The Next Race

Privacy Policy

Version 1.5 · In force from 1 October 2026

This policy explains what personal data The Next Race collects, why it is held, who it is shared with, how long it is kept and what rights you have over it. It applies to the website at thenextrace.run, the web application at app.thenextrace.run, and the Android application published as com.thenextrace.run (together, "the Service").

The short version. The Service holds the training, race, travel and wellness data you put into it or connect to it. It is not used to advertise to you, it is not sold or shared for anyone else's marketing, it is not used to train machine learning models, and there are no analytics or tracking cookies. Health data from a connected wellness device is used only with your explicit consent, and you can withdraw that consent and delete the data at any time.

1. Who is responsible for your data

Max Slinger, trading as The Next Race, is the data controller for the personal data described in this policy, within the meaning of the UK General Data Protection Regulation (UK GDPR) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018. A controller is the party that decides why and how personal data is processed.

The Service is operated from the United Kingdom. Article 13(1)(a) UK GDPR requires the identity and contact details of the controller to be given, and they are set out in full in section 16.

No data protection officer is appointed, because the Service does not meet any of the conditions in Article 37(1) UK GDPR: it is not a public authority, its core activities do not consist of large-scale regular and systematic monitoring, and it does not process special category data on a large scale. Correspondence about data protection should be sent to the contact address in section 16.

2. The personal data collected

Personal data means information relating to an identified or identifiable living individual. The Service processes the following categories.

Account and identity data

You sign in with a Google Account. Google returns a signed identity token from which the Service reads your email address, display name, a stable Google account identifier and, where present, a link to your profile picture. The Service never receives, sees or stores your Google password.

About you

Your year of birth, which you give when you sign up. It confirms you are 18 or over, and it is used for age grading and heart-rate zones. If you choose to add them, your sex (for age grading), your body weight (to estimate calories) and your maximum heart rate (for training zones). Body weight and maximum heart rate are health data. See section 3.

Training and activity data

Wellness and health data

If, and only if, you connect a wellness account: daily readiness score, sleep duration and sleep score, resting heart rate, heart rate variability and its balance, body temperature deviation, blood oxygen saturation, an estimated VO2 max, a daily stress indication, and any day you mark yourself unwell. This is health data and is treated as special category data. See section 3.

Race, travel and trip data

Location data

A home location you enter as free text, the locations of races you add, accommodation addresses you enter, and the GPS tracks described above. Only if you tap From here on a race-morning card, the app asks for your location once, to open walking directions in Google Maps. It goes into that link on your phone and is never sent to us or kept.

Preferences and settings

Units, currency, theme and palette, notification choices, coaching style, and similar display settings.

Technical data

The app has no analytics package, no advertising technology and no cross-site tracking. The website at thenextrace.run counts visits with Cloudflare Web Analytics, which sets no cookie, stores nothing on your device and does not follow you to other websites. It records the page, the referring site, the browser and the country of each visit.

If you join the waitlist

Your email address, when you asked to join, and when you confirmed it. Nothing else is asked for.

Bookings you forward

The text and subject line of a booking confirmation you forward to your trips address. Your device reads it to fill in a trip leg.

Whether you have to provide any of this

There is no statutory or contractual requirement to give any of it. The only data that must be provided is the identity information Google returns at sign-in, because without it there is no account to attach anything to and the Service cannot be provided. Everything else is optional, and the consequence of not providing it is simply that the feature it feeds does not work: no connected activity account means no imported runs, no connected wellness account means no readiness figures, no home location means no travel times or nearest-race sorting.

3. Health data and explicit consent

Data about your sleep, heart rate, heart rate variability, body temperature, blood oxygen, body weight, injuries and recorded illness is data concerning health and is therefore special category data under Article 9(1) UK GDPR. Processing it is prohibited unless a condition in Article 9(2) applies.

The condition relied on is Article 9(2)(a): your explicit consent, and you give it in words, not just by using a feature:

No health data is collected unless you take one of those steps.

You may withdraw consent at any time by disconnecting the account in the Service's settings, or by clearing what you entered. Withdrawal does not affect the lawfulness of processing carried out before it. On withdrawal the Service stops retrieving new health data; to remove health data already held, use the deletion right in section 10.

Heart rate and cadence recorded during an activity are also data concerning health, whether they come from a connected account or a file you import, and are processed on the same basis.

4. Lawful bases for processing

Article 6(1) UK GDPR requires a lawful basis for every processing operation.

