The Next Race

Cookie Policy

Version 1.10 · In force from 1 October 2026

This policy lists every cookie and every item of browser storage The Next Race uses, what each one is for and how long it lasts. It covers thenextrace.run, app.thenextrace.run and the Android application, and should be read with the Privacy Policy.

The short version. One cookie, and it exists to keep you signed in. There are no advertising cookies, no analytics cookies and nothing that tracks you across other websites. Everything else the Service stores stays in your own browser and is never sent anywhere. The website counts visits without cookies, and you can turn that off (section 5).

1. Why there is no consent banner

Storing information on your device, or reading information already stored there, is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). Consent is needed unless an exemption applies. Three apply here.

Strictly necessary, regulation 6(4)(b)

Storage that is strictly necessary to provide a service you have asked for needs no consent. The test is taken from your point of view, not ours: the question is whether the Service could do what you asked without it. Signing you in, holding a change you made while offline until it can be sent, and keeping a copy of your own data so the app opens on a train with no signal all meet that test. Convenience to us would not.

Remembering your display preferences

Since 5 February 2026, PECR as amended by the Data (Use and Access) Act 2025 also exempts storage whose sole purpose is to remember how you like the Service to look, provided you are told about it and have a simple, free way to say no. Your theme, palette, units and similar display choices sit here rather than under strictly necessary, because the Service would still work without them; it would just forget what you picked. You were told by this page, and the way to say no is a switch in the app, described in section 5.

Counting visits to the website

The website at thenextrace.run, though not the app, counts visits with Cloudflare Web Analytics. It sets no cookie and stores nothing on your device, but its script reads timing details from your browser, so it relies on the exemption the same Act added for statistics: counting visits only to improve the website, with nothing that identifies or follows you. Cloudflare records the page, the referring site, the browser and the country of each visit. There is no advertising, no profiling and no cross-site tracking anywhere on the Service. You can turn visit counting off with the switch in section 5.

Where the stored data is also personal data, it is processed under the UK GDPR on the bases set out in section 4 of the Privacy Policy. PECR and the UK GDPR apply together: meeting a PECR exemption does not remove the UK GDPR obligations, and this policy should be read alongside that one.

2. Cookies

The Service sets one cookie of its own.

NamePurposeDurationType
rc_sess Keeps you signed in, and authenticates requests for your own uploaded files. It exists because an image tag cannot carry an authorisation header, and the alternative, putting a credential in the address, would write it into your browser history. The cookie holds an opaque session reference and no personal data. It is set only after you have successfully signed in. 30 days, or until you sign out Strictly necessary · first party

rc_sess is HttpOnly, so no script on the page can read it; Secure, so it is only ever sent over HTTPS; and SameSite=Lax, so another website that embeds a link to your files receives no cookie and no access. Only a one-way hash of the session is stored on the server, so the database never holds a usable credential.

Cookies set by Google when you sign in

Signing in loads Google Identity Services from accounts.google.com. Google may set or read its own cookies on its own domain as part of authenticating you. Those cookies are set by Google as controller, are not readable by The Next Race, and are governed by Google's privacy policy and the cookie settings on your Google Account. The Service sets no third-party cookie of its own.

3. Browser storage on this device

Most of what the Service remembers is kept in localStorage, not in a cookie. The practical difference matters: a cookie is sent to the server with every request, whereas local storage stays on your device and is read only by the page itself. None of the items below is transmitted to any server, though several are copies of data the Service already holds for you.

How the app looks

These are remembered so the Service looks the way you set it. They rely on the display exemption in section 1, and you can stop this device keeping them with the switch described in section 5.

KeyWhat it holdsDuration
theme_mode, palette, theme_syncLight, dark or system, the colour palette you picked, and whether that follows you to your other devicesUntil cleared
training_unitWhether distances show in kilometres or milesUntil cleared
reduce_motionWhether animations are reducedUntil cleared
event_layoutHow a race page is laid outUntil cleared
tp_cal_colour, tp_prog_styleHow the training plan calendar and progress are shownUntil cleared
rc_ft_modeWhether your fitness trend shows VDOT or a predicted timeUntil cleared
rc_rb_view, rc_rb_map_posList or map in the race listings, and where you left the mapUntil cleared
rc_dnsdnf_openA section you left openUntil cleared

Your details and choices

These record information you gave or a choice you made, which PECR counts as strictly necessary. Most are copies of what your account holds, so the app works before it has loaded and with no connection.

