Legal

Privacy Policy

Last updated: April 2026

Vela is built by athletes, for athletes. Your data is yours. We collect only what we need to provide the service, we never sell it, and we never share it with third parties for advertising purposes.

What we collect

To provide the Vela intelligence service, we collect and process the following categories of data:

How we use your data

Third-party integrations

Vela connects to platforms you authorise. We access only the data scopes required for the service — read-only where possible. We do not share your data with these platforms beyond what is required for authentication and data retrieval. Current integrations: Garmin Connect, Strava, TrainingPeaks.

Data storage and security

Your data is stored in Supabase infrastructure hosted in the EU (Ireland region). Data in transit is encrypted via TLS 1.2+. Data at rest is encrypted at the database level. We maintain access logs and audit trails for all data access events.

Data retention

We retain your data for as long as your account is active. If you delete your account, we will permanently delete all associated data within 30 days, except where we are required to retain records for legal compliance.

Your rights

Under GDPR, you have the right to access, correct, export, or delete your personal data at any time. To exercise these rights, email privacy@vela.fit. We will respond within 30 days.

Contact

For any privacy questions or concerns: privacy@vela.fit

This policy applies to the Vela web application and associated backend services. We may update this policy from time to time — significant changes will be communicated by email.