This policy lists every cookie and every item of browser storage The Next Race uses, what each one is for and how long it lasts. It covers thenextrace.run, app.thenextrace.run and the Android application, and should be read with the Privacy Policy.
The short version. One cookie, and it exists to keep you signed in. There are no advertising cookies, no analytics cookies and nothing that tracks you across other websites. Everything else the Service stores stays in your own browser and is never sent anywhere. The website counts visits without cookies, and you can turn that off (section 5).
1. Why there is no consent banner
Storing information on your device, or reading information already stored there, is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). Consent is needed unless an exemption applies. Three apply here.
Strictly necessary, regulation 6(4)(b)
Storage that is strictly necessary to provide a service you have asked for needs no consent. The test is taken from your point of view, not ours: the question is whether the Service could do what you asked without it. Signing you in, holding a change you made while offline until it can be sent, and keeping a copy of your own data so the app opens on a train with no signal all meet that test. Convenience to us would not.
Remembering your display preferences
Since 5 February 2026, PECR as amended by the Data (Use and Access) Act 2025 also exempts storage whose sole purpose is to remember how you like the Service to look, provided you are told about it and have a simple, free way to say no. Your theme, palette, units and similar display choices sit here rather than under strictly necessary, because the Service would still work without them; it would just forget what you picked. You were told by this page, and the way to say no is a switch in the app, described in section 5.
Counting visits to the website
The website at thenextrace.run, though not the app, counts visits with Cloudflare Web Analytics. It sets no cookie and stores nothing on your device, but its script reads timing details from your browser, so it relies on the exemption the same Act added for statistics: counting visits only to improve the website, with nothing that identifies or follows you. Cloudflare records the page, the referring site, the browser and the country of each visit. There is no advertising, no profiling and no cross-site tracking anywhere on the Service. You can turn visit counting off with the switch in section 5.
Where the stored data is also personal data, it is processed under the UK GDPR on the bases set out in section 4 of the Privacy Policy. PECR and the UK GDPR apply together: meeting a PECR exemption does not remove the UK GDPR obligations, and this policy should be read alongside that one.
2. Cookies
The Service sets one cookie of its own.
| Name | Purpose | Duration | Type |
|---|---|---|---|
rc_sess |
Keeps you signed in, and authenticates requests for your own uploaded files. It exists because an image tag cannot carry an authorisation header, and the alternative, putting a credential in the address, would write it into your browser history. The cookie holds an opaque session reference and no personal data. It is set only after you have successfully signed in. | 30 days, or until you sign out | Strictly necessary · first party |
rc_sess is HttpOnly, so no script on the page can read it;
Secure, so it is only ever sent over HTTPS; and SameSite=Lax, so
another website that embeds a link to your files receives no cookie and no access. Only a
one-way hash of the session is stored on the server, so the database never holds a usable
credential.
Cookies set by Google when you sign in
Signing in loads Google Identity Services from accounts.google.com. Google may set
or read its own cookies on its own domain as part of authenticating you. Those cookies are set
by Google as controller, are not readable by The Next Race, and are governed by
Google's privacy policy and
the cookie settings on your Google Account. The Service sets no third-party cookie of its own.
3. Browser storage on this device
Most of what the Service remembers is kept in localStorage, not in a cookie.
The practical difference matters: a cookie is sent to the server with every request, whereas
local storage stays on your device and is read only by the page itself.
None of the items below is transmitted to any server, though several are
copies of data the Service already holds for you.
How the app looks
These are remembered so the Service looks the way you set it. They rely on the display exemption in section 1, and you can stop this device keeping them with the switch described in section 5.
| Key | What it holds | Duration |
|---|---|---|
theme_mode, palette, theme_sync | Light, dark or system, the colour palette you picked, and whether that follows you to your other devices | Until cleared |
training_unit | Whether distances show in kilometres or miles | Until cleared |
reduce_motion | Whether animations are reduced | Until cleared |
event_layout | How a race page is laid out | Until cleared |
tp_cal_colour, tp_prog_style | How the training plan calendar and progress are shown | Until cleared |
rc_ft_mode | Whether your fitness trend shows VDOT or a predicted time | Until cleared |
rc_rb_view, rc_rb_map_pos | List or map in the race listings, and where you left the map | Until cleared |
rc_dnsdnf_open | A section you left open | Until cleared |
Your details and choices
These record information you gave or a choice you made, which PECR counts as strictly necessary. Most are copies of what your account holds, so the app works before it has loaded and with no connection.
| Key | What it holds | Duration |
|---|---|---|
home_location, home_currency | The place travel times and nearest races are measured from, and the currency trip costs are totalled in | Until cleared |
home_airport | The airport flights are searched from, if you picked one | Until cleared |
birth_year, sex, body_weight_kg | Your year of birth, and your sex and body weight if you gave them | Until cleared |
plan_coaching, plan_garmin_autosync, plan_heat_watch, plan_heat_notes | Coaching style, whether planned sessions go to your watch on their own, and hot-day paces and notes | Until cleared |
race_lists, race_suggest_hidden, suggest_after_marathon | Your race lists, races you turned down, and how long after a marathon races are suggested | Until cleared |
rc_gb_auto | Whether the way back from a race is planned automatically | Until cleared |
rc_search_recent | Your recent searches | Until cleared |
rc_trashwarn_*, nostalgia_dismissed_*, rc_tripcopy_no_*, rc_note_no_* | Prompts and notes you dismissed, so they do not come back | Until cleared |
rc_keep_look | Only there if you turned off remembered display settings: your choice not to keep them | Until you turn the switch back on |
Most of the items in both tables are also synchronised to your account, so the same choices follow you to another device. Dismissed prompts, recent searches and list or map positions are local to this browser.
