Privacy

Last updated: Aug 22, 2026

Controller

The controller for the processing of personal data on vrame within the meaning of Art. 4 no. 7 GDPR is:

Jörn HeilmannRichardstraße 1844137 DortmundGermanysupport@vrame.cc

Our approach

vrame is deliberately built to collect as little as possible. There is no tracking via scripts or cookies on your device, no ad networks and no profiling of your behaviour. From the server access data that arises anyway, we only produce aggregated, anonymised visitor statistics - see the next section for details.

Fonts are served from our own server, not from Google Fonts. There are no external scripts, no embedded videos and no third-party maps. Loading the site therefore creates no connection to anyone else's servers.

For the same reason there is no cookie banner on vrame: the only cookies used are those technically required to run the service or those storing a setting you chose yourself. Neither requires consent under § 25 (2) TDDDG.

This policy explains what data nevertheless arises, and what it is used for.

Hosting and server logs

vrame runs on servers operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in a data centre located in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner.

When you load the site, technically necessary access data is processed: IP address, date and time, the address requested, the volume of data transferred, the status code, the referrer and the browser identifier. This data is required to deliver the site and serves security and troubleshooting purposes.

The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in operating the platform securely and reliably. Log data is deleted after 14 days at the latest.

From the same access data, we use the self-hosted, open-source software GoAccess to automatically produce aggregated visitor statistics - for example pages viewed, browser, operating system and referring sites. The report is not publicly accessible, IP addresses are anonymised within it (last octet removed), and since it is built from log data that is itself deleted after 14 days, it always reflects only a rolling two-week window. No third party is involved. The legal basis is likewise Art. 6 (1) (f) GDPR; here our legitimate interest lies in understanding how the platform is used.

This data is not combined with your account.

Cookies and local storage

vrame uses the following cookies. All of them are set by vrame itself, and none serves advertising or analysis of your behaviour.

  • bb_session

    A random, anonymous session identifier for duel voting. It makes it possible to show you suitable duels and to count your votes without you having to sign in. The identifier contains no information about you personally.

    Duration
    1 year
    Legal basis
    Art. 6 (1) (f) GDPR
  • pb_auth

    Your login session. Only set if you have an account and sign in.

    Duration
    until logout
    Legal basis
    Art. 6 (1) (b) GDPR
  • vrame_color_mode

    Stores whether you want the site shown in light mode, dark mode or according to your system setting.

    Duration
    1 year
    Legal basis
    Art. 6 (1) (f) GDPR
  • vrame_measurement_units

    Stores whether distances and weights are shown in kilometres and kilograms or in miles and pounds.

    Duration
    1 year
    Legal basis
    Art. 6 (1) (f) GDPR
  • i18n_redirected

    Stores your chosen language so you are not redirected again on your next visit.

    Duration
    1 year
    Legal basis
    Art. 6 (1) (f) GDPR
  • duel-current

    Stores the duel bike pair currently shown to you, so it is kept when you reload the page instead of being replaced with a new one.

    Duration
    5 minutes
    Legal basis
    Art. 6 (1) (f) GDPR

Account and profile

When you create an account we process the data required for it: your email address, your password in encrypted form, and an automatically generated username.

You may optionally add further details: a display name, a profile picture, a short text about yourself, your region, your Instagram handle, your preferred language and your notification settings.

The legal basis is Art. 6 (1) (b) GDPR, as this data is required to perform the user relationship. Optional profile details rest on Art. 6 (1) (a) GDPR; you can change or remove them at any time in the settings.

Your email address is not visible to other users.

Bikes and photos

For every bike you upload we store the details you enter along with the photos. This includes the name, brand, model, category, description, weight and model year.

Bikes you make public appear in duels, in the ranking and on their own detail page. They are therefore visible to all visitors and may be indexed by search engines.

If you have set a region in your profile, it is also applied to your bikes for the regional ranking. In the settings you can choose to hide your location; your bikes are then excluded from the regional statistics.

Please note that photos can carry additional technical information, such as the location where they were taken or the camera model. Check before uploading whether you want to publish that.

When you report a bike, we store the bike concerned, the reason you selected, the processing status and your account. This is necessary to review the case and to detect misuse of the reporting function; the legal basis is Art. 6 (1) (f) GDPR. Who reported a bike is visible only to us, never to the person affected.

The legal basis for bike and photo data is Art. 6 (1) (b) GDPR.

Comments

Signed-in users can write comments on every bike detail page. For this we store the text of the comment, your account as its author, the bike it belongs to, the time it was written and the accounts mentioned in the text.

Comments are visible to signed-in users only. Visitors who are not signed in see neither the comments nor the input field; the comments are not part of the page source either and are not indexed by search engines. This is deliberately stricter than for bikes and photos, which are publicly visible.

When you write a comment, your display name, your handle and your profile picture are visible to all signed-in users, even if you have set your profile to "private" in the settings. The remaining profile details such as your bio, region or linked accounts are unaffected.

