Skip to content
TRACKMX
HomePrivacyTermsSupport

TrackMX legal

Privacy Policy

How TrackMX handles data in the current beta codebase.

Effective and last updated
July 22, 2026
Public support
[email protected]

On this page

ScopeCurrent dataLocationSubmissionsIntegrationsProvidersRetentionYour choicesSecurityChildrenContact

1. Scope and responsible party

This policy covers the TrackMX mobile app, the TrackMX website, and related beta support. “TrackMX,” “we,” and “us” refer to the operator of these services.

Ownership TODO

The operating legal entity and owner mailing address have not yet been finalized. Until that is completed, privacy requests go to [email protected].

Current core processing

2. Data the app presently handles

Authentication and account records

Depending on deployment configuration, TrackMX supports Sign in with Apple, email one-time codes, or an internal development-only anonymous method. The authentication system handles provider identifiers, email address where email sign-in is used, verification and session records, and a TrackMX rider ID. TrackMX does not ask for or store an Apple password.

Profile, settings, and Garage

We store information a rider adds or changes, such as display name, handle, profile and cover images, bio, home track, units and feedback settings, discovery preferences, privacy defaults, bikes, bike-hour corrections, maintenance and parts records, setup notes, Riding Gear records, and related photos. Visibility settings control whether supported profile, ride, and Garage surfaces are private, follower-visible, or public.

Rides, files, and derived data

When a rider imports or records a supported ride, TrackMX may handle the original FIT file, source filename and fingerprint, ride time and duration, assigned bike and track, precise route coordinates contained in the ride, telemetry, laps, jump estimates and confidence, speed, heart-rate fields when present, weather snapshots, debrief notes, and derived ride statistics. Raw telemetry and new rides are private by default in the current implementation; a rider may choose another supported visibility setting.

Track follows and notifications

We store which tracks a rider follows; category choices for status/closures, announcements, and events; broader notification preferences; optional quiet hours; notification history and read state; and delivery state. If push is enabled, we store the Expo push token, device platform, Expo project ID, authorization status, optional app version and device name, and delivery receipts or errors. Tokens are used to deliver requested notifications and are not exposed through rider-facing queries.

Support and account requests

In-app support records include the rider ID, category (feedback, bug, privacy, or account deletion), message, optional app version, status, and timestamps. Email support also necessarily handles the sender address and message contents. Do not send passwords, full payment details, or unrelated sensitive files to support.

3. Location-related features

TrackMX asks for foreground/when-in-use location only in context—for nearby discovery or a rider-initiated track map action. During discovery, device coordinates are rounded before storage and labeled approximate. A rider can instead save a manually entered city or riding area, or browse without location. Background location is not required to browse.

Imported ride files and Apple Health routes can contain precise route coordinates. Those ride routes are different from the approximate discovery area and may be used for track matching, maps, lap analysis, and ride review. Visibility controls and a configurable public start/end map-redaction distance help limit sharing, but riders should review visibility before sharing any location-bearing content.

4. User submissions and public-source updates

Riders may submit or edit track geometry and facts, event or track corrections, condition reports, profile and social content where enabled, photos, source/evidence links, moderation reports, appeals, and support messages. These records can include author or reporter identity, timestamps, links to a ride or setup, and moderation state. Public or follower sharing happens only on surfaces where that visibility is supported and selected.

TrackMX also imports selected public track or venue updates from verified public sources. Stored fields can include the source identity and URL, provider IDs, post or page-authored reply text, publication and fetch times, original permalink, and provider-hosted media URLs. Imported updates preserve attribution and may require review. General public comments from riders are deliberately ignored by the external-update importer. An imported post does not, by itself, become authoritative track status.

Optional integrations

5. Garmin, Apple Health, Sentry, and PostHog

Garmin Connect

The codebase contains an official Garmin Connect Activity API path, but it becomes active only on a deployment with approved Garmin credentials and callbacks. If a rider chooses to connect on such a deployment, Garmin hosts sign-in and consent. TrackMX may then store Garmin API user ID, granted permissions, server-side access and refresh tokens, connection and sync status, activity IDs, downloaded FIT files, and imported ride data. TrackMX does not receive or store the rider’s Garmin password. Disconnect is designed to delete the Garmin registration and clear local connection credentials; already imported rides remain subject to the normal retention and deletion process.

