The Next Race

Privacy Policy

Version 1.0 · In force from 7 September 2026

This policy explains what personal data The Next Race collects, why it is held, who it is shared with, how long it is kept and what rights you have over it. It applies to the website at thenextrace.run, the web application at app.thenextrace.run, and the Android application published as com.dreamvisual.racecalendar (together, "the Service").

The short version. The Service holds the training, race, travel and wellness data you put into it or connect to it. It is not used to advertise to you, it is not sold or shared for anyone else's marketing, it is not used to train machine learning models, and there are no analytics or tracking cookies. Health data from a connected wellness device is used only with your explicit consent, and you can withdraw that consent and delete the data at any time.

1. Who is responsible for your data

The Next Race is the data controller for the personal data described in this policy, within the meaning of the UK General Data Protection Regulation (UK GDPR) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018. A controller is the party that decides why and how personal data is processed.

The Service is operated from the United Kingdom. Contact details are in section 15. No data protection officer is appointed, because the Service does not meet the criteria in Article 37 UK GDPR; correspondence about data protection should be sent to the contact address below.

2. The personal data collected

Personal data means information relating to an identified or identifiable living individual. The Service processes the following categories.

Account and identity data

You sign in with a Google Account. Google returns a signed identity token from which the Service reads your email address, display name, a stable Google account identifier and, where present, a link to your profile picture. The Service never receives, sees or stores your Google password.

Training and activity data

Wellness and health data

If, and only if, you connect a wellness account: daily readiness score, sleep duration and sleep score, resting heart rate, heart rate variability and its balance, body temperature deviation, blood oxygen saturation, an estimated VO2 max, a daily stress indication, and any day you mark yourself unwell. This is health data and is treated as special category data. See section 3.

Race, travel and trip data

Location data

A home location you enter as free text, the locations of races you add, accommodation addresses you enter, and the GPS tracks described above. The Service does not request or use your device's live location.

Preferences and settings

Units, currency, theme and palette, notification choices, coaching style, and similar display settings.

Technical data

There is no analytics package, no advertising technology and no cross-site tracking on the Service.

3. Health data and explicit consent

Data about your sleep, heart rate, heart rate variability, body temperature, blood oxygen and recorded illness is data concerning health and is therefore special category data under Article 9(1) UK GDPR. Processing it is prohibited unless a condition in Article 9(2) applies.

The condition relied on is Article 9(2)(a): your explicit consent. That consent is given by the deliberate act of connecting a wellness account and authorising the Service to read it. No health data is collected unless you take that step.

You may withdraw consent at any time by disconnecting the account in the Service's settings. Withdrawal does not affect the lawfulness of processing carried out before it. On withdrawal the Service stops retrieving new health data; to remove health data already held, use the deletion right in section 10.

Heart rate and cadence recorded during an activity are also data concerning health. They are processed on the same basis, by the deliberate act of connecting the activity account they come from.

4. Lawful bases for processing

Article 6(1) UK GDPR requires a lawful basis for every processing operation.

PurposeLawful basis
Creating and maintaining your account; authenticating youArticle 6(1)(b), performance of a contract with you
Storing and displaying your races, training, plans, trips and packing listsArticle 6(1)(b), performance of a contract
Importing activity data from a service you have connectedArticle 6(1)(b), and Article 9(2)(a) explicit consent for the heart rate and cadence within it
Importing wellness and sleep data from a service you have connectedArticle 6(1)(a) consent, and Article 9(2)(a) explicit consent
Retrieving weather, travel and geographic information for a race you have addedArticle 6(1)(b), performance of a contract
Sending you reminders and alerts you have enabledArticle 6(1)(a), consent, withdrawable in settings
Rate limiting, abuse prevention and keeping the Service secureArticle 6(1)(f), legitimate interests in protecting the Service and its users
Recording errors so faults can be found and fixedArticle 6(1)(f), legitimate interests in a working and reliable service
Keeping records needed to answer a legal claim or a regulatorArticle 6(1)(c), legal obligation, and Article 6(1)(f)

Where legitimate interests are relied on, that interest has been balanced against your rights and freedoms. The processing concerned is limited to what is needed to keep the Service running safely, and you may object to it under section 10.

5. Where the data comes from

6. Who your data is shared with

Your personal data is not sold, rented or shared for anyone else's marketing, and it is not used to train machine learning or artificial intelligence models. It is disclosed only as set out below.

