Legal
Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Activity Frame("we", "us", or "our") handles personal data when you use activityframe.com, the webapp, and the related TRMNL plugin that displays Strava activity stats on an e-ink device. By using the Service, you acknowledge this Policy. For product rules, see our Terms of Service.
This document describes our product practices in plain language. It is not formal legal advice.
1. Who we are
Activity Frame is operated as a product reachable at activityframe.com. For privacy questions or data-subject requests, contact support@drproduct.nl. We act as the controller of personal data we process to provide your Activity Frame account and display configuration.
2. Scope
This Policy covers:
- The marketing site and authenticated webapp at activityframe.com
- Account creation and sign-in (email/password and Google Sign-In)
- Strava OAuth connection and activity data used for configured screens
- TRMNL plugin install, linking, and device polling of your display markup
It does not govern Strava, TRMNL, Google, or other third-party products. Their own policies apply when you use those services.
3. Data we collect
Depending on how you use the Service, we may process:
- Account data: email address, optional display name, password credentials (hashed by our auth provider), and authentication identifiers.
- Google Sign-In data: basic profile information Google returns for authentication (typically email and name/avatar identifiers), used to create or sign in to your account.
- Strava connection data: Strava athlete identifier, OAuth access and refresh tokens, token expiry, and activity or athlete stats needed to render the screens you enable (for example distance, elevation, dates, and similar display fields).
- TRMNL / device data: plugin or install identifiers, link status, screen configuration, and secrets used in polling URLs so TRMNL can refresh your device.
- Usage and technical data: basic product events needed for security, rate limiting, troubleshooting, and reliable delivery (such as request metadata and error logs).
We aim to process only what is needed to run the Service. We do not ask for payment card data in the current product.
4. How we use data
We use personal data to:
- Create and secure your account and sessions
- Connect and maintain Strava and TRMNL integrations you authorize
- Generate and serve the display screens you configure
- Respond to support requests and investigate abuse or outages
- Improve reliability and protect the Service against misuse
- Comply with legal obligations where applicable
We do not sell your personal information. We do not use Google or Strava user data for advertising or cross-context behavioral ads.
5. Legal bases (EEA/UK)
Where GDPR or UK GDPR applies, we typically rely on:
- Contract: processing needed to provide the Service you request (account, connections, screen rendering).
- Legitimate interests: securing the Service, preventing abuse, and basic operational analytics that do not override your rights.
- Consent: where required for optional connections or similar choices (for example authorizing Strava or Google).
- Legal obligation: when we must retain or disclose data to comply with law.
6. Strava data
When you connect Strava, you authorize Activity Frame to access Strava data under the scopes requested in the OAuth consent screen. We use that data only to power your configured screens and related account features. Activity data obtained via Strava is intended for display to you (and on your linked TRMNL device), not for public social feeds or other athletes.
Your use of Strava remains subject to Strava's Terms and Privacy Policy. If this Policy conflicts with Strava's Privacy Policy regarding Strava data, Strava's Privacy Policy controls for that conflict. You can disconnect Strava in the webapp; after disconnect we stop using Strava tokens for new sync and clear stored Strava credentials as implemented in the product.
7. Google Sign-In
If you choose "Sign up / Continue with Google," Google authenticates you and shares limited account information with us (such as email) so we can create or recognize your Activity Frameaccount. We use Google user data only for authentication and account administration as described here. We do not sell Google user data or use it for personalized advertising. You can review Google's policies in your Google Account settings and revoke app access there at any time.
8. Third parties and subprocessors
We use trusted providers to operate the Service. They process data only as needed to provide their services to us:
- Supabase — authentication, database, and related backend infrastructure (project hosted in the EU region we configure).
- Vercel — application hosting and edge delivery for activityframe.com.
- Google — optional Sign-In / OAuth identity provider.
- Strava — activity source you connect; Strava processes data under its own terms when you use Strava.
- TRMNL — device platform that polls your configured endpoint to refresh e-ink screens; TRMNL processes data under its own terms.
We may also disclose data if required by law, to protect rights and safety, or in connection with a business transfer, subject to appropriate safeguards.
9. International transfers
Our primary application database is configured in the European Union (eu-central-1). Some providers (for example Google authentication or global hosting/CDN components) may process data in other countries, including the United States. Where required, we rely on appropriate transfer mechanisms and vendor terms. By using the Service you understand that processing may occur in countries with different data-protection rules than your home country.
10. Retention and deletion
We retain personal data for as long as your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. You can disconnect Strava or TRMNL from the webapp. To request account deletion or a copy of your data, email support@drproduct.nl. We will respond within a reasonable period and as required by applicable law. Some logs or records may be retained for a limited time for security or legal reasons.
11. Security
We use commercially reasonable administrative and technical measures to protect personal data, including encrypted transport (HTTPS), access controls, and treating TRMNL polling URLs or secrets as credentials. No method of transmission or storage is perfectly secure. Do not share polling URLs, API secrets, or account credentials publicly.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. You may also withdraw consent where processing is consent-based, without affecting prior lawful processing. To exercise rights, contact support@drproduct.nl. You may lodge a complaint with your local supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
13. Cookies and local storage
We use cookies and similar technologies as needed for authentication, session continuity, and security. We do not use third-party advertising cookies as part of the core Activity Frame product experience described here. Your browser settings may allow you to block cookies; some features (including sign-in) may not work if essential cookies are disabled.
A short cookie notice may appear on first visit. If you accept it, we store a local preference in your browser (localStorage) so we do not show the notice again.
14. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
15. No sale of personal information
We do not sell personal information and do not share it for cross-context behavioral advertising. If that changes, we will update this Policy and provide any required opt-out mechanisms.
16. Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last updated" date. For material changes, we may provide additional notice (for example in the product or by email). Continued use after the effective date means you acknowledge the updated Policy.
17. Contact
Privacy questions and data requests: support@drproduct.nl.
Related: Terms of Service.