Apple Health

The current iOS code requests read-only access only after the rider chooses to connect. It can list completed workouts, read selected workout and route information, create a lower-fidelity imported ride, keep the Apple workout identifier for duplicate prevention, and store a bounded route preview. It does not write to Apple Health. Full route, heart-rate and elevation handling, incremental updates, revocation behavior, and physical-device validation remain incomplete beta work; the website does not describe them as production-ready.

Sentry and PostHog

Sentry and PostHog are not currently wired. TrackMX does not currently send app crash reports or product analytics to those services. If either is added later, this policy and the app’s disclosures will be updated before collection begins.

6. Service providers and disclosures

TrackMX uses providers only for functions described here. Current or deployment-dependent providers include:

  • Convex for backend functions, authentication records, database, scheduled work, HTTP endpoints, and file storage.
  • Apple for Sign in with Apple and, only with a rider’s separate permission, Apple Health access.
  • Resend when email one-time-code authentication is configured.
  • Expo for app updates and push notification token delivery/receipts.
  • OpenFreeMap / OpenStreetMap-based data for map tiles on map-enabled screens.
  • Garmin only when a rider connects the optional official Activity API integration.
  • Exa, Apify, and/or Meta for operations-controlled discovery and selected public track-source updates. Candidates are reviewed before becoming canonical track or event records, except specifically configured source-update feeds.
  • Twilio only for a separately consented pre-signup SMS pilot if that feature is enabled. SMS is not created from an ordinary track follow.
  • Cloudflare to deliver this public website and handle ordinary network/security logs. This site does not contain a contact form or custom analytics.

We may also disclose information when required by law, to protect riders or the service, or as part of a business transfer subject to appropriate notice and safeguards. TrackMX does not sell personal data or use it for advertising in the current implementation.

7. Retention and deletion

Account, ride, Garage, follow, and support records are retained while needed to provide the beta, until the rider deletes or corrects them where supported, or requests account deletion. Provider tokens are retained only while the related connection remains active or needs to be safely disconnected. Imported public-source history and moderation/audit records may be retained to preserve provenance, safety decisions, and community track integrity.

The in-app deletion request is implemented, but permanent purge automation and a final legal retention schedule are not yet complete. Submitting a request is therefore an audited support step: it immediately makes the profile, Garage, and up to the supported beta bound of existing rides private; disables track-alert categories and registered push devices; records the request; and signs the rider out on the requesting device. Support then removes or de-identifies account data and files in dependency order. Shared community track identity and public schedule/source history may remain in de-identified or reassigned form so that deleting one rider does not remove a place used by others.

Retention TODO

TrackMX still needs counsel-approved periods for support/audit records, provider logs, and backups, plus tested automated purge and recovery. We will replace this notice with a defined schedule before broader release.

8. Access, export, correction, and deletion

The app provides profile, privacy, location/discovery, follow, and notification controls. Settings → Account & data can create a bounded portable JSON export and submit an authenticated deletion request by requiring the word DELETE.

For privacy questions, correction, export help, or deletion when the app is unavailable, email [email protected]. For deletion, use the subject “Account Deletion,” send from the sign-in email when possible, and include the account email and TrackMX handle. We may ask for reasonable verification before acting.

9. Security

Current safeguards include authenticated ownership checks, role-gated operations/support access, server-only provider credentials, short-lived OAuth state, push-token access restrictions, bounded support inputs, and moderation controls. No online service can promise absolute security. If you believe your account or data is at risk, contact support promptly.

10. Children and minors

The current beta does not implement age assurance or a guardian-consent workflow and is not offered to children under 13. Do not create an account for a child under 13. Before TrackMX intentionally enrolls minors, it must finalize eligibility, parental/guardian consent where required, and minor-specific privacy defaults and social/location safeguards.

If you believe a child under 13 has provided personal data, email [email protected] so we can investigate and delete it as appropriate.

11. Changes to this policy

We will update the date and publish revised language when data practices materially change. If a change requires consent, TrackMX will request it in an appropriate way before the new processing begins.

12. Contact

Email privacy and support requests to [email protected].

TODO — legal entity: identify the TrackMX service operator.
TODO — owner mailing address: publish an official address after the owner confirms it.

TRACKMX

Track discovery and source-conscious updates for motocross riders. Currently in beta.

PrivacyTermsSupportContact
PUBLIC SUPPORT[email protected]

© 2026 TrackMX. Beta software. Confirm track information with the venue.