Privacy Policy
Last updated: 18 July 2026
1. Who We Are
HUTCLUB LIMITED ("we", "us") is the data controller of personal data processed via the RunClub app and website. Company number 15147202, registered in England & Wales. Registered office: Aston House, 62-68 Oak End Way, Gerrards Cross, SL9 8FU. Contact: support@run-club.app.
2. Data We Collect
- Account data: name, username, email, profile photo, date of birth, mobile phone number, Firebase user ID.
- Activity data: GPS coordinates, distance, pace, duration, splits, active calories, elevation gain, and — on iOS only, if you grant Apple Health access — heart rate. On Android we do not read heart rate at all (see section 4a).
- Social data: posts, comments, likes, friend connections, club memberships.
- Contact-book data: if — and only if — you use the optional “Find Friends from Contacts” feature and grant contacts permission, the email addresses and phone numbers in your address book are sent to our servers to check which of them already have a RunClub account (see section 4b).
- Device & usage data: device type, OS version, app version, crash logs, anonymised analytics.
- Payment data: handled by Apple (iOS in-app purchases), Google Play (Android in-app purchases) or Stripe (web and venue subscriptions) — we do not see or store your card details.
3. How We Use Your Data
- To operate the Service (display your runs, surface your club's events, render the social feed).
- To send transactional emails (welcome, password reset, deal alerts).
- To improve the Service via aggregated analytics.
- To prevent fraud, abuse and policy violations.
- To verify your age (you must be 16 or over to use RunClub) — your date of birth is used to confirm eligibility at signup and is not displayed publicly.
- To secure your account — your mobile phone number is used for two-factor authentication, account recovery, and to alert you to suspicious sign-in activity. It is not used for marketing.
4. Legal Basis
We rely on the following lawful bases under Article 6 UK-GDPR for the purposes above:
- Performance of a contract (Art. 6(1)(b)) — running your account, hosting your runs and posts, processing your subscription, providing customer support.
- Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud and abuse prevention, service-level analytics (e.g. crash reporting). You can object to processing on this basis at any time.
- Consent (Art. 6(1)(a)) — marketing emails, optional analytics cookies, app usage analytics (Firebase Analytics / Crashlytics, off by default in the iOS app; opt in via Settings → Privacy → Share anonymous usage data), push notifications, and health-data access (Apple Health on iOS, Health Connect on Android). You can withdraw this consent at any time without affecting the lawfulness of processing before withdrawal.
- Legal obligation (Art. 6(1)(c)) — keeping certain financial and tax records for the periods HMRC requires.
Special category (health) data — Article 9. Where we process health-related data from Apple HealthKit on iOS (workouts, heart rate, distance, GPS routes) or from Health Connect on Android (running workouts, distance, active calories — see section 4a), we rely on your explicit consent under Article 9(2)(a) UK-GDPR. You provide this when you grant the permission inside iOS or Android. You can withdraw it at any time — on iOS by revoking HealthKit access in Settings → Privacy & Security → Health, on Android by revoking RunClub's access in the Health Connect app (Settings → Apps → Health Connect → App permissions) — or by emailing support@run-club.app. Health data is never sold, and never shared with third parties for advertising.
4a. Health Connect (Android)
On Android, RunClub connects to Health Connect so your runs stay in sync between RunClub and your other fitness apps. This connection is entirely optional, is off until you turn it on in RunClub → Settings → Health Connect, and the app works fully without it.
The data types we access, and why:
- Exercise (read): to import running workouts you recorded in other apps (for example Garmin, Strava or Samsung Health) so they appear in your RunClub feed and stats.
- Exercise (write): to save runs you record in RunClub back to Health Connect, so your other apps can see them.
- Distance (read and write): the distance of each run — read so imported runs carry their distance, written so exported runs carry it.
- Active calories burned (read and write): the calories for each run — read so imported runs carry them, written so exported runs carry them.
These four are the only Health Connect data types RunClub requests, and each is used solely to display and sync your runs. We do not request heart rate, cycling pedalling cadence, exercise routes, or any other Health Connect data type on Android.
Runs imported from Health Connect are stored in your RunClub account on our servers (Firebase / Google Cloud, section 5) so they appear on your feed, profile and stats across your devices — exactly like a run you record in RunClub itself. Health Connect data is never sold, never shared with third parties for advertising, and never used for any purpose other than showing and syncing your runs.
You can disconnect at any time in RunClub → Settings → Health Connect, or revoke access in the Health Connect app (Settings → Apps → Health Connect → App permissions). Revoking stops all further reading and writing immediately. Runs already imported into your account stay there until you delete them individually or delete your account (section 6).
4b. Find Friends from Contacts
RunClub offers an optional way to find people you already know: “Find Friends from Contacts”. It is off by default, runs only when you tap it and grant your device's contacts permission, and you can use RunClub fully without it — friends can also be found by username search.
When you use it, the email addresses and phone numbers from your address book are transmitted to our servers and matched against existing RunClub accounts, so we can show you which of your contacts are already on RunClub. We use this data only for that matching. We do not use it for marketing, we do not use it for advertising or profiling, we do not sell it, and we do not share it with third parties. We do not contact the people in your address book, and contacts who are not RunClub users are not shown to you as results.
