1. Who we are
Mappa Studio is operated by Sportschord Ltd. When we say “we”, “us”, or “our” in this policy we mean Sportschord Ltd. For any data-related questions, contact us at info@sportschord.com.
2. What data we collect
- Account information — email address and hashed password (if you register), or Strava profile name and athlete ID (if you connect Strava).
- Route data — GPX files you upload, or activity data imported from your Strava account (GPS coordinates, timestamps, elevation, distance, activity name).
- Design preferences — poster settings (colours, typography, layout) stored in your browser via localStorage.
- Order and payment data — shipping address, order details, and payment status. Card details are processed entirely by Stripe and never touch our servers.
- Usage analytics — anonymous page-view and performance data collected by Vercel Analytics and Vercel Speed Insights.
3. How we use your data
- To generate and display your poster designs.
- To process and fulfil print orders (via our print partner Prodigi).
- To process payments securely (via Stripe).
- To send transactional emails — order confirmations, shipping updates, and support replies (via Resend).
- To improve the product through anonymous analytics.
4. Why we process your data
Under GDPR, we rely on the following legal bases:
- Contract — we need your data to process your order and deliver the product you paid for.
- Legitimate interest — anonymous analytics help us improve the service.
- Consent — connecting Strava is optional and you can revoke it at any time.
5. Third-party services
We only share data with the services we need to run Mappa Studio:
- Stripe — payment processing. Subject to the Stripe Privacy Policy.
- Strava — activity data import (only when you connect your account). Subject to the Strava Privacy Policy.
- Prodigi — print fulfilment. We share your shipping address and poster file to produce and ship your order.
- Mapbox — map rendering. Mapbox may collect anonymised telemetry data.
- Resend — transactional email delivery.
- Vercel — hosting, anonymous analytics, and performance monitoring.
6. Strava data
When you connect Strava, we request read access to your activities. We import activity metadata (name, distance, elevation, date) and GPS coordinates to render your route on a poster. We don't keep raw Strava data beyond your active session and any orders you place. You can disconnect Strava at any time from your account, which immediately revokes our access.
7. Cookies and local storage
We use essential cookies to keep you logged in. We use browser localStorage to save your design preferences between visits. Vercel Analytics tracks page views without cookies.
8. Data retention
- Order data — retained for the duration required by applicable tax and accounting law (typically 6 years in the UK).
- Account data — retained while your account is active. You can request deletion at any time.
- Session cookies — expire after 30 days.
- Poster assets — temporary files are automatically purged within 24 hours of generation.
9. Your rights
Under GDPR and UK data protection law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Request erasure of your data (“right to be forgotten”).
- Export your data in a portable format.
- Withdraw consent (e.g., disconnect Strava).
- Lodge a complaint with the ICO (UK) or your local supervisory authority.
To exercise any of these rights, email info@sportschord.com.
10. Security
We use HTTPS everywhere, hash passwords with bcrypt, store sessions in httpOnly secure cookies, and never see or store your card details. Access to production systems is tightly restricted.
11. Changes to this policy
We may update this policy from time to time. If we make significant changes, we'll let you know on the website. Continued use of Mappa Studio after changes means you accept the updated policy.