Privacy Policy

How Strave collects, uses, shares, retains, and protects personal data.

Last updated: 24 July 2026

1. Controller and contact

The controller responsible for Strave is Lucas-Konstantin Reich, Strave, Königsborner Str. 40, 39175 Biederitz, Germany.

For privacy questions or to exercise a data-protection right, contact legal@strave.gg.

2. Data we process

Account and identity data

  • Email address, username, profile details, authentication records, and securely stored credential data.
  • Linked Discord, Ubisoft, and other game or service accounts, including identifiers and information those services provide with your authorisation.
  • Age or eligibility confirmations and organisation roles. Where Stripe Connect is used, identity and business verification is primarily performed by Stripe.

Team, organisation, event, and match data

  • Team and organisation names, logos, memberships, permissions, and affiliations.
  • Registrations, rosters, attendance, brackets, schedules, results, statistics, standings, and prize records.
  • Event rulebooks, custom signup answers, protests, disputes, admin calls, and organiser decisions.

Communications and moderation data

  • Event and match chats, support tickets, reports, attachments, and communications with Strave or an organiser.
  • Moderation flags, investigation records, evidence, staff notes, decisions, sanctions, appeals, and organiser strikes.
  • Anti-cheat logs and associated game-account or device information provided by the relevant anti-cheat service.

Technical, usage, and payment data

  • IP address, timestamps, browser, device, security events, request logs, and diagnostic information.
  • Page views, navigation, feature usage, performance, approximate region, and account-associated product activity.
  • Where Stripe is used: connected-account identifiers, payment status, amount, currency, fee, refund, and dispute information. Strave does not receive complete card details.

3. Why we process data and our legal bases

  • Performing our contract: creating accounts, providing events and matches, processing registration, delivering chats and support, maintaining standings, and providing requested platform features (Article 6(1)(b) GDPR).
  • Legitimate interests: securing the service, preventing fraud and cheating, enforcing rules, investigating reports, protecting users, improving reliability, understanding product use, and establishing or defending legal claims (Article 6(1)(f) GDPR).
  • Legal obligations: tax, accounting, payment, consumer-protection, law-enforcement, and other duties that apply to Strave (Article 6(1)(c) GDPR).
  • Consent: optional processing for which Strave specifically asks permission. Consent may be withdrawn for the future at any time (Article 6(1)(a) GDPR).

4. Chat and automated moderation

Strave may automatically analyse account names, chats, reports, and other submitted content to detect prohibited language, spam, fraud, malicious links, cheating indicators, or attempts to evade restrictions. A system may block content, limit delivery, or create a flag for review.

Automated signals can be incomplete or wrong. A decision that requires a contextual assessment and has a comparably significant effect, such as a permanent account ban, will not be based solely on an automated flag. Where available, decision notices explain how to request review.

Chats and related metadata are retained where needed to operate an event, investigate abuse, handle disputes, protect users, and document enforcement. Access is limited according to role and purpose.

5. Anti-cheat and linked accounts

Users may connect more than one Ubisoft account. Strave may associate accounts where reliable information indicates that they belong to the same person, including to prevent ban evasion and preserve competitive integrity. Associated accounts may include publisher-ban history and may not all be visible to other users.

Anti-cheat files, including supported log and debug files, may be kept for up to 12 months to investigate potential violations, handle appeals, and maintain competitive integrity. Relevant evidence or a derived ban record may be kept longer where necessary for an active sanction, dispute, legal claim, or ban-evasion prevention.

6. Public information and ban notices

Profiles, teams, organisations, events, rosters, results, statistics, and standings may be public because public competitive records are a core part of Strave.

For a Strave cheating ban, Strave may publish the affected competitive account, decision date, reason category, scope, and duration where this is necessary to inform services that use the ban list and protect competitive integrity. We balance that interest against the affected person’s rights before publication.

Underlying evidence is not public by default

Evidence may contain personal data, witness information, security methods, or information about other people. It is disclosed only where there is an appropriate purpose and legal basis, and may be redacted.

7. When data is shared

  • Event organisers: registration, roster, signup-answer, match, protest, and payment information needed to operate their event. Independent organisers are responsible for their own use of participant data.
  • Service providers: companies that provide hosting, database, storage, authentication, email, observability, security, anti-cheat, support, and payment services under appropriate contractual safeguards.
  • Partnered match services: limited ban or eligibility information where the service has agreed to use Strave’s ban list.
  • Authorities and affected parties: where disclosure is legally required or reasonably necessary to protect rights, safety, security, or defend a legal claim.

Strave does not sell personal data.

8. International transfers

Some providers may process data outside the European Economic Area. Where required, Strave uses an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism and applies appropriate supplementary safeguards.

9. Retention

Strave keeps personal data only for as long as needed for the purpose for which it was collected. Retention depends on account status, event lifecycle, active disputes or sanctions, security risk, legal limitation periods, and statutory accounting or documentation requirements.

  • Account and operational data is generally kept while the account or relevant event remains active.
  • Chat, report, and moderation records may be kept after an event or account ends where needed for disputes, safety, sanctions, or legal claims.
  • Ban records and account associations may be kept while necessary to enforce the restriction, prevent evasion, and handle appeals.
  • Anti-cheat source files are generally kept for up to 12 months.
  • Payment, tax, and transaction records are kept for applicable statutory retention periods.
  • Aggregated or irreversibly anonymised statistics may be retained without a fixed period.

10. Account deletion

When an account is deleted, Strave deletes or anonymises data that is no longer needed. Public event records may be anonymised rather than removed where retaining the competition history is necessary.

Deletion does not cover information Strave must or may continue to keep for payments, legal obligations, active sanctions, anti-cheat, investigations, security, dispute resolution, or legal claims. Access to retained data remains limited to its continuing purpose.

11. Your rights

Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, or portability of your personal data. You may object to processing based on legitimate interests and withdraw consent for future processing.

You also have the right to lodge a complaint with a data-protection supervisory authority, particularly in the EU country where you live or work or where you believe an infringement occurred.

To exercise a right, contact legal@strave.gg. Strave may request information needed to verify your identity.

12. Security and changes

Strave uses technical and organisational safeguards appropriate to the risk, including access controls, encryption in transit, monitoring, backups, and restricted administrative access. No service can guarantee absolute security.

We may update this notice when our services or legal obligations change. We will provide reasonable notice of a material change before it takes effect where required.