Processors acting on instructions

ProcessorRoleData involved
CloudflareHosting, database, file storage, content delivery and network security for the whole ServiceAll stored data, and network data such as your IP address
Google (Identity Services)Sign-inYour Google identity, handled by Google under its own policy

Third parties you connect, acting as their own controllers

Connecting an account causes data to flow between that provider and the Service. Each provider handles your data under its own privacy policy, which you should read before connecting.

ServiceDirectionData involved
StravaRead into the ServiceActivities, splits, routes, heart rate, cadence, gear
OuraRead into the ServiceReadiness, sleep, resting heart rate, HRV, temperature, SpO2
intervals.icuWritten from the Service, at your requestPlanned workouts you choose to send to your watch

Information providers

To show a forecast, a route, a journey time or a landmark, the Service asks external providers for information about a place or a coordinate. These requests are made by the Service's own servers, not by your browser, and carry no account identifier, no name and no email address. The providers are: Open-Meteo (weather, air quality and elevation), Open Topo Data (elevation), OpenStreetMap-based geocoding and routing services including Nominatim, Photon, Valhalla and Stadia Maps, Overpass, Wikidata and Wikipedia (landmarks and images), Protomaps (map tiles), AeroDataBox (flight status), Realtime Trains and Transport for London (train and underground times), and Frankfurter (exchange rates).

A coordinate you supply, such as a race start or an accommodation address, is personal data in context even though it is sent without your name attached. It is sent only for the specific lookup you asked for.

Other disclosures

Data may also be disclosed where required by law, court order or a regulator; where necessary to establish, exercise or defend legal claims; and to a successor entity if the Service is transferred, in which case you will be told before your data becomes subject to a different policy.

7. International transfers

Some of the recipients above process data outside the United Kingdom. Where personal data is transferred out of the UK, one of the following applies:

Content delivery networks serve static files from the location nearest to you, which may be outside the UK. You may request details of the safeguards applied to a particular transfer using the contact address below.

8. How long data is kept

DataRetention
Account, races, training, trips, wellness and uploaded filesFor as long as your account is open. Deleted on request, or when the account is closed.
Items you delete inside the ServiceHeld in a recoverable bin for 30 days, then permanently removed.
Sign-in sessions30 days from issue, or immediately on sign-out. Only a one-way hash of the session token is stored, never the token.
Access tokens for connected accountsUntil you disconnect the account, or the provider expires them. Stored encrypted.
Error recordsKept while useful for diagnosis and cleared periodically. Not used to build a profile of you.
Cached lookups (weather, geocoding, route data)Short-lived, from minutes to one month, then discarded.
IP address for rate limitingTransient, in a counter measured in minutes. Not stored against your account.

9. Security

Article 32 UK GDPR requires measures appropriate to the risk. The following are in place:

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, it will be reported to the Information Commissioner's Office within 72 hours as required by Article 33, and you will be told without undue delay where Article 34 requires it.

10. Your rights

Under the UK GDPR you have the right to:

Requests are answered within one month, extendable by two further months for complex requests, in which case you will be told within the first month. There is no charge unless a request is manifestly unfounded or excessive. Identity may need to be verified before a request is actioned.

11. Automated decision-making and profiling

The Service calculates predictions and estimates from your data, including a predicted finish time, a fitness and fatigue estimate, a readiness score and a training load risk indication. These are analytical outputs shown to you as information. They produce no legal effect and no similarly significant effect within the meaning of Article 22 UK GDPR: nothing is decided about you, no access is granted or refused, and the figures are advisory. You remain free to disregard them.

12. Children

The Service is not intended for children and is not directed at them. It is not knowingly offered to anyone under 18, and no attempt is made to collect data from children. If you believe a child has provided personal data, contact the address below and it will be deleted.

13. Cookies and local storage

The Service uses one strictly necessary cookie to keep you signed in, and stores settings and an offline copy of your own data in your browser. There are no advertising, analytics or tracking cookies, which is why no consent banner is shown: the Privacy and Electronic Communications Regulations 2003 exempt storage that is strictly necessary to provide a service you have requested. Full detail is in the Cookie Policy.

14. Changes to this policy

This policy may be updated to reflect changes to the Service or to the law. The version number and date at the top of this page always show the current version. Where a change materially affects how your data is used, you will be told in the Service before it takes effect, and where the change relies on your consent, you will be asked for it again.

15. Contact and complaints

To exercise any right in section 10, ask a question about this policy, or request details of a particular international transfer, write to:

Data protection, The Next Race
privacy@thenextrace.run

If you are not satisfied with the response, you have the right to complain to the UK's supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk/make-a-complaint

You may complain to the ICO without contacting us first, though raising it directly is usually quicker.