PurposeLawful basis
Creating and maintaining your account; authenticating youArticle 6(1)(b), performance of a contract with you
Storing and displaying your races, training, plans, trips and packing listsArticle 6(1)(b), performance of a contract
Importing activity data from a service you have connectedArticle 6(1)(b), and Article 9(2)(a) explicit consent for the heart rate and cadence within it
Importing wellness and sleep data from a service you have connectedArticle 6(1)(a) consent, and Article 9(2)(a) explicit consent
Checking you are 18 or over, and age grading your resultsArticle 6(1)(b), performance of a contract
Keeping a record of your consent to health dataArticle 6(1)(c), legal obligation, because Article 7(1) requires consent to be shown
Retrieving weather, travel and geographic information for a race you have addedArticle 6(1)(b), performance of a contract
Sending you reminders and alerts you have enabledArticle 6(1)(a), consent, withdrawable in settings
Rate limiting, abuse prevention and keeping the Service secureArticle 6(1)(f), legitimate interests in protecting the Service and its users
Recording errors so faults can be found and fixedArticle 6(1)(f), legitimate interests in a working and reliable service
The waitlistArticle 6(1)(a), your consent. You can withdraw it at any time with the unsubscribe link in any email
Bookings you forward to your trips addressArticle 6(1)(b), providing the Service you asked for
Keeping records needed to answer a legal claim or a regulatorArticle 6(1)(c), legal obligation, and Article 6(1)(f)

Where legitimate interests are relied on, that interest has been balanced against your rights and freedoms. The processing concerned is limited to what is needed to keep the Service running safely, and you may object to it under section 10.

5. Where the data comes from

6. Who your data is shared with

Your personal data is not sold, rented or shared for anyone else's marketing, and it is not used to train machine learning or artificial intelligence models. It is disclosed only as set out below.

Processors acting on instructions

ProcessorRoleData involved
CloudflareHosting, database, file storage, content delivery and network security for the whole Service, and counting website visitsAll stored data, and network data such as your IP address
Google (Identity Services)Sign-inYour Google identity, handled by Google under its own policy
ResendSending email: invitations, and the waitlist's confirmation and launch emailsYour email address and the content of the email

Third parties you connect, acting as their own controllers

Connecting an account causes data to flow between that provider and the Service. Each provider handles your data under its own privacy policy, which you should read before connecting.

ServiceDirectionData involved
StravaRead into the ServiceActivities, splits, routes, heart rate, cadence, gear
OuraRead into the ServiceReadiness, sleep, resting heart rate, HRV, temperature, SpO2
intervals.icuWritten from the Service, at your requestPlanned workouts you choose to send to your watch

Information providers

To show a forecast, a route, a journey time or a landmark, the Service asks external providers for information about a place or a coordinate. These requests are made by the Service's own servers, not by your browser, and carry no account identifier, no name and no email address. The providers are: Open-Meteo (weather, air quality and elevation), Open Topo Data (elevation), OpenStreetMap-based geocoding and routing services including Nominatim, Photon, Valhalla and Stadia Maps, Overpass, Wikidata and Wikipedia (landmarks and images), Protomaps (map tiles), AeroDataBox (flight status), National Rail Enquiries (Darwin live departure and arrival boards), Realtime Trains and Transport for London (train and underground times), Transitous (train times in Europe), postcodes.io (turning a UK postcode into a place), Frankfurter (exchange rates), and Ignav and Travelpayouts (flight fares). To show flight fares, our servers send Ignav and Travelpayouts the airport codes and dates of a trip. They receive no name, email address or account identifier.

A coordinate you supply, such as a race start or an accommodation address, is personal data in context even though it is sent without your name attached. It is sent only for the specific lookup you asked for.

Requests your browser makes itself

Most lookups go through our servers, so the other service never learns who you are. Three come straight from your browser, which means that service sees your IP address: map tiles from Stadia Maps, the Strava preview of a run on a race page, and the default cover photo from Unsplash. If you tap Open in Uber, Uber receives the two addresses in the link. If you tap Compare on Aviasales or open a fare's booking link, that site receives the trip's airports and dates in the link.

Checking you are a person

The waitlist and account-deletion forms use Cloudflare Turnstile to check that a person, not a script, is sending them. Turnstile reads signals from your browser for that check and nothing else.

Other disclosures

Data may also be disclosed where required by law, court order or a regulator; where necessary to establish, exercise or defend legal claims; and to a successor entity if the Service is transferred, in which case you will be told before your data becomes subject to a different policy.

7. International transfers

Some of the recipients above process data outside the United Kingdom. Where personal data is transferred out of the UK, one of the following applies:

Content delivery networks serve static files from the location nearest to you, which may be outside the UK. You may request details of the safeguards applied to a particular transfer using the contact address below.

