Privacy policy

Effective 1 December 2026

This policy explains what personal data the Stride app and this website collect, why, who we share it with and the choices you have. We have tried to write it plainly. If anything is unclear, email privacy@stridedating.co.uk.

1. Who we are

Stride is provided by MargoDevelopments (“Stride”, “we”, “us”), of [Registered / postal address]. We are the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office (ICO) under registration number [ICO registration number — add once registered].

For anything about your personal data, contact privacy@stridedating.co.uk.

2. What we collect

Information you give us

  • Account: your email address. You sign in with a one-time code sent to that address; we do not use passwords.
  • Profile basics: display name, date of birth (we show your age, not your birthday), gender, who you are interested in, the age range and distance you want to see, and a short bio.
  • Optional profile details: photos with optional captions and activity tags, prompt answers, interests, a “teach you” line, job title, employer, education, height, hometown, languages, drinking, smoking, whether you have or want children, and movement details (goal, usual move times, effort level, home parkrun, first-date ideas and an upcoming event).
  • Approximate location: your home area, rounded to about 1 km (see Location).
  • Activity in the app: likes and passes, matches, date plans (time, route or meeting point) and their status, including whether a date went ahead, messages, people you block (with an optional reason), and reports you make.
  • Optional phone number and blocked contacts: if you choose to add them, stored only as one-way codes (see Phone number and contact blocking).
  • Support emails: whatever you choose to tell us when you contact us.

Information from Strava, if you connect it

See Strava data for exactly what we read and keep.

Information collected automatically

Our hosting and authentication provider keeps technical logs (such as IP address, device and app version, and request times) for security, abuse prevention and troubleshooting. The app does not contain advertising or analytics software, and we do not track you across other apps or websites.

3. How we use it and our lawful bases

UK data protection law requires a lawful basis for each use of personal data.

What we doLawful basis
Create and run your account, show your profile to compatible people, show you people who fit your preferences, handle likes, matches, dates and messagesContract: necessary to provide the service you asked for
Use information that reveals your sexual orientation, and any other sensitive information you choose to share (see section 4)Your explicit consent
Import and use Strava activity data to work out your movement signals and improve matchesYour explicit consent, given when you choose to connect Strava
Keep the community safe: age checks against your date of birth, automatic filtering of links, contact details and abusive words in profile text, handling reports, blocks, warnings and bans, and preventing fraud and abuseLegitimate interests (keeping users safe and the service secure)
Verify your optional phone number and apply contact blocks you ask for (see section 7)Legitimate interests (keeping users safe), at your request
Keep reports after an account is deleted, de-identifiedLegitimate interests (safety of other users), and legal claims
Send service emails such as sign-in codes and important noticesContract
Answer your support requestsContract or legitimate interests
Comply with the law, for example responding to lawful requests from the policeLegal obligation

We do not sell your personal data, and we do not use it for advertising. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Matching and ordering of profiles is automated, but it only affects who you see, and you can always change your preferences.

4. Sensitive information

Some information on a dating app is “special category” data under UK GDPR, which gets extra protection.

  • Sexual orientation. Your gender together with the genders you are interested in can reveal your sexual orientation. We need this to show you to the right people.
  • Things you choose to share. Your photos, bio, prompts and messages may reveal other sensitive information, such as religion, ethnicity or health. Only share what you are comfortable with.
  • Activity and fitness data. Data about your exercise could, in some cases, reveal information about your health. We treat it with the same care as health data: we keep it to a minimum, never show it raw to anyone else, and use it only to describe how you move.

We process this information only with your explicit consent. You give it when you add the information to your profile or connect Strava, and you can withdraw it at any time by editing or removing that information, revoking Strava access, or deleting your account. Withdrawing consent does not affect processing that happened before. Without gender and interest information we cannot show you matches.

5. Strava data

Connecting Strava is optional. If you connect, you approve access on Strava’s own screen, and we ask only for permission to read your activities (the activity:read scope). We cannot post to Strava or change anything in your Strava account.

