Privacy Policy
How Horsell Runners uses personal data on this website and in the members area.
Who we are
Horsell Runners is responsible for the personal data described in this notice when we operate this website and members area. We are an informal community running group based in the UK.
Questions, requests, or concerns about privacy can be sent to runners@willhouston.co.uk.
Information we use
Website enquiries
When you use Contact Us, we receive your name, email address, subject, and message. We use this to reply to your enquiry. The form also uses Cloudflare Turnstile to protect the site from automated abuse.
Members area and profile
To create and administer a members-area account, we use your verified email address, an authentication-provider identifier, membership status, and account timestamps such as sign-in, approval and revocation dates. New accounts await administrator approval. Members may add their first name, last name, and an optional link to their Strava athlete profile.
We use Auth0 for sign-in. If a social sign-in option such as Google is available through Auth0, that provider handles the sign-in itself. This website uses the verified email address and identity identifier returned by Auth0; it does not receive your Google password or access token.
Event plans and optional follow-up
When a member shares plans for a race or event, we store the selected event and the member name from their profile. Other authenticated members can see names of members who have shared plans. Public visitors can see only aggregate participant counts for club races.
A member may choose to receive a post-event email asking for a blog story. If they opt in, we use the email address linked to their member profile for that one optional follow-up. It is not shown to other members.
Where In The World
Members can add a place where they have run. We store the selected place name, country, and its geocoded latitude and longitude, together with the member name, optional event name and date, and a Strava activity or shared-activity link. This is not device tracking and we do not obtain activity data from Strava.
Public visitors can see each selected location, its existing approximate map coordinates, an aggregate count of distinct runners, and deduplicated run dates. Public visitors cannot see names, profiles, activity links, member identifiers, or which member recorded a date. Entries are intentionally shared with other authenticated members through the map and location pages, including the stored map coordinates and any activity link supplied. Do not add an entry unless you are comfortable sharing that information with other members.
Technical and security information
Our hosting and security providers may process technical information such as IP address, browser/device information, request logs, and security-check information when you visit the site. This is used to deliver, secure, diagnose, and protect the service.
Why we use information
We normally rely on our legitimate interests in running a safe and useful community running-group website, administering the members area, helping members coordinate activities, responding to enquiries, and preventing misuse. We balance those interests against members' privacy and limit access to member information.
We rely on consent for the optional post-event blog follow-up because a member actively selects that option. You can withdraw that consent by contacting us before the follow-up is sent. The Contact Us form asks for consent before we reply; we use the details for that enquiry and any necessary follow-up.
We may also use information where necessary to meet a legal obligation or establish, exercise, or defend legal claims. We will explain if a different legal basis applies to a new use.
Who can see your information
- Public visitors can see public website content, approved race details, aggregate race-plan counts, and aggregate Where In The World locations, counts, and dates. They cannot see member names, email addresses, profiles, activity links, member identifiers, or member-level map entries through the public site.
- Authenticated members can see shared event-plan names and Where In The World entries, including the information described above.
- Administrators can access member email addresses, names, membership status, account creation and last-sign-in dates, and administrative roles to manage access. They do not receive members' Strava profile links through the member-administration screen.
Service providers and external links
We use Cloudflare (opens in a new tab) to host the site, run server functions and database services, and provide Turnstile security checks. We use Auth0/Okta (opens in a new tab) for member authentication and Resend (opens in a new tab) to deliver contact messages, approval notifications, and opted-in follow-up emails.
Google Groups runs the mailing list separately. Following our mailing-list link takes you to Google's service; this website does not add you to the list. Members' location searches are sent from our server to OpenStreetMap Nominatim. Map tiles and the public location map are provided by OpenStreetMap. We also link to Strava when a member supplies a Strava link. Those providers process information under their own terms and privacy notices.
Some blog posts may contain privacy-enhanced YouTube embeds, and approved race cards may load an organiser's image from an approved external host. Following any external link or loading an embedded third-party service is subject to that provider's privacy practices.
International processing
Cloudflare, Auth0/Okta, Google, Resend, Strava, YouTube and other online providers may process information outside the UK. Their processing is governed by their own privacy information and safeguards. We do not make claims here about the particular transfer mechanism used by any provider; please review the provider's privacy information if you need more detail.
Cookies and similar technology
The members area uses two strictly necessary, signed HTTP-only cookies: a short-lived sign-in-flow cookie and a member-session cookie. They are used to complete secure sign-in and keep members signed in. They are not available to page JavaScript.
We do not use advertising cookies, analytics cookies, or application local storage/session storage. The site's Progressive Web App feature may store public pages and public assets in browser cache storage for offline use. It does not cache member pages or member API responses.
How long we keep information
We do not currently operate fixed retention periods in the website. We keep account and member-feature information while it is needed to operate the members area and for a reasonable period afterwards where necessary. We retain contact information long enough to handle the enquiry. Security, provider, and backup retention may be subject to the relevant provider's operational practices.
You can ask us to remove personal data by contacting us. We will consider the request in line with applicable law and explain if we need to retain limited information, for example for legal claims or security. Removing a member account does not necessarily remove every historic event-plan or map entry automatically, so we will handle those requests manually.
Your rights
Depending on the circumstances, you may have rights to request access to your personal data; correction; erasure; restriction; objection to processing based on legitimate interests; and data portability. You can withdraw consent at any time where we rely on it, without affecting processing before withdrawal. To use these rights, contact us using the address above.
You can complain to the UK Information Commissioner's Office at ico.org.uk (opens in a new tab). We would appreciate the opportunity to address concerns first.
Children
We do not set an age restriction through this website and do not intentionally collect special-category data. If you are a parent or guardian with a question about a child's personal data, please contact us.
Changes to this policy
We may update this policy when the website or our data practices change. We will publish the updated version here and revise the date at the top.