Privacy policy

ACE Races Privacy Policy

Last updated: 5 June 2026

This Privacy Policy explains how ACE Races collects, uses, stores, and shares personal data when you use our website, Shopify store, mobile app, web app, virtual races, digital challenges, physical challenge products, merchandise, emails, customer support, and related services.

It is written to cover both the ACE Races app and the ACE Races Shopify store at ace-races.co.uk.

1. Who we are

ACE Races is the controller of your personal data for the purposes described in this policy.

If you have any questions about this policy or how we handle personal data, please contact us at the email address above.

2. Who this policy applies to

This policy applies to:

  • visitors to the ACE Races website and Shopify store;
  • customers who buy races, challenges, medals, T-shirts, merchandise, digital products, subscriptions, or other ACE Races products;
  • people who use the ACE Races mobile app or web app;
  • people who take part in ACE Races virtual races or digital challenges;
  • people whose details are provided by a buyer, for example a participant name for a child, family member, friend, group, charity, or workplace entry;
  • people who connect optional activity services such as Strava or Apple Health;
  • people who contact us for support or enquiries; and
  • admin users and internal users who help operate ACE Races systems.

3. The personal data we collect

The personal data we collect depends on how you interact with ACE Races.

Identity and contact data

This may include your name, email address, phone number, billing address, shipping address, account details, customer ID, participant names, certificate names, and any contact details you give us.

Order, purchase, and fulfilment data

When you buy or attempt to buy through our Shopify store, we may process order numbers, products purchased, line items, quantities, prices, discounts, taxes, delivery status, fulfilment status, returns, refunds, subscription status where relevant, and records needed to provide race entries, challenge access, medals, merchandise, certificates, and customer support.

Payment information is processed by Shopify and payment providers. ACE Races does not need to store full payment card details to provide the service.

Login and account data

If you sign in to the app or web experience, we may process your email address, one-time passcode records, account/session identifiers, authentication status, device/session data, and records needed to keep your account secure.

Challenge, participant, and activity data

When you use ACE Races, we may process challenge entries, participant slots, participant names, manual distance entries, activity type, distance, progress, completion status, milestone status, digital badge status, certificate details, challenge history, private ACE Score or tier progress, streaks, monthly summaries, personal bests, and other performance or progress information used to provide your ACE Races experience.

If you submit completion evidence, photos, files, notes, or support information, we may process that information to verify completion, provide rewards, resolve support issues, or keep appropriate records.

Connected activity services

If you choose to connect Strava, we may process connection status, access tokens, refresh tokens, token expiry data, selected activity data, activity dates, activity type, distance, duration, and related data needed to import activities into ACE Races.

If you choose to use Apple Health, ACE Races may read workout or distance data from Apple Health so you can log distance towards your virtual challenges. We only use Apple Health data for app functionality that you request. We do not sell Apple Health data and do not use Apple Health data for advertising.

Connected activity services are optional. You can choose not to connect them and use manual entry where available.

Device, app, technical, and diagnostic data

When you use our website, Shopify store, mobile app, web app, or related services, we may process technical data such as IP address, browser type, device type, operating system, app version, app update information, time zone, pages or products viewed, referring website, search terms, app or session identifiers, request metadata, crash data, diagnostic data, service logs, and security records.

The ACE Races app may use secure device storage to keep session or integration details on your device. If you enable notifications, we may process notification permission status and push notification tokens so we can send app notifications.

Location and route-related data

ACE Races challenges may include route maps, waypoint content, GPX route material, or location-themed challenge content. This does not necessarily mean we collect your live location.

If an app feature asks to use your device's live location, your device should request permission first. Where location permission is used, we will use it only for the feature explained at the time and in line with this policy.

Cookies, analytics, and marketing data

We may process cookie identifiers, local storage data, Shopify analytics data, website and app usage data, email engagement data, marketing consent or preference data, advertising or campaign attribution data, and similar information used to operate, improve, protect, and market ACE Races.