What we read

When you connect, we read your Strava activities from the previous 90 days: activity type, distance, moving time, average speed, start time, start coordinates and activity name.

What we keep

  • For each activity: type, distance, moving time, average speed, start time, and start coordinates rounded to about 1 km. We do not store routes, maps, GPS tracks, heart rate, photos or activity names.
  • Summary signals worked out from those activities: which activity types you do, roughly how active you are each week, your average pace, whether you seem to do parkrun, and your usual move times.
  • Your Strava athlete ID and the access tokens needed to keep the connection working, stored in a private part of our database that the app cannot read.

Activity names are used only at the moment of import, to help spot parkrun, and are then discarded.

What other people see

Never your raw activities, routes, maps, exact distances, pace, times or locations. Other people may see coarse signals only: the activity types you do (and which ones you share with them), whether you do parkrun, and move times. Weekly volume is used behind the scenes to suggest compatible people, but it is not shown.

Stopping and deleting

  • You can revoke Stride’s access at any time in Strava (Settings, then My Apps). After that we can no longer read anything from Strava.
  • To have the activity data we have already imported deleted without deleting your account, email privacy@stridedating.co.uk from your account’s email address and we will delete it.
  • When you delete your Stride account, we revoke our Strava access and delete all your Strava tokens, activities and derived signals.

Strava’s handling of your data is covered by Strava’s privacy policy. Stride is not affiliated with or endorsed by Strava.

6. Location

  • The app asks for your approximate location only while you are using it. It never asks for background location. On Android it requests coarse location only.
  • Before your location is stored, our server rounds it to two decimal places, which is about 1 km. That rounded home area is all we keep.
  • Once set, you can change your home area once every 30 days. This stops anyone narrowing down where you live by watching distances change.
  • Other people see only a distance band (for example, roughly how far away you are), never your location or an exact distance.

7. Phone number and contact blocking

Adding a phone number is optional. It lets you block people by their number, and stops people who have blocked your number from seeing you.

  • Verifying your number: we text you a one-time code through our SMS provider (see Who we share data with) to check the number is yours. Our authentication provider keeps your verified number with your account, as it does your email address. Other users never see it.
  • How we store it for matching: we turn your number into a keyed one-way code (a cryptographic hash using a secret key only our server holds). We use that code, not your number, to apply contact blocks.
  • Blocking contacts: you choose specific people from your contacts, or type a number. We never upload your address book: the app reads your contacts on your phone, only when you choose to, and sends only the numbers you pick. For each one we keep only a keyed one-way code, its last 4 digits (so you can recognise it in your list) and any name you add yourself. Nobody but you sees your list.
  • What a contact block does: you won’t see each other, and if you were matched the match ends. The other person is not told. It also applies if they join Stride or add that number later.
  • Lawful basis: legitimate interests (keeping users safe), and your request when you add a number or block a contact.
  • Removing it: you can remove your number, unblock a contact or clear your whole list at any time in the app. Deleting your account deletes all of it.

8. What other people see

Your profile is shown only to people you are mutually compatible with (each of you fits the other’s gender, age range and distance preferences) and to your current matches. Nobody you have blocked, or who has blocked you (including by phone number), can see you. Your email address, date of birth, exact location and any details you have hidden are never shown to other users.

9. Photos

Photos are kept in private storage. They are not public on the internet: the app can only load a photo for someone who is allowed to see your profile. When you delete a photo or your account, the file is deleted.

10. Messages

Messages are stored so we can deliver them and show your conversation history. Only you and your match can read them in the app. We do not read your messages, except when a conversation is reported to us, when needed to investigate a safety concern or misuse of the service, or when the law requires it. If you or your match unmatches, the conversation is hidden from both of you. Messages are deleted when the match or either account is deleted.

