TrailCompanionPrivacy Policy

Privacy Policy

In accordance with EU Regulation 2016/679 (GDPR) — Last updated: May 15, 2026

1. Data Controller

The data controller for personal data collected through https://trailcompanion.fr is:

Data controller
CAVELLINI Florian
SIRET
103 863 577 00013
Contact
florian@trailcompanion.fr

For any question about the protection of your personal data, contact us at florian@trailcompanion.fr.

2. Data Collected, Purposes and Legal Bases

TrailCompanion collects only the data strictly necessary to provide the service:

CategoryData processedPurposeLegal basis (GDPR)
Account dataEmail address, display nameAccount creation and management, authentication, transactional communicationsPerformance of a contract — Art. 6(1)(b) GDPR
Race prep dataRace plans, logistics notes, widget configurations, planning data created by the userProviding planning features, saving and syncing workspacesPerformance of a contract — Art. 6(1)(b) GDPR
Usage & analytics dataPage views, site navigation, marketing events triggered after consent (PostHog analytics)Audience measurement, product improvement, conversion trackingConsent — Art. 6(1)(a) GDPR
Payment & subscription dataStripe Customer ID, subscription status — TrailCompanion does not store payment card numbersSubscription management, access activation, billingPerformance of contract + legal obligation — Art. 6(1)(b) and 6(1)(c) GDPR

3. Cookies and Trackers

TrailCompanion uses the following categories of cookies:

CategoryToolPurposeConsent required
Strictly necessaryInternal session cookieUser authentication, session managementNo (essential to service)
AnalyticsPostHogAudience measurement, product improvementYes (consent banner)

No advertising cookies. TrailCompanion does not use cookies for targeted advertising. Analytics cookies are only activated after the user grants explicit consent via the cookie banner.

4. Data Retention

Account data
For the duration of the account + 3 years after deletion request
Race prep data
For the duration of the account, deleted upon account closure
Analytics data (PostHog)
13 months maximum, then automatically deleted
Payment data (Stripe reference)
10 years (French accounting obligations)

5. Data Recipients and Sub-processors

TrailCompanion does not sell personal data to third parties. The following sub-processors may process data solely on our behalf:

Vercel Inc.
Web application hosting — USA (EU SCCs in place)
Railway Corp.
Database hosting — USA (EU SCCs in place)
Stripe Payments Europe Ltd
Payment processing — Dublin, Ireland (EU)
OpenAI OpCo, LLC
AI language model powering the planning assistant — USA (EU SCCs in place)
PostHog Inc.
Product analytics — USA/EU (EU SCCs in place)

6. International Transfers

Some sub-processors are based outside the European Economic Area (EEA). In all such cases, personal data is transferred under appropriate safeguards — specifically Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46 GDPR.

7. Your Rights

Under GDPR, you have the following rights with regard to your personal data:

  • Right of access — you can request a copy of the personal data we hold about you.
  • Right to rectification — you can ask us to correct inaccurate or incomplete data.
  • Right to erasure — you can request deletion of your account and associated personal data, subject to legal retention obligations.
  • Right to data portability — you can request an export of the personal data you provided to us.
  • Right to restriction — you can ask us to temporarily restrict processing while a dispute is resolved.
  • Right to object — you can object to processing based on legitimate interest.
  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, send an email to florian@trailcompanion.fr. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés, France's data protection authority) at www.cnil.fr.

8. Security

TrailCompanion implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Measures include HTTPS encryption, access control, and regular security reviews of the infrastructure.

9. Contact

For any data protection request or question: florian@trailcompanion.fr