Privacy Policy

Effective: September 2026

TrackList connects your Strava runs with your Spotify listening history to create visual run records. This policy explains exactly what data we collect, why we need it, and how we protect it. We've written it in plain English — no legal maze.

What we collect

Your account (via Strava)

Strava activity data

Spotify listening history

Last.fm scrobble history

Generated posters


Why we collect it

Everything we collect serves one purpose: matching the songs you listened to with the runs you recorded, and generating a poster that visualises both.

We also measure product usage to understand signup, connection, and poster-generation failures. We do not sell analytics data or collect it for advertising.


How your data is stored

Your data is stored in a PostgreSQL database hosted on Neon (a managed Postgres service), running on Vercel's infrastructure in the United States.


Third-party services we rely on

PostHog processes product analytics: page visits, campaign tags, referring domains, signup and connection outcomes, poster actions, and Premium outcomes. We associate these events with a pseudonymous identifier derived from your internal account ID. We do not send names, emails, provider account IDs, OAuth credentials, activity details, routes, or listening history to PostHog. Session recording and automatic interaction capture are disabled.

We do not share your data with ad networks or data brokers.


What we don't do

We do not sell or license your data. The service providers described above process data to operate TrackList. We do not use your data to train machine learning or AI models. We do not serve ads.


Cookies and local storage

TrackList does not use advertising cookies. PostHog uses browser storage and cookies to associate visits and campaign attribution with subsequent product usage and your pseudonymous account identifier.

We store your session token (a JWT) in your browser's localStorage so you stay logged in between visits. This token is scoped to TrackList only and is not readable by other websites.

You can clear this at any time by logging out of the app or clearing your browser's site data for this domain.


Your data, your rights

You can request deletion of your account and all associated data at any time by emailing us. We'll process your request and confirm deletion within 30 days.

You can also revoke TrackList's access to Strava or Spotify at any time through each service's connected apps settings:

Revoking access in those settings will prevent TrackList from fetching new data, but won't automatically delete existing data from our database — contact us to request full deletion.


Changes to this policy

If we make material changes to this policy, we'll update the date at the top. For significant changes, we'll do our best to notify you via the app. Continued use of TrackList after changes take effect constitutes acceptance of the updated policy.


Contact

Questions, deletion requests, or anything else about your privacy:

privacy@tracklist.run