A new comment triggers notifications: to the owner of the bike, to everyone who has previously commented on the same bike, and to everyone mentioned with "@" in the comment. These people always receive an in-app notification. Whether an email is sent in addition is controlled separately for each of these three kinds in your settings; every email also contains an unsubscribe link that switches off exactly that one kind. The legal basis for the notifications is Art. 6(1)(f) GDPR.

The text of your comment is not sent by email. The notification emails only contain the name of the bike, the name of the commenting person and a link to the page.

You can edit your own comments at any time; an edited comment is visibly marked as "edited" for everyone. If you mention a person with "@" for the first time while doing so, they are notified just like with the original comment - if the same person has already been notified for this comment once, mentioning them again does not trigger another notification.

You can delete your own comments at any time. In addition, the owner of a bike may remove any comment on their own bike. If a bike or an account is deleted, the associated comments are deleted along with it; the retention period for backups described below applies.

If you report a comment, we store the reported comment, the associated bike, the selected reason, the processing status and your account. Who submitted a report is visible to us only, not to the person concerned. The legal basis is Art. 6(1)(f) GDPR.

Please do not put other people’s personal data into comments. The legal basis for the comments themselves is Art. 6(1)(b) GDPR.

Duels, votes and protection against manipulation

For every vote cast we store which bike won, the anonymous session identifier from the bb_session cookie, and, if you are signed in, your account.

We also store a check value derived from your IP address. It is produced using SHA-256 together with a server secret known only to us. The IP address itself is not stored, and it cannot be reconstructed from the check value. The value serves solely to detect large-scale automated voting.

So that nobody votes on their own bikes, we record the link between a session identifier and an account. These links are deleted automatically after 90 days.

The number of votes without signing in is limited. No additional data is stored for this.

The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in a manipulation-free ranking and in protection against abuse.

Email notifications

If you have an account, we send you emails required to operate the service, for instance to confirm your address or reset your password. The legal basis is Art. 6 (1) (b) GDPR.

In addition we optionally tell you about achievements for your bikes. You can switch these notifications off at any time in the settings, and every email contains an unsubscribe link. The legal basis is Art. 6 (1) (f) GDPR.

We also tell you about news regarding vrame – such as new features or the ranking for your region going live. You can switch these notifications off separately at any time in the settings, and every email contains an unsubscribe link that ends exactly this category. The legal basis is Art. 6 (1) (f) GDPR.

For delivery we use the Mailjet service operated by Sinch Email SAS, 13-13 bis rue de l'Aubrac, 75012 Paris, France. A data processing agreement is in place with the provider, and processing takes place within the European Union.

We do not send third-party advertising and do not share your email address for advertising purposes.

Strava login and import

You can sign in using your Strava account. You are redirected to Strava, where you decide whether to grant vrame access. We receive no data before that.

What is transmitted is your Strava identifier, your name, your profile picture and, if you agree to it, the bikes stored in your Strava account together with their name, description and mileage. We use this data to create your account and to import or update your bikes.

To keep the data in sync we store the access and refresh tokens issued by Strava. They permit access only to the data you released, and are not passed on to third parties.

The provider is Strava, Inc., 208 Utah Street, Suite 200, San Francisco, CA 94103, USA, so data is transferred to the United States. Strava is certified under the EU-US Data Privacy Framework, and the transfer is based on the European Commission's adequacy decision under Art. 45 GDPR. Even so, access by US authorities cannot be entirely ruled out.

The legal basis is your consent under Art. 6 (1) (a) GDPR and, for performing the user relationship, Art. 6 (1) (b) GDPR. You can disconnect at any time in the settings, and we then delete the tokens. vrame can be used in full without Strava.

No data is sent from vrame back to Strava.

Who can see your data

In the settings you decide who may see your full profile page: all visitors, only signed-in users, or only you. The default is signed-in users.

Regardless of that setting, your display name and profile picture remain visible, so it is clear who a bike belongs to.

Bikes you have made public are unaffected by this setting and continue to appear in duels and the ranking. Whether a bike is public is set per bike.

Your email address, your notification settings and your votes are never visible to others.

Retention and deletion

Account and profile data is stored for as long as your account exists. You can delete it at any time in the settings, which removes your profile, your bikes and your photos.

Votes already cast are retained in anonymised form so that other bikes' ratings remain traceable; the link to your account is removed.

Links between session and account are deleted after 90 days, and server logs after 14 days at the latest.

To protect against data loss we keep encrypted backups on storage operated by Hetzner Online GmbH in Germany. Deleted data may still be contained in those backups for up to 30 days before they are overwritten in the normal rotation.

Beyond that we retain data only where statutory retention obligations apply.

Your rights

You have the following rights in relation to us:

  • access to the data we process about you (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure of your data (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • receipt of your data in a portable format (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent with effect for the future (Art. 7 (3) GDPR)

Right to lodge a complaint

An email to support@vrame.cc is enough to exercise any of these rights. Many of them you can also handle directly in the settings.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany. You may also contact the supervisory authority where you live.

Changes to this policy

We update this privacy policy when platform features or the legal position change. The version published here is the one that applies; the date is shown at the top of this page.

For significant changes we also notify registered users by email.