Privacy Policy · Run Love Sprint
Legal & Privacy

Privacy Policy

Last updated: 2 July 2026  ·  Questions? hello@runlovesprint.com

01 Who we are

Run Love Sprint Ltd is a company registered in England and Wales (company number 17113721). We operate the Run Love Sprint platform, a social running community app and website at runlovesprint.com.

Run Love Sprint Ltd is the data controller for all personal data collected through our platform. If you have any questions about this policy or how we handle your data, contact us at hello@runlovesprint.com.

02 What data we collect

Account and profile data

  • Identity: Display name, username, date of birth, gender
  • Contact: Email address (from sign-up, Sign in with Google, or Sign in with Apple, including via Apple's private email relay if you choose to hide your email)
  • Profile content: Photos, headline, bio, running pace, weekly distance, experience level, what you're looking for (running mates, dates, etc.)
  • Optional: Sexuality (only if you choose to display it), Strava profile URL

Coach and pacer profiles

If you list yourself as a coach or pacer, we also collect: your coach or pacer status, qualifications and certifications you choose to share, hourly rates, availability, delivery type (in person, online, hybrid), and distances you offer.

Location data

Your location is approximate, based on the London neighbourhood you select during onboarding. We use this to show you nearby runners, runs, and events. We do not use your device's GPS.

Activity data

  • Runs you create, join, or attend
  • Groups and events you interact with
  • Connections you make and messages you send
  • Ticket counts, actions that earned tickets (connections made, runs joined, referrals completed, etc.), draws entered, and any prizes won
  • Partner offers viewed through RLS Rewards

Referrals

If you make a referral, we collect the referee's name and email address to send them an invitation. Status (pending, accepted, expired) is tracked against your account.

Premium interest

If you express interest in Premium features via the in-app form, we collect: name, email address, phone number (optional), and your message. This is held separately from your account and used only to contact you about Premium availability.

Pre-registration data

  • Name, email address, and stated interests submitted via the "Register your interest" form on our website, before creating an account

Technical data

  • Sign-in identifiers from Google or Apple when you use those authentication methods
  • IP address, browser type, device type and operating system
  • Pages visited and features used (via analytics; see Section 05)
  • App crash reports and error logs
  • Push notification tokens, including platform identifier (iOS or Android), to deliver notifications to your device. These are managed via Firebase Cloud Messaging (see Section 05)
🔒 Premium charging is not yet enabled. When introduced, payments will be processed by the relevant app store and we will update this policy accordingly. Run Love Sprint does not currently store or process payment card information.

03 How and why we use your data

Purpose Legal basis (UK GDPR)
Creating and managing your account Contract: necessary to provide the service
Showing your profile to other users in Discover Contract: core feature of the platform
Connecting you with other runners (Mate, Date, Sprint) Contract: core feature of the platform
Run, group, and event management Contract: core feature of the platform
Sending transactional emails (account confirmation, password reset, access links) Contract: necessary to provide the service
Sending pre-launch and launch communications to those who have registered interest Consent: you opted in via the registration form
Displaying distance to nearby runners, runs, and partner stores Legitimate interest: core community feature based on neighbourhood selection
Analytics: understanding how the platform is used Consent: only after you accept analytics cookies
Crash reporting and error monitoring Legitimate interest: maintaining a safe, functioning service. Crash reporting is enabled by default in the mobile app. A future update will introduce an opt-out mechanism.
Safety, fraud prevention, and moderation Legitimate interest: protecting users and the integrity of the platform
Complying with legal obligations Legal obligation

04 Special category data

Some data we collect is classified as special category data under UK GDPR and requires additional care. This applies to:

  • Sexuality: You may optionally disclose your sexuality on your profile. This is never required. If you choose to share it, it is used for: (a) displaying on your profile to other users you have chosen to share it with via your privacy settings; (b) matching preferences if you have chosen to filter potential connections by sexuality; (c) eligibility for runs or events with sexuality-based visibility restrictions. We do not share this data with third parties or use it for targeted advertising.
  • Date of birth: Used solely to confirm you are 18 or over. Your age is calculated from your date of birth and displayed on your profile and in Discover. Your exact date of birth is never visible to other users.
ℹ️ The legal basis for processing special category data where you have voluntarily provided it is explicit consent (Article 9(2)(a) UK GDPR). You can withdraw consent and remove this data at any time through your profile settings.

