Privacy Policy

We collect only the data needed to operate the platform and process payments. We never sell your data, and we provide clear controls for club admins and members. This policy applies under the Australian Privacy Act 1988 and, where applicable, the European General Data Protection Regulation (GDPR).

Last updated: February 10, 2026

Overview

This policy explains what data we collect, how we use it, and the choices you have. Catalystr is operated by Matthieu Rouillac (ABN 57661015177), a sole trader registered in Australia.

Data We Collect

We collect account data, club data, payment metadata, and usage telemetry needed to provide the service.

  • Account details such as email, name, and profile information.
  • Club configuration, member roles, and membership status.
  • Payment-related metadata from Stripe (no raw card data).
  • Usage and diagnostic data to improve reliability.

How We Use Data

We use your data for the following purposes:

  • Operating the platform and delivering its features.
  • Securing accounts and detecting abuse.
  • Processing payments and managing subscriptions.
  • Improving the service and developing new features.

Third-Party Services

We share data with service providers only as needed to deliver the service.

  • Stripe for payment processing and identity verification.
  • Supabase for authentication, database, and file storage.
  • Mapbox for route and map display (anonymized usage).

Strava Data

If you connect your Strava account, we access activity data to power challenges and leaderboards.

  • We import activity summaries (type, distance, elevation, time) — not raw GPS tracks.
  • You can disconnect your Strava account at any time from your profile settings.

Security

We apply access controls, encryption in transit (TLS), row-level security on our database, and least-privilege practices to protect your data.

Data Retention

We retain your data for as long as your account is active. When you delete your account, personal data is removed within 30 days. Anonymized usage data may be retained for analytics.

International Transfers

Our infrastructure is hosted in the United States (Vercel) and Singapore (Supabase). By using the service, you consent to the transfer of data to these regions. We ensure adequate protections through our service providers' security practices.

Your Rights

Under the Australian Privacy Act and GDPR (where applicable), you have the following rights:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (right to erasure).
  • Export your data in a portable format.

Cookies

We use cookies for authentication and session management. See our Cookie Policy for details.

Children's Privacy

Catalystr is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.

Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email or an in-app notice. Continued use of the service after changes constitutes acceptance.

Contact

For privacy questions, contact support@catalystr.com.