Privacy Policy

Version 2.0 · Last updated: 30 May 2026

This Privacy Policy explains how Racekeep Limited, trading as Fitvent ("Fitvent", "we", "our", "us") collects, uses, shares, and protects your personal data when you use the Fitvent platform (fitvent.com and related subdomains, mobile and embedded experiences). It is written to satisfy the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Act 2018, the Irish ePrivacy Regulations (S.I. 336/2011), and other Irish and EU laws that apply to us.

Please read it carefully. If anything is unclear, contact us at hello@fitvent.com.

Contents

  1. 1. Who we are (the data controller)
  2. 2. Scope of this policy
  3. 3. Personal data we collect
  4. 4. How we collect personal data
  5. 5. Why we use your data and our legal bases
  6. 6. Who we share your data with
  7. 7. International data transfers
  8. 8. How long we keep your data
  9. 9. Your rights under data protection law
  10. 10. Cookies and similar technologies
  11. 11. Children and young people
  12. 12. Automated decision-making and profiling
  13. 13. Marketing communications
  14. 14. How we protect your data
  15. 15. Changes to this policy
  16. 16. How to make a complaint
  17. 17. Contact us

1. Who we are (the data controller)

The data controller responsible for your personal data under the GDPR is:

We have not formally appointed a Data Protection Officer because the GDPR does not require us to do so. The address above is the right place to send all data-protection enquiries; we respond within one month as required by Article 12(3) GDPR.

2. Scope of this policy

This policy applies to personal data we process as a data controller: data we decide how and why to use. Examples include your account on Fitvent, your purchases through our checkout, your marketing preferences, and your interactions with our website.

We also process personal data as a data processor on behalf of event organisers who use Fitvent to run their events. For example, when you register for an event, the event organiser decides what registration questions to ask, what to do with the answers, and how to communicate with you. That organiser is the data controller for that data and has their own privacy notice. We act only on their documented instructions and under a written processor agreement that meets Article 28 GDPR. If you have questions about how an event organiser uses your data, contact the organiser directly. If they do not respond, contact us and we will help.

3. Personal data we collect

We collect the following categories of personal data:

3.1 Identification and contact data

3.2 Account and authentication data

3.3 Event registration and participation data

3.4 Health-related data (special category)

Some events ask medical-screening questions or process other health-related information (e.g. allergies, medical conditions, fitness to participate). Health data is a "special category" of data under Article 9 GDPR and is processed only where: (a) you have given your explicit consent (Article 9(2)(a)); or (b) processing is necessary for reasons of public interest in the area of public health, including ensuring high standards of safety (Article 9(2)(i)); or (c) processing is necessary to protect your vital interests where you are physically incapable of giving consent (Article 9(2)(c)). Health data is restricted to authorised personnel and is not used for marketing.

3.5 Payment data

3.6 Communications data

3.7 Device and usage data

3.8 Race-day media (only where the event organiser has enabled photos)

4. How we collect personal data

5. Why we use your data and our legal bases

Under Article 6 GDPR every use of personal data must rely on a legal basis. Below is the basis we rely on for each purpose:

PurposeLegal basis
Creating and operating your account; letting you sign in; resetting your password.Performance of a contract with you (Art 6(1)(b)).
Processing your event registration, ticket transfer, name change, refund, or other action you request.Performance of a contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)) in fulfilling instructions on behalf of the event organiser.
Taking payment, issuing receipts, refunding when required.Performance of a contract (Art 6(1)(b)); compliance with a legal obligation (Art 6(1)(c)) including the requirements of revenue, accounting and anti-money-laundering law.
Sending you transactional emails about your booking (confirmation, ticket, schedule updates, cancellations).Performance of a contract (Art 6(1)(b)).
Sending you marketing about future events from us or, with your consent, from organisers you have bought from.Your consent (Art 6(1)(a)) or our legitimate interest in keeping returning customers informed of similar events (Art 6(1)(f)), subject in each case to the soft opt-in / opt-out rules under the ePrivacy Regulations.
Preventing fraud, detecting abuse, securing the platform, rate-limiting, and investigating misuse.Legitimate interests (Art 6(1)(f)) and, where applicable, compliance with a legal obligation (Art 6(1)(c)).
Customer-support enquiries, including investigating complaints.Performance of a contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)).
Improving the platform: bug fixes, analytics on aggregated usage, A/B testing.Legitimate interests (Art 6(1)(f)).
Processing health-related information for safety (medical screening, emergency contacts, etc.).Your explicit consent (Art 9(2)(a)); or processing necessary on grounds of substantial public interest in safety (Art 9(2)(g) read with the Data Protection Act 2018).
Race-day biometric face-matching to help you find your photos.Your explicit consent (Art 9(2)(a)) given when you opt in to the race-photo feature.
Defending or asserting legal claims; complying with court orders, regulatory requests, lawful demands by law enforcement.Compliance with a legal obligation (Art 6(1)(c)); establishment, exercise or defence of legal claims (Art 9(2)(f) for special category data).

6. Who we share your data with

We do not sell your personal data. We share it only with the following categories of recipient, and only as much as each one needs to do what we have asked them to do.

6.1 Event organisers

When you register for an event, the organiser running that event receives your registration data as a separate controller (see section 2). Each organiser has their own privacy policy.

6.2 Service providers we use to run Fitvent (our processors)

We use the following sub-processors. Each is bound by a written data-processing agreement under Article 28 GDPR.

