Last updated: 6 September 2026
This policy explains what information PACE collects — including location and, if you connect it, Apple Health or Health Connect data — why we collect it, and the rights available to you wherever you live.
1. Who We Are
PACE ("PACE", "we", "us", or "our") is a mobile application that helps runners find clubs, join group runs, track training, and stay connected with their running community. The PACE app is operated by Stefan-Andrei Pascutoi and Ana-Maria Cirtog, based in Bucharest, Romania. This Privacy Policy applies to everyone who uses the PACE app, anywhere in the world, regardless of which club or country you run with. If you have questions about this policy or how your data is handled, contact us at team@joinpaceapp.com.
2. Scope — International Use
PACE is available to runners and clubs internationally, not only in Romania. Depending on where you live, additional rights and rules may apply to you in addition to those described here, including: • The EU General Data Protection Regulation (GDPR) and UK GDPR, if you are located in the European Economic Area (EEA), the EU, or the United Kingdom. • The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), if you are a California resident. • Other applicable national data protection laws (e.g. in Switzerland, Canada (PIPEDA), Australia, Brazil (LGPD)). Where local law gives you stronger rights than described in a particular section, your local rights apply. Section 12 ("Your Rights") explains how to exercise them regardless of where you live.
3. Information We Collect
Account information: your name, email address, password (stored as a secure hash by our authentication provider), and account role (runner or admin). Profile information: profile photo, pace band, city and country, date of birth, gender, phone number, and any health conditions you voluntarily choose to share with your club (e.g. allergies, asthma, injuries). Date of birth is required at sign-up so we can confirm you meet the minimum age in Section 15. Profile visibility choices: PACE stores a separate on/off setting for each of your email address, phone number, date of birth, city, and health conditions, controlling whether that field is shown to other members. These settings are set in Profile → Edit Profile and default to not shared for the sensitive fields. Location data: with your permission, PACE accesses your device's location to (a) show clubs, runs, and routes near you on the Explore map, (b) suggest nearby club runs on your Home screen within a radius you choose (default 10 km, configurable in Explore), and (c) help you find your way to a run's meeting point. Location is requested only while you are using the app. PACE does not collect your location in the background, does not track your movements, and does not store a history of where you have been. Place search text: when you search for a city, country, or meeting point (for example while creating a route or completing your profile), the text you type is sent to our maps provider to return matching places. Health & fitness data — only if you choose to connect Apple Health (iOS) or Google Health Connect (Android). See Section 7 for the full detail. In summary we read: running workouts and their type, distance, duration and pace; workout routes (GPS samples); heart-rate samples during a workout; resting heart rate; and VO₂max / "Cardio Fitness" readings where your device or watch records them. On Android we additionally read steps, speed and total calories burned from Health Connect. We request read-only access and never write to Apple Health or Health Connect. Data derived from your workouts: from the above, PACE computes and stores kilometre splits, a heart-rate-zone time distribution for a run, moving time, elevation, personal bests, estimated fitness (VDOT) and training paces, training-load figures, and a session classification (easy / threshold / long, and so on). These are calculations about your own runs, stored in your own account. Perceived effort you record yourself: an optional 1–10 rating of how hard a run felt, and the time you gave it. This is something you type in, not something read from a sensor. Run, club, and social activity data: runs you join, sign up for or check into (including the pace group and distance you chose, and the energy level and sleep hours you optionally give when joining a run), clubs you belong to and requests to join them, guest passes, challenges, goals you set, feed posts, comments, reactions and kudos, medals and medal nominations, XP, levels, streaks, and leaderboard standing. Check-in QR codes: to check you in at a run, PACE generates a short-lived QR token containing your name, pace group and streak, which a club admin scans. Tokens expire and are not used for anything else. Photos you choose to share: with your permission, PACE can access your device camera and photo library so you can set a profile photo, add photos to a feed post or run gallery, and add a photo to a route you create. PACE only ever receives the specific photos you select. Content you submit: club rules you accept, route descriptions, tips and reviews you write, run results you log, and text you enter in any other part of the app. Support communications: messages you send us via Help & Support or Profile → Report a Bug, including your name, email address, the ticket text, and any details you choose to provide, plus our replies. A bug report additionally attaches your app version and build, your platform and operating system version, your device model, and the screen you opened the form from, so that we can reproduce the problem on the same build you are running. Those details are listed in full on the report form before you send it, they are never collected unless you choose to send a bug report, and they never include your location or anything from your runs or health data. Club administration records: if you are a member of a club, your club's admins can see your attendance at that club's runs, your check-ins and results, and club-level statistics. Actions admins take (such as approving a join request or awarding a medal) are recorded in an audit log for that club. Technical data: our service providers keep standard server logs (including IP address, timestamps and request details) as part of operating the service securely, and our over-the-air update service receives basic device and app-version information in order to serve the correct update. PACE does not include any analytics, advertising, attribution or crash-reporting SDK — we do not track your behaviour across apps or websites, and we do not build advertising profiles. Calendar & biometric permissions: with your permission, PACE may add a run or race to your device calendar (one-way — PACE does not read your existing calendar entries), and use Face ID / Touch ID to unlock a securely stored session on your device for faster sign-in. Biometric data is processed entirely by your device's operating system and is never accessed, transmitted, or stored by PACE. Push notification token: if you allow notifications, your device's push token is stored so we can send you run reminders and club announcements.
