This policy lists every cookie and every item of browser storage The Next Race uses, what each one is for and how long it lasts. It covers thenextrace.run, app.thenextrace.run and the Android application, and should be read with the Privacy Policy.
The short version. One cookie, and it exists to keep you signed in. There are no advertising cookies, no analytics cookies and nothing that tracks you across other websites. Everything else the Service stores stays in your own browser and is never sent anywhere.
1. Why there is no consent banner
Storing or reading information on your device is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). Consent is required, except where the storage is strictly necessary to provide a service that you have expressly requested.
Every item listed below falls within that exemption: each one either signs you in, remembers a setting you chose, or holds a copy of your own data so the Service works without a connection. None of them is used for advertising, measurement or tracking. Since there is nothing to consent to, no banner is shown. If that ever changes, consent will be sought before any non-essential storage is set, and this policy will be updated first.
Where the stored data is personal data, it is also processed under the UK GDPR on the bases set out in section 4 of the Privacy Policy.
2. Cookies
The Service sets one cookie of its own.
| Name | Purpose | Duration | Type |
|---|---|---|---|
rc_sess |
Keeps you signed in, and authenticates requests for your own uploaded files. It exists because an image tag cannot carry an authorisation header, and the alternative, putting a credential in the address, would write it into your browser history. The cookie holds an opaque session reference and no personal data. It is set only after you have successfully signed in. | 30 days, or until you sign out | Strictly necessary · first party |
rc_sess is HttpOnly, so no script on the page can read it;
Secure, so it is only ever sent over HTTPS; and SameSite=Lax, so
another website that embeds a link to your files receives no cookie and no access. Only a
one-way hash of the session is stored on the server, so the database never holds a usable
credential.
Cookies set by Google when you sign in
Signing in loads Google Identity Services from accounts.google.com. Google may set
or read its own cookies on its own domain as part of authenticating you. Those cookies are set
by Google as controller, are not readable by The Next Race, and are governed by
Google's privacy policy and
the cookie settings on your Google Account. The Service sets no third-party cookie of its own.
3. Browser storage on this device
Most of what the Service remembers is kept in localStorage, not in a cookie.
The practical difference matters: a cookie is sent to the server with every request, whereas
local storage stays on your device and is read only by the page itself.
None of the items below is transmitted to any server, though several are
copies of data the Service already holds for you.
Your settings
| Key | What it holds | Duration |
|---|---|---|
theme_mode, palette | Light, dark or system, and the colour palette you picked | Until cleared |
training_unit | Whether distances show in kilometres or miles | Until cleared |
home_currency | The currency trip costs are converted to | Until cleared |
home_location | The place your travel times and nearest-race sorting are measured from | Until cleared |
event_layout | How a race page is laid out | Until cleared |
reduce_motion | Whether animations are reduced | Until cleared |
tp_cal_colour, tp_prog_style, plan_coaching | Training plan display and coaching style | Until cleared |
rc_dnsdnf_open, rc_gb_auto, rc_trashwarn_*, nostalgia_dismissed_* | Small interface states: a section left open, a prompt you dismissed | Until cleared |
The settings in the first six rows are also synchronised to your account, so the same choices follow you to another device. The rest are local to this browser.
Working offline
| Key | What it holds | Duration |
|---|---|---|
rc_cache_* | A copy of your races, runs and plans, so the app opens and shows something with no connection | Replaced on each load; cleared on sign-out and when a new version ships |
rc_offline_queue | Changes you made while offline, held until they can be sent | Until sent |
rc_trip_*, rc_rmt_* | Trip documents and your race-morning timeline, kept readable on the day even with no signal | Until cleared |
rc_seen_* | What a race looked like last time you opened it, so "what changed" can be shown | Until cleared |
rc_predlog_*, rc_heatcalib_v1 | Past prediction figures and a heat-tolerance calibration, used to keep estimates consistent | Until cleared |
| Weather cache | The last forecast fetched for a place and date, so reopening a race is instant | Short-lived, then refetched |
Files stored for offline use
| Store | What it holds | Duration |
|---|---|---|
Service worker cache (shell-*) | The application itself: page, fonts, icons and map library, so it opens without a connection | Replaced on each new version; old versions removed automatically |
Map tile cache (rc-fly-tiles-*) | Map imagery for a course you chose to save for offline use. Only ever created by you tapping the download control, which states the size first | Until you remove it, up to a fixed number of saved courses |
4. The Android application
The Android app displays the same web application inside a system web view, so the cookie and storage above behave as they do in a browser. In addition, the app keeps your preferences and a small summary of your next race in Android's own app storage, so the home-screen widget, reminders and offline screen can work while the app is closed. That data stays on the device and is removed when the app is uninstalled or its storage is cleared in Android settings.
The app contains no advertising or analytics software development kit.
5. Removing or refusing this storage
- Sign out in the Service. This clears the session cookie and the cached copy of your data.
- Clear site data in your browser for
app.thenextrace.run. This removes the cookie, local storage and the offline caches in one step. - Block cookies in your browser settings. You may do so, but signing in will not work and your uploaded photographs will not load, because
rc_sessis what authorises them. - Remove a saved offline map from the download control on the course it belongs to.
- Android: clear the app's storage, or uninstall it, from Android settings.
Clearing this storage removes nothing from your account. Your races, runs and plans are held on the server and reappear when you sign in again. To delete the account data itself, see section 10 of the Privacy Policy.
6. Changes to this policy
This policy is updated whenever a cookie or storage item is added, changed or removed. The version and date at the top of the page show the current version. A non-essential cookie would require your consent before being set, and this policy would be updated before it was introduced.
7. Contact
Data protection, The Next Race
privacy@thenextrace.run
You may also complain to the Information Commissioner's Office, the UK supervisory authority for both the UK GDPR and PECR, at ico.org.uk/make-a-complaint or on 0303 123 1113.