Privacy policy

Your ride data should stay under your control.

This policy explains how VELO processes account information, activity files, routes, sensor data, and third-party authorization information.

Effective: 29 July 2026 Version 1.0 Operator: 湖南湘江新区共演纪软件开发有限责任公司

1. Controller and scope

VELO is operated by 湖南湘江新区共演纪软件开发有限责任公司. This policy applies to the VELO WeChat Mini Program, official website, ride history, route, segment, and data-sync services.

Garmin-specific processing is described in the Garmin Data Policy.

Third-party services have their own privacy policies. Users should also review those policies when leaving VELO for a third-party service.

2. Information we process

  • WeChat OpenID, nickname, and avatar for account access;
  • optional rider profile fields such as city, bike type, FTP, weight, and heart-rate settings;
  • FIT/GPX files, timestamps, distance, speed, elevation, power, heart rate, and cadence;
  • GPS track points and simplified routes for maps and segment matching;
  • third-party identifiers, OAuth tokens, and authorization status when a user connects a platform;
  • limited operational logs required for security and troubleshooting.

Optional fields such as FTP, weight, and year of birth may be left blank. VELO does not invent values when those fields are absent.

3. Why we use information

  • create and maintain a VELO account;
  • parse rides and show route and performance information;
  • match road-cycling segments and calculate personal results;
  • save and export user-created route books;
  • apply user visibility, power, and heart-rate privacy choices;
  • process disconnect, deletion, account closure, and data-rights requests;
  • secure, maintain, and troubleshoot the service.

VELO does not sell ride tracks for advertising profiles and does not provide third-party synchronized ride data to an external AI or large language model for training.

4. Sharing and publication

Users can make an activity private and hide power or heart-rate fields. Garmin-imported rides are planned to be private by default and published only after a user action.

We do not sell ride tracks or OAuth tokens. Production infrastructure and backups are hosted in Tencent Cloud's Guangzhou region in Mainland China. Garmin activity data is not provided to external AI or LLM services.

  • we do not sell or rent ride tracks or third-party authorization tokens;
  • we do not provide machine-readable raw Garmin data to another platform;
  • we do not automatically publish Garmin-imported activities without user consent;
  • we do not send Garmin activity data to third parties outside Mainland China.

We may provide information within the legally required scope when required by applicable law or a competent judicial or administrative authority.

5. Storage and retention

  • production data is processed and stored in Mainland China;
  • accounts and ride history are kept while the account remains active, unless deleted earlier;
  • OAuth tokens are deleted when the user disconnects the third-party service;
  • operational backups expire within 30 days;
  • raw Garmin activity files are retained for no more than 30 days after successful parsing;
  • longer retention applies where required by law.

Manually uploaded FIT/GPX files and automatically synchronized Garmin files follow different rules. When an activity or account is deleted, VELO attempts to delete its manually uploaded file at the same time. A storage failure may leave a residual file until VELO manually reviews and deletes it; the file will no longer be used to provide the service. Users may email us to request that review and deletion.

6. User rights

Users may request:

  • access to, correction of, or supplementation of profile information;
  • deletion of an individual ride and its track;
  • withdrawal of third-party authorization and termination of future sync;
  • a copy or transfer of personal information;
  • account closure and deletion or de-identification of associated personal data;
  • an explanation of VELO's personal-information processing rules.

Account closure is irreversible. Personal account data, rides, tracks, segment results, and third-party tokens are deleted through the product's confirmation flow. To preserve the integrity of content already shared with the community, route books and published meetup content, meeting points, descriptions, and media may remain after association with the account is removed. This content may still contain information the user supplied or uploaded. Before closing an account, users may delete or edit content for which the product provides self-service controls. For published meetups and other content without such controls, users may email us to request review and deletion.

7. Security and incidents

VELO uses HTTPS, access control, least privilege, logging, and backup isolation. Third-party tokens must not appear in public APIs, web pages, or application logs. Garmin tokens will be encrypted at rest before production access is made available.

If a security incident may affect user rights, VELO will take remedial measures required by law and notify affected users, where practicable, through the product or available contact channels.

8. Children

VELO is designed for adult road cyclists and is not intentionally offered to children under 14. If VELO learns that a child's personal information was processed without guardian consent, it will delete that information promptly.

9. Policy changes

Material changes will update the effective date on this page and, where appropriate, be presented in the product for consent. If a new processing purpose is not directly or reasonably related to the original authorization, VELO will obtain new consent.

10. Contact

Controller: 湖南湘江新区共演纪软件开发有限责任公司

Email: chengyuxiang@synexissoftware.cn

VELO will verify that a requester is connected to the relevant account and respond within the period required by law. Only information necessary for identity and account verification will be requested.