Version 2.0 · Last updated: 30 May 2026
This Privacy Policy explains how Racekeep Limited, trading as Fitvent ("Fitvent", "we", "our", "us") collects, uses, shares, and protects your personal data when you use the Fitvent platform (fitvent.com and related subdomains, mobile and embedded experiences). It is written to satisfy the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Act 2018, the Irish ePrivacy Regulations (S.I. 336/2011), and other Irish and EU laws that apply to us.
Please read it carefully. If anything is unclear, contact us at hello@fitvent.com.
The data controller responsible for your personal data under the GDPR is:
We have not formally appointed a Data Protection Officer because the GDPR does not require us to do so. The address above is the right place to send all data-protection enquiries; we respond within one month as required by Article 12(3) GDPR.
This policy applies to personal data we process as a data controller: data we decide how and why to use. Examples include your account on Fitvent, your purchases through our checkout, your marketing preferences, and your interactions with our website.
We also process personal data as a data processor on behalf of event organisers who use Fitvent to run their events. For example, when you register for an event, the event organiser decides what registration questions to ask, what to do with the answers, and how to communicate with you. That organiser is the data controller for that data and has their own privacy notice. We act only on their documented instructions and under a written processor agreement that meets Article 28 GDPR. If you have questions about how an event organiser uses your data, contact the organiser directly. If they do not respond, contact us and we will help.
We collect the following categories of personal data:
Some events ask medical-screening questions or process other health-related information (e.g. allergies, medical conditions, fitness to participate). Health data is a "special category" of data under Article 9 GDPR and is processed only where: (a) you have given your explicit consent (Article 9(2)(a)); or (b) processing is necessary for reasons of public interest in the area of public health, including ensuring high standards of safety (Article 9(2)(i)); or (c) processing is necessary to protect your vital interests where you are physically incapable of giving consent (Article 9(2)(c)). Health data is restricted to authorised personnel and is not used for marketing.
Under Article 6 GDPR every use of personal data must rely on a legal basis. Below is the basis we rely on for each purpose:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; letting you sign in; resetting your password. | Performance of a contract with you (Art 6(1)(b)). |
| Processing your event registration, ticket transfer, name change, refund, or other action you request. | Performance of a contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)) in fulfilling instructions on behalf of the event organiser. |
| Taking payment, issuing receipts, refunding when required. | Performance of a contract (Art 6(1)(b)); compliance with a legal obligation (Art 6(1)(c)) including the requirements of revenue, accounting and anti-money-laundering law. |
| Sending you transactional emails about your booking (confirmation, ticket, schedule updates, cancellations). | Performance of a contract (Art 6(1)(b)). |
| Sending you marketing about future events from us or, with your consent, from organisers you have bought from. | Your consent (Art 6(1)(a)) or our legitimate interest in keeping returning customers informed of similar events (Art 6(1)(f)), subject in each case to the soft opt-in / opt-out rules under the ePrivacy Regulations. |
| Preventing fraud, detecting abuse, securing the platform, rate-limiting, and investigating misuse. | Legitimate interests (Art 6(1)(f)) and, where applicable, compliance with a legal obligation (Art 6(1)(c)). |
| Customer-support enquiries, including investigating complaints. | Performance of a contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)). |
| Improving the platform: bug fixes, analytics on aggregated usage, A/B testing. | Legitimate interests (Art 6(1)(f)). |
| Processing health-related information for safety (medical screening, emergency contacts, etc.). | Your explicit consent (Art 9(2)(a)); or processing necessary on grounds of substantial public interest in safety (Art 9(2)(g) read with the Data Protection Act 2018). |
| Race-day biometric face-matching to help you find your photos. | Your explicit consent (Art 9(2)(a)) given when you opt in to the race-photo feature. |
| Defending or asserting legal claims; complying with court orders, regulatory requests, lawful demands by law enforcement. | Compliance with a legal obligation (Art 6(1)(c)); establishment, exercise or defence of legal claims (Art 9(2)(f) for special category data). |
We do not sell your personal data. We share it only with the following categories of recipient, and only as much as each one needs to do what we have asked them to do.
When you register for an event, the organiser running that event receives your registration data as a separate controller (see section 2). Each organiser has their own privacy policy.
We use the following sub-processors. Each is bound by a written data-processing agreement under Article 28 GDPR.
