Skip to main content
RHRunHub

Privacy policy

Privacy Policy
Last updated: 1 September 2026The site notice and terms are a separate page.

1. Data Controller

Oscar Woodruff
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany

Email: runhub@masticfrog.de. Telephone: 0157 9234 1658. You can also use the contact page, and the full particulars are in the site notice.

2. Data We Collect

Account data

When you register, we store your email address, your name, and optionally a profile picture. This is necessary to provide your account (Art. 6(1)(b) GDPR).

Sign-in data

You can sign in via email magic link, passkey (WebAuthn), or social login (Google, GitHub, Apple, Facebook/Meta). When you use a social login, the provider shares your email, name, and profile picture with us. OAuth tokens required for the sign-in flow are stored but never shared with third parties. The legal basis is Art. 6(1)(b) GDPR.

Session cookies

We use strictly necessary cookies to keep you signed in (session token, CSRF token, callback URL). These are required for the site to function and do not require your consent under § 25 TTDSG.

Security & audit logs

For security purposes we log sign-in events and content changes. These logs may include your IP address, browser user-agent, and a timestamp. The legal basis is our legitimate interest in protecting the platform (Art. 6(1)(f) GDPR).

Crash reports

When a page fails to load properly, your browser sends us a report so we can fix it. It contains the address of the page, the error message, and which browser you were using — and, as a yes or no, whether you were signed in. It does not contain your IP address, your account, your name, or anything you typed. Your IP address is used for a few seconds to stop one browser flooding us with reports, and is never written down. Because a crash report identifies nobody, we keep them for as long as they are useful: an error that happens twice a year is one we can only find by having last year's. The legal basis is our legitimate interest in keeping the site working (Art. 6(1)(f) GDPR).

Contact form and edit suggestions

The form at /info/contact takes your name, email address, a subject and a message. If you send a correction from an event page, we take the message and, only if you choose to give them, a name and an email address. We use these to answer you and to act on what you told us. The legal basis is our legitimate interest in responding to enquiries and in keeping the event data accurate (Art. 6(1)(f) GDPR).

Contact messages are not stored on this website; they are delivered to us as email. Delivery goes through Mailjet (Mailjet SAS, France) acting as a processor, so the message passes through their servers. A suggested correction is stored, because a moderator has to review it before anything changes on a page. Both are deleted once they are no longer needed and nothing requires us to keep them.

Analytics

We use a self-hosted instance of Umami to understand how visitors use the site. Umami does not use cookies and does not collect personal data — it records aggregated, anonymised statistics such as page views, browser language, and country. No consent is required.

3. Third-Party Services

If you choose to sign in with a social provider, your browser will connect directly to that provider. The following providers may receive your data as part of the OAuth flow:

  • Google LLC (USA) — Google Sign-In
  • GitHub Inc. / Microsoft (USA) — GitHub Sign-In
  • Apple Inc. (USA) — Sign in with Apple
  • Meta Platforms Inc. (USA) — Facebook Login

These providers are located in the United States. Transfers are safeguarded by Standard Contractual Clauses (Art. 46 GDPR). You are not required to use a social login; email and passkey sign-in are available as alternatives.

Map tiles

Pages showing a course or a start location load map tiles directly from OpenStreetMap Foundation (United Kingdom). Your browser contacts their servers to fetch the images, so your IP address and the tiles you request are visible to them. We do not send them anything else, and no cookie is set. This happens only on pages that display a map.

4. Data Retention

Account data is retained for as long as your account is active. Security audit logs are retained for up to 12 months and are deleted automatically by a nightly job, so that is a limit the system enforces rather than an intention it states. Crash reports are kept indefinitely and are not subject to a retention period, because they identify nobody — see “Crash reports” above for exactly what one contains. Session tokens expire automatically. If you delete your account, your personal data is removed from our systems, except where retention is required by law.

Account deletion is not yet available through the UI. During this launch phase, please contact us to request deletion.

5. Your Rights

Under GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Request erasure of your data (Art. 17)
  • Restrict how we process your data (Art. 18)
  • Receive your data in a portable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)

To exercise any of these rights, please use our contact page.

6. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority in the EU member state of your habitual residence, place of work, or the place of an alleged infringement (Art. 77 GDPR).