Legal
Privacy Policy
Last updated: July 17, 2026 · Version 2.2
Who we are
Running Legacy (runninglegacy.com) is operated by Russell Carter. We provide a youth running club management platform and a youth running book platform for athletes, parents, and coaches.
What data we collect
For adult accounts (parents and coaches):
- Email address and full name
- Password (stored as a one-way bcrypt hash; we cannot read it)
- Date of birth (for age verification at registration)
- Phone number (optional; for SMS notifications only)
- Parental consent timestamps, IP address, and browser agent (required by COPPA)
- Club membership history, event RSVPs, and run logs (if you participate as a runner)
For student accounts (children):
- Display name only (e.g. “Emma R.”), no last name, no photo
- Date of birth and current grade
- Run logs: distance, duration, date, and optional coach notes
- Emergency contact: name, relationship, and phone number
- Medical notes (optional; allergies or conditions visible only to coaches)
- Event RSVPs, attendance history, badge history, and challenge submissions
We practice data minimization: we collect only the information reasonably necessary to run a youth club, and nothing more from children (a display name, not a full name; no child photo is required to participate). We do not use advertising trackers, ad pixels, or behavioral advertising of any kind. We do use privacy-respecting usage analytics to operate and improve the service (see Usage analytics below): a child's activity is analyzed only within our own systems and is never sent to a third-party analytics service. Fonts are self-hosted at build time, with no CDN calls to Google Fonts. GPS data from challenge submissions is extracted from photo EXIF metadata only; we do not request browser geolocation from children.
COPPA (Children's Online Privacy Protection Act)
Running Legacy is designed specifically for youth athletes. We comply with the Children's Online Privacy Protection Act (COPPA) and the FTC's 2025 rule amendments, which are in active enforcement as of April 22, 2026.
No child self-registration
Children under 13 cannot create their own accounts. All student accounts are created by a verified parent or legal guardian. We do not knowingly allow self-registration by anyone under 13.
Verifiable Parental Consent (VPC)
We use the FTC-approved “email-plus” method for verifiable parental consent:
- The guardian reviews and checks two separate consent checkboxes: one for data collection and use, one for disclosure to named third parties.
- We send a confirmation email to the guardian's verified email address with a one-time link (valid 24 hours).
- The guardian clicks the link. Only after that click is consent recorded as “confirmed.”
- A receipt email is sent summarizing what data we collect, which third parties receive it, and how to revoke consent.
Service providers who support our internal operations
The vendors below process data only to provide the service on our behalf, what COPPA treats as “support for the internal operations” of the service, not a disclosure to a third party. They are contractually limited to that purpose and may not use the data for their own ends. Because we do not disclose children's personal information to third parties for any purpose that is not integral to the service (no advertising, monetization, analytics, profiling, or AI training), the FTC-approved “email-plus” consent method is appropriate for our service.
- Resend: transactional email provider. Receives guardian and coach email addresses for sending notifications. Child email addresses are used only when the child has a login account.
- Twilio: SMS provider. Receives phone numbers only if a guardian provides one and enables SMS notifications. This is optional.
- PostHog: product-analytics provider for adult (coach and guardian) usage only, to help us understand and improve how the tools are used. It receives de-identified usage events tied to an internal account id, never names, emails, or dates of birth. Student usage is never sent to PostHog — a child's activity is analyzed only in our own database. No session recording is used.
- Fly.io: cloud infrastructure provider (United States) that hosts the application and its PostgreSQL database. The database runs on a private network and is not exposed to the public internet. Fly processes data only to run the service on our behalf and has no independent right to use it.
- Tigris: S3-compatible object storage (United States) that holds uploaded photos (with location EXIF stripped before storage) and encrypted database backups. It stores files on our behalf and may not use them for any other purpose.
Student accounts use email + password only. Google OAuth is never offered to student accounts. No student data is ever sold, licensed, or shared for advertising.
Usage analytics
To understand and improve how the service is used, we record de-identified usage events (such as which pages are visited and which features are used) tied only to an internal account id — never a name, email, or date of birth — with no session recording and no cross-site tracking.
- Children: a child's usage is analyzed only within our own systems (COPPA “support for internal operations”) and is never sent to any third-party analytics provider.
- Adults (parents and coaches): the same de-identified events are also processed by PostHog (listed above) to help us improve the tools. No advertising, no profiling for external use, no session recording.
Data retention
We retain a child's personal information only as long as reasonably necessary for the purpose it was collected: operating that child's participation in their running club (roster, events, run logs, badges, and the family link that lets a guardian manage the account), and never indefinitely. The specific timelines:
- Active membership: retained while the student is an active member of a club, because that is the business need the data serves.
- After deactivation or a guardian deletion request: retained for 30 days to allow cancellation, then permanently purged, including challenge-submission photos.
- Inactivity backstop: a student account that has been inactive for 24 months — no login, no logged run, and not enrolled in any active season — has its personal information purged automatically, so data is never kept beyond its purpose.
Parental rights
- Review: Sign in and visit Dashboard → Children → [child's name] to see all data collected for your child.