4. How We Use Your Data
We use the information described above to: • Provide the core PACE service: club discovery, run scheduling, sign-ups, check-ins, and your run history. • Power location-based features: nearby clubs, runs and routes on Explore, and the "Suggested" runs section on Home (within your chosen radius). • Calculate and display your goals, personal bests, training insights, XP, levels, streaks, medals, and leaderboard standing. • Show pace-compatible runners, familiar faces, and pace groups for a run. • Enable social features such as the Feed, posts, reactions, comments, and peer medal nominations. • Let club admins organise runs, manage membership, record attendance, and recognise members. • Send you club announcements, run reminders, and in-app notifications you have not opted out of. • Respond to support requests and communicate with you about your account. • Review reported content and enforce our Terms of Use. • Maintain the security, integrity, and proper functioning of the app, and prevent abuse. • Improve PACE using aggregated, anonymised statistics. We do not use your data for advertising, we do not sell or share your personal data, and we do not use your data to train machine-learning models. See Section 9.
5. What Other People Can See
PACE is a social app, so some information is visible to others by design: • Members of clubs you belong to can see your display name, profile photo, pace band, your attendance and check-ins at that club's runs, your feed posts and comments, your medals, and your position on club leaderboards. • Admins of clubs you belong to additionally see your attendance record with that club, your run results, and any profile field you have chosen to share (see Section 3, "Profile visibility choices"). • Anyone using the app can see content you post publicly, such as a route you publish or a review you leave on a route. • Your live location is never shared with anyone. Other members do not see where you are. They may see the city you have chosen to display on your profile, and whether you have checked in to a run you both joined. • Your health data is not visible to other members, other than the summary figures that are inherently part of a shared feature — for example the distance credited to a club leaderboard or challenge you have entered, or a personal best you display on your profile. Your heart rate, heart-rate zones, VO₂max, perceived-effort ratings, workout routes and splits are visible only to you.
6. Location Data — Specific Disclosures
Location permission is optional but required for location-based features (the Explore map, nearby clubs and runs, and Home's "Suggested" runs). If you decline or later revoke location permission, these features will be limited or hidden, but the rest of the app continues to work. PACE requests location only while the app is in use ("when in use"). We do not request "always" / background location access, we do not run any background location task, and PACE cannot access your location when it is closed or in the background. Your location is used on your device to find nearby results, and is sent to our maps provider to render maps and calculate directions. PACE does not store a history of your device location. Location coordinates are stored only where they are part of content you deliberately create or join — for example the start point of a route you draw, or a run's meeting point. You can change or revoke location permission at any time in your device Settings, and you can change the "Suggested" runs search radius (5–50 km) in Explore at any time.
7. Health Data — Specific Disclosures (Apple Health / Health Connect)
Connecting a health source is entirely optional. PACE works without it. If you choose to connect Apple Health (iOS) from Profile → Connected Sources, PACE requests read-only access to: workouts, walking/running distance, workout routes, heart rate, resting heart rate, and VO₂max. If you choose to connect Google Health Connect (Android), PACE requests read-only access to: exercise sessions, exercise routes, distance, heart rate, resting heart rate, VO₂max, steps, speed, and total calories burned. PACE never requests write access to Apple Health or Health Connect, and never modifies or deletes your health records. Specific commitments about this data: • We do not sell, rent, trade, or share your health and fitness data with any third party, data broker, or advertiser, for any purpose. • We do not use your health data for advertising, marketing, re-marketing, or any use-based data mining, and we do not use it to train machine-learning models. • Health data is used solely to provide health, fitness and training features inside your own PACE account — your run history, goals, personal bests, training insights, leaderboards, medals and XP. • Health data is not disclosed to any third party without your explicit consent, and is not used for any purpose other than those described in this policy. Health-derived data is visible only to you, except for the specific summary figures that are inherently part of a shared feature you have opted into — see Section 5. Where you sync a workout that overlaps a club run you attended, PACE links the two so the distance credited to that club run is the distance you actually ran. You can disconnect Apple Health / Health Connect at any time from Profile → Connected Sources, or by revoking permission in your device's Health settings. Disconnecting stops future syncing. To also delete health data already synced to PACE, delete your account (Section 11) or contact us at team@joinpaceapp.com.
