1. Who is responsible
Wind Ride is a personal, non-commercial project run by one person in their spare time in the Netherlands. It is not a company. Under the GDPR that person is the data controller:
- Controller: Andrea Leandri
- Contact: [email protected]
- Country: the Netherlands. Dutch law applies, and the service runs on a server in the EU.
There is no data protection officer. For a project this size the law does not require one, and the email address above reaches the only person who could answer anyway.
2. What this covers
The website at windride.win and the Wind Ride apps for Android and iOS, which are the same thing: each app is a wrapper that opens this website full-screen. There is no separate app database, and nothing is collected on the phone that the website does not already collect. See sections 10 and 11.
3. What is recorded, and why
Your account
Created when you sign up, kept until you delete it:
- Your username and email address. The email is what verifies the account and what lets you reset a forgotten password.
- A hash of your password — never the password itself. Nobody, including the person running this, can read it back.
- The date the account was created, and whether the email has been verified.
- Your preferences: display language, profile icon, routing engine, whether the intro film plays, which one-time on-screen hints you have already seen, and whether you agreed to be emailed about updates.
- Your answer to “how did you hear about Wind Ride”, if you gave one. It is optional and skippable.
- The IP address, country and city you signed up from, recorded once at sign-up. This is a spam and abuse check — it is how a wave of throwaway accounts from one place becomes visible. It is not updated afterwards, and your later sessions are not geolocated.
Short-lived verification and password-reset codes are stored alongside the account until they are used or expire.
Your rides
When you download a GPX, a record of that ride is saved so it can appear under GPX download later: the route line itself, the distance, the estimated time, a wind score, the wind at the time you planned it, the name of the start point, and which mode generated it.
The route line is location data about you — it usually starts where you are, or where you intend to start. It is treated that way. It is visible only to you when signed in, unless you deliberately switch on a share link (section 9), and it is deleted with your account.
The technical log
Every route generation, sign-in, sign-up, account change, export and contact message appends one line to a technical log. Each line holds the time, what happened, the username it happened under, and the settings involved — distance, cruising speed, difficulty, departure time, which avoidances were on, the wind strategy, and how long the work took.
This is what makes it possible to tell a capacity problem from a bug, and to see which settings riders actually use. It does not contain coordinates — no start point, no route line, nothing that says where you rode. When you send a message through Get in touch, the log records the subject and how many characters the message was, not the message itself.
Cookies
Two, both strictly functional. There is no consent banner because there is nothing here that needs consent.
- A session cookie, set when you sign in, which keeps you signed in for up to 90 days. It is signed, HttpOnly, and only ever sent over HTTPS.
wr_intro, which remembers that you asked not to see the intro film. It holds the word “off” and nothing else.
4. What is never recorded
No analytics. No advertising. No tracking pixels, no fingerprinting, no third-party cookies, no Google Analytics, no Meta pixel, no cross-site profile of you anywhere.
No payment details — donations go through an external service that is never told which account you are.
Nothing is sold, rented, or handed to a data broker, under any circumstances. There is no business model here that could make that tempting.
5. Who else sees it
A handful of services are involved in making the site work. They fall into two groups, and the difference matters: some are asked by the Wind Ride server on your behalf, so they never learn anything about you; others are asked by your browser directly, which means they see your IP address.
Asked by the server — these never see you
- Open-Meteo (wind and weather forecasts) receives coordinates along a candidate route, requested by the Wind Ride server. It does not receive your IP address, your username, or anything that connects a route to a person.
- BRouter (road routing) runs on the same server. Nothing leaves the machine.
- Resend or Gmail SMTP, whichever is configured, deliver the verification, password-reset and notification emails. They handle your email address, because that is what delivering an email means.
Asked by your browser — these see your IP address
- Cloudflare sits in front of every request as the connection’s entry point, and passes on a country and city derived from your IP address.
- Map tile providers, depending on which base map you pick: CARTO, the OpenStreetMap Foundation, OpenStreetMap France (CyclOSM) and Thunderforest (OpenCycleMap). Each sees your IP address and which map squares you looked at, which is a rough indication of where you were looking.
- Google Fonts serves the two typefaces the site is set in, and therefore sees your IP address when the page loads.
Hosting: the server is a Hetzner machine in the EU. Hetzner can technically reach the disk it runs on, as any host can.