- Correct: Contact us at runner@runninglegacy.com to correct inaccurate information.
- Delete: Go to Dashboard → Children → [child's name] → “Delete account” to begin the 30-day deletion process.
- Revoke consent: Go to Account Settings → Privacy → “Revoke parental consent.” This suspends all associated student accounts and begins the deletion process.
If we ever learn that we collected personal information from a child under 13 without the required verifiable parental consent, we will delete that information promptly. To report such a concern, email runner@runninglegacy.com.
CCPA (California Consumer Privacy Act)
We do not sell or share your personal information, and we do not use or disclose the personal information of anyone under 16 for cross-context behavioral advertising. California residents (and residents of other US states with comparable laws) have the right to:
- Know the categories of personal data we collect, the purposes, and how long we keep it
- Request a copy of your data (go to Account Settings → “Download my data,” or email us)
- Request correction or deletion of your account and all associated data
- Opt out of the sale or sharing of personal information (we do none)
- Not be discriminated against for exercising these rights
To submit a request, email runner@runninglegacy.com. We will verify your identity using information associated with your account before acting on a request, and we will respond within 45 days (we may extend once by another 45 days where permitted, with notice). The categories and retention periods for the data we hold are described in the sections above.
Strava integration
Running Legacy can optionally sync your runs from Strava on a per-user, opt-in basis. The integration follows these rules:
- You initiate the connection from Account Settings → “Connect with Strava.” You're redirected to strava.com to authorize. We never collect Strava login credentials.
- Read-only access. We request the
readandactivity:readOAuth scopes only. We cannot post to your Strava account, change your activities, or write any data back to Strava. - What we receive. When you record a new activity on Strava (via your watch, phone, or any device that uploads to Strava), Strava sends us a webhook event. We then fetch that activity's public metadata: type, start time, duration, distance, elevation gain, splits, and GPS polyline.
- Home-start GPS trimming. Before storing any GPS track, we automatically remove the first and last 200 meters of the polyline. This protects your home, school, or club starting location from being inferred from the route shape.
- Only runs are imported. Bike rides, swims, and other non-run activity types are ignored even when Strava sends their events.
- Disconnect any time. Account Settings → Workout Sync → “Disconnect Strava” immediately deletes your OAuth tokens from our database and stops all future sync. Previously-synced runs remain in your account; you can delete them individually from the run detail page.
- Student accounts. Strava's minimum age is 13. Strava sync is not offered for COPPA-covered student accounts under 13, and the “Connect with Strava” button does not appear on those accounts.
Strava is a registered trademark of Strava, Inc. Running Legacy displays Strava data subject to Strava's API Agreement and brand guidelines. See Strava's API Agreement for details on Strava's data-handling commitments to you.
Strava-specific data rights
Per Strava's API Agreement §2.5(e), as a connected Strava athlete you have the following rights regarding any data we collected from Strava on your behalf:
- Support contact. Email runner@runninglegacy.com for help with your Strava connection, sync issues, or questions about data we hold.
- Access your data. Account Settings → “Download my data” gives you a JSON export of every Run, Workout, polyline, and Strava activity ID we have stored for you.
- Delete your data. Two options: (a) Account Settings → Workout Sync → “Disconnect Strava” immediately revokes our OAuth tokens and stops future sync (previously-synced runs remain; delete them individually from each run detail page); or (b) Account Settings → “Delete my account” removes everything we hold about you, including all Strava-sourced workouts.
- Navigate to your Strava account. Every run detail page sourced from Strava includes a “View on Strava” link that takes you directly to the activity record on strava.com so you can edit, comment, or delete it at the source.
- Source deletions cascade. When you delete an activity on Strava, Strava sends us a webhook event and we delete the corresponding Run + Workout rows from our database automatically. Per §2.5(f).
Data security
We maintain a written information-security program with a designated owner, a risk assessment, safeguards proportionate to the sensitivity of children's data, and at least an annual review, as required by the amended COPPA Rule. In practice: passwords are hashed with bcrypt (cost factor 12), all data is transmitted over HTTPS, the application and database are hosted on Fly.io in the United States with the database on a private network not exposed to the public internet, and database backups are encrypted.
School-affiliated clubs
If a club is operated by a school district or school-sponsored program, FERPA (Family Educational Rights and Privacy Act) may apply. School-affiliated clubs require a Data Use Agreement between the school and Running Legacy before student data may be shared. Contact runner@runninglegacy.com to obtain one.
Account deletion
Adult users can delete their account from Account Settings. Deletion immediately removes your profile, all associated run logs, posts, RSVPs, and badges. Student data linked to your account is queued for deletion (30-day soft-delete window) per our data retention policy above.
Changes to this policy
We review this policy at least once a year and update it as our practices or the law change. The “Last updated” date at the top reflects the current version. For material changes (new data uses, new sharing, or changes to children's data handling) we will notify active users by email and, where consent is required, ask you to accept the updated terms before continuing.
Contact
Privacy questions or data requests: runner@runninglegacy.com
Legal inquiries: runner@runninglegacy.com