8. How long data is kept

DataRetention
Account, races, training, trips, wellness and uploaded filesFor as long as your account is open. Deleted on request, or when the account is closed.
BackupsWe keep copies of the database so we can recover from a fault. A copy holds what the Service held on the day it was made, so after you delete something, or your account, it stays in older copies until they are deleted, 90 days after they were made. The copies are kept on the owner's computer, outside any cloud sync, where only that account can read them. A weekly copy is also kept for 8 weeks in the Service's private storage at Cloudflare, which nothing in the Service can show to anyone. If a copy is ever restored, anything deleted since it was made is deleted again before the Service is back in use. Cloudflare, which runs the database, can also restore it to any moment in the last 7 days.
Record of your consent to health dataFor as long as your account is open, so the consent can be shown if asked. Deleted with the account.
Items you delete inside the ServiceHeld in a recoverable bin for 30 days, then permanently removed.
Sign-in sessions30 days from their last use, renewed while you use the Service, and never more than 180 days after you signed in. Signing out ends one at once. Only a one-way hash of the session token is stored, never the token.
Access tokens for connected accountsUntil you disconnect the account, or the provider expires them. Stored encrypted.
Error recordsKept while useful for diagnosis and cleared periodically. Not used to build a profile of you.
Cached lookups (weather, geocoding, route data)Short-lived, from minutes to one month, then discarded.
Waitlist addressUnconfirmed, 7 days. Confirmed, until you unsubscribe, or 12 months after the app opens to everyone, whichever comes first.
Forwarded bookingsUntil you add or dismiss them, and 30 days at most.
Website visit countsHeld by Cloudflare as totals. No record is kept against you.
IP address for rate limitingTransient, in a counter measured in minutes. Not stored against your account.

9. Security

Article 32 UK GDPR requires measures appropriate to the risk. The following are in place:

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, it will be reported to the Information Commissioner's Office within 72 hours as required by Article 33, and you will be told without undue delay where Article 34 requires it.

10. Your rights

Under the UK GDPR you have the right to:

Requests are answered within one month, extendable by two further months for complex requests, in which case you will be told within the first month. There is no charge unless a request is manifestly unfounded or excessive. Identity may need to be verified before a request is actioned.

11. Automated decision-making and profiling

The Service calculates predictions and estimates from your data, including a predicted finish time, a fitness and fatigue estimate, a readiness score and a training load risk indication. These are analytical outputs shown to you as information. They produce no legal effect and no similarly significant effect within the meaning of Article 22 UK GDPR: nothing is decided about you, no access is granted or refused, and the figures are advisory. You remain free to disregard them.

12. Children

The Service is for adults, 18 and over. You give your year of birth when you sign up, and an account is not set up for anyone younger. If you believe a child has provided personal data, contact the address below and it will be deleted.

13. Cookies and local storage

The Service uses one strictly necessary cookie to keep you signed in, and stores settings and an offline copy of your own data in your browser. There are no advertising or tracking cookies, which is why no consent banner is shown: the Privacy and Electronic Communications Regulations 2003 exempt storage that is strictly necessary to provide a service you have requested, and allow display choices and visit counting as long as you can say no. You can turn off remembered display settings in the app, and visit counting on the website, at any time. Full detail is in the Cookie Policy.

14. Changes to this policy

This policy may be updated to reflect changes to the Service or to the law. The version number and date at the top of this page always show the current version. Where a change materially affects how your data is used, you will be told in the Service before it takes effect, and where the change relies on your consent, you will be asked for it again.

15. Complaining about how your data is handled

You have a statutory right to complain directly to us about anything in this policy or about how your personal data has been processed. That right is given by section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025, and in force since 19 June 2026.

How to complain.

A complaint does not have to use any particular form of words, cite any law, or arrive by any particular route. It helps to say what happened, when, and what you would like done about it. A complaint made in any other channel we operate is still treated as a complaint.

What happens then.

16. Contact details, and complaining to the regulator

To exercise any right in section 10, complain under section 15, ask a question about this policy, or request details of the safeguards applied to a particular international transfer, contact the controller. Account deletion can also be requested directly at the deletion request page.

Max Slinger, trading as The Next Race
Data protection enquiries
[email protected]
Suite 792, 80A Ruskin Ave, Welling DA16 3QQ

If you are not satisfied with how a complaint has been handled, or you would rather not raise it with us at all, you may complain to the UK supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk/make-a-complaint

Since 19 June 2026 the ICO may ask whether you have raised the matter with us first, and may decline to take a complaint further until you have. Nothing here removes your right to approach the ICO, or to seek a remedy in the courts under Article 79 UK GDPR.