Last updated: 10 April 2026
Segment Club ("we," "us," "our") operates a cycling community platform at www.segmentclub.com ("the Service"). We are committed to protecting your privacy and handling your personal information in accordance with Australian law.
This Privacy Policy explains how we collect, hold, use, and disclose your personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as well as the Spam Act 2003 for electronic marketing communications.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. This policy is freely available on our website at all times.
For all privacy-related inquiries, access requests, corrections, complaints, or to exercise any of your rights under this policy, please contact us using the details above. We will respond within 30 days in accordance with Australian privacy law.
When you create an account, we collect:
You may also sign up using Google OAuth or Strava OAuth, in which case we receive your name and email from the respective provider. We ask you to set a password during this process so you can also sign in with email.
During onboarding, we collect:
If you connect your Strava account (via OAuth with scope read,activity:read_all), we collect and store:
Strava data is synced in real time via webhooks when you create, update, or delete activities. You can disconnect Strava at any time from your account settings, which will stop future data collection. Previously synced data will be retained unless you request its deletion.
You may optionally link social media profile URLs (not login credentials) for the following platforms: Facebook, Instagram, X (Twitter), LinkedIn, YouTube, TikTok, and Reddit. These are used for community connection and points eligibility only.
When you contact us via the website contact form, we collect your name, email, phone (optional), subject, and message content. This data is stored in our database and used to respond to your inquiry.
When you submit a bug report or feature suggestion, we collect the content you provide (title, description, steps to reproduce) and any screenshots you upload. Screenshots are stored in secure cloud storage.
We automatically collect technical data through:
Google Analytics (GA4)
Tracking ID: G-VJKEJ70F65. Collects page views, user interactions, device type, browser, operating system, approximate geographic location (from IP address), and browsing behaviour. Data is processed by Google LLC (USA). Google's privacy policy: policies.google.com/privacy
Microsoft Clarity
Project ID: w6vxxiz5w4. Records anonymous user session replays, click heatmaps, scroll behaviour, and interaction patterns to help us improve the user experience. Personal data such as keystrokes in form fields is automatically masked. Data is processed by Microsoft Corporation (USA). Microsoft's privacy policy: privacy.microsoft.com
We use the following cookies:
sc_ref) — stores a referral code for 30 days to attribute sign-ups to the referring member. Browser-specific; does not persist across browsers or devices.We collect personal information that is reasonably necessary for the following purposes (APP 3):
We may use your personal information to send you marketing communications about our services, partner offers, events, and news that we think may interest you. You can opt out of marketing communications at any time by:
We will action your opt-out request within 5 working days at no cost to you, in compliance with the Spam Act 2003.
We may create aggregated, anonymised datasets from cycling activity data, performance metrics, and usage patterns. This data cannot identify individual users and may be used for:
Providing your personal information is voluntary. However, if you choose not to provide certain information:
We share personal information with the following service providers who process data on our behalf:
| Service | Provider | Country | Purpose |
|---|---|---|---|
| Database & Auth | Supabase | USA / Europe | User accounts, data storage, authentication |
| Hosting | Vercel | USA | Website hosting and deployment |
| Resend | USA | Transactional and marketing emails | |
| Analytics | Google (GA4) | USA | Website usage analytics |
| Session Recording | Microsoft Clarity | USA | UX improvement via session replays and heatmaps |
| Activity Data | Strava | USA | Cycling activity sync (with your authorisation) |
| Redemption Tracking | Google Sheets | USA | Partner voucher redemption logging |
We take reasonable steps to ensure these overseas recipients handle your personal information in accordance with the Australian Privacy Principles (APP 8).
When you redeem a reward, we share your name, email, and voucher code with the relevant reward partner (e.g., Bespoke CC, Ciovita) via a shared Google Sheet so they can fulfil your voucher. This is limited to the specific redemption and is necessary to provide the reward.
We may disclose your personal information if required or authorised by law, including in response to court orders, subpoenas, or requests from Australian government agencies.
Where your personal information is collected directly by us and you would reasonably expect to receive marketing communications (for example, because you signed up for an account and were notified that marketing is one of the purposes), we may use your information for direct marketing. We always provide a simple, free opt-out mechanism.
In compliance with the Spam Act 2003, every commercial electronic message we send will:
We keep records of consent (who consented, when, and how) as required by the Australian Communications and Media Authority (ACMA).
This Privacy Policy is our primary instrument for complying with APP 1. It is freely available on our website, clearly expressed in plain English, and kept up to date. We review this policy regularly and update it when our practices change.
We only collect personal information that is reasonably necessary for our functions and activities. We do not collect sensitive information (such as health data, racial origin, or political opinions) unless expressly provided by you through third-party integrations (e.g., heart rate data from Strava, if you choose to share it).
At or before the time of collection, we notify you of the purposes for which your information is collected, as described in Sections 3 and 4 of this policy.
We only use or disclose your personal information for the purposes for which it was collected, or for directly related secondary purposes that you would reasonably expect.
See Section 7 above for our full direct marketing practices and your opt-out rights.
We disclose personal information to overseas recipients as described in Section 6.1. We take reasonable steps to ensure these recipients comply with the APPs.
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:
No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Under the Australian Privacy Principles, you have the following rights:
You can request access to the personal information we hold about you. Much of your data is accessible directly through your account (My Garage, Settings). For a comprehensive data access request, contact our Privacy Officer.
You can update most of your personal information directly in your account settings and onboarding profile. If information is inaccurate, out-of-date, incomplete, or misleading, you can request correction by contacting us.
You can request deletion of your account and personal information by contacting us via our Contact Us page. We will process your request within 30 days. Please note:
You can opt out of receiving marketing communications at any time by clicking "unsubscribe" in any marketing email or by contacting us. We will action your request within 5 working days at no cost. This does not affect transactional emails (e.g., password resets, voucher codes).
You can disconnect your Strava account at any time from your account settings. This will stop future data syncing. To have previously synced data deleted, please contact us.
If you believe we have breached the Australian Privacy Principles, you can lodge a complaint with us using the contact details in Section 2. We will investigate and respond within 30 days.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
We retain your personal information for as long as necessary to provide the Service and fulfil the purposes outlined in this policy:
After account deletion, we destroy or de-identify personal information unless retention is required or authorised by law.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately and we will take steps to delete it.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
We encourage you to review this policy periodically.
This Privacy Policy is governed by the laws of the Commonwealth of Australia, including the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Spam Act 2003. Any disputes arising from this policy will be subject to the jurisdiction of the courts of New South Wales, Australia.