Last updated 6 August 2026
Domestique exists to tell you when part of your bike is due for attention. To do that it needs to know how far you have ridden and on which bike. Everything we collect serves that purpose, and we have tried hard to collect nothing that does not.
The rest of this page sets out the detail. It describes the software as it actually behaves, not as a general statement of intent.
Domestique is operated by KD Technology Services Pty Ltd (ABN 80 673 305 783), Newtown NSW 2042, Australia. In this policy, "we", "us" and "our" mean that company, and it is the entity responsible for the information described here.
It is also the entity you deal with if you want a copy of your information, want something corrected, or want to make a complaint. Those requests go to the address at the end of this page and are handled by a person, not a queue.
This policy covers the Domestique application, including the rider app and the workshop console used by partner bike shops. It applies to riders who create an account, and to shop staff who are given access to a workshop console.
Domestique is currently in closed testing. Accounts are created by invitation only, and the number of participants is deliberately small. Some features described here may change before general release; this page will be updated when they do.
Information you give us when you create an account: your mobile number, which is how invitations are issued and identity is proved; an email address, which becomes your sign-in and where service reminders are sent; and a password, which is stored only as a cryptographic hash and is never visible to us.
Information Strava gives us, with your permission and only after you authorise it on Strava's own screen: your Strava display name, profile photo and the city on your profile; the bikes on your Strava gear list, with their names and recorded distances; and, for each ride, the activity name, sport type, distance, moving time, start time and which bike it was tagged to.
We do not receive or store your route. No GPS coordinates, no map data, no start or end locations, no segments and no heart rate, power or other biometric streams. Domestique needs to know that a ride happened, how far it was, and on which bike. It has no use for where you were, so it does not ask for it.
Information you record yourself: the components fitted to each bike and their condition; service history, including dates, costs and notes; fit measurements, if you choose to record them; photographs you upload; marketplace listings and the messages you send about them; and your reminder preferences, timezone and units.
Technical information needed to operate the service: a push notification token if you enable notifications on a device, and server logs recording that a request happened and whether it succeeded. Logs are used for diagnosing faults and are not used to build a profile of you.
We do not use your information to build advertising profiles, we do not sell or rent it, and we do not share it with data brokers. There are no third-party analytics or advertising trackers embedded in the application.
A workshop can only raise a quote against a rider who has chosen to affiliate with it. That choice is made by you, in the app, and can be withdrawn in the same place at any time. No action by a shop can add you to its customer list, and there is no directory of riders for shops to search.
A shop you have affiliated with can see your name, or the display name from your Strava profile, and your email address. That is what it needs to raise a quote against the right person.
A shop cannot see your bikes, their makes or models, or how many you own. It cannot see your wear counters, your mileage, or what is coming due. It cannot see your service history, including work carried out by any other shop. A workshop quotes on what is in front of it on the stand, not on what the app knows about you.
Once a quote has been raised, that shop can see the quote it wrote, your response to each line of it, and the work it subsequently carried out. If you remove the affiliation, the shop keeps the records of jobs it has already done — as any business must for its own accounts — but can raise nothing new.
Verification codes and some notifications are sent by SMS. These are sent through a shared gateway, which means they arrive from a number that is not unique to Domestique and that is used by other applications operated by the same provider.
Two consequences worth stating plainly. Replies to that number do not reach us, and every message we send points you back into the app, where any response is recorded against the correct job. And the content of an SMS is, by the nature of the medium, not encrypted end to end — so our messages never contain more than a short code or a brief notice with a link.
If you set a PIN to lock the app, that PIN never leaves your device. It is not sent to us, it is not stored in our database, and it is not recoverable by us or by anyone with access to our systems.
What is kept on the device is a salted hash, derived using PBKDF2 with SHA-256 over at least 100,000 iterations and a random salt. If you forget the PIN, the only remedy is to clear it on the device — we cannot retrieve it for you, which is the point.
Application data is stored in a managed PostgreSQL database provided by Supabase, hosted in the Asia-Pacific region. Access is governed by row-level security, which means each rider's records are scoped to their own account at the database itself rather than by the application asking politely.
Your Strava access and refresh tokens are held in Supabase Vault, an encrypted secret store. The application's own tables hold references to those secrets, not the tokens themselves, so a person reading the database tables cannot use what they find there to reach your Strava account.
We rely on a small number of processors, each for a single purpose: Strava, for the ride and gear data you have authorised; Supabase, for database, authentication and file storage; Resend, for sending email; Expo, for delivering push notifications to devices; and an SMS gateway operated by the same provider as this application, for text messages. Each receives only what it needs to perform its function.
Some of these processors operate outside Australia. Where information is transferred overseas, it is transferred for the purposes described in this policy and no other.
Domestique connects to Strava using OAuth. You authorise the connection on Strava's own screen, and we never see or store your Strava password. We request read access to your activities and gear, and nothing beyond that.
You can disconnect at any time, from within Domestique or from your Strava account settings. Disconnecting stops all further synchronisation immediately and removes the stored tokens. Rides already synchronised remain in your Domestique history, because they are part of the service record for your bikes — deleting your account removes those as well.
We keep your information for as long as your account exists, because the value of a service history is precisely that it is long-lived. A chain fitted three years ago is only useful information if the record of it is still there.
Verification codes expire within minutes and are deleted once used. Server logs are retained for a short period for fault diagnosis. If you delete your account, your data is removed as described below.
You can delete your account from the Rider screen. Doing so removes your bikes, components, service history, fit records, marketplace listings, messages, notifications, reminder preferences, quotes and Strava connection, including the stored tokens.
Some records survive deletion in a form that is no longer connected to you. A workshop that carried out paid work retains its own record of that job, as any business must for tax and warranty purposes. Aggregate operational data, which contains nothing that identifies an individual, may also be retained.
Deletion is not reversible. If you want a copy of your data first, ask us before you delete and we will provide it.
You may ask us for a copy of the information we hold about you, ask us to correct it if it is wrong, ask us to delete it, or object to a particular use of it. Requests are handled within a reasonable period and at no cost.
KD Technology Services Pty Ltd is an Australian company, and this policy is intended to operate consistently with the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you are in the United Kingdom or the European Economic Area, you also have rights of access, rectification, erasure, restriction, portability and objection under the applicable data protection law, and a right to complain to your local supervisory authority.
If you are not satisfied with how we have handled a privacy matter, tell us first and we will try to put it right. If that does not resolve it, you may complain to the Office of the Australian Information Commissioner.
All traffic between the app and our servers uses HTTPS. Passwords are stored as hashes and never in plain text. Access to each rider's records is enforced at the database by row-level security, so a fault in the application cannot expose one rider's data to another. Sensitive credentials, including Strava tokens, are held in an encrypted secret store rather than in ordinary database columns.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your information, we will tell you and the relevant regulator as required by law, and we will tell you what actually happened rather than the least alarming version of it.
Domestique is not intended for children under 16, and connecting it to Strava requires a Strava account, which has its own age requirements. We do not knowingly collect information from children under 16. If you believe a child has created an account, contact us and we will remove it.
We will update this page when the software changes in a way that affects what we collect or how we use it, and the date at the top will change with it. Where a change materially affects your privacy, we will tell you in the app or by email rather than relying on you to notice.
For any question about this policy, or to make a request about your information, email us. A person reads that address, and we would rather hear about a concern early than late.
KD Technology Services Pty Ltd, ABN 80 673 305 783, Newtown NSW 2042, Australia.