ScratlasVirtual Passport
Scratlas

Privacy

Effective date: 2026-08-11

Who operates Scratlas

Data Controller: Harold Choo
Privacy Contact: support@scratlas.com
Website: www.scratlas.com

Data from Strava

With your authorization, Scratlas receives profile name and avatar, activity summaries, and activity location fields needed to resolve country and supported region. When Activity Memories is enabled (on by default), Scratlas may fetch the documented primary photo from a detailed activity response and retain its remote URL and display metadata. We request read and activity:read by default. You may explicitly choose activity:read_all, which includes “Only You” activities and privacy-zone data.

Why we process information

We process Strava data after your authorization and consent so Scratlas can provide your private passport and progress views. We process account and security information as necessary to operate and protect the service. If you contact Support, we process the contact information and message you provide to respond to and manage your request. These purposes do not make support messages Strava Data unless you voluntarily include Strava information in them.

Purpose and retention

We use this data only to display your private passport. Activity summaries—including activity names, dates, types, distances, times, and elevation—resolved countries and regions, passport stamps, totals, and Activity Memories metadata are maintained only as part of the same transient cache. Scratlas targets a complete revalidation from Strava within six days. It does not display the cached activity data or its derived information after seven days without successful revalidation, and expired activity, media, and derived records are automatically deleted. Failed refreshes do not mark the cache as current. Cached profile name and avatar are also cleared when the cache expires.

Support messages

If you use the Support form, Scratlas may collect your optional name, email address, and message contents. We use this information only to respond to and manage the support request. We do not use support contact information for advertising or marketing.

Coordinates and security

Coordinates are processed transiently on the server for country/region resolution and immediately discarded. They are not persisted, logged, returned to the browser, or disclosed to other Scratlas users. OAuth tokens are encrypted before storage and kept server-side.

Service providers

Scratlas uses third-party providers for application hosting and server execution, server-side database and storage, aggregate site analytics, and delivery of Support messages. These providers process information only as needed to provide those services. Scratlas does not use these providers to sell Strava Data, target advertising, or disclose one athlete’s Strava Data to another user.

What we do not do

We do not sell Strava Data, use it for advertising, AI, analytics reuse, product-improvement analytics, or disclosure to other Scratlas users. We do not create public Scratlas pages or public maps from Strava Data. We do not retrieve Strava videos because the current public DetailedActivity API does not document an equivalent video collection, and we do not scrape Strava or use undocumented endpoints. Activity Memories can be turned off without reconnecting.

Your choices, rights, and data access

You can see Scratlas’s currently retained Strava-derived information in your private Scratlas account. You may contact Scratlas Support to request information about data Scratlas currently holds about you. Strava’s own export tools remain the appropriate place to obtain the complete original Strava dataset. You can withdraw consent by disconnecting. Disconnect & Delete Strava Data revokes access, deletes local Strava and derived data, clears the session, and shows a durable written confirmation ID and timestamp. Strava-side deletion and revocation are handled through Strava’s revoke endpoint and deauthorization webhooks. You may also use Strava’s own connected-app settings and privacy controls.

Strava statements

Strava may monitor and collect Usage Data relating to API access and may use Usage Data for any business purpose, including API or platform enhancements, support, and compliance. Strava’s own privacy practices are described in its Privacy Policy.

Policy reference: Strava API Policy effective June 1, 2026.

Scratlas is independently operated by Harold Choo.