Garmin data policy

Authorized cycling data, used only for visible rider features.

This policy describes how VELO plans to process cycling activity data through the Garmin Connect Developer Program. Garmin sync is still in the application and development stage and is not available to users.

Effective: 29 July 2026 Version 1.0 Region: Mainland China

1. Authorization

VELO will connect to Garmin Connect only through Garmin's official OAuth 2.0 authorization flow. VELO will not ask for or store a Garmin username, password, or verification code, and will not obtain data through web scraping or unofficial login methods.

Users can review the requested data scope on Garmin's authorization page. VELO will not retrieve an activity until the user has completed explicit authorization.

2. Data scope

Version 1 requests cycling activity summaries, authorized activity files, and the minimum Garmin user and activity identifiers required for account linking and idempotency.

Version 1 does not request health, sleep, women's health, training plan, or course-write access.

3. Purposes

  • create a Garmin cycling activity under the user's VELO account;
  • show personal ride history, tracks, and activity summaries;
  • match road-cycling segments and calculate personal results;
  • show power, heart rate, cadence, and training metrics only when present;
  • process authorized backfill and new-activity notifications;
  • handle duplicate notifications, retries, disconnect, and deletion.

Garmin data is not used for credit, insurance, employment, advertising profiles, or purposes unrelated to the user's authorization.

4. Publication and external sharing

Garmin-imported activities are planned to be private by default. A user may choose to publish a summary inside VELO and may separately hide power or heart-rate fields.

A user-initiated static share card may contain selected activity summary fields and Garmin source attribution. VELO does not provide raw FIT files, OAuth tokens, or machine-readable Garmin data to WeChat or another platform.

VELO does not sell or rent Garmin data, and other VELO users cannot download a user's raw Garmin activity file.

5. Processing and storage location

Garmin data for the Mainland China version of VELO is processed and stored in Mainland China, primarily in Tencent Cloud's Guangzhou region. VELO does not send Garmin activity data to third parties outside Mainland China.

Access and refresh tokens will be encrypted at rest before production access is made available and will not appear in public APIs, web pages, reports, or application logs.

6. Retention, disconnect, and deletion

  • raw Garmin FIT files are retained for no more than 30 days after successful parsing;
  • structured activities remain while the VELO account is active, until deleted by the user;
  • OAuth tokens are deleted from the primary database immediately after disconnect;
  • disconnecting stops all new Garmin sync;
  • historical activities can be retained or deleted by the user;
  • operational backups expire within 30 days;
  • closing a VELO account deletes personal account, ride, track, and authorization data.

7. AI and model-training boundary

VELO does not send Garmin activities, tracks, sensor data, or user identifiers to an external AI or LLM service. Garmin data is not used to train an internal or external machine-learning model.

If VELO later introduces automated processing involving Garmin data, we will first update this policy, explain the processing logic, and obtain separate consent where required.

8. User rights

Users may view connection status, withdraw authorization, disconnect Garmin, stop new sync, delete imported activities, request access, correction, a copy or transfer of personal information, close their VELO account, or raise a question or complaint about data processing.

9. Security and incidents

VELO uses transport encryption, access control, least privilege, notification idempotency, failure isolation, and expiring backups. Before launch, we will validate authorization, backfill, new-activity notification, duplicate delivery, token refresh, disconnect, deletion, and reauthorization on a real Garmin path.

If a security incident affects Garmin data, VELO will take remedial, notification, and cooperation measures required by applicable law and the Garmin developer agreement.

10. Contact

Controller: 湖南湘江新区共演纪软件开发有限责任公司

Email: chengyuxiang@synexissoftware.cn

Garmin and Garmin Connect are products or services of Garmin and its affiliates. VELO is independently operated and does not claim endorsement by Garmin.