05 Third-party services

We use the following third-party services to operate RLS. Each processes your data only as necessary to provide the relevant service.

Service Purpose Data processed Privacy policy
CookieYes Cookie consent management Consent preferences cookieyes.com/privacy-policy
Firebase Cloud Messaging Push notification delivery Device push tokens, platform identifier firebase.google.com/support/privacy
Firebase Crashlytics Crash reporting and error monitoring Crash logs, user ID linked to crash reports. Crash reporting is enabled by default in the mobile app. A future update will introduce an opt-out mechanism. firebase.google.com/support/privacy
Apple Sign In Service Account authentication and user verification Email address (or Apple's private relay email if you chose to hide it), Apple ID identifier, name (if you chose to share it) apple.com/legal/privacy/en-ww
Google Identity Services (Sign in with Google) Authentication via Google account Email address, basic profile information (name, profile photo if shared by user) policies.google.com/privacy
Mapbox Maps, geocoding, location search Search queries, coordinates for displayed pins mapbox.com/legal/privacy
Resend Transactional email delivery Name, email address resend.com/legal/privacy-policy
Supabase Database, authentication, file storage All account and profile data supabase.com/privacy
Vercel Web hosting and deployment IP address, request logs vercel.com/legal/privacy-policy

All third-party processors are contractually required to process your data only on our instructions and in accordance with UK GDPR.

06 Data storage and transfers

Your data is stored on Supabase infrastructure hosted in the European Union. Vercel serves our web platform from servers that may include locations outside the UK and EEA.

Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or reliance on adequacy decisions, in accordance with UK GDPR Chapter V.

07 How long we keep your data

Data type Retention period
Active account data Held for as long as your account is active
Deleted account data Profile hidden immediately on deletion request; personal data removed within 30 days (completed manually by the RLS team during beta)
Pre-registration interest data Held until you create an account or request removal, whichever is sooner
Messages Retained while either participant's account is active; permanently deleted when both participants have deleted their accounts
Transaction and legal records Up to 7 years where required by law
Analytics data Aggregated and anonymised; not linked to individual accounts
ℹ️ When you delete your account, your profile is immediately hidden from other users. All personally identifiable data is permanently deleted within 30 days. During the beta period, this 30-day purge is completed manually by the RLS team. As the platform develops, we will automate this process. This cannot be undone.

08 Your rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Ask us to correct inaccurate or incomplete data
  • Erasure: Ask us to delete your data (your "right to be forgotten"). You can also do this directly by deleting your account in Settings
  • Restriction: Ask us to restrict processing of your data in certain circumstances
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal

To exercise any of these rights, email hello@runlovesprint.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data correctly.

If you are a resident of the European Union, equivalent rights apply under EU GDPR. You also have the right to lodge a complaint with your local data protection authority. We are based in the UK; the ICO is named above for UK residents.

09 Children and age restrictions

⚠️ Run Love Sprint is strictly for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered, please contact us immediately at hello@runlovesprint.com and we will remove the account promptly.

We collect date of birth during registration to confirm users are 18 or over. By providing this information, users confirm it is true. Any account found to belong to someone under 18 is removed immediately.

10 Cookies

We use cookies and similar technologies on our website. For full details of the cookies we use, the purposes they serve, and how to manage your preferences, please see our Cookie Policy.

Cookies are used only on our website (runlovesprint.com). The native mobile app does not use cookies. Crashlytics, local app caching, and push notification tokens are separate technologies covered elsewhere in this policy.

11 Security

We take the security of your personal data seriously. Our security measures include:

  • All data encrypted at rest in Supabase, and transmitted over HTTPS/TLS encryption
  • Row-level security (RLS) policies on all database tables, users can only access data they are authorised to see
  • Authentication handled by Supabase Auth and (for users who choose it) Google Identity Services, with industry-standard session management and token handling
  • No passwords stored in plain text
  • Regular security reviews of our codebase and database policies

If you discover a security vulnerability, please report it responsibly to hello@runlovesprint.com.

12 Changes to this policy

We will update this policy when we change how we collect or use personal data. The date at the top of this page reflects the most recent update. If we make significant changes, we will notify you by email or through the app before the changes take effect.

13 Contact us

For any questions, requests, or concerns about your personal data:

✉️
Run Love Sprint Ltd
hello@runlovesprint.com
Company number 17113721  ·  Registered in England and Wales

You can also contact the ICO directly if you have concerns about how we handle your data: ico.org.uk/concerns