This policy explains what personal data The Next Race collects, why it is held, who it is
shared with, how long it is kept and what rights you have over it. It applies to the website
at thenextrace.run, the web application at app.thenextrace.run, and the Android application
published as com.dreamvisual.racecalendar (together, "the Service").
The short version. The Service holds the training, race, travel and wellness data you put into it or connect to it. It is not used to advertise to you, it is not sold or shared for anyone else's marketing, it is not used to train machine learning models, and there are no analytics or tracking cookies. Health data from a connected wellness device is used only with your explicit consent, and you can withdraw that consent and delete the data at any time.
1. Who is responsible for your data
The Next Race is the data controller for the personal data described in this policy, within the meaning of the UK General Data Protection Regulation (UK GDPR) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018. A controller is the party that decides why and how personal data is processed.
The Service is operated from the United Kingdom. Contact details are in section 15. No data protection officer is appointed, because the Service does not meet the criteria in Article 37 UK GDPR; correspondence about data protection should be sent to the contact address below.
2. The personal data collected
Personal data means information relating to an identified or identifiable living individual. The Service processes the following categories.
Account and identity data
You sign in with a Google Account. Google returns a signed identity token from which the Service reads your email address, display name, a stable Google account identifier and, where present, a link to your profile picture. The Service never receives, sees or stores your Google password.
Training and activity data
- Runs and rides: date, start time, distance, duration, pace, elevation gain, heart rate, cadence, per-kilometre and per-mile splits, and the activity name and description.
- Route data: the recorded GPS track of each activity, stored as an encoded polyline. A GPS track can reveal where you live, work and habitually run.
- Footwear and equipment names and their accumulated mileage, where a connected account supplies them.
- Planned training: training plans, individual sessions, workouts you build, and any notes on them, including injury or "niggle" notes you choose to record.
Wellness and health data
If, and only if, you connect a wellness account: daily readiness score, sleep duration and sleep score, resting heart rate, heart rate variability and its balance, body temperature deviation, blood oxygen saturation, an estimated VO2 max, a daily stress indication, and any day you mark yourself unwell. This is health data and is treated as special category data. See section 3.
Race, travel and trip data
- Races you have entered, are considering, or have completed, with dates, distances, entry status, goal times, results, bib numbers, wave or corral allocations and your own notes.
- Course files you upload, including GPX route files and race information packs, and anything they contain.
- Travel itineraries: flight numbers, train services, departure and arrival times, booking references you choose to record, accommodation names and addresses, check-in and check-out times, and journey costs.
- Packing lists and templates.
- Photographs you upload, including any location or device metadata embedded in them.
Location data
A home location you enter as free text, the locations of races you add, accommodation addresses you enter, and the GPS tracks described above. The Service does not request or use your device's live location.
Preferences and settings
Units, currency, theme and palette, notification choices, coaching style, and similar display settings.
Technical data
- Your IP address, processed transiently to apply rate limits and to protect the Service against abuse. It is not stored against your account.
- Error records, which may include the failing operation, a timestamp and a message. These are kept to diagnose faults.
- Standard network information handled by the hosting provider, such as request timing and status codes.
There is no analytics package, no advertising technology and no cross-site tracking on the Service.
3. Health data and explicit consent
Data about your sleep, heart rate, heart rate variability, body temperature, blood oxygen and recorded illness is data concerning health and is therefore special category data under Article 9(1) UK GDPR. Processing it is prohibited unless a condition in Article 9(2) applies.
The condition relied on is Article 9(2)(a): your explicit consent. That consent is given by the deliberate act of connecting a wellness account and authorising the Service to read it. No health data is collected unless you take that step.
You may withdraw consent at any time by disconnecting the account in the Service's settings. Withdrawal does not affect the lawfulness of processing carried out before it. On withdrawal the Service stops retrieving new health data; to remove health data already held, use the deletion right in section 10.
Heart rate and cadence recorded during an activity are also data concerning health. They are processed on the same basis, by the deliberate act of connecting the activity account they come from.
