Privacy Policy
We do not sell data
RaceOS does not sell participant data, and has no commercial data-sales business. There is no "commercial" consent tier anywhere in this platform — revenue comes only from the service capabilities organizers and sponsors pay for directly, never from your data.
Why we collect data
Data is collected for two purposes only:
- Giving each participant free, personalized insight into their own performance.
- Advancing sports science through internal, anonymized computational research.
No identifiable data — names, phone numbers, or any re-identifiable record — ever leaves our anonymized boundary. Anything used for research is aggregated and de-identified first.
Consent tiers
Registration asks for consent in three separate tiers, never bundled together:
- Results — required to participate: timing, bib assignment, and publishing your result.
- Insights — optional: free personal analytics beyond your basic result.
- Research — optional: your anonymized data contributing to aggregate sports-science research.
Medical and incident data
Any medical or emergency-contact information you provide is accessed on an incident-scoped basis only — a responder can see it only while actively responding to your specific reported incident, never as standing visibility into every runner's medical data.
Optional Apple Health run data
If you choose to connect Apple Health in the Runner app, RaceOS reads heart rate, steps, walking/running distance, active energy and available running dynamics (stride length, speed, power and ground contact time) only for a run you record. Source-labelled samples are stored in your private run journal and kept distinct from GPS distance and official race timing. We do not use Apple Health data for advertising, sponsor profiling, or marketing, and you can revoke access in iPhone Health settings. Apple Health data is not added to an internal research dataset merely because you connected it.
How your data is protected
- Analytics keys use salted pseudonyms, not your real identity.
- Personal data is segregated from operational data marts.
- Aggregate outputs are k-anonymity enforced before they leave the anonymized boundary.
- Government ID, where collected for verification, is stored hashed.
- Every access to your data is logged in a full audit trail.
Marketing communications
Marketing use of your contact details always requires a separate, explicit opt-in at registration — off by default, and never bundled into the consent required just to participate in your event.
Your public roster listing
You can opt out of appearing on an event's public roster at registration — see how roster opt-out works for exactly what that does and does not affect.