Privacy Policy.
Last updated: 30 June 2026
Stockholm Run Club ("SRC", "we", "us") is a free community running group based in Stockholm, Sweden. This policy explains what personal data we collect when you create an account on stockholmrunclub.com, why we collect it, and the rights you have over it.
We've tried to keep this in plain language. If anything is unclear, get in touch at [email protected].
Who is responsible for your data
The data controller responsible for your personal data is:
Stockholm Run Club, operated by Louis Eric Desbonnet
Stockholm, Sweden
[email protected]
This means we decide what data is collected and how it is used, and we are your point of contact for any questions or requests.
What we collect
When you create and use an account, we collect:
- Your email address and password — to create your account and let you log in. Your password is stored in hashed form by our authentication provider; we never see or store it in plain text.
- Your name — so we can identify you within the club and on event sign-ups.
- Your phone number — to reach you about runs and events you've joined.
- Emergency contact details — the name and contact details of a person you nominate, used only in case of an emergency during a run or event.
- Running pace and performance data — to help organise runs by pace and improve the experience.
We do not collect more than we need, and we don't ask for anything we don't use.
Why we use it, and our legal basis
Under the GDPR we need a lawful basis for each use of your data:
- Running your account and the club — logging you in, organising runs by pace, contacting you about events you've joined — this is necessary to provide the service you signed up for (performance of a contract), and in some cases our legitimate interest in running the club.
- Transactional emails — sign-up confirmations, run and event reminders — necessary to provide the service you've asked for.
- Emergency contact details — kept on the basis of legitimate interest (and, if ever needed, vital interests) to keep runners safe during activities.
We do not send marketing emails or newsletters, and we do not use your data for advertising or profiling.
A note on emergency contacts: when you give us a third person's details, you're responsible for making sure you have a reason to share them — ideally that you've let that person know.
Cookies
We only use strictly necessary cookies — the session and authentication cookies that keep you logged in. These are required for the site to work, so we don't need a consent banner for them.
We do not use any analytics, tracking, or advertising cookies.
Who we share your data with
We don't sell your data, and we don't share it for marketing. We do use a small number of service providers ("processors") who handle data on our behalf, under contract:
- Supabase — hosting, database, authentication, and storage of your account data. Your account data is stored in the EU, in Supabase's Dublin (Ireland) region.
- Resend — sending account and transactional emails (sign-up confirmations, run and event reminders). To do this, Resend processes the recipient's email address and name. Resend is a US-based provider; where your data is processed outside the EU/EEA, that transfer is covered by Standard Contractual Clauses and Resend's data processing agreement.
Each provider acts only on our instructions and is bound by a data processing agreement.
Where your data is stored / international transfers
Your data is hosted within the EU/EEA — specifically in Dublin, Ireland. We aim to keep it there.
Some of our providers are companies headquartered outside the EU/EEA (for example, in the United States) even though they store your data in the EU. Where any personal data is transferred outside the EU/EEA, that transfer is covered by appropriate safeguards such as Standard Contractual Clauses and the provider's data processing agreement.
How long we keep it
We keep your account data for as long as you have an active account. If you delete your account, we delete your associated personal data, except where we're legally required to keep certain records for a limited period. You can ask us to delete your account at any time.
Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data (“right to be forgotten”)
- Restrict or object to how we use it
- Data portability — receive your data in a portable format
- Withdraw consent at any time, where we rely on consent
To exercise any of these, email us at [email protected]. We'll respond within one month. There's no charge for this.
Complaints
If you think we've handled your data improperly, you have the right to lodge a complaint with the Swedish supervisory authority, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY") — imy.se. We'd appreciate the chance to address your concern first, but the right is yours either way.
Changes to this policy
If we change this policy, we'll update the date at the top and, for significant changes, let you know through the site or by email.
Contact
Questions about this policy or your data? Email [email protected].