KeyWhat it holdsDuration
home_location, home_currencyThe place travel times and nearest races are measured from, and the currency trip costs are totalled inUntil cleared
home_airportThe airport flights are searched from, if you picked oneUntil cleared
birth_year, sex, body_weight_kgYour year of birth, and your sex and body weight if you gave themUntil cleared
plan_coaching, plan_garmin_autosync, plan_heat_watch, plan_heat_notesCoaching style, whether planned sessions go to your watch on their own, and hot-day paces and notesUntil cleared
race_lists, race_suggest_hidden, suggest_after_marathonYour race lists, races you turned down, and how long after a marathon races are suggestedUntil cleared
rc_gb_autoWhether the way back from a race is planned automaticallyUntil cleared
rc_search_recentYour recent searchesUntil cleared
rc_trashwarn_*, nostalgia_dismissed_*, rc_tripcopy_no_*, rc_note_no_*Prompts and notes you dismissed, so they do not come backUntil cleared
rc_keep_lookOnly there if you turned off remembered display settings: your choice not to keep themUntil you turn the switch back on

Most of the items in both tables are also synchronised to your account, so the same choices follow you to another device. Dismissed prompts, recent searches and list or map positions are local to this browser.

Working offline

These are strictly necessary under regulation 6(4)(b): without them the Service cannot do the thing you asked it to do, which is open and stay usable with no connection.

KeyWhat it holdsDuration
rc_cache_*A copy of your races, runs and plans, so the app opens and shows something with no connectionReplaced on each load; cleared on sign-out and when a new version ships
rc_offline_queueChanges you made while offline, held until they can be sentUntil sent
rc_trip_*, rc_rmt_*Trip documents and your race-morning timeline, kept readable on the day even with no signalUntil cleared
rc_alarms_*The race-morning alarms you set in your phone's Clock app, so the timeline can tell you when one of its times has movedUntil cleared
rc_seen_*What a race looked like last time you opened it, so "what changed" can be shownUntil cleared
rc_predlog_*, rc_heatcalib_v1, heat_k, rc_racebias_v1, rc_drift_v1Past prediction figures, your heat response, how your races compare with predictions, and heart-rate drift on past runs, kept so estimates stay consistent and do not have to be worked out againUntil cleared
rc_pacing_*Pacing plans you made for a race, so they open on race morning with no signalUntil cleared
rc_poster_*How you last set up a race's poster (map style, size and text), so it opens the way you left it, and a small picture of the last one you savedUntil cleared
rc_story_*How you last set up a race's story pictures (which ones, your headline and what you chose to hide), so they open the way you left themUntil cleared
rc_keepsake_*The words you changed on a keepsake picture, so it opens the way you left itUntil cleared
rc_palette_default, rc_palettes_allowedWhich colour palettes the app offers, so it opens in the right colours before it has loadedReplaced on each load
rc_fly_offline, rc_fly_tiles_verWhich course flyovers you have saved for offline use, so the app knows which map imagery it is holdingUntil you remove the saved course
Weather cacheThe last forecast fetched for a place and date, so reopening a race is instantShort-lived, then refetched

Files stored for offline use

StoreWhat it holdsDuration
Service worker cache (shell-*)The application itself: page, fonts, icons and map library, so it opens without a connectionReplaced on each new version; old versions removed automatically
Reload note (rc-flags)A one-off note that makes Reload fetch the newest version of the app rather than the saved oneRemoved when it has been read
Map tile cache (rc-fly-tiles-*)Map imagery for a course you chose to save for offline use. Only ever created by you tapping the download control, which states the size firstUntil you remove it, up to a fixed number of saved courses

On the website

The website at thenextrace.run keeps its own small items, separate from the app's.

KeyWhat it holdsDuration
rc-site-themeLight or dark, if you pressed the button at the foot of the page. Display exemption; you can turn it off in section 5Until cleared
rc-site-nocount, rc-site-nokeepOnly there if you used a switch in section 5: your choice not to be counted, or not to have light or dark rememberedUntil you turn the switch back on
Cloudflare TurnstileOn the waitlist and account-deletion forms, Turnstile runs in a frame from challenges.cloudflare.com to check that a person, not a script, is sending them, and may keep a short-lived item of its own there for that check. Strictly necessary for securityFor the check only

4. The Android application

The Android app displays the same web application inside a system web view, so the cookie and storage above behave as they do in a browser. In addition, the app keeps your preferences and a small summary of your next race in Android's own app storage, so the home-screen widget, reminders and offline screen can work while the app is closed. That data stays on the device and is removed when the app is uninstalled or its storage is cleared in Android settings.

The app contains no advertising or analytics software development kit.

5. Removing or refusing this storage

Switches

Everything at once

Clearing this storage removes nothing from your account. Your races, runs and plans are held on the server and reappear when you sign in again. To delete the account data itself, see section 10 of the Privacy Policy.

6. Changes to this policy

This policy is updated whenever a cookie or storage item is added, changed or removed. The version and date at the top of the page show the current version. A non-essential cookie would require your consent before being set, and this policy would be updated before it was introduced.

7. Contact and complaints

The Next Race
Data protection enquiries
[email protected]

You have a statutory right to complain to us first, under section 164A of the Data Protection Act 2018. Receipt is acknowledged within 30 days and the outcome follows without undue delay. Section 15 of the Privacy Policy sets out how that works.

You may also complain to the Information Commissioner's Office, the UK supervisory authority for both the UK GDPR and PECR, at ico.org.uk/make-a-complaint or on 0303 123 1113.