strava.com privacy report
Privacy audit of strava.com. Grade E (31/100). 42 tracker requests from 10 owners across 3 jurisdictions. See the full breakdown and how to ask for deletion.
E
Privacy
0/100
Data flow
22/100
Security
76/100
Practices
70/100
Trackers detected on strava.com
We found 42 tracker requests across 20 hostnames, controlled by 10 distinct companies.
| Owner | Country | Category | Requests |
|---|---|---|---|
| Cybot (Cookiebot) | DK | Consent management | 18 |
| US | Advertising | 12 | |
| Unclassified (EasyPrivacy) | — | Advertising | 3 |
| LinkedIn (Microsoft) | US | Advertising | 2 |
| Meta | US | Advertising | 2 |
| Intercom | IE | Live chat | 2 |
| YouTube (Google) | US | Third-party embed | 2 |
| US | Advertising | 1 |
Where strava.com sends your data
Tracker hosts on this site are controlled from these jurisdictions:
- United States CLOUD Act Schrems II risk: high 19 requests
- Denmark EU adequacy 18 requests
- Ireland EU adequacy 2 requests
Learn more: the US CLOUD Act, Schrems II, the Digital Markets Act.
What this means for you
Security headers
HTTPS enforced: yes. Security headers score: 68/100.
No major issues detected in HTTP security headers.