| Provider | What they do for us | Location |
|---|---|---|
| Stripe Payments Europe, Ltd. (with Stripe, Inc.) | Payment processing, fraud detection, Connect marketplace payouts | Ireland, with transfers to the United States |
| Clerk, Inc. | Authentication, sign-in, password management | United States |
| Supabase, Inc. (using AWS infrastructure) | Primary application database | Ireland (eu-west-1) |
| Vercel Inc. | Hosting for the Fitvent web application and edge network | Ireland (primary), with global edge points |
| Render Services, Inc. | Hosting for our background workers and queue infrastructure | Germany (Frankfurt) |
| Upstash Inc. | Rate-limit and inventory counters (Redis) | EU region |
| Resend (Resend, Inc.) | Sending transactional and marketing emails | United States, with EU delivery infrastructure |
| Twilio Inc. | Sending SMS and WhatsApp messages, and SMS one-time codes | United States |
| Amazon Web Services EMEA SARL | Object storage (S3) for waivers, logos, race-day photos; face matching (Rekognition) when an organiser enables the photo feature | Ireland (eu-west-1) |
| Cloudflare, Inc. | DNS, edge caching, DDoS protection | Global |
| OpenAI, L.L.C. | Generative-AI features (for example, summarising event drafts an organiser provides) | United States |
| Anthropic, PBC | Generative-AI features (Claude models) | United States |
| Duffel Technology Ltd. | Optional hotel and travel booking for participants who buy accommodation through us | United Kingdom |
We keep this list up to date. If we appoint a new sub-processor we will update this page and, where required, give you advance notice.
Some of the providers listed in section 6 are based outside the European Economic Area (EEA), in particular in the United States and the United Kingdom. When we transfer your personal data outside the EEA we rely on one of the following safeguards approved by the European Commission:
You can request a copy of the safeguard that applies to a specific transfer by emailing hello@fitvent.com.
We keep personal data only for as long as we need it for the purposes described in this policy, and then we delete it or anonymise it. Specific retention periods include:
| Category | How long |
|---|---|
| Account profile and login history | While your account is active; then 12 months after you ask us to delete it (to support investigation of any subsequent dispute). |
| Event registration data and waivers | 7 years after the event date (to support audit, insurance, and statutory limitation periods for personal-injury claims). |
| Payment records, invoices, refund records | 7 years after the transaction (Section 886 Taxes Consolidation Act 1997 and accounting record-keeping rules). |
| Marketing preferences and unsubscribe records | Indefinitely while you remain unsubscribed, so we do not re-mail you. |
| Customer-support correspondence | 3 years after the ticket closes. |
| Race-day photos and face-matching templates | Photos: 18 months after the event, then archived without the templates. Face-matching templates: deleted within 30 days of the event finishing, or sooner if you withdraw consent. |
| Application logs, security logs, error reports | Up to 90 days, then deleted; truly aggregated metrics may be kept indefinitely. |
| Cookies (non-essential) | See section 10. |
Where the law requires us to keep data for longer, or where we need to keep it to defend a legal claim, we will do so but we will keep only what is needed.
You have the following rights under the GDPR:
To exercise any of these rights, email hello@fitvent.com from the address linked to your account, or include enough information for us to verify your identity. We respond within one month and will only extend this where the request is particularly complex (Article 12(3) GDPR).
We use cookies and similar local-storage technologies to make Fitvent work and to understand how it is used. Under the Irish ePrivacy Regulations, we ask for your consent before placing any cookie that is not strictly necessary.
These are placed without consent because the platform cannot work without them. They include the session cookie that keeps you signed in, an anti-CSRF token, a cart token while you are checking out, and the cookie that records your cookie preferences. They expire when you sign out or within a few hours of inactivity.
These remember preferences such as theme, language, and the most recent organisation you were viewing. They expire after 12 months. We set them only with your consent.
We use privacy-preserving analytics to understand how people use Fitvent in aggregate. Where these involve cookies or store identifiers on your device, we ask for your consent first.
Some pages embed third-party content (e.g. a Stripe payment field). Those third parties may set their own cookies; their privacy and cookie policies apply.
You can withdraw cookie consent at any time through the cookie settings link in the site footer, or by clearing cookies in your browser. Browser-level "Do Not Track" signals are honoured for analytics cookies.
Section 31 of the Irish Data Protection Act 2018 sets the digital age of consent at 16. We do not knowingly process personal data of anyone under 16 on the basis of their own consent. Where a young person under 16 takes part in an event:
If you believe we have collected data from a child without proper consent, contact us and we will delete it immediately.
We do not make decisions that produce a legal effect on you, or a similarly significant effect on you, based solely on automated processing. In particular:
We will only send you marketing emails about events or features that we reasonably believe you will be interested in:
Every marketing email contains a one-click unsubscribe link. You can also unsubscribe from your account settings or by emailing us. Unsubscribing only stops marketing email; we will still send you essential service emails about events you are registered for.
Where an event organiser is the marketer, we forward your message preferences to them; they are responsible for honouring them.
We take the security of your personal data seriously. Our measures include:
We may update this policy from time to time, for example to reflect changes in the law or in how the platform works. The "last updated" date and version number at the top of this page tell you the latest revision. Where a change is material we will notify you directly (for example by email or via an in-platform notice) before it takes effect.
We hope to resolve any concerns directly. If you believe we have breached your data-protection rights you also have the right to lodge a complaint with the Irish Data Protection Commission:
You can also complain to the supervisory authority in the EU country where you live or work, or where the alleged infringement happened.
For any privacy enquiry, including to exercise any of the rights in section 9, contact:
See also our Terms & Conditions.