8. Legal Bases for Processing (EEA / UK Users)
If you are located in the EEA, EU, or UK, we rely on the following legal bases under the GDPR / UK GDPR: • Contract (Art. 6(1)(b)): processing your account, profile, and run/club data is necessary to provide the PACE service you signed up for. • Consent (Art. 6(1)(a)), and explicit consent for health data as data concerning health (Art. 9(2)(a)): for location access, the optional Apple Health / Health Connect integration, health conditions you choose to share with your club, perceived-effort ratings, camera and photo library access, calendar access, and push notifications. Each of these is optional and revocable. • Legitimate interests (Art. 6(1)(f)): for security, fraud prevention, debugging, content moderation, and improving the app, balanced against your rights and interests. • Legal obligation (Art. 6(1)(c)): where we must retain or disclose information to comply with the law. You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal. We do not carry out any automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 GDPR.
9. Data Sharing & Third-Party Service Providers
We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable laws. We have not sold or shared personal data in the preceding twelve months. PACE contains no advertising SDK, no analytics SDK, no attribution SDK, and no crash-reporting SDK. We do not track you across other companies' apps or websites, and the app does not use the Advertising Identifier (IDFA). We share data only with the following service providers, acting as our processors/sub-processors under data protection agreements: • Supabase — database, authentication, file storage, edge functions, and real-time infrastructure. Stores your account, profile, run, club, support, and (with your consent) health-derived data. Hosted in the EU (Frankfurt, eu-central-1). • Cloud infrastructure providers used by Supabase to host that infrastructure. • Mapbox — powers the Explore map, route display, place search, and directions. When you use map or place-search features, your location and/or the text you search is sent to Mapbox so it can return maps, places and directions, in accordance with Mapbox's privacy policy. • Expo — delivers push notifications to your device using a device push token, and delivers over-the-air app updates (which involves your device requesting the correct update for its app version and platform). We do not share the content of your profile, health or run data with Expo. • Netlify — hosts joinpaceapp.com, including this policy page and club invite links. Netlify receives standard web server logs for visits to those pages. Other PACE members and your club's admins can see the information described in Section 5. We may disclose information if required to do so by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of PACE, our users, or others. If PACE is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will notify you via the app before your data becomes subject to a different privacy policy. If we add any new category of service provider — including any analytics or crash-reporting tool — we will update this section and notify you in-app before it is enabled, and will ask for your consent where the law requires it.
10. International Data Transfers
PACE's primary database is hosted in the European Union. Some service providers described in Section 9 may process data in other countries, including outside the EEA/UK (for example the United States), in accordance with their own data residency configurations. Where personal data originating in the EEA/UK is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent mechanisms with our service providers. If you are located in a country with its own cross-border data transfer requirements (for example, Switzerland, Brazil under the LGPD, or Australia under the Privacy Act), we take reasonable steps to ensure any transfer of your data outside that country is subject to contractual or other safeguards recognised as adequate under your local law. You may request more information about these safeguards by contacting us at team@joinpaceapp.com.
11. Data Retention & Deletion
We retain your personal data for as long as your account is active, and for a limited period afterwards as described below. You can permanently delete your account at any time from Profile → Delete My Account. This deletes your account and the personal data attached to it — your profile, run history, check-ins, synced health data and health-derived figures, goals, personal bests, medals, XP, posts and comments — from PACE's active systems, generally within 30 days, except where we are required to retain certain records for longer to comply with legal, tax, security, or dispute-resolution obligations, in which case such data is retained only for as long as necessary for that purpose and is not used for any other purpose. Some records that are inherently about a club rather than about you may be retained in a form that no longer identifies you — for example a run's total attendance count. Aggregated or anonymised data that can no longer be used to identify you may be retained indefinitely. Support communications are retained for as long as needed to resolve your request and for a reasonable period afterwards for quality and audit purposes. Backups are retained on a rolling basis by our infrastructure provider and are overwritten in the ordinary course; data deleted from active systems is removed from backups as those backups age out.
