← Back to Pacedrops
Privacy Policy
Last updated: August 3, 2026
Pacedrops ("we", "our", "the app") connects your Strava runs with your Last.fm listening history to show which songs you listened to during each run. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
When you use Pacedrops, we collect:
- From Strava: Your name, profile picture, and run data (distance, duration, pace, heart rate, GPS route, elevation). We access this through Strava's official API with your permission.
- From Last.fm: Your listening history (song names, artist names, album art, timestamps) for the time window of each run.
- Account data: An encrypted authentication token to keep you logged in.
- Things you mark yourself: Songs you add to your favourites. We store the artist and track name against your account.
- Playlists we build for you: A record of each playlist we create on your behalf, so we can update it rather than making a new one every time.
2. How We Use Your Data
- Match your music to your runs based on timestamps
- Generate shareable story cards showing your run soundtrack
- Build playlists from what you run to, and from songs you mark as favourites
- Work out where you stand on each song in the in-app game ("In play"), and show you what changed after a run
3. Strava Data Retention
In compliance with Strava's API Agreement (Section 6.2), we do not cache Strava data for longer than 7 days. After 7 days, Strava-specific fields (distance, pace, heart rate, elevation, GPS route) are cleared from our database. If you view an older run, we re-fetch the data from Strava in real time.
4. Data Sharing
We do not sell or rent your personal data. We never share your name, your Strava data, or your pace with other users.
Spotify
To build a playlist we send song and artist names to Spotify's API so it can find the matching tracks. We do not send your name, your runs, or your pace. Playlists are created on a Pacedrops-owned Spotify account and shared with you by link; you are never asked to connect your own Spotify account.
Shared playlists and the in-app game
Two features use everyone's listening together:
- Monthly community playlists are built from the songs Pacedrops runners played and are public on Spotify. They contain song and artist names only. They do not say who played what, and they never contain anyone's pace, name or runs.
- In play compares runners on each song. You are shown your own position and counts of other runs, for example "2nd of 5" or "3 runs came for it". Other runners are never named, and their pace, distance and identity are never shown to you. The same is true of what others see about you.
This is a requirement of Strava's API Agreement as well as our own policy: Strava data provided by a user is only ever displayed back to that user.
5. Data Storage & Security
- Your Strava access tokens are encrypted using AES-256-GCM before storage
- All communication uses HTTPS
- Data is stored on managed cloud infrastructure with access restricted to the app
6. Your Rights
- Delete your account: You can delete all your data at any time from Settings in the app. This permanently removes your account, all runs, songs, insights and favourites, deletes the playlists we built for you, and revokes our access to your Strava account. Monthly community playlists are not deleted, as they are built from everyone and name nobody.
- Revoke Strava access: You can disconnect Pacedrops from your Strava account at any time via Strava's settings. When you do, we automatically delete your account.
- Disconnect Last.fm: You can unlink your Last.fm account from Settings at any time. Future runs will no longer sync music.
7. Children
Pacedrops is not intended for children under 13. We do not knowingly collect data from children.
8. Changes
We may update this policy from time to time. The latest version will always be available at this URL.
9. Contact
Questions about your data? Reach us at privacy@pacedrops.com or DM us on Instagram.