RacePack — Privacy Policy
Effective Date: 1 January 2027 Last Updated: [Update on each revision]
This Privacy Policy explains how RacePack Solutions, a subsidiary of SokoTech Solutions Ltd (a company registered in Kenya, "RacePack," "we," "us," or "our"), collects, uses, shares, and protects your personal data when you use the RacePack app or website (together, the "Platform"). It should be read alongside our Terms of Service.
1. What Data We Collect
1.1 Account information
Full name, phone number, email address (optional), date of birth (where required for event eligibility), and a hashed password or phone-based OTP session — we never store your OTP code itself.
1.2 Registration information
Event registrations, bib numbers, t-shirt size, race distance selection, and (for group/organiser accounts) business details collected during KYC.
1.3 Payment information
We do not store your full card number or M-Pesa PIN. Payments are processed by Paystack and, where applicable, Stripe — we retain only transaction references, amounts, and status needed to confirm your registration and issue refunds.
1.4 Health and emergency information (optional, explicit consent required)
Blood type, medical conditions/allergies relevant to emergency care, and emergency contact name/phone. This is never required to use RacePack — you can register for events without providing any of it. See §5 below for how this specific category is protected.
1.5 Location data
If you grant location permission, we use your device's location only while the app is in use to show nearby events and directions. We do not track your location in the background, and location is never stored against your account profile beyond what's needed to render the current map view.
1.6 Device and usage data
Device type, OS version, app version, crash reports (via Sentry), and basic usage analytics needed to keep the app working and find bugs.
1.7 Photos
If you upload a profile photo, it's stored to display on your profile. We do not access your photo library beyond the specific image you choose to upload.
2. Why We Collect It (Legal Bases)
- Contract performance — to register you for events, issue your digital bib, and process payments you've requested.
- Legitimate interest — to prevent fraud, keep the platform secure, and improve the app based on aggregated usage patterns.
- Legal obligation — to comply with KYC/AML requirements for organisers and vendors, and tax record-keeping.
- Consent — for marketing messages, optional health data, and any feature that explicitly asks for your permission (camera, location, biometrics, push notifications).
3. Who We Share It With
We share data only with the parties needed to run the service:
| Recipient | What they get | Why |
|---|---|---|
| Paystack / Stripe | Payment amount, your name, contact details | Process your payment |
| Event Organisers | Your name, contact details, registration info | They need this to run the event you registered for — see our Terms §6.3 (Organiser as data processor relationship) |
| Twilio | Your phone number | Send WhatsApp/SMS notifications (bib ready, event reminders) |
| Supabase | Account credentials (hashed) | Authentication infrastructure |
| AWS (S3 + CloudFront) | Uploaded documents/images | File storage and delivery |
| Sentry | Crash reports, device info (no PII unless it appears in a stack trace, which we scrub where possible) | Bug detection |
We do not sell your personal data to anyone, for any reason.
4. International Transfers
Your data is primarily stored in Kenya (af-south-1 region for file storage) and Ireland (Supabase's EU infrastructure). If you're outside Kenya, this means your data crosses borders to reach our servers — we rely on standard contractual safeguards with our infrastructure providers to protect it in transit and at rest.
5. Health and Emergency Data — Extra Protection
This category gets stricter handling than everything else on this list:
- Entirely optional. You can use RacePack fully without ever providing it.
- Single purpose. Used only to display on your emergency QR code for race marshals/medical personnel in an actual emergency — never for marketing, profiling, or any other purpose.
- Encrypted at rest using AES-256-GCM, with the decryption key stored separately from the database.
- Access-gated. Only reachable via your personal emergency QR code, and only when someone is physically present with you and scans it.
- Auto-deleted within 90 days of your event date, or immediately if you delete it yourself from profile settings.
- Legal basis: your explicit consent (GDPR Article 9(2)(a) and equivalent). You can withdraw consent at any time by deleting the data.
6. How Long We Keep It
| Data category | Retention |
|---|---|
| Account data | Active account + 7 years after closure (fraud prevention, regulatory) |
| Payment records | 7 years (tax/accounting requirement) |
| Race results | Indefinitely (part of the public sporting record) |
| Photos | 3 years after the event, or immediately on request |
| Health/emergency data | 90 days after event date, or immediately on request |
7. Your Rights
Depending on where you live, you may have the right to: access your data, correct it, delete it, export it (data portability), restrict how we process it, or object to processing. To exercise any of these, email privacy@racepack.io — we respond within 30 days.
Kenya (KDPA): lodge a complaint with the Office of the Data Protection Commissioner (ODPC) — info@odpc.go.ke UK: Information Commissioner's Office (ICO) — ico.org.uk EU: your national data protection authority — list at edpb.europa.eu Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au US (California): CCPA rights via privacy@racepack.io India: DPDP Act 2023 rights via privacy@racepack.io
8. Marketing Communications
We send event recommendations and platform updates by push notification, WhatsApp, and email. Opt out any time by:
- Replying STOP to any WhatsApp message
- Using the unsubscribe link in any email
- Adjusting notification settings in the app
- Emailing privacy@racepack.io
You can't opt out of transactional messages (registration confirmations, security alerts) while your account is active — these aren't marketing, they're how the service works.
9. Cookies (Website Only)
racepack.io uses cookies for login sessions, basic analytics, and (where applicable) marketing attribution. Manage your preferences via the cookie consent banner on first visit.
10. Children
RacePack is intended for users 18 and older. If you're registering a minor for an event, you do so through your own adult account as their parent/guardian — see Terms §4.1. We don't knowingly collect data directly from children.
11. Security
We use industry-standard measures including encryption in transit (TLS) and at rest for sensitive fields, access controls limiting who at RacePack can see your data, and regular dependency/vulnerability monitoring. No system is perfectly secure — if you believe your account has been compromised, contact security@racepack.io immediately.
12. Changes to This Policy
We'll notify you of material changes via the app, WhatsApp, or email, with at least 30 days' notice before they take effect — same process as our Terms of Service §19.
13. Contact Us
Deleting your account
You can delete your RacePack account and the personal data attached to it at any time, from either place:
- In the app: Profile → Delete account.
- On the web, without the app: racepack.io/account/delete — verify with the email on your account and confirm. This works after you have uninstalled the app.
Deletion closes the account immediately. The personal data behind it is removed within 30 days, as the Kenya Data Protection Act requires. Anonymised payment records are retained because the money genuinely moved and our accounts must show it; they are no longer connected to you.
Privacy questions or rights requests: privacy@racepack.io Security incidents: security@racepack.io General support: support@racepack.io
Mailing Address: SokoTech Solutions Ltd (trading as RacePack Solutions) [Registered Address], Nairobi, Kenya