Legal
Privacy Policy
NXTRUNN LLC · Last updated: August 29, 2026
This single Privacy Policy covers both the consumer app and the Partners Portal because NXTRUNN LLC is the data controller for both, uses the same core infrastructure and subprocessors, and applies one privacy program across the platform. Where the consumer app and the Partners Portal differ, the difference is labeled [App] or [Portal]. A separate Subprocessor List (companion document) and Cookie Policy supplement this Policy.
1. Who we are and how to contact us
NXTRUNN LLC provides a running-community platform for runners, run clubs, coaches, businesses ("Run Spaces"), and event organizers. NXTRUNN LLC is the controller of the personal data described in this Policy.
- Privacy contact / Data Protection Officer: legal@nxtrunn.com. General user requests: info@nxtrunn.com (app), partners@nxtrunn.com (portal).
- Registered address: NXTRUNN LLC, 1317 Edgewater Dr #2018, Orlando, FL 32804, United States.
- EU / UK representative (Art. 27 GDPR / UK GDPR): not currently appointed. NXTRUNN is a U.S.-based business; if and when we begin actively offering the platform to residents of the EEA or the UK, we will appoint an Article 27 representative and publish their details here.
2. Age requirement — NXTRUNN is 18+
NXTRUNN is an adults-only platform. You must be at least 18 years old to create an account or use the platform. We enforce this at sign-up through an explicit 18+ attestation presented with mandatory Community Guidelines acceptance. We do not ask for or collect your exact date of birth for this gate. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a person under 18, we will delete it. If you believe a minor has provided us data, contact us at legal@nxtrunn.com.
Because NXTRUNN is 18+, "children's privacy" laws aimed at under-13/under-16 users — e.g., COPPA, GDPR Art. 8 — are addressed by excluding minors entirely rather than by obtaining parental consent.
3. The personal data we collect
We collect the following categories of personal data. Not every category applies to every user.
3.1 Data you provide
- Account & identity — name/display name, username, email address, password/authentication credentials (managed by our auth provider, Clerk), and your 18+ attestation and Community Guidelines consent record (including the accepted policy version and timestamp). We do not collect your exact date of birth.
- Profile — avatar/photo, bio, city/state/country, general location, running interests, marathon count, and optional social handles (Instagram, Strava, TikTok, Threads), race-registration name.
- [App] Running & activity data — runs you log (distance, duration, pace, route name, notes, photos), training schedules, challenge/academy progress, RunnDown workouts, and race/finisher results. This includes workout and fitness data you choose to sync through supported Activity Connections, such as Apple Health (HealthKit), Health Connect on Android, and, when available and separately authorized, Garmin Connect or COROS. Depending on the provider, your permissions, and the recorded activity, imported data may include a provider connection identifier; activity ID and type; start date and time; duration; distance; pace or speed; calories; heart rate; cadence; elevation; laps or splits; device information; GPS route or track data; and activity or FIT files.
- [App] Health-related data (see §4) — injury logs: body part, severity, onset/recovery dates, and your free-text descriptions, plus "recovery mode" status, and the health/fitness metrics you choose to import through a supported Activity Connection.
- [App] Race funds — self-entered savings goals, target race, bib number, and budget items.
- User-generated content — posts, comments, reviews (of Run Spaces and coaches), race reports, photos, and other content you submit, plus reports/flags you file about other content.
- [Portal] Business & verification data — business/club/organization name, role, contact details, listings and event content, and identity/ownership-verification documents you upload.
- Communications — messages you send us (support tickets, emails).
3.2 Data collected automatically
- Precise location / GPS [App] — when you check in at a venue or Run Space, we may collect precise GPS coordinates from your device to confirm the check-in. On mobile, this requires your operating-system location permission, which you can revoke at any time. Some features also use approximate/address-level location via our maps provider (Mapbox).
- Device & technical data — IP address, device/browser type, app version, push-notification tokens (mobile), and diagnostic/crash data (via Sentry).
- Usage & analytics — feature usage and interaction events (via PostHog, where enabled).
- Cookies & similar technologies — see our Cookie Policy.
3.3 Data from third parties
- Authentication providers (Clerk, and any social/SSO sign-in you choose) — basic identity details.
- Payment processors — for event tickets, merchandise, and partner subscriptions, Stripe provides payment status, subscription status, and limited transaction metadata. For consumer memberships, the Apple App Store and Google Play process the purchase and provide subscription status. We never receive or store your full card number.
