Privacy
What we collect, why, where it lives — and how you get rid of it.
Last updated: 7 September 2026In short: you can read the public pages with no account and no cookies — we do not track you there. Personal data only appears once you create an account, and even then we keep to what each function actually needs. Your GPS tracks never leave your browser.
Who is responsible
The controller under the GDPR is Eckhard Völcker, Driessenstraße 8, 83707 Bad Wiessee, Germany — see the imprint. He is also your contact for privacy matters. An informal message to info@vfworks.com is enough for any question or to exercise your rights.
Part A — Public pages, no account
No tracking, no advertising cookies
These pages embed no analytics or advertising services — no Google Analytics, no pixel, and no consent banner, because there is nothing to consent to. Fonts are served from our own domain so your browser never contacts Google while you read. We set exactly two cookies, both for you rather than about you: if you have signed in to the app, your own sign-in session lives as a cookie on our domain — the public pages read it solely to show YOU your own numbers; without signing in that cookie does not exist. The second one remembers your unit system — kilometres or miles, explained in the next section. Third-party tracking never takes place either way.
Units and your country
So that kilometres or miles fit you without being asked, your browser asks us once on your first visit which country your request comes from. The answer is the country code our hosting provider technically attaches to every request anyway — we run no additional service for this, evaluate no IP address ourselves, and store or log nothing in the process. Only the unit system derived from it is remembered by your browser as a cookie (zrg_units) on our domain; that is not a location — a country is not a place. If you pick your units yourself using the switch, your choice applies permanently and beats any automatic guess. Signed in, we additionally store the chosen unit in your account so it follows you to every device; deleting the account removes it too. The legal basis is our legitimate interest in an intelligible display (Art. 6(1)(f) GDPR).
Server logs
As with any web server, a technical log entry is created when you load a page: IP address, timestamp, the address requested, browser identification. These entries arise at our hosting providers, serve operation and attack defence, and are deleted there automatically after a short period. The legal basis is our legitimate interest in running a working, secure service (Art. 6(1)(f) GDPR).
The calculators on these pages
The Power Lab, Segment Lab and Bike Lab compute inside your browser. Whatever you type into a slider stays there — nothing is transmitted and nothing is stored. The comparison curves rest on pre-aggregated, anonymous distributions drawn from public Zwift racing profiles; no individual rider is contained in them or recoverable from them.
GPX and FIT files
When you upload a recording it is read and processed inside your browser. The file is never transmitted to us. Your GPS track — where you actually rode — does not leave your device. Even what we store about a segment is deliberately coordinate-free: length, gradient and elevation profile, but no position.
Map view in the race calendar
The race calendar first shows a small overview map that we serve ourselves — country outlines and markers, no external service. Only when you choose “Open map” does your browser load the interactive map: the MapLibre GL library from the jsDelivr content network (Prospect One, Poland) and the map tiles, fonts and icons from OpenFreeMap (a non-profit community project). Technically these two providers then receive your IP address, browser details, the referring page and the addresses of the requested map tiles — zooming and panning loads new tiles continuously, which reveals the area you are looking at. Your own location is never requested; the races themselves live in our data, not in the tiles. No cookies are set and nothing from your account is transmitted. Without that click no data reaches these providers. The legal basis is our legitimate interest in a spatial view that you trigger yourself (Art. 6(1)(f) GDPR). We are working on serving the tiles ourselves; this section will disappear once that is done. Map data © OpenStreetMap contributors (ODbL).
Feedback
The feedback box lets you write to us without signing in. We store your text, the category, a timestamp and — only if you attach them yourself — a screenshot and an e-mail address for our reply. Without contact details the report is anonymous. The basis is your voluntary submission; you can ask us to delete it at any time.
Club Discord coupling
Clubs can connect their internal Discord server to the club RaceHub. Our bot then posts race polls, confirmed lineups (with the names of the riders lined up) and captain-triggered scout comparison tables into the channel the club chose — Discord (Discord Inc., USA) processes these messages under its own terms, so your details may be transferred to a third country. If you reply in Discord via button, we store your reply (yes/reserve/no or spot confirmation) exactly as if you had clicked it on the platform. For the mapping we store your Discord account ID in your club's member list; a link is only created by your own action (your click, /link) or set up by your captain with you. You can remove the link at any time via your captain or the address above; deleting your account removes it as well. The legal basis is running the club's racing operations (Art. 6(1)(b) GDPR).
Club applications (e.g. DNSTY)
Some clubs on this platform accept applications through a form — today that is DNSTY. It includes your Zwift ID (required: without it the club cannot activate you), an e-mail address for the reply, and the club's form fields such as an introduction, your goal and your sponsor on the team. We store this application with us so the club's officers can review it and activate you; the legal basis is initiation of the membership (Art. 6(1)(b) GDPR). In addition the club is notified by a message into its internal Discord channel — Discord (Discord Inc., USA) processes that message under its own terms, so your details may be transferred to a third country. If your application is declined we delete the free-text fields and contact address after the decision; you can request deletion at any time via the address above. ZRG-R does not accept applications through the platform.