ProviderWhat they do for usLocation
Stripe Payments Europe, Ltd. (with Stripe, Inc.)Payment processing, fraud detection, Connect marketplace payoutsIreland, with transfers to the United States
Clerk, Inc.Authentication, sign-in, password managementUnited States
Supabase, Inc. (using AWS infrastructure)Primary application databaseIreland (eu-west-1)
Vercel Inc.Hosting for the Fitvent web application and edge networkIreland (primary), with global edge points
Render Services, Inc.Hosting for our background workers and queue infrastructureGermany (Frankfurt)
Upstash Inc.Rate-limit and inventory counters (Redis)EU region
Resend (Resend, Inc.)Sending transactional and marketing emailsUnited States, with EU delivery infrastructure
Twilio Inc.Sending SMS and WhatsApp messages, and SMS one-time codesUnited States
Amazon Web Services EMEA SARLObject storage (S3) for waivers, logos, race-day photos; face matching (Rekognition) when an organiser enables the photo featureIreland (eu-west-1)
Cloudflare, Inc.DNS, edge caching, DDoS protectionGlobal
OpenAI, L.L.C.Generative-AI features (for example, summarising event drafts an organiser provides)United States
Anthropic, PBCGenerative-AI features (Claude models)United States
Duffel Technology Ltd.Optional hotel and travel booking for participants who buy accommodation through usUnited Kingdom

We keep this list up to date. If we appoint a new sub-processor we will update this page and, where required, give you advance notice.

6.3 Other recipients

7. International data transfers

Some of the providers listed in section 6 are based outside the European Economic Area (EEA), in particular in the United States and the United Kingdom. When we transfer your personal data outside the EEA we rely on one of the following safeguards approved by the European Commission:

You can request a copy of the safeguard that applies to a specific transfer by emailing hello@fitvent.com.

8. How long we keep your data

We keep personal data only for as long as we need it for the purposes described in this policy, and then we delete it or anonymise it. Specific retention periods include:

CategoryHow long
Account profile and login historyWhile your account is active; then 12 months after you ask us to delete it (to support investigation of any subsequent dispute).
Event registration data and waivers7 years after the event date (to support audit, insurance, and statutory limitation periods for personal-injury claims).
Payment records, invoices, refund records7 years after the transaction (Section 886 Taxes Consolidation Act 1997 and accounting record-keeping rules).
Marketing preferences and unsubscribe recordsIndefinitely while you remain unsubscribed, so we do not re-mail you.
Customer-support correspondence3 years after the ticket closes.
Race-day photos and face-matching templatesPhotos: 18 months after the event, then archived without the templates. Face-matching templates: deleted within 30 days of the event finishing, or sooner if you withdraw consent.
Application logs, security logs, error reportsUp to 90 days, then deleted; truly aggregated metrics may be kept indefinitely.
Cookies (non-essential)See section 10.

Where the law requires us to keep data for longer, or where we need to keep it to defend a legal claim, we will do so but we will keep only what is needed.

9. Your rights under data protection law

You have the following rights under the GDPR:

To exercise any of these rights, email hello@fitvent.com from the address linked to your account, or include enough information for us to verify your identity. We respond within one month and will only extend this where the request is particularly complex (Article 12(3) GDPR).

10. Cookies and similar technologies

We use cookies and similar local-storage technologies to make Fitvent work and to understand how it is used. Under the Irish ePrivacy Regulations, we ask for your consent before placing any cookie that is not strictly necessary.

10.1 Strictly necessary cookies and storage

These are placed without consent because the platform cannot work without them. They include the session cookie that keeps you signed in, an anti-CSRF token, a cart token while you are checking out, and the cookie that records your cookie preferences. They expire when you sign out or within a few hours of inactivity.

10.2 Functional

These remember preferences such as theme, language, and the most recent organisation you were viewing. They expire after 12 months. We set them only with your consent.

10.3 Analytics

We use privacy-preserving analytics to understand how people use Fitvent in aggregate. Where these involve cookies or store identifiers on your device, we ask for your consent first.

10.4 Third-party content

Some pages embed third-party content (e.g. a Stripe payment field). Those third parties may set their own cookies; their privacy and cookie policies apply.

You can withdraw cookie consent at any time through the cookie settings link in the site footer, or by clearing cookies in your browser. Browser-level "Do Not Track" signals are honoured for analytics cookies.

11. Children and young people

Section 31 of the Irish Data Protection Act 2018 sets the digital age of consent at 16. We do not knowingly process personal data of anyone under 16 on the basis of their own consent. Where a young person under 16 takes part in an event:

If you believe we have collected data from a child without proper consent, contact us and we will delete it immediately.

12. Automated decision-making and profiling

We do not make decisions that produce a legal effect on you, or a similarly significant effect on you, based solely on automated processing. In particular:

13. Marketing communications

We will only send you marketing emails about events or features that we reasonably believe you will be interested in:

Every marketing email contains a one-click unsubscribe link. You can also unsubscribe from your account settings or by emailing us. Unsubscribing only stops marketing email; we will still send you essential service emails about events you are registered for.

Where an event organiser is the marketer, we forward your message preferences to them; they are responsible for honouring them.

14. How we protect your data

We take the security of your personal data seriously. Our measures include:

15. Changes to this policy

We may update this policy from time to time, for example to reflect changes in the law or in how the platform works. The "last updated" date and version number at the top of this page tell you the latest revision. Where a change is material we will notify you directly (for example by email or via an in-platform notice) before it takes effect.

16. How to make a complaint

We hope to resolve any concerns directly. If you believe we have breached your data-protection rights you also have the right to lodge a complaint with the Irish Data Protection Commission:

You can also complain to the supervisory authority in the EU country where you live or work, or where the alleged infringement happened.

17. Contact us

For any privacy enquiry, including to exercise any of the rights in section 9, contact:

See also our Terms & Conditions.