- Device health platforms (Apple Health / HealthKit and Health Connect on Android) [App] — if you connect them, NXTRUNN reads only the workout and fitness data types you authorize on your device to populate RunDown. You grant access through your device's permission screen and can revoke it at any time in your device settings.
- Connected-account fitness platforms (Garmin Connect and COROS) [App] — if and when a connection is available, NXTRUNN will not receive activity data from that provider unless you affirmatively connect your account and authorize the requested permissions. The provider then transmits authorized activity data to NXTRUNN through its OAuth/API connection. You can disconnect in NXTRUNN and can also revoke access through the provider. Disconnecting stops future imports; activities already imported into RunDown remain until you delete them, request their deletion, or delete your NXTRUNN account, subject to the Data Retention & Deletion Policy.
- Activity Connection limits [App] — we request only the data needed to provide RunDown. Imported activities are private by default. Using an imported activity for an optional public leaderboard or run-club challenge requires the separate participation and visibility choices presented for that feature; connecting a provider does not enroll you automatically. We never use imported health or fitness data for advertising or marketing, never sell it, and never share it with data brokers.
4. Sensitive / special-category data (health) — important
[App] Injury logs, "recovery" features, and workout/fitness metrics imported through Apple Health (HealthKit), Health Connect on Android, Garmin Connect, or COROS involve information about your physical health. Under the EU/UK GDPR, Brazil's LGPD, and similar laws, health data is a special category requiring heightened protection. We process this data only:
- to provide the injury-tracking, training-recovery, and RunnDown workout features you choose to use;
- on the basis of your explicit consent, which you give by voluntarily entering injury information or by connecting a health/fitness integration (GDPR Art. 9(2)(a)); and
- you can delete injury logs at any time, disconnect a health/fitness integration in your device settings at any time, and all such data is purged when you delete your account.
We do not use injury or health/fitness data for advertising, and we do not sell it.
5. Why we use your data, and our legal bases (GDPR/UK GDPR/LGPD)
- Create and operate your account; provide core features — account, profile, activity, UGC — Contract (Art. 6(1)(b))
- Adults-only eligibility and Community Guidelines consent — 18+ attestation, accepted policy version, and timestamp — Contract / legitimate interests (Art. 6(1)(b)/(f))
- Process payments, memberships, tickets, payouts — payment metadata, order data — Contract (Art. 6(1)(b))
- Location check-ins — GPS coordinates — Consent (Art. 6(1)(a)) — via OS permission
- Health/injury features and supported Activity Connections — injury logs, authorized activity, route, and fitness metrics — Explicit consent (Art. 9(2)(a))
- Security, fraud prevention, rate limiting, abuse/moderation — technical, audit, report data — Legitimate interests (Art. 6(1)(f)) / legal obligation
- Product analytics & improvement — usage/analytics — Consent where required, else legitimate interests
- Service emails (transactional) — email, account — Contract / legitimate interests
- Marketing emails (if any) — email — Consent (opt-in) — you may unsubscribe anytime
- Comply with law, respond to legal requests — as required — Legal obligation (Art. 6(1)(c))
For users in jurisdictions without a "legal basis" framework, we process data as reasonably necessary to provide the platform, as permitted by applicable law (e.g., PIPEDA, Australia Privacy Act).
6. Who we share data with (subprocessors)
We share personal data with vetted service providers ("subprocessors") strictly to operate the platform, under contracts that limit their use of the data. Key categories — see the Subprocessor List companion document for the full, current roster:
- Authentication: Clerk.
- Database & storage: Supabase (primary database), Cloudflare R2 (photos, documents, media).
- Payments & payouts: Stripe and Stripe Connect (tickets, merch, partner subscriptions/payouts); Apple App Store and Google Play (consumer memberships).
- Maps & location: Mapbox.
- Email: AWS SES.
- Error monitoring: Sentry.
- Product analytics: PostHog (where enabled).
- Caching / rate limiting: Upstash (Redis).
- AI features: Anthropic (Claude).
- Digital wallet passes: Apple Wallet, Google Wallet.
- [App] Weather: OpenWeather.
- [Portal] Merchandise fulfillment: Printful.
- Hosting / distribution: Vercel, Apple App Store, Google Play.