Club requests to the platform
To bring a club onto the platform you fill in a form on the Club RaceHub page. We collect details about the club (name, tag, ZwiftPower team ID, colour, rough squad size, race formats, logo address), about the person asking (name, Zwift ID, e-mail address) and a free-text motivation. We store the request in order to review it, ask follow-up questions and, where applicable, create the club; the legal basis is initiation of the usage relationship (Art. 6(1)(b) GDPR). If the request is declined we delete the motivation text, the e-mail address and the contact person's details; only the fact that the request existed is kept. You can request deletion at any time via the address above.
Part B — Account, Zwift ID and club
The account
An account needs an e-mail address and a password. Sign-in runs through Amazon Cognito in the Frankfurt region (eu-central-1); we never see your password. The purpose is to provide the personal functions, the legal basis is performance of the user relationship (Art. 6(1)(b) GDPR). Delete the account and the associated profile data goes with it.
What the account record holds
A few items belong to the account itself, and we name them for completeness: display name and e-mail, how you sign in (e-mail or Google), your language, when you linked your rider, your last sign-in and how many times you have signed in, your role (rider or admin), and the record of when you acknowledged this policy and which version of it. The sign-in figures serve operations — we build no usage profiles from them and do not analyse them for behaviour.
The acknowledgement record is our obligation, not your burden: it holds which version of this policy you read. If we change it substantively we ask again — and the earlier record stays alongside, so it remains traceable what applied when.
Your Zwift ID and what comes with it
If you link your Zwift ID we fetch your publicly visible racing profile: display name, category, number of races, best efforts across several durations, weight and the figures derived from them. All of this is already public — we retrieve it, organise it and compute with it; we do not uncover anything hidden. You authorise the link yourself, and without it the personal functions simply stay empty.
We refresh your profile when you use the tools and the data is more than a week old — never speculatively. If you stop coming back, we stop fetching.
Two roles: club rider and solo rider
With an account you are one of two things, and the server decides which — never the page in your browser. As a club rider you are on your club's roster: your racing numbers, entries and team assignments are visible to your club-mates and theirs to you — that is what a club is for. As a solo rider the service is an analysis for you alone: you receive your own entry and nothing else, the club's rider list is never sent to you, and no club member sees your numbers either.
The distinction runs through everything: the rider views, the season poll (solo sees only their own answer plus a bare total), the personal layer on the public pages — and feedback, which when signed in carries your name and role.
Race entry, season poll and teams
Inside the club you record whether you are starting a race, whether you want to ride a season and which team you are on. These entries are club-internal and serve the line-up. Your identity always comes from your sign-in token, never from something the page claims — you cannot file an entry for somebody else.
Your garage in the Bike Lab
In the Bike Lab you can build a garage: your favourite frames with their upgrade stage and your wheelsets. Without signing in this list lives solely in your browser (localStorage) and never leaves your device. Signed in, you can save it to your profile — it then sits in a protected area of our storage assigned to you alone and follows you across devices. It is in-game material (virtual bikes), not sensitive data; we store only the list itself plus a timestamp. Delete your account and the garage goes with it.
Connecting intervals.icu
You may voluntarily connect your account to intervals.icu so workouts land straight in your training calendar. You grant that authorisation at intervals.icu itself; all we keep is the access key, held in a protected area that is never delivered to a browser. Disconnect and the key is deleted and access ends immediately. Everything still works without a connection — you simply download the workout as a file.
Planned but not yet active: reading training metrics for fuelling plans. When we switch that on we will ask you separately for it, store only summarised values rather than raw recordings, and deliberately leave out health data such as sleep or heart-rate variability.
No AI profiling
Every number on these pages comes from formulas with named sources — physics, statistics, published models. There is no automated decision-making and no profiling within the meaning of Art. 22 GDPR, and no AI model is trained on your data.
Who receives data
| Amazon Web Services (AWS) | Hosting, storage and sign-in (Cognito), Frankfurt region — eu-central-1 |
| Vercel | Delivery of the public pages |
| Discord (Discord Inc., USA) | Club application notifications (your form input) and — since 29 Aug 2026 — the clubs' Discord coupling: race polls, your button replies, lineups with names and scout comparison tables in the respective club's internal channel (details in the Discord coupling section). |
| jsDelivr (Prospect One, Polen) · OpenFreeMap | Only if you choose “Open map” in the race calendar: map library (jsDelivr) and map tiles (OpenFreeMap) — details in the map view section |
| intervals.icu | Only if you connect it yourself — you authorise there directly |
| Zwift / zwiftracing.app | Source of your public racing profile — we read there, we write nothing |
We do not sell data, we run no advertising and we pass nothing to ad networks.
How long we keep things
Account and profile data stay as long as your account exists — including the garage. Entries and team assignments stay as long as the planner carries that season. Access keys for intervals.icu vanish when you disconnect. Feedback is kept until it is dealt with. Club applications stay until the decision; on rejection we delete the free text and contact address. Server logs are deleted by the hosting providers after a short period.
Your rights
You can ask what data we hold, have it corrected or deleted, restrict its processing, receive it in a portable format, and object to processing based on legitimate interest. An informal message is enough; we need no proof beyond your account. You may also complain to a data protection supervisory authority.
You can delete the account yourself inside the app. That removes your profile, the link and the associated personal storage. Records of races already run may remain in the club's season history — tell us if you want those gone too.
What we are currently cleaning up
The link between your account and your Zwift ID is currently also stored in our internal source-code repository. Only we can access it; it is not public.
This statement describes the service's actual data flows and is updated whenever they change. A legal review is planned before broad marketing begins.