6. Why it is allowed to be recorded
- Your account, your rides, the site working at all — necessary to provide the service you asked for (GDPR Article 6(1)(b)).
- The technical log, the sign-up IP, the lockout after three wrong passwords — legitimate interest in keeping a free service running and not abused (Article 6(1)(f)).
- Emails about updates, or asking what you make of it — consent, and only consent (Article 6(1)(a)). The box on the sign-up form is unticked, you have to tick it yourself, and you can untick it later in the account menu without giving a reason.
Verification and password-reset emails are not in that last group: they are part of the account working, so they are sent whether or not you agreed to anything else.
7. How long it is kept
- Your account and your rides — until you delete the account. Then they are gone immediately, not queued or archived.
- An account that is never verified — deleted automatically after 7 days, along with its codes.
- Verification and reset codes — minutes, then they expire.
- The technical log — 12 months. Anything older than that is deleted automatically by the service itself, rather than by someone remembering to do it. Inside those 12 months it is an append-only file, so lines written before you deleted your account keep the username they were written under. That is the one thing account deletion does not reach, and it is called out here rather than buried — but it ages out like everything else.
- The session cookie — 90 days, or until you sign out.
wr_intro— 5 years, or until you clear your browser data.
8. Your rights
Under the GDPR you can ask for any of the following, and they cost nothing:
- A copy of your data (access), and a machine-readable copy to take elsewhere (portability).
- A correction of anything wrong. Username, email and password are editable yourself in the account menu.
- Deletion. There is a delete button in the account menu that does it immediately and irreversibly, with the one exception in section 7. You can also just email and ask. Step by step, and exactly what goes.
- To object to the processing done on legitimate interests, or to withdraw consent to update emails at any time.
- Restriction of processing while a dispute is sorted out.
Email [email protected]. You will get an answer within a month, usually within a day or two.
If you are not happy with that answer, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
9. Share links
A ride is private to your account unless you switch on a share link for it, which is off by default and per-ride.
Once it is on, anyone holding that link can see the ride without signing in. The card shows the shape of the route and the numbers — it never shows your name, your username or your email address. Switching the link off breaks it permanently; it cannot be switched back on as the same link.
10. The Android app
The Wind Ride app in the Google Play Store is a wrapper: it opens windride.win full-screen using the browser engine already on your phone. Everything above applies to it unchanged, and these are the only additions:
- Location. If you tap the locate button, the app asks Android for your position and uses it to place the start point on the map. It is used at that moment and not stored — unless it becomes the start of a route you then download, in which case it is in that ride’s record like any other start point. There is no background location and no tracking while you ride. You can refuse the permission and everything else still works.
- Google Play. Google records the install itself, and any crash reports your phone is set to send. That is between you, your phone and Google — Wind Ride does not receive it, and there is no analytics SDK in the app.
11. The iOS app
The Wind Ride app in the App Store is a wrapper, like the Android one: it opens windride.win full-screen using the browser engine already on your phone. Everything above applies to it unchanged, and these are the only additions:
- Location. If you tap the locate button, the app asks iOS for your position and uses it to place the start point on the map. It is used at that moment and not stored — unless it becomes the start of a route you then download, in which case it is in that ride’s record like any other start point. There is no background location and no tracking while you ride. You can refuse the permission and everything else still works.
- Files. A route you download is written into the app’s own folder on your phone, where the Files app can find it under Wind Ride. It stays on the device. Sharing one hands it to whichever app you pick — Garmin Connect, Komoot, Messages — and what happens to it then is between you and that app.
- Notifications. If you ask to be told when the wind suits a route, your phone gives the app a device token and the app sends it here, so the server can address a message to that install. Apple delivers the message, which means Apple sees the token and the fact that something was sent. The text is the ride’s name and what the wind is doing. Turn the schedule off, or notifications off in iOS Settings, and the token stops being used.
- The App Store. Apple records the install itself, and any crash reports your phone is set to send. That is between you, your phone and Apple — Wind Ride does not receive it, and there is no analytics SDK in the app.
12. Children
Wind Ride is not aimed at children and is not designed for them. Accounts are not knowingly created for anyone under 16. If you believe a child has made an account, email and it will be removed.
13. Changes to this policy
This page may change as the service does. The date at the top says when it last did, and material changes are noted in the release notes. If a change ever meant doing something genuinely new with your data, you would be asked rather than informed.
Questions about any of it: [email protected].