Note on Activity Connections: Apple Health (HealthKit) and Health Connect on Android are device-level integrations, not subprocessors. Garmin Connect and COROS are independent third-party platforms from which NXTRUNN may receive data at your direction through provider-authorized OAuth/API connections; they are not NXTRUNN subprocessors merely because you connect an account. Each provider's privacy policy governs the information it holds, while this Policy governs the information NXTRUNN receives and processes.
We also share data:
- with other users, when you choose to make content public (profile, posts, reviews, public check-ins);
- with payees, when you buy a ticket — the event organizer receives the order/attendee information needed to admit you;
- for legal reasons — to comply with law, enforce our terms, prevent fraud, or protect rights and safety;
- in a business transfer — in connection with a merger, acquisition, or sale of assets (with notice as required).
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. (See the California Privacy Notice and applicable regional notices.)
7. International data transfers
NXTRUNN operates globally and our subprocessors may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, Switzerland, or other regions with transfer restrictions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum / Swiss addendum as applicable), reliance on the EU-US Data Privacy Framework where a provider is certified, or other lawful transfer mechanisms.
8. How long we keep your data (retention)
We keep personal data only as long as needed for the purposes above or as required by law. See the Data Retention & Deletion Policy for the detailed schedule. In summary: account and content data are retained while your account is active; some records (e.g., transaction/tax records, fraud-prevention and security logs, and data-subject-request records) are retained longer where law requires.
9. Your privacy rights
Depending on where you live, you may have rights to: access your data; correct it; delete it; export/port it; object to or restrict certain processing; withdraw consent; and not be subject to unlawful automated decision-making. You also have the right to lodge a complaint with your data-protection authority.
You can exercise core rights directly in-product:
- [App] Export your data: Settings → Data & Export → Download all data. The self-serve JSON export includes account identity, profile/settings, workouts and health activity, injury logs, posts/comments, events, check-ins, rewards, Passport and Race Fund data, notifications, support history, and other consumer account records. Security credentials such as push tokens and widget token hashes are excluded.
- [App] Manage an Activity Connection in the applicable NXTRUNN connection settings or revoke it through your device or provider account. Disconnecting stops future imports. You may delete imported activities through available RunDown controls or request deletion at legal@nxtrunn.com.
- Delete your account permanently in Settings → Data & Export, or request deletion at nxtrunn.com/account-deletion if you cannot access the app (see §8 and the Data Retention & Deletion Policy).
- [Portal] Request or schedule a data export from the portal.
To exercise any right, email legal@nxtrunn.com (or info@nxtrunn.com for app / partners@nxtrunn.com for portal). We will verify your identity and respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA/CPRA, extendable as permitted). We will not discriminate against you for exercising your rights.
10. Security
We use technical and organizational safeguards including encryption in transit, scoped access controls, rate limiting, audit logging, and security monitoring. No system is perfectly secure; see our Security Statement for more. Report security concerns to legal@nxtrunn.com.
11. Cookies and tracking
We use cookies and similar technologies for essential functions (sign-in, security), and — where you consent — for analytics. See the Cookie Policy. A cookie-consent mechanism governs non-essential cookies and lets you accept, reject, or manage them at any time.
12. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Some features use automated logic (e.g., fraud/rate-limit checks, content ranking, AI-assisted tools); these do not replace meaningful human involvement in significant decisions.
13. Region-specific disclosures
- California (USA): see the California Privacy Notice (CCPA/CPRA).
- EEA / UK: legal bases are in §5; you may complain to your supervisory authority or the UK ICO.
- Brazil (LGPD): you have rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing; our privacy contact is above.
- Canada (PIPEDA) / Australia (Privacy Act): you may access and correct your data and complain to the OPC (Canada) or OAIC (Australia).
- Other regions: where local law grants additional rights (e.g., Quebec Law 25, and U.S. state laws such as Colorado, Virginia, and Connecticut), we honor them — contact legal@nxtrunn.com.
14. Changes to this Policy
We may update this Policy. We will revise the "Last updated" date and, for material changes, provide additional notice (e.g., in-app or by email). Your continued use after an update means you accept the revised Policy where permitted by law.
15. Contact
Questions or requests: legal@nxtrunn.com · info@nxtrunn.com (app) · partners@nxtrunn.com (portal) · NXTRUNN LLC, 1317 Edgewater Dr #2018, Orlando, FL 32804, United States.