Working offline
These are strictly necessary under regulation 6(4)(b): without them the Service cannot do the thing you asked it to do, which is open and stay usable with no connection.
| Key | What it holds | Duration |
|---|---|---|
rc_cache_* | A copy of your races, runs and plans, so the app opens and shows something with no connection | Replaced on each load; cleared on sign-out and when a new version ships |
rc_offline_queue | Changes you made while offline, held until they can be sent | Until sent |
rc_trip_*, rc_rmt_* | Trip documents and your race-morning timeline, kept readable on the day even with no signal | Until cleared |
rc_alarms_* | The race-morning alarms you set in your phone's Clock app, so the timeline can tell you when one of its times has moved | Until cleared |
rc_seen_* | What a race looked like last time you opened it, so "what changed" can be shown | Until cleared |
rc_predlog_*, rc_heatcalib_v1, heat_k, rc_racebias_v1, rc_drift_v1 | Past prediction figures, your heat response, how your races compare with predictions, and heart-rate drift on past runs, kept so estimates stay consistent and do not have to be worked out again | Until cleared |
rc_pacing_* | Pacing plans you made for a race, so they open on race morning with no signal | Until cleared |
rc_poster_* | How you last set up a race's poster (map style, size and text), so it opens the way you left it, and a small picture of the last one you saved | Until cleared |
rc_story_* | How you last set up a race's story pictures (which ones, your headline and what you chose to hide), so they open the way you left them | Until cleared |
rc_keepsake_* | The words you changed on a keepsake picture, so it opens the way you left it | Until cleared |
rc_palette_default, rc_palettes_allowed | Which colour palettes the app offers, so it opens in the right colours before it has loaded | Replaced on each load |
rc_fly_offline, rc_fly_tiles_ver | Which course flyovers you have saved for offline use, so the app knows which map imagery it is holding | Until you remove the saved course |
| Weather cache | The last forecast fetched for a place and date, so reopening a race is instant | Short-lived, then refetched |
Files stored for offline use
| Store | What it holds | Duration |
|---|---|---|
Service worker cache (shell-*) | The application itself: page, fonts, icons and map library, so it opens without a connection | Replaced on each new version; old versions removed automatically |
Reload note (rc-flags) | A one-off note that makes Reload fetch the newest version of the app rather than the saved one | Removed when it has been read |
Map tile cache (rc-fly-tiles-*) | Map imagery for a course you chose to save for offline use. Only ever created by you tapping the download control, which states the size first | Until you remove it, up to a fixed number of saved courses |
On the website
The website at thenextrace.run keeps its own small items, separate from the app's.
| Key | What it holds | Duration |
|---|---|---|
rc-site-theme | Light or dark, if you pressed the button at the foot of the page. Display exemption; you can turn it off in section 5 | Until cleared |
rc-site-nocount, rc-site-nokeep | Only there if you used a switch in section 5: your choice not to be counted, or not to have light or dark remembered | Until you turn the switch back on |
| Cloudflare Turnstile | On the waitlist and account-deletion forms, Turnstile runs in a frame from challenges.cloudflare.com to check that a person, not a script, is sending them, and may keep a short-lived item of its own there for that check. Strictly necessary for security | For the check only |
4. The Android application
The Android app displays the same web application inside a system web view, so the cookie and storage above behave as they do in a browser. In addition, the app keeps your preferences and a small summary of your next race in Android's own app storage, so the home-screen widget, reminders and offline screen can work while the app is closed. That data stays on the device and is removed when the app is uninstalled or its storage is cleared in Android settings.
The app contains no advertising or analytics software development kit.
5. Removing or refusing this storage
Switches
- In the app: You › This browser › Remember display settings on this device. Turn it off and the items under "How the app looks" are no longer kept on this device. The app opens in its standard look, then picks up your choices from your account once it has loaded.
On this website, in this browser
Everything at once
- Sign out in the Service. This clears the session cookie and the cached copy of your data.
- Clear site data in your browser for
app.thenextrace.run, or forthenextrace.runfor the website. This removes the cookie, local storage and the offline caches in one step. - Block cookies in your browser settings. You may do so, but signing in will not work and your uploaded photographs will not load, because
rc_sessis what authorises them. - Remove a saved offline map from the download control on the course it belongs to.
- Android: clear the app's storage, or uninstall it, from Android settings.
Clearing this storage removes nothing from your account. Your races, runs and plans are held on the server and reappear when you sign in again. To delete the account data itself, see section 10 of the Privacy Policy.
6. Changes to this policy
This policy is updated whenever a cookie or storage item is added, changed or removed. The version and date at the top of the page show the current version. A non-essential cookie would require your consent before being set, and this policy would be updated before it was introduced.
7. Contact and complaints
The Next Race
Data protection enquiries
[email protected]
You have a statutory right to complain to us first, under section 164A of the Data Protection Act 2018. Receipt is acknowledged within 30 days and the outcome follows without undue delay. Section 15 of the Privacy Policy sets out how that works.
You may also complain to the Information Commissioner's Office, the UK supervisory authority for both the UK GDPR and PECR, at ico.org.uk/make-a-complaint or on 0303 123 1113.