Request correction of inaccurate personal information
  • Opt out of the sale or sharing of your personal information (note: we do not sell or share personal information for cross-context behavioral advertising)
  • Limit the use of sensitive personal information (note: we use sensitive personal information, including health-related data such as heart rate variability and breathing metrics, only as necessary to provide the Service and its health analytics features)
  • Non-discrimination for exercising your privacy rights

We do not collect precise geolocation, or any device geolocation at all. Coordinates used by real-time riding describe the virtual route's map geometry and your avatar's position on it, not your physical location.

To exercise these rights, please contact us at https://ridecave.com/contact.

11. Consumer Health Data

Some of the data we process, including heart rate, heart rate variability, RR intervals, PVC detection results, breathing rate, tidal volume, and minute ventilation, may be considered consumer health data under laws such as the Washington My Health My Data Act and Nevada's consumer health data law. For all users, regardless of where you live: we collect this data only when you choose to connect a compatible sensor and use the related features; we use it solely to provide the Service and its health and fitness analytics to you; we do not sell it; and we do not use it for advertising. You consent to this collection and use by connecting your sensors and using these features, and you may withdraw that consent by disconnecting your sensors and requesting deletion of previously stored data. To make a request about your consumer health data, contact us at https://ridecave.com/contact.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on the Service with a new "Last Updated" date. For significant changes, we may also notify you via email or an in-app notification. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Cave Works LLC
https://ridecave.com/contact

By using Ride Cave, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.