Privacy Policy

Effective date: July 2026

Racebeats, operated by SIA RACEBEATS, is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you use our platform at https://racebeats.com.

By using Racebeats, you agree to the terms of this Privacy Policy.

1. Who We Are

SIA RACEBEATS
Registered in Latvia (registration number: 40203648399)
Email: konrads@racebeats.com
Website: https://racebeats.com

2. Information We Collect

When you use Racebeats, we may collect and store the following information:

A. Account and Profile Information

  • Full name
  • Email address
  • Phone number
  • Date of birth
  • Gender
  • Country
  • Team affiliation
  • Strava avatar and profile link
  • If you sign in with an email and password, your password (stored only as a salted hash).
  • If you sign in with Google, your Google account identifier.

B. Strava Activity Data

Fetched via the Strava API with your consent:
  • Activity details (e.g., name, distance, elevation, speed, heart rate, power output)
  • GPS/route data, start date/time, and duration
  • Athlete ID (used for internal linking only)
  • Activity authenticity indicators (whether an activity was manually entered, recorded on a trainer, or virtual)

C. Participation, Results, and Events

  • Your event registrations and the results and rankings generated for you
  • Check-in records (whether and when you checked in at an event)
  • Finisher certificates, which display your name and result

D. Payment Data

For paid events, we store:
  • Amount, currency, any optional donation, and any coupon used
  • Payment status and the payment reference from our payment provider

Your card and bank details are handled directly by Stripe and are never stored by Racebeats. If you are an organizer, we store your Stripe account identifier and onboarding status so that event revenue can be paid out to you.

E. Communications

  • Emails we send you, such as account, verification, notification, invitation, and invoice messages
  • If you subscribe to our mailing list, your subscription and the version of this policy you consented to

F. Technical and Security Data

  • Your IP address, which we use for security and abuse prevention and store in hashed (non-reversible) form where possible
  • Active session and device information
  • Essential cookies and server logs

Only activities recorded using Strava are used for results. No manually uploaded, third-party, or non-Strava activity files are collected.

3. How We Use Your Information

We use your data for the following purposes, each with a lawful basis under the GDPR:
  • Providing the platform and authenticating you — to perform our contract with you.
  • Processing payments for paid events and issuing invoices — to perform our contract with you.
  • Generating statistics and rankings, and verifying results — to perform our contract and for our legitimate interest in fair competition.
  • Sending transactional emails and event notifications — to perform our contract with you.
  • Sending marketing or mailing-list emails — with your consent, which you can withdraw at any time.
  • Security, fraud and abuse prevention, rate-limiting, and login alerts — for our legitimate interest in keeping the platform safe, and to meet legal obligations.
  • Keeping financial records — to comply with legal obligations such as accounting and tax.

4. Sharing Your Information

We do not sell or rent your personal data. We share your information only in the following cases:
  • Event organizers receive your registration profile when you register for their events. They act as independent controllers of that data.
  • Other users and the public may see limited public data (such as your name, Strava avatar, and profile link) and anonymized statistics.
  • Legal disclosures may be made where required by law.
We also rely on the following service providers (sub-processors), each under its own privacy policy:
  • Strava — activity data and sign-in (privacy policy)
  • Google — sign-in (privacy policy)
  • Stripe — payment processing (privacy policy)
  • Resend — email delivery (privacy policy)
  • Better Stack (Logtail) — log management (privacy policy)
  • MongoDB Atlas — database hosting (privacy policy)

5. International Data Transfers

Some of our service providers may process your data outside the European Economic Area. Where they do, the transfer is protected by appropriate safeguards, such as the European Commission's Standard Contractual Clauses.

6. Data Retention

We keep your data only as long as necessary:
  • Account and profile data is kept until you delete your account.
  • If you delete your account, we remove your personal information and stored Strava activity data.
  • Financial and invoice records are kept for as long as the law requires (for example, for accounting and tax).
  • Security logs are kept only for a short period, in hashed form.
  • Anonymized data already included in event statistics may remain in a non-identifiable form.

7. Your Rights

Under the GDPR, you have the right to:
  • Access the data we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your account and associated data.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a portable format.
  • Withdraw consent — for example, by disconnecting your Strava account or unsubscribing from emails.

To exercise your rights, email us at konrads@racebeats.com. You also have the right to lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija).

8. Cookies and Tracking

Racebeats uses essential cookies only, necessary for:
  • User authentication
  • Protection against cross-site request forgery (CSRF)
  • Session security

We do not use advertising or third-party tracking cookies. Analytics shown to organizers are aggregate event metrics, not cross-site tracking.

9. Security

We use industry-standard practices to secure your data, including:
  • HTTPS encryption
  • Salted hashing of passwords
  • Access controls and rate-limiting
  • Regular server monitoring

While we strive to protect your data, no platform can guarantee absolute security. You use Racebeats at your own risk.

10. Children's Privacy

Racebeats is not intended for individuals under the age of 16. We do not knowingly collect personal data from children.

11. Changes to This Privacy Policy

We may update this Privacy Policy occasionally. Any significant changes will be announced on our website or emailed to you directly.

12. Contact Us

For questions or concerns about your data, contact:

SIA RACEBEATS
Email: konrads@racebeats.com