Legal

Privacy policy

Last updated: 11 October 2026 · Version 1.1

This policy explains how XLC Studio uses your personal data when you take part in a challenge we run, such as the Advent Challenge. We collect only what a challenge needs.

1. Who we are

The data controller is XLC Studio, run by Xavier Cook as a sole trader in the UK. If we become a limited company, we will update this policy.

We are responsible for your data under UK GDPR and the Data Protection Act 2018.

2. What we collect

  • Email address: to identify your entry and send your reward code.
  • Strava athlete ID: if you connect Strava, to link your account to your entry.
  • Strava activity details: distance, sport type, date and whether it was entered manually. Nothing else is used.
  • Uploaded activity files: if you upload a file instead.
  • Challenge records: days completed, dates, milestones and reward codes.
  • Consent record: when you agreed, which policy version, and whether you agreed to share with the brand or opted in to marketing.

3. Why we use it

We use your data only to check your challenge days, issue reward codes, and share your completion with the brand running the challenge so it can give you your reward (see section 6). We do not use it for advertising or profiling.

4. Lawful basis

We rely on your consent (UK GDPR Article 6(1)(a)), given in separate steps:

  • when you join, to check your days and issue codes;
  • when you connect Strava;
  • sharing with the brand: a separate tick box naming the brand, for example “Share my name/email and completion status with Mile Pie” (exact wording follows the challenge); and
  • marketing (optional): a separate, unticked box. You can take part without it.

We record each consent with its date and policy version. You can withdraw consent at any time (section 9). That does not affect earlier processing, but we can no longer check your challenge days.

5. Strava

If you connect Strava, you authorise access on Strava. Strava has its own privacy policy, which we do not control.

  • Your Strava data is shown only to you. When available, Strava is used only to confirm your own runs, and brands never receive Strava details. For now, completion is confirmed from runs you upload.
  • We read only the fields in section 2.
  • Access tokens are stored encrypted on our servers.
  • If you revoke access, we stop reading your data and delete what we hold.

6. Brands

Challenges are run on behalf of brands. With your consent, we share your completion with the brand, never your running data.

The brand receives only:

  • a participant identifier (name or email, or just a reward code, depending on the challenge);
  • the challenge you completed, with the date and any milestones; and
  • your reward code.

It receives nothing from your activities: no runs, routes, files or Strava details.

Once the brand has the list, it is the controller of that copy. It may use it only to provide your reward, unless you separately opted in to its marketing. We never sell your data. If you don’t tick the sharing box, we can’t pass your details on and you may not get the reward.

7. How long we keep it

DataRetention
Strava activity data (distance, sport type, date, manual flag)Cached for up to 7 days, then deleted. Only the daily completion flag is kept.
Uploaded activity filesDeleted 2 days after review. Only the completion flag is kept.
Completion flags and reward code recordsUntil the campaign ends, then deleted.
Email, Strava athlete ID, consent recordUntil the campaign ends, then deleted.
Brand’s copy of the completion listUntil the promotion ends plus 90 days, so the brand can honour rewards and answer queries. It must then delete it.

If you ask us to delete your data, we will also ask the brand to delete what we passed it. We keep only a minimal record that we handled the request.

8. Who processes data for us

Our service providers (processors) act only on our instructions:

  • Netlify: website hosting and serverless functions.
  • Supabase: database and file storage.

Where providers process data outside the UK, transfers are covered by safeguards such as the UK International Data Transfer Addendum.

9. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erasure: we delete your data within 30 days and confirm by email;
  • withdraw consent at any time;
  • restrict or object to processing, and data portability;
  • complain to the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint or 0303 123 1113. Please contact us first so we can try to put things right.

To exercise any right, email XavierLeCreative@gmail.com.

10. How to disconnect Strava and request deletion

Disconnect Strava

  • On strava.com, go to Settings → My Apps and choose Revoke Access; or
  • use “Disconnect Strava” on your challenge page, where available.

We then stop reading your activities and delete the Strava data we hold.

Request deletion of everything

Email XavierLeCreative@gmail.com from your sign-up address with the subject “Delete my data”. We will delete your data within 30 days and confirm.

11. Minimum age

You must be 16 or over. We do not knowingly collect data from under-16s. If you think one has signed up, tell us and we will delete their data.

12. Security

We use encryption in transit, encrypted token storage and database access controls, and collect as little as possible.

13. Cookies

We don’t use advertising or analytics cookies. A challenge page may use a necessary cookie or local storage to keep you signed in.

14. Changes

If we change how we use your data, we will update the version and date above and ask for consent again where needed.