Communications and support data

If you contact us or receive messages from us, we may process support messages, email records, order communications, one-time passcode email records, notification records, delivery or bounce information, and related correspondence.

Admin and audit data

For internal operations, we may process admin login/session data, actions taken in admin tools, audit logs, access records, and security monitoring information.

4. How we collect personal data

We collect personal data:

  • directly from you when you browse, buy, sign in, enter participant details, log activity, contact us, or use the app;
  • from Shopify, where needed to process orders, customer accounts, product access, fulfilment, returns, refunds, and challenge entitlement;
  • from payment providers, where needed to confirm payment status and manage transactions;
  • from Strava or Apple Health, where you choose to connect or permit those services;
  • from email, analytics, advertising, support, hosting, app update, and infrastructure providers;
  • automatically through cookies, local storage, app storage, logs, diagnostics, pixels, tags, and similar technologies; and
  • from internal systems where needed to operate and protect ACE Races.

5. How we use personal data

We use personal data to:

  • operate the ACE Races website, Shopify store, mobile app, web app, and related services;
  • process purchases, payments, refunds, returns, subscriptions, delivery, and fulfilment;
  • provide race entries, digital challenge access, medals, merchandise, badges, certificates, and rewards;
  • recognise Shopify purchases and connect them to app journeys where relevant;
  • support participant slots, participant names, family entries, group entries, certificates, and rewards;
  • authenticate users using one-time passcodes and account/session controls;
  • record manual entries and imported activities;
  • calculate progress, completion, milestones, badges, certificates, private ACE Score, and private performance summaries;
  • allow optional Strava and Apple Health features to work;
  • send order, account, service, support, one-time passcode, and notification messages;
  • send marketing where you have requested it, consented, or where otherwise permitted by law;
  • operate cookies, analytics, advertising measurement, and campaign reporting where used;
  • improve product pages, app journeys, challenge experiences, customer support, and business operations;
  • detect fraud, misuse, abuse, technical faults, security incidents, and service availability issues;
  • operate admin tools, audit logs, access controls, and internal reporting; and
  • comply with legal, regulatory, tax, accounting, app store, platform, dispute, or law-enforcement obligations.

6. Lawful bases for processing

Under UK data protection law, we rely on different lawful bases depending on the purpose.

  • Contract: where processing is needed to provide products or services you request, such as orders, app access, challenge tracking, digital rewards, certificates, support, and fulfilment.
  • Legitimate interests: where processing is needed to operate, secure, improve, administer, analyse, and grow ACE Races, provided those interests are not overridden by your rights.
  • Consent: where you choose optional features such as some cookies, marketing sign-up, push notifications, Strava connection, Apple Health access, or other optional integrations.
  • Legal obligation: where processing is needed for tax, accounting, consumer law, regulatory, platform, dispute, or legal requirements.

Some activity or health-related information may be treated as health or special-category data under data protection law. Where required, we rely on your explicit consent or another lawful condition before processing that data.

7. Cookies and similar technologies

We use cookies, local storage, app storage, pixels, tags, logs, and similar technologies to operate the website, Shopify store, app, account features, security controls, analytics, and marketing measurement.

These technologies may help us keep you signed in, remember preferences, support checkout, protect against fraud, understand website and app usage, measure campaigns, improve performance, and support customer journeys.

Where required, cookie choices may be managed through the website's cookie banner or privacy controls. You can also adjust browser settings, but some features may not work properly if cookies or storage are disabled.

8. Marketing and advertising

We may send marketing communications where you have signed up, consented, bought from us and have not opted out, or where otherwise permitted by law.

We may use Shopify, Klaviyo or similar email platforms, analytics tools, and advertising platforms to understand and improve marketing performance. You can opt out of marketing emails using the unsubscribe link in those emails or by contacting us.

We do not use Apple Health data for advertising.