4. Lawful bases for processing
Article 6(1) UK GDPR requires a lawful basis for every processing operation.
| Purpose | Lawful basis |
|---|---|
| Creating and maintaining your account; authenticating you | Article 6(1)(b), performance of a contract with you |
| Storing and displaying your races, training, plans, trips and packing lists | Article 6(1)(b), performance of a contract |
| Importing activity data from a service you have connected | Article 6(1)(b), and Article 9(2)(a) explicit consent for the heart rate and cadence within it |
| Importing wellness and sleep data from a service you have connected | Article 6(1)(a) consent, and Article 9(2)(a) explicit consent |
| Retrieving weather, travel and geographic information for a race you have added | Article 6(1)(b), performance of a contract |
| Sending you reminders and alerts you have enabled | Article 6(1)(a), consent, withdrawable in settings |
| Rate limiting, abuse prevention and keeping the Service secure | Article 6(1)(f), legitimate interests in protecting the Service and its users |
| Recording errors so faults can be found and fixed | Article 6(1)(f), legitimate interests in a working and reliable service |
| Keeping records needed to answer a legal claim or a regulator | Article 6(1)(c), legal obligation, and Article 6(1)(f) |
Where legitimate interests are relied on, that interest has been balanced against your rights and freedoms. The processing concerned is limited to what is needed to keep the Service running safely, and you may object to it under section 10.
5. Where the data comes from
- From you, when you enter a race, upload a file, record a result or change a setting.
- From Google, when you sign in, limited to the identity fields in section 2.
- From services you connect, using OAuth authorisation that you grant and can revoke. The Service holds an access token for each connected account and uses it only to read the data described above and, where you ask it to, to write a planned workout to your calendar.
- From public information sources, such as a public race calendar entry, used to prefill race details. This is information about events, not about you.
6. Who your data is shared with
Your personal data is not sold, rented or shared for anyone else's marketing, and it is not used to train machine learning or artificial intelligence models. It is disclosed only as set out below.
Processors acting on instructions
| Processor | Role | Data involved |
|---|---|---|
| Cloudflare | Hosting, database, file storage, content delivery and network security for the whole Service | All stored data, and network data such as your IP address |
| Google (Identity Services) | Sign-in | Your Google identity, handled by Google under its own policy |
Third parties you connect, acting as their own controllers
Connecting an account causes data to flow between that provider and the Service. Each provider handles your data under its own privacy policy, which you should read before connecting.
| Service | Direction | Data involved |
|---|---|---|
| Strava | Read into the Service | Activities, splits, routes, heart rate, cadence, gear |
| Oura | Read into the Service | Readiness, sleep, resting heart rate, HRV, temperature, SpO2 |
| intervals.icu | Written from the Service, at your request | Planned workouts you choose to send to your watch |
Information providers
To show a forecast, a route, a journey time or a landmark, the Service asks external providers for information about a place or a coordinate. These requests are made by the Service's own servers, not by your browser, and carry no account identifier, no name and no email address. The providers are: Open-Meteo (weather, air quality and elevation), Open Topo Data (elevation), OpenStreetMap-based geocoding and routing services including Nominatim, Photon, Valhalla and Stadia Maps, Overpass, Wikidata and Wikipedia (landmarks and images), Protomaps (map tiles), AeroDataBox (flight status), Realtime Trains and Transport for London (train and underground times), and Frankfurter (exchange rates).
A coordinate you supply, such as a race start or an accommodation address, is personal data in context even though it is sent without your name attached. It is sent only for the specific lookup you asked for.
Other disclosures
Data may also be disclosed where required by law, court order or a regulator; where necessary to establish, exercise or defend legal claims; and to a successor entity if the Service is transferred, in which case you will be told before your data becomes subject to a different policy.
7. International transfers
Some of the recipients above process data outside the United Kingdom. Where personal data is transferred out of the UK, one of the following applies:
- the country is covered by UK adequacy regulations under Article 45 UK GDPR; or
- the transfer is made under the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018; or
- the transfer is necessary for the performance of a contract with you under Article 49(1)(b), which is the case when you connect a provider hosted outside the UK.
Content delivery networks serve static files from the location nearest to you, which may be outside the UK. You may request details of the safeguards applied to a particular transfer using the contact address below.
