Privacy Policy
Effective date: 20 August 2026
RunHub ("RunHub", "we", "us") is operated by Marc Donegan, an individual based in England. This policy explains what personal data we collect through the RunHub app and website, why, and what rights you have over it.
If you have questions, contact support@wearerunhub.co.uk.
1. Who this applies to
RunHub has two kinds of users:
- Runners — people who discover run clubs, RSVP to runs, and check in when they attend.
- Hosts — people who create and manage a club, schedule runs, and view attendance for their own club.
This policy covers both. Where something applies to only one, we say so.
2. What we collect
Account information (everyone)
- Full name, email address
- Password (if you sign up with email) — we never see this in plain text; it's handled by our authentication provider (Supabase Auth)
- If you sign up with Sign in with Apple or Google: the name and email your Apple/Google account shares with us, and an identifier used to link your RunHub account to that sign-in method. We only receive what Apple/Google chooses to share — for Apple, that can be limited to a one-time relay email address if you choose "Hide My Email."
- Your role (Runner or Host)
Date of birth and gender
- Date of birth and gender — required to create an account. Gender includes a "prefer not to say" option.
- Your date of birth and gender are never shown to hosts, other members, or any individual.
- Hosts see aggregated, club-wide demographic statistics only:
- Gender is shown per category (male/female/prefer not to say) only if your club has at least 5 members in that category.
- Age bands (18-24, 25-34, 35-44, 45-54, 55+) are shown only if your club has at least 10 members with a date of birth on file. Once that threshold is met, all bands are shown at their real percentage.
Location data
- Device location, if you grant permission — used to sort/show nearby clubs in Discover. You can decline this and still use the app.
- Club and run locations set by hosts — when a host creates a club or run, they set a location via address search or map pin.
Activity data
- Clubs you join, runs you RSVP to, and your check-in history (when you attended, which club, streaks)
- If you're a host: the clubs/runs you create and manage, and the attendance register for your own club (who RSVP'd, who checked in)
Guest check-in data (host-entered or self-serve link)
There are two ways someone can be checked into a run without a RunHub account, and both collect the same thing: a name, nothing else.
- A host checks you in. Hosts can log a guest's attendance directly, using just a name. If you're a host doing this: you're providing data about someone else, and you should have a reasonable basis for doing so (e.g. they're standing next to you and know you're logging their attendance).
- You check yourself in via a shared link. Hosts can share a link to a specific run (for example, in a group chat) that lets anyone check themselves in without installing the app or creating an account. This asks for your name only — no email address, and no account is created.
We don't link this to any other data about you unless you separately create a RunHub account. To request removal of a guest check-in, email support@wearerunhub.co.uk with the run date, and name it was recorded under.
Content hosts create
Club descriptions, FAQs, meeting point/parking notes, Instagram links, and any images uploaded for a club.
Support communications
If you email us for support, we keep that correspondence to resolve your query and improve the app.
Crash reports
If the app crashes, Apple's built-in crash reporting sends us a report: what went wrong, your app version, OS version, and device model. It's stored in our own database, not a third-party analytics company. If you're signed in, the report may be linked to your account so we can investigate; we never use it for advertising or tracking.
Cookies and tracking
The RunHub app does not use any other analytics SDK, advertising ID, or tracking cookie. The website at wearerunhub.co.uk similarly uses no analytics or tracking cookies today — it's a single static page. If that changes, we'll update this section first and name the tool before it ships.
Marketing communications
If you opt in to our waitlist, we may email you occasional product updates or launch announcements. Every such email includes a way to unsubscribe. Unsubscribing won't affect transactional emails we need to send about your account (e.g. support replies, security notices).
3. Why we process this data, and our legal basis
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating and running your account | Necessary to perform our contract with you (our Terms & Conditions) |
| Showing you clubs/runs, enabling RSVP and check-in | Necessary to perform our contract with you |
| Recording guest attendance (host-entered, or self-serve via a shared check-in link) — no account created | Legitimate interest (accurate attendance records for the host's club) |
| Discovery sorted by distance | Consent (you grant location permission; you can withdraw it any time in iOS Settings) |
| Collecting date of birth and gender at sign-up; aggregated, group-level demographic stats for hosts | Necessary to perform our contract with you (collection); legitimate interest (helping hosts understand their community) |
| Responding to support requests | Legitimate interest in resolving your query |
| Sending marketing/product-update emails | Consent — you can withdraw any time by unsubscribing |
| Security, fraud prevention, abuse prevention | Legitimate interest / legal obligation |
4. Who we share it with
- Supabase — our backend/database provider, which stores your data on our behalf. Our Supabase project is hosted in the EU/UK region.
- Apple / Google — only if you sign in with those providers, per their own privacy policies.
- Other users, within a club: if you RSVP or check in, the club's host(s) can see your name and attendance status. Other members may see who else has RSVP'd, depending on the screen. Hosts see aggregated, non-identifiable age and gender statistics for their club as a whole — never your individual date of birth or gender.
- We do not sell your data, and we do not share it with advertisers or use it for ad targeting.
- We may disclose data if required by law, or to protect the safety of our users.
5. How long we keep it
We keep your data while your account is active. We don't auto-delete dormant accounts — if you stop using RunHub without deleting your account, your data stays as-is until you delete it yourself or ask us to. You can delete your account at any time from your Profile screen in the app. When you do, we anonymize your attendance history (so club-level statistics stay accurate) and delete your profile and account credentials.
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (subject to the anonymization note above for attendance records)
- Restrict or object to certain processing
- Data portability — receive your data in a portable format
- Withdraw consent at any time for anything based on consent (e.g. location), without affecting the lawfulness of processing before withdrawal
- Complain to the ICO (Information Commissioner's Office, ico.org.uk) if you believe we've mishandled your data
To exercise any of these, contact support@wearerunhub.co.uk.
7. Children
RunHub is not directed at, and is not intended for use by, anyone under 18. This is enforced at sign-up — the date-of-birth picker only allows dates 18 years ago or earlier. We do not knowingly collect data from children under 18.
8. Security
We rely on Supabase's Row Level Security to enforce that users can only access data they're authorized to see, and industry-standard encryption in transit. No system is perfectly secure, and we can't guarantee absolute security. If a data breach occurs that's likely to put your rights or freedoms at risk, we'll notify the ICO and affected users as required under UK GDPR.
9. International transfers
Our Supabase project is hosted in the EU/UK region, so your data stays within the UK/EEA. Apple and Google may process sign-in data outside the UK/EEA under their own privacy policies, in connection with Sign in with Apple or Google Sign-In.
10. Changes to this policy
We'll update the effective date above when this changes, and for material changes, make a reasonable effort to notify you in-app.
