Privacy

Your route is a map of your life — where you live, when you leave, how fast you move. We treat it that way. It is parsed in your browser, stored only if you buy or save, never sold, and never fetched from Strava or any other account. Everything below is the long version.

Last updated 11 August 2026

Who is responsible

MJ Projects B.V., the company behind Lope.studio, is the data controller for everything described here. Our full details:

Registered name
MJ Projects B.V.
Address
Vasteland 78, 3011 BN Rotterdam, The Netherlands
KvK number
88360040
VAT ID
NL864593065B01

We are too small to be required to appoint a Data Protection Officer, so privacy questions go to that address and are answered by the person who built the thing.

Your GPS route, specifically

When you drop a GPX or KML file onto the site, it is read in your browser. The file itself is never uploaded — the preview you see is drawn on your own machine, from your own file. If you close the tab without saving or buying, nothing about that route ever reaches us.

Two things change that, and only two: saving a design to your email, and buying. In both cases we store the simplified route line we need to draw the poster — not your original file, not the timestamps, not your heart rate.

A route can reveal your home address. Ours is a poster business, not an analytics one, so we never enrich it, profile it, match it against anything, or hand it to advertisers. The only company that ever sees the finished artwork is the print lab, and only for orders that are actually being printed.

We never connect to Strava, Garmin, Komoot or any other account. There is no OAuth button because there is no integration — you export a file and give it to us, which means you can see exactly what we got.

What else we collect, and why we are allowed to

Under the GDPR every use of your data needs a legal basis. Ours, in full:

Route + poster settings
To draw and print the poster you asked for — performance of a contract. Before you buy, if you asked us to email your design to you, consent.
Name + shipping address
To deliver a physical order — performance of a contract. Physical tiers only; a digital download never asks for an address.
Email address
Order confirmations and delivery updates — contract. Occasional email about new work, if you are a customer or ticked the box — consent, or the soft opt-in the Dutch Telecommunicatiewet allows for our own similar products. Every message can unsubscribe in one click.
Payment details
Handled entirely by Stripe. Card numbers never touch our servers and we could not retrieve one if we wanted to — contract.
IP address
Kept briefly to rate-limit abuse of the upload and email endpoints — legitimate interest in keeping the service standing up.
Usage events
Which steps of the flow people finish and which they abandon — legitimate interest. Cookieless and not tied to you personally until you give us an email. Detail on the tracking page.
Invoice records
Kept because Dutch tax law says so — legal obligation.

No automated decision-making, no profiling with legal effects, no advertising profiles built from your route. The service is not directed at children under 16.

How long we keep it

Different records have genuinely different lifespans, and the honest answer is a table rather than one number:

30 days
A design you made but never bought. Long enough to come back and finish; deleted automatically after that.
24 months
The route and settings behind an order you placed. So we can reprint it under the guarantee, or make you a second copy.
7 years
Invoice and order records. Dutch tax law requires it (art. 52 AWR). These records hold no route data.
Until you unsubscribe
Your email on our list. Plus three years of silence, after which we delete it unasked.

The 30-day deletion of unfinished designs runs automatically, not on request. The seven-year invoice record is the one thing we cannot delete early even if you ask — it is a legal obligation, it holds no route data, and it is the only exception to everything else on this page.

Who else touches it

Six companies help run this shop. Each is contractually bound to use your data only for the job we hired them for — with one honest exception, noted under the table:

CompanyWhat they getWhere
Stripe Payments Europe, Ltd.Taking payment and preventing fraudName, email, billing and shipping address, payment detailsIreland, with transfers to Stripe, Inc. (US) under Standard Contractual Clauses
Prodigi (UK) LtdPrinting and shipping physical ordersRecipient name, shipping address, email, phone, and the poster fileUnited Kingdom (covered by the EU adequacy decision); EU orders are printed at Prodigi's EU lab nearest the delivery address
SupabaseStoring your design so it can be printed and reopenedYour simplified route, poster settings, email address, order recordsEU region (Frankfurt); US parent company under Standard Contractual Clauses
ResendSending order confirmations, downloads and delivery updatesEmail address, order details, download linksUnited States, under Standard Contractual Clauses
PostHogUnderstanding which parts of the site work and which breakAnonymous usage events; your email only after you give us oneEU Cloud (Frankfurt)
VercelHosting and serving the websiteTechnical request data, including IP addressUnited States, with EU edge regions, under Standard Contractual Clauses

The exception is Stripe. It handles the payment itself on our instructions, but for fraud, sanctions and anti-money-laundering checks it decides for itself what it needs — the law makes it the controller of that part, and its own privacy policy governs it. In practice that means a question about the charge comes to us, and a question about a fraud decision has to go to Stripe, because we cannot overrule it.

Where a company processes data in the United States, the transfer runs on the European Commission's Standard Contractual Clauses. We do not sell data to anyone, ever, and there is no category of "partner" beyond the six above.

What you can make us do

These are rights, not favours, and asking costs you nothing. You can ask us to show you everything we hold on you, correct it, delete it, hand it over in a portable file, restrict what we do with it, or object to a use you disagree with. Where we rely on your consent, you can withdraw it at any time — that stops future use but does not undo what already happened.

Email hello@lope.studio from the address you ordered with. We answer within one working day and complete the request within a month, free of charge.

If we handle it badly you can complain to the Dutch data protection regulator, the Autoriteit Persoonsgegevens, or to the authority where you live. You can come to us first if you want to, but that is entirely your call.

Security, and what happens if it goes wrong

Everything runs over HTTPS. Route data sits in an EU-hosted database reachable only by the application. Payment details never reach our servers. Access to production data is limited to the people who need it, which at our size is a short list.

If a breach ever puts your data at risk, we notify the Autoriteit Persoonsgegevens within 72 hours and tell you directly when the risk to you is high — in plain language, saying what happened and what to do about it.

Changes

When this policy changes we update the date at the top. If a change actually affects you — a new processor, a new purpose — we email everyone on our list rather than quietly editing the page and hoping nobody notices.

Anything here unclear? Email hello@lope.studio and a human will answer.

Privacy · Terms · Returns · Shipping · Tracking