12. Your Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data: • Access — request a copy of the personal data we hold about you, and information about how it is processed. • Rectification — correct inaccurate or incomplete data (most can be edited directly in Profile → Edit Profile). • Erasure ("right to be forgotten") — request deletion of your account and personal data (Profile → Delete My Account, or by contacting us). • Restriction & objection — ask us to limit or stop certain processing, including objecting to processing based on legitimate interests. • Portability — receive your data in a structured, commonly used, machine-readable format. • Withdraw consent — for location, health data, photos, calendar, and notifications, at any time, with no effect on the lawfulness of prior processing. • Know / opt out of sale or sharing — (California and similar laws) we do not sell or share personal data, so there is nothing to opt out of; you may still exercise your right to know and to delete. • Non-discrimination — (California and similar laws) we will not discriminate against you for exercising your privacy rights. • Lodge a complaint — with your local data protection authority (in the EEA/UK) or other applicable regulator, if you believe your rights have been violated. To exercise any of these rights, use the relevant in-app control where available, or contact us at team@joinpaceapp.com. We will respond within the timeframe required by applicable law (e.g. one month under GDPR, extendable in certain cases). We may need to verify your identity before acting on a request.
13. Cookies, Local Storage & Similar Technologies
The PACE mobile app does not use browser "cookies". The app uses on-device local storage (AsyncStorage and the device keychain/keystore) to remember your preferences — such as your saved "Suggested runs" search radius, your signed-in session, and onboarding progress — so the app works smoothly between sessions. This data stays on your device. PACE does not use the Advertising Identifier (IDFA), and does not ask for App Tracking Transparency permission, because it does not track you across other companies' apps or websites. If PACE ever adds an analytics or crash-reporting SDK that uses identifiers comparable to cookies, this Privacy Policy will be updated and an in-app notice shown before it is enabled, and you will be asked for consent where required by law (e.g. ePrivacy/GDPR for EEA/UK users). joinpaceapp.com serves this policy and a small number of informational pages. It uses only cookies strictly necessary for the site to function, and does not run advertising or analytics cookies. If non-essential cookies are added in future, a consent banner will be shown to visitors where required.
14. Security
We use industry-standard measures to protect your data, including: • Encryption in transit (HTTPS/TLS) between the app and our backend. • Hardware-backed secure storage for authentication tokens (iOS Keychain / Android Keystore). • Database access controls via Supabase Row Level Security (RLS), so each account can only access data it is authorised to see. • Password hashing using industry-standard algorithms — we never store your password in plain text. • Encryption at rest for the database and file storage, as provided by our infrastructure provider. No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and any relevant authorities as required by applicable law (within 72 hours of becoming aware, where the GDPR applies).
15. Children's Privacy
PACE is not directed at, and must not be used by, children under 16 years of age (or the higher age of digital consent in your country, where applicable). Sign-up requires a date of birth and accounts cannot be created below this age. We do not knowingly collect personal data from children below this age. If you believe a child has created an account or provided us with personal data, please contact us at team@joinpaceapp.com so we can investigate and, if appropriate, delete the data.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the app, our practices, or legal requirements. If we make material changes, we will notify you via an in-app notice before they take effect. The "Last updated" date at the top of this page indicates when this policy was last revised. Continued use of PACE after changes take effect constitutes acceptance of the updated policy, to the extent permitted by law.
17. Features Not Enabled in This Version
PACE's roadmap includes club sponsors and perks, partner venues, races and virtual runs, direct messages between runners, and a "runners nearby" map. These features are switched off in this release: no sponsor, venue, partner, race entry, direct-message, or runner-location data is collected or shared. If any of them is enabled in a future version, we will update this policy first — naming any new recipient of your data in Section 9 and describing the new data in Section 3 — and the update will be notified in-app before the feature goes live. In particular: • Venues and event partners: where an event is organised with a third-party venue or partner, only information reasonably necessary for the event (such as your name and RSVP status) would be shared with that partner, and that partner would be named in Section 9 first. • Runners nearby: any feature that shows your position to other members would be off by default, would require your explicit opt-in, and would let you choose whether an approximate or exact position is shown. • Paid or ticketed events: a third-party payment processor would handle payment details — PACE itself would not store your card or payment account details. Any such processor would be named in Section 9 and in Section 11 ("Fees") of our Terms of Use before payment features go live.
18. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at: Stefan-Andrei Pascutoi and Ana-Maria Cirtog Bucharest, Romania Email: team@joinpaceapp.com PACE is operated by individuals based in the EU (Romania), so no separate EU representative under Article 27 GDPR is required; the contact above handles all data protection inquiries, including from EEA, UK, and Swiss users. Wherever you live, you also have the right to lodge a complaint with your local data protection or privacy regulator (for example, a supervisory authority in the EEA/UK, the OAIC in Australia, the OPC in Canada, or the ANPD in Brazil).