Back

Privacy Statement

Last updated: 21 August 2026  ·  Applicable law: GDPR (EU 2016/679)

1. Who We Are (Data Controller)

RaceArchitect is a service for running coaches and athletes, operated by React BV (Belgium), which is the data controller responsible for the processing of your personal data. For all privacy-related inquiries please contact us at privacy@racearchitect.com.

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: username, email address, first and last name, date of birth, gender, country, profile picture.
  • Performance and health data: race results, fitness scores, lactate test results, training logs, daily readiness check-ins (sleep, muscle soreness, energy and stress levels, resting heart rate), and any unavailability periods you mark with a reason such as injury or illness.
  • Connected fitness data: when you connect Strava, we import activity name, distance, pace, heart rate, heart-rate zones, elevation and per-kilometre splits for your runs. If you upload a GPX course file for race-day pacing, its route and elevation profile are stored.
  • Communication data: messages exchanged between athletes and coaches inside the platform.
  • Visitor chat data: if you ask a question through the chat on our website without an account, we store your question and any name or email address you choose to add, so we can answer you. Your IP address is stored briefly to limit misuse of the form. A small identifier is kept in your browser's local storage so you see the reply when you come back.
  • Test-day registration data: when you sign up for a lactate test day without creating an account, we collect your name, email, phone number, date of birth, and a written health declaration confirming you are fit to take part in a maximal-effort test.
  • Payment and billing data: for coaching subscriptions and paid lactate test days: your chosen payment method, the amount, a structured payment reference, and — when an invoice is issued — your name and address on the invoice, which we must keep for the legal accounting retention period. We never store your card or bank account details; online payments are processed by our payment provider (Mollie). If you switch on automatic renewal, a customer reference and payment mandate are held at Mollie so the next term can be collected — you can stop this at any time from your subscription page.
  • Security data: if you enable two-factor authentication, an encrypted authenticator secret and hashed recovery codes; a signed “trusted device” cookie so you are not asked again on that device for a limited period.
  • Usage and analytics data: login timestamps, browser language preference, and pseudonymous page-view statistics (device type, browser, operating system, and country derived from your IP address at the time of the request — the IP address itself is never stored).

3. Legal Basis for Processing

We process your data on the following legal bases (Art. 6 GDPR):

  • Contract performance (Art. 6(1)(b)): to provide you access to your training plans, race goals and coaching communication.
  • Consent (Art. 6(1)(a)): for optional features you actively switch on, such as connecting Strava or uploading a GPX course file.
  • Explicit consent (Art. 9(2)(a)): for health-related data — lactate test results, the health declaration on a test-day signup, and daily readiness check-ins — which you provide voluntarily so your coach can tailor your training safely.
  • Legal obligation (Art. 6(1)(c)): to issue and retain invoices for the statutory accounting retention period.
  • Legitimate interest (Art. 6(1)(f)): to improve and secure the service — including error monitoring, pseudonymous usage analytics and account security measures such as two-factor authentication — and to send at most one re-engagement email after a subscription has lapsed. You can object to that email at any time (see your rights below).

4. How We Use Your Data

  • Providing and personalising your training plans and performance analysis.
  • Enabling communication between athlete and coach.
  • Generating pace recommendations and race predictions based on fitness-score methodology.
  • Matching your synced Strava activities to your planned sessions and displaying heart-rate zones and splits.
  • Generating short AI workout descriptions to help you understand a session at a glance.
  • Processing payments and issuing invoices for coaching subscriptions and paid lactate test days.
  • Sending you service emails about your account and payments — such as a notice before an automatic renewal is collected, or a reminder when your subscription is about to end. The optional weekly training digest can be switched off in your account settings and every edition contains an unsubscribe link.
  • Securing your account and preventing unauthorised access, including through two-factor authentication.
  • Monitoring and improving the reliability and performance of the service.

5. Data Sharing

We do not sell your personal data. Your data may be shared with:

  • Your coach (trainer): coaches assigned to your account can view your performance data, training logs and messages.
  • Anthropic (Claude API): the text of your training sessions is sent to Anthropic's Claude API to generate the optional AI workout descriptions shown in your plan, and — when a coach generates an AI training plan — the plan parameters (race distance, target time, number of weeks and a fitness score). Your name, contact details and health data are never included, and coaching chat messages are never sent to an AI — chat is a direct, human-only conversation between you and your coach.
  • Strava: if you choose to connect your Strava account, we exchange OAuth authorisation with Strava and retrieve your run activities on your behalf. Nothing is shared back to Strava.
  • Mollie: when you pay online — for a subscription or a lactate test day — your payment is handled directly by Mollie, our payment service provider. We never see or store your card or bank details. If you opt in to automatic renewal, Mollie also holds the payment mandate; revoking it stops future charges.
  • Hosting provider (Hetzner): your data is stored on servers located in the European Union.
  • Error monitoring (Sentry): when enabled, technical error reports (which may incidentally include a username or request path) are sent to Sentry to help us diagnose and fix bugs.
  • Email provider (Twilio SendGrid): transactional emails (password resets, invites, digests, invoices) are delivered through Twilio SendGrid, which processes your email address and the message content in the United States. This transfer is safeguarded by the EU–US Data Privacy Framework and standard contractual clauses.

6. Data Retention

We retain your personal data for as long as your account is active. When you delete your account, your personal data will be permanently removed within 30 days, except where retention is required by law — for example, issued invoices, which we must keep for the legal accounting retention period. If you register for a lactate test day without creating an account, your registration data is kept for as long as reasonably needed to run that test day and provide your results, or until you ask us to remove it. A chat conversation started from our website without an account is automatically deleted after 365 days. Pseudonymous page-view statistics are deleted after 90 days and technical performance logs after 30 days. Database backups — including an encrypted off-site copy stored within the EU — are kept for 30 days and are then automatically deleted.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15): request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): correct inaccurate or incomplete data via your account settings.
  • Right to erasure (Art. 17): request deletion of your account and associated data.
  • Right to data portability (Art. 20): request your data in a structured, machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interest.
  • Right to restriction (Art. 18): request that we restrict processing of your data.

You can exercise the rights of access, erasure and data portability yourself at any time from the My Account page: “Download my data” gives you a full export of your personal data, and “Delete my account” permanently removes your account. For any other request, contact us at privacy@racearchitect.com. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données): www.gegevensbeschermingsautoriteit.be.

8. Cookies and Local Storage

We use a login session cookie (sessionid), a security cookie (csrftoken) and a language preference cookie. If you enable two-factor authentication, a signed “trusted device” cookie lets you skip the second step on that browser for a limited number of days. Your browser's local storage is used to remember that you dismissed a promotional banner and, if you use the visitor chat, to hold the identifier that shows you the reply to your question. No third-party advertising or tracking cookies are set.

9. Changes to This Policy

We may update this Privacy Statement. The date at the top of this page reflects the most recent revision, and we will announce material changes on the platform before they take effect.