8. How long data is kept
| Data | Retention |
|---|---|
| Account, races, training, trips, wellness and uploaded files | For as long as your account is open. Deleted on request, or when the account is closed. |
| Items you delete inside the Service | Held in a recoverable bin for 30 days, then permanently removed. |
| Sign-in sessions | 30 days from issue, or immediately on sign-out. Only a one-way hash of the session token is stored, never the token. |
| Access tokens for connected accounts | Until you disconnect the account, or the provider expires them. Stored encrypted. |
| Error records | Kept while useful for diagnosis and cleared periodically. Not used to build a profile of you. |
| Cached lookups (weather, geocoding, route data) | Short-lived, from minutes to one month, then discarded. |
| IP address for rate limiting | Transient, in a counter measured in minutes. Not stored against your account. |
9. Security
Article 32 UK GDPR requires measures appropriate to the risk. The following are in place:
- All traffic is encrypted in transit using TLS, with HTTP Strict Transport Security enforced.
- Access tokens for connected accounts are encrypted at rest with a key held separately from the database.
- Sign-in tokens are stored only as SHA-256 hashes, so the database does not hold a usable credential.
- The session cookie is
HttpOnly,SecureandSameSite=Lax, so it cannot be read by script and is not sent from another site's pages. - A Content Security Policy restricts what the pages may load and where they may send data, and blocks injected scripts.
- Requests are rate limited at the network edge and per account.
- Every database query is scoped to the signed-in account, and an automated check in the build refuses any query that is not.
- Files you upload are served only to an authenticated session, not from a public link.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, it will be reported to the Information Commissioner's Office within 72 hours as required by Article 33, and you will be told without undue delay where Article 34 requires it.
10. Your rights
Under the UK GDPR you have the right to:
- Be informed about how your data is used, which is the purpose of this policy.
- Access a copy of your personal data (Article 15). The Service also has a self-service export that produces a complete file of your data at any time.
- Rectification of inaccurate or incomplete data (Article 16). Most data can be corrected directly in the Service.
- Erasure of your data (Article 17), including closing your account entirely.
- Restriction of processing in the circumstances set out in Article 18.
- Data portability (Article 20): a machine-readable copy of the data you provided, which the export function supplies.
- Object to processing carried out on the basis of legitimate interests (Article 21).
- Withdraw consent at any time, without affecting processing already carried out (Article 7(3)).
Requests are answered within one month, extendable by two further months for complex requests, in which case you will be told within the first month. There is no charge unless a request is manifestly unfounded or excessive. Identity may need to be verified before a request is actioned.
11. Automated decision-making and profiling
The Service calculates predictions and estimates from your data, including a predicted finish time, a fitness and fatigue estimate, a readiness score and a training load risk indication. These are analytical outputs shown to you as information. They produce no legal effect and no similarly significant effect within the meaning of Article 22 UK GDPR: nothing is decided about you, no access is granted or refused, and the figures are advisory. You remain free to disregard them.
12. Children
The Service is not intended for children and is not directed at them. It is not knowingly offered to anyone under 18, and no attempt is made to collect data from children. If you believe a child has provided personal data, contact the address below and it will be deleted.
13. Cookies and local storage
The Service uses one strictly necessary cookie to keep you signed in, and stores settings and an offline copy of your own data in your browser. There are no advertising, analytics or tracking cookies, which is why no consent banner is shown: the Privacy and Electronic Communications Regulations 2003 exempt storage that is strictly necessary to provide a service you have requested. Full detail is in the Cookie Policy.
14. Changes to this policy
This policy may be updated to reflect changes to the Service or to the law. The version number and date at the top of this page always show the current version. Where a change materially affects how your data is used, you will be told in the Service before it takes effect, and where the change relies on your consent, you will be asked for it again.
15. Contact and complaints
To exercise any right in section 10, ask a question about this policy, or request details of a particular international transfer, write to:
Data protection, The Next Race
privacy@thenextrace.run
If you are not satisfied with the response, you have the right to complain to the UK's supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk/make-a-complaint
You may complain to the ICO without contacting us first, though raising it directly is usually quicker.