You can revoke contacts permission at any time in your device settings (iOS: Settings → Privacy & Security → Contacts; Android: Settings → Apps → RunClub → Permissions → Contacts). To request deletion of contact data associated with your account, email support@run-club.app and we will action it under section 7.
5. Sharing
We do not sell your personal data. We share data with the following processors and partners, each under a written data-processing agreement:
- Firebase / Google Cloud — authentication, Firestore database, file storage, push notifications.
- Google Analytics 4 (via Firebase Analytics) — anonymised app and website usage analytics, where you have consented.
- Amazon Web Services (SES) — sending transactional and marketing emails.
- Stripe — processing venue subscription payments (we do not see card numbers).
- Apple — processing iOS in-app subscription payments and providing HealthKit, push and authentication services.
- Google Play — processing Android in-app subscription payments.
We may also disclose data where we are required to do so by law, regulation or a binding order.
5a. Run Club Directory (Publicly Available Information)
RunClub publishes a directory of running clubs to help runners find local groups. Some directory listings are compiled by us from publicly available information — for example a club's own website, public social media profiles, parkrun pages and public running-club listings. These listings are clearly labelled as “Directory” and are not created or managed by the club.
A directory listing contains only limited, non-sensitive information: the club's name, the town or area it operates in, its public website or social handle, and a short factual description. We do not publish personal contact details (such as an organiser's personal email) that may be gathered during this process — those are held internally only.
If you run or represent a club and would like your listing amended, claimed or removed, you can do so at any time using the “Claim this club” or “Request removal” options on the listing page, or by emailing support@run-club.app. We action removal requests promptly, normally within a few working days. Where a listing contains personal data, the rights set out in section 7 also apply.
6. Data Retention
Account data is retained while your account is active. After deletion, personal data is removed from production systems within 30 days, except where retention is required by law (e.g. financial records, which we retain for 6 years to meet HMRC obligations). Anonymised, aggregated statistics may be retained indefinitely.
7. Your Rights
Under UK-GDPR you have the right to:
- Access the personal data we hold about you (Article 15);
- Rectification — correct data that is wrong or out of date (Article 16);
- Erasure — have your data deleted (Article 17);
- Restriction of processing in certain circumstances (Article 18);
- Portability — receive a copy in a machine-readable format (Article 20);
- Object to processing carried out on legitimate-interests grounds (Article 21);
- Withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal;
- Lodge a complaint with the Information Commissioner's Office at ico.org.uk.
The easiest way to exercise any of these rights is via our Request your data page, or by emailing support@run-club.app. We respond within one calendar month as required by law.
7a. International Users — Regional Rights
If you are resident outside the UK, your local data protection law may give you additional or differently named rights. We honour them through the same mechanisms described above — the Request your data page handles every request type below regardless of the legal label.
- European Economic Area (EU-GDPR): the rights described in §7 above apply identically. Complaints to your national supervisory authority, or to our lead authority (UK ICO).
- California residents (CCPA / CPRA): right to know, delete, correct, port your data; right to opt out of the “sale” or “sharing” of personal information; right to limit use of sensitive personal information; right to non-discrimination for exercising your rights. We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information beyond the purposes described in this Policy.
- Other US state residents (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, Indiana, Tennessee, Montana, Florida, New Jersey, New Hampshire, Minnesota, Maryland and others with comprehensive privacy laws): the same set of rights — access, deletion, correction, portability and opt-out — applies under your state law and we will honour them.
- Canadian residents (PIPEDA + Quebec Law 25): access, correction, and withdrawal of consent. Quebec residents also have explicit data portability rights and the right to be notified of automated decision-making.
- Australian residents (Privacy Act 1988 and the Australian Privacy Principles): access, correction, and the right to complain to the Office of the Australian Information Commissioner (OAIC).
- New Zealand residents (Privacy Act 2020): access, correction, and the right to complain to the Office of the Privacy Commissioner (OPC).
- Brazilian residents (LGPD): access, correction, anonymisation, portability, deletion, and information about processors with whom we share your data.
For any of the above, use our Request your data page or email support@run-club.app. We will verify your identity before responding and complete the request within the timeframe required by your local law (typically 30–45 days). If you believe we have not handled your data correctly, you may complain to the data protection regulator in your country in addition to (or instead of) raising it with us.
8. International Transfers
Some of our processors are located outside the UK and EEA, including in the United States (Firebase / Google Cloud, Stripe), the EU (Amazon Web Services SES, eu-west-1) and other jurisdictions. Where personal data is transferred outside the UK or EEA, we rely on the safeguards approved by the relevant regulator — Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (UK-IDTA) where applicable — together with supplementary measures such as encryption in transit and at rest. We do not transfer personal data to jurisdictions that lack adequate protection without these safeguards in place.
9. Cookies
The website uses essential cookies for authentication and limited analytics cookies. See our Cookie Policy for details.
10. Children
RunClub is not intended for children under 16. We do not knowingly collect data from children under 16.
11. Changes
We may update this Policy from time to time. Material changes will be notified in-app or by email.
12. Contact
Questions? Email support@run-club.app.