9. Sharing personal data

We may share personal data with trusted providers and partners where needed to operate ACE Races, including:

  • Shopify, for ecommerce, checkout, customer accounts, order management, store analytics, and related services;
  • payment providers, to process payments, refunds, fraud checks, and transaction records;
  • delivery, fulfilment, printing, merchandise, medal, and logistics providers;
  • Strava, where you choose to connect your Strava account;
  • Apple Health, in the sense that we read permitted data from Apple Health on your device when you choose to use that feature;
  • email, notification, and customer communication providers;
  • hosting, database, app update, infrastructure, monitoring, and security providers;
  • analytics, advertising, and marketing providers where used;
  • App Store, Google Play, Expo/EAS, and other platform providers where needed for app distribution, updates, diagnostics, or compliance;
  • professional advisers such as accountants, insurers, legal advisers, and compliance advisers; and
  • regulators, courts, authorities, law enforcement, or other parties where required by law or to protect rights, safety, and security.

We do not sell your personal data.

Your ACE Score, challenge progress, and performance data are intended to be private to your account unless you choose to share content yourself. If you use sharing features or post content on social media or third-party platforms, that content may become visible to others.

10. International transfers

Some providers may process personal data outside the UK. Where this happens, we aim to use appropriate safeguards such as adequacy decisions, approved contractual protections, or other lawful transfer mechanisms available under data protection law.

11. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including service delivery, legal, tax, accounting, contractual, support, fraud-prevention, security, and dispute needs.

Examples include:

  • order and transaction records may be kept for tax, accounting, consumer law, fraud prevention, and support purposes;
  • one-time passcodes are short-lived and expire after a limited period;
  • session records may be kept for the active session period and related security needs;
  • challenge, participant, completion, badge, certificate, and progress records may be kept while your account remains active and afterwards where needed for support, proof of completion, reporting, audit, or disputes;
  • Strava or Apple Health connection data may be kept while the connection remains active and removed or made inactive when you disconnect where technically possible;
  • support and communications records may be kept for customer service and legal recordkeeping; and
  • admin audit logs may be kept for security, governance, and accountability.

We may keep data for longer where required by law or where needed to establish, exercise, or defend legal claims.

12. Security

We use technical and organisational measures designed to protect personal data. These may include passwordless sign-in, time-limited one-time passcodes, rate limiting, server-side checks, secure storage where supported, restricted admin access, access controls, CSRF protections for admin changes, logging, health monitoring, and service security controls.

No system can be guaranteed to be completely secure, but we work to protect personal data using safeguards appropriate to the nature of the service.

13. Your rights

Depending on your circumstances and where you live, you may have the right to:

  • request access to personal data we hold about you;
  • request correction of inaccurate personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • request transfer of certain personal data;
  • withdraw consent where we rely on consent; and
  • complain to a data protection regulator.

To exercise your rights, contact us at info@ace-races.co.uk.

If you are in the UK, you can complain to the Information Commissioner's Office (ICO). We would appreciate the chance to deal with your concern first.

14. Children and family entries

ACE Races supports family-friendly challenges and adults may buy entries for children, family members, friends, groups, charities, or workplaces. Where a child takes part, the account, purchase, participant details, and app use should be managed by a parent, guardian, or responsible adult where required by law.

If you believe a child has provided personal data to us inappropriately or without suitable involvement from a parent or guardian, please contact us so we can review the matter.

15. Third-party services and links

Our website, store, app, emails, and services may link to or integrate with third-party services such as Shopify, payment providers, Strava, Apple Health, App Store, Google Play, Expo/EAS, analytics providers, advertising platforms, social media platforms, and support or email tools.

Those services have their own privacy notices and terms. We encourage you to read them. We are not responsible for third-party privacy practices except where we act as controller of your personal data.

16. Do Not Track

Some browsers offer a Do Not Track setting. Because there is not yet a consistent industry standard for responding to these signals, we do not currently alter our website or app data practices solely in response to them.

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to ACE Races, the app, Shopify store, technology, legal requirements, or how we process personal data.

When we make material changes, we will update the Last updated date above and, where appropriate, notify users through the website, app, email, or other suitable channels.

18. Contact us

For privacy questions, rights requests, or complaints, contact:

ACE Races
Email: info@ace-races.co.uk
Website: ace-races.co.uk