Privacy notice
This site is a personal project, not a company. It processes very little and there is no advertising. Google Analytics runs only with your consent. Below is exactly what is collected, on what basis, who sees it and what you can ask for.
What is processed
Everything this site knows about you comes from one of three places:
- For the account: your email address and name. If you sign in with Google, Facebook or Discord, also the profile picture from there; your password there never passes through this site. If you upload your own photo — that, shrunk to 192 px; it shows on the leaderboard and in the menu, and you remove it from the profile. If you sign in with email and password, the password — kept only as a one-way hash it cannot be recovered from. If you turn on two-factor sign-in, the secret for the codes and the one-time recovery codes (hashed). Plus the time zone we show times in (Sofia by default).
- From you: the GPX files you upload, their names and the checkpoints on them. A GPX contains coordinates, which is location data — the route you ran or intend to run. If you claim to organise a race and the claim is approved, we also keep which organiser you represent. Emails: a reminder three days before each race you have a plan for (on by default); an email three days after the race inviting you to upload your run for analysis; short how-to emails (making a plan, putting it on the watch). All of them stop from your profile — one switch for the reminders and one for everything. We keep when you stopped them and the reason, if you gave one. Sign-in emails (confirmation, new password) always arrive.
- Your settings as a runner: target time, maximum pace, the gradient at which you start hiking, how you descend, your planned rests and technical sections. Which races you have marked “I’m registered”, “I ran it” or “Did not start” — by hand or from an uploaded run (only the count is shown to others). Plus the watch pairing code and when the watch last pulled a plan.
- If you upload a recorded run to compare against a plan: the distance along the course and the elapsed time, one point every 100 metres. The file itself is never sent — it is read in your browser — and no coordinates survive it, so there is no trace of where you were. From all your uploaded runs the site works out two factors — how much more or less time climbs and descents take you against the flat — and your future plans tune themselves to them; they are shown on every plan. Remove the comparison and the recording goes with it, and the factors are worked out again without it. Once there are enough runs, the administrator may tune the shared model on them — from the totals, without showing who ran what.
- From the watch, on every sync: its Connect IQ per-device identifier, the model's part number, the firmware version and the field's own version. The identifier survives a re-pairing — it is how two of your watches are told apart in the list, and how one left on an old version is spotted. It does not come from Garmin Connect and carries no serial number; Connect IQ does not give applications one. It goes when you unpair the watch. If the watch shows a code and you enter it here, we keep the code and who entered it for 15 minutes, then it is deleted.
- Technical: IP address and browser details in the server logs, as on any website. They are not used for profiling and are not tied to your account.
- Arrival counts: when you come from another site — Google, a social network — one counter goes up for the day, the source and the page. Your address is not kept, nor a cookie, nor any identifier, so there is no way to see that you came back. A download of the watch software also stores a one-way fingerprint of the address, mixed with the day and a secret key: it collapses your two downloads this morning into one person and links to nothing tomorrow. Kept for 90 days.
- A message from the contact form: name (optional), email and text. It goes to us by email (through Resend) and stays there — it is not kept on the site. Against spam, only a one-way fingerprint of your address and email is kept, for 15 minutes.
- Page counting by the host (Vercel): page, country, device and browser, with no cookie and no visitor id. Vercel already processes every request to this site — this is a new purpose, not a new recipient.
- When you last signed in and how many times — recorded at sign-in only, never on a page view, so that it says which accounts are still in use. Which of our notices you have dismissed, so you are not shown one twice. Your points and what they were given for (a plan, a course, a race mark, a share, a paired watch). The points leaderboard shows your name, photo, level and points, and the kinds of action they came from — by kind and count, not which races; you hide from it in Profile → “Emails & leaderboard”. A log of the actions on your account (sign-ins, plans, settings — with date and time) that only the administrator sees: for security and in case of a dispute. Kept for 12 months.
The lawful basis
- Your account, courses and plans — performance of a contract (Art. 6(1)(b)). The service cannot work without them: there is no pacing plan without a GPX and a target time.
- Logs, the action log and abuse prevention — legitimate interests (Art. 6(1)(f)) in keeping the site working and not misused. Also on legitimate interests — being listed on the points leaderboard, with a right to object: one switch in your profile and your name is gone from it.
- Consent (Art. 6(1)(a) GDPR and the ePrivacy rules) — for Google Analytics. Asked for explicitly before anything loads, and refusing does not affect anything else on the site. It can be withdrawn at any time from "Cookie settings".
Who else sees it
Nothing is sold and nothing goes to advertisers. These providers are involved in running the site:
- VercelprocessorHosts the site and runs its code.
- DigitalOceanprocessorThe machine the database runs on — accounts, courses and plans live there.
- ResendprocessorSends the emails: sign-up confirmation, the reminders before a race, the email after it and the how-to emails.
- GooglerecipientYour own account, if you sign in with it. Google learns that you signed in here.
- Meta (Facebook)recipientYour own profile, if you sign in with Facebook. We receive your name and email; Facebook learns that you signed in here.
- DiscordrecipientYour own profile, if you sign in with Discord. We receive your name and email; Discord learns that you signed in here.
- Google AnalyticsprocessorOnly if you allowed it: which pages you view, country and device, a truncated IP address, an identifier in the _ga cookie. No advertising and no Google signals. Kept for 14 months.
- OpenStreetMap FoundationrecipientMap tiles are fetched from their servers, so viewing a map sends them your IP address. Nothing else is sent.
Some of these providers are based outside the EU. Those transfers rely on the European Commission's standard contractual clauses, which they operate under.
How long it is kept
- Your account and the courses you uploaded are kept while you have an account. Delete the account and they go with it.
- One exception: a race you uploaded is a shared reference other people have built plans on. Such a course passes to the administrator rather than being deleted, and its link to you is removed.
- Sessions expire on their own within 30 days.
- If an address is banned for abuse, the address itself is kept separately — no name, no picture, nothing else — with the date and a short note why. It is the only thing that outlives deleting an account, and that is deliberate: a ban that disappears with the account is not a ban. It is kept while the ban stands; lifting it deletes the row. If you believe it is a mistake, write to the address above.
- Backups are kept for 7 days and deleted automatically. That means deleted data continues to exist in a copy for up to 7 days after deletion — lawful and ordinary, but you should know it.
Security
The connection to the site is encrypted (HTTPS). Passwords are kept only as a one-way hash, and two-factor codes hashed. The database is in the EU, reachable only by the site and the administrator, with limited sign-in attempts and automatic blocking of suspicious addresses. Backups are encrypted and delete themselves. No measure is a full guarantee — if you notice something, write to us.
Your rights
Under the GDPR you have the rights below. Write to the address above and you will get an answer within one month.
- Access and portability (Art. 15 and 20): a copy of everything held about you, in a machine-readable form.
- Rectification (Art. 16): correcting what is wrong. Most of it you can change yourself in settings.
- Erasure (Art. 17): deletion of your account and data, subject to the races exception above.
- Restriction and objection (Art. 18 and 21) to processing based on legitimate interests.
- Withdrawing consent at any time — for Google Analytics from "Cookie settings" at the bottom of every page.
Complaints
If you believe your data is being handled unlawfully you may complain to the Commission for Personal Data Protection (CPDP). I would be grateful if you came to me first — it is usually quicker. www.cpdp.bg
Changes
If any of this changes materially, the date above is updated. The site is under active development, and this notice is written to describe what the code does today rather than what is planned.