Strava's Flyby feature and Beacon feature can share your live or recent location data with other users, allowing them to see where you were during an activity or where you are in real time.
These features can expose your precise real-time or recent location to other Strava users, including your home start/end point, which poses significant personal safety risks especially for vulnerable users.
Real-time and retrospective location sharing features raise GDPR lawful basis and data minimisation concerns, and may engage personal safety obligations under applicable law. The Flyby feature has a history of regulatory and press scrutiny. Compliance teams should assess whether opt-in consent (rather than opt-out) is the appropriate mechanism for these high-risk sharing features.
Compliance intelligence locked
Regulatory citations, enforcement risk, and due diligence action items.
Watcher: regulatory citations. Professional: full compliance memo.
Strava collects highly sensitive personal data including precise GPS location, health metrics, and fitness activity, which is used for AI model training, advertising, and publicly accessible features like the Global Heatmap. Consumers should be aware that even with default settings, their anonymized or aggregated activity data may contribute to public features visible to anyone. You can adjust your privacy controls in Strava account settings at https://www.strava.com/settings/privacy to limit data visibility and opt out of certain data uses.