strava.com privacy report

Privacy audit of strava.com. Grade E (31/100). 42 tracker requests from 10 owners across 3 jurisdictions. See the full breakdown and how to ask for deletion.

Last audited today Re-audit

E
31 / 100
Poor
Privacy
0/100
Data flow
22/100
Security
76/100
Practices
70/100

Trackers detected on strava.com

We found 42 tracker requests across 20 hostnames, controlled by 10 distinct companies.

OwnerCountryCategoryRequests
Cybot (Cookiebot) DK Consent management 18
Google US Advertising 12
Unclassified (EasyPrivacy) — Advertising 3
LinkedIn (Microsoft) US Advertising 2
Meta US Advertising 2
Intercom IE Live chat 2
YouTube (Google) US Third-party embed 2
Reddit US Advertising 1

Where strava.com sends your data

Tracker hosts on this site are controlled from these jurisdictions:

  • United States CLOUD Act Schrems II risk: high 19 requests
  • Denmark EU adequacy 18 requests
  • Ireland EU adequacy 2 requests

Learn more: the US CLOUD Act, Schrems II, the Digital Markets Act.

What this means for you

Security headers

HTTPS enforced: yes. Security headers score: 68/100.

No major issues detected in HTTP security headers.

Take action

Recently audited sites

This report was generated by the Dazr website privacy check. The audit fetches the public home page of strava.com, identifies tracker requests, classifies their owners and jurisdictions, and grades the result. Reports refresh when re-run via the live tool.

Audited 7 October 2026. Last cached 7 October 2026.