11. Reports and moderation

When you report someone, we store the reason, any details you add, who was reported, which match it relates to and when. Reports are sent to our moderation inbox containing account identifiers and the report itself, not names or email addresses. We review reports and may warn, restrict or remove accounts, and may share information with the police where there is a risk of harm. Text you add to your profile is automatically checked for links, contact details and abusive language before it is saved.

12. Who we share data with

We use a small number of service providers (processors) who handle data on our behalf, under contracts that require them to protect it and use it only on our instructions.

ProviderWhat forWhere
SupabaseDatabase, authentication (including sign-in emails), private photo storage and server functionsData hosted in London, UK (AWS eu-west-2)
Expo (EAS)Building the app and delivering app updatesUnited States
[SMS provider — e.g. Twilio]Sending phone verification codes, if you add a phone number (receives your number and the code)[Where]
ResendSending service and moderation emails, once enabledUnited States
VercelHosting this websiteGlobal network, United States company

We also work with independent organisations that are controllers of their own data:

  • Strava, if you connect it (see section 5).
  • Apple and Google, who distribute the app and will process payments if we offer optional paid features. Their own privacy policies apply.
  • Police and other authorities, when the law requires it or to protect someone from serious harm.
  • A buyer or successor, if our business is ever sold or reorganised, subject to this policy.

Other users see your profile as described in section 8.

If we add new providers or new kinds of processing (for example push notifications, crash reporting or in-app purchases), we will update this policy before that processing starts.

13. International transfers

Our main database and photo storage are in the UK. Some providers listed above are based in, or may access data from, the United States or other countries. Where personal data leaves the UK, we rely on UK adequacy regulations (including the UK–US data bridge where the provider is certified) or the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with any additional safeguards needed. Contact us for more detail.

14. How long we keep data

  • Your account and profile: for as long as your account exists.
  • When you delete your account: your profile, photos, prompts, interests, likes, passes, matches, dates, messages, blocks, phone number, blocked contacts, Strava connection and activity data are deleted straight away. Backups held by our hosting provider roll off within their normal backup cycle.
  • Reports: kept for up to 2 years after they are made, to protect other users and deal with repeat offenders. If you made a report and then delete your account, your link to the report is removed. If you were reported, the report stays linked only to an identifier that no longer matches any account.
  • Passes: someone you pass on is hidden from you for 30 days.
  • Support emails: for as long as needed to resolve your request, then deleted.
  • Technical logs: for the short periods set by our providers.

We may keep information longer where the law requires it or to deal with legal claims.

15. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • rectification of inaccurate data (you can edit most of it in the app);
  • erasure (you can delete your account in the app);
  • restriction of processing in certain circumstances;
  • portability: a copy of data you gave us in a machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, where we rely on it.

To use any of these rights, email privacy@stridedating.co.uk from the email address on your account (so we can confirm it is you). We will reply within one month, and it is free in most cases.

16. Children

Stride is only for adults aged 18 and over. We check your date of birth when you sign up and do not knowingly collect data from anyone under 18. If you believe someone under 18 is using Stride, please report them in the app or email support@stridedating.co.uk, and we will remove the account.

17. Security

  • All data is encrypted in transit (HTTPS/TLS).
  • Row-level security in our database means each person can only read and change what they are allowed to.
  • Photos are in private storage and only served to people allowed to see them.
  • Strava access tokens are kept in a private database schema that the app cannot reach.
  • Access to production systems is limited to the people who need it.

No system is perfectly secure. If a breach affects your data and puts you at high risk, we will tell you and the ICO as the law requires.

18. Cookies and this website

This website (stridedating.co.uk) does not use cookies, analytics or tracking, and loads no third-party scripts or fonts. Our host, Vercel, processes your IP address and basic request details to deliver pages and protect against abuse.

19. Changes to this policy

We will update this policy when our practices change, and always before we start a new kind of processing. If a change is significant, we will tell you in the app or by email. The date at the top shows when it last changed.

20. Contact and complaints

Email privacy@stridedating.co.uk or write to MargoDevelopments, [Registered / postal address].

If you are unhappy with how we have handled your data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.