Legal documents

Privacy policy

Translation provided for information. In case of discrepancy, the French version prevails: French version

1. Introduction and identity of the data controller

Protecting your personal data is a priority for RaceUp. This privacy policy explains how we collect, use, store and protect your personal data, in accordance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and amended French Law No. 78-17 of 6 January 1978 (loi Informatique et Libertés).

Data controller

ControllerTimothy ALCAIDE
StatusSole trader (auto-entrepreneur)
SIREN824 385 348
SIRET824 385 348 00027
Registered office11 rue du Professeur Jean Granier, 34070 Montpellier, France
Emailcontact@raceup.org
Websitehttps://raceup.org

Data Protection Officer (DPO)

DPOTimothy ALCAIDE
Emailcontact@raceup.org

2. Personal data collected

2.1 Event participants' data

When you register for a sports event via RaceUp, we collect the following data:

Identification data:

  • Last name and first name
  • Date of birth
  • Gender
  • Nationality (if required by the Organizer)

Contact details:

  • Email address
  • Phone number
  • Postal address

Event-related data:

  • Chosen race, category, options
  • Clothing size (t-shirt, etc.)
  • Sports club or team
  • Sports licence number (FFA, FFTRI, etc.)
  • Health Prevention Pass (PPS) or medical certificate
  • Health information provided voluntarily (allergies, specific needs)
  • Emergency contact (name and phone number)

Payment data:

  • Payment data (card number, etc.) is collected and processed exclusively by Stripe, our PCI-DSS certified payment provider. RaceUp never stores your bank details.

Technical data:

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited and length of visit
  • Traffic source (referrer)
  • Session identifiers

2.2 Event organizers' data

If you are an organizer using RaceUp, we also collect:

  • Company name or name of the association/business
  • Legal form
  • SIRET number or RNA number (associations)
  • EU VAT number (if applicable)
  • Contact details of the legal representative
  • Bank details (via Stripe Connect) to receive payments
  • Information about the events created

2.3 Cookies and trackers

We use cookies for:

Strictly necessary cookies (no consent required):

  • Authentication and keeping you signed in
  • Security and fraud prevention
  • Remembering technical preferences

Analytics cookies (with consent):

  • Analysis of website usage (anonymized statistics)
  • Improving the user experience

You can manage your cookie preferences through your browser settings or the consent banner displayed on your first visit.

PurposeLegal basis (Art. 6 GDPR)Data concerned
Managing event registrationsPerformance of a contract (6.1.b)Identification data, contact details, registration data
Passing registrations on to OrganizersPerformance of a contract (6.1.b)All registration data
Payment processing (via Stripe)Performance of a contract (6.1.b)Payment data
Sending confirmations and ticketsPerformance of a contract (6.1.b)Email, registration data
Managing user accountsPerformance of a contract (6.1.b)Identification data, contact details
Managing Organizer accountsPerformance of a contract (6.1.b)Business data
Customer supportLegitimate interest (6.1.f)Identification data, contact details, history
Improving the platformLegitimate interest (6.1.f)Technical data, usage data
Security and fraud preventionLegitimate interest (6.1.f)Technical data, IP
Keeping invoicesLegal obligation (6.1.c)Billing data
Responding to legal requestsLegal obligation (6.1.c)All relevant data

Processing of sensitive data

Health data (medical certificate, PPS, medical information) is collected on the basis of your explicit consent (Art. 9.2.a GDPR) and is necessary for your participation in the event in accordance with the Organizer's requirements and sports regulations.

4. Recipients of the data

4.1 The event Organizer

IMPORTANT: When you register for an event, all your registration data is passed on to the Organizer.

The Organizer becomes the data controller of this data for:

  • Organizing the event (participant management, safety)
  • Regulatory obligations (insurance, sports federations)
  • Communication about the event
  • Publishing results (unless you object)

You should consult the Organizer's privacy policy to find out about its data protection practices.

4.2 Our technical processors

We use the following providers, with whom we have concluded contracts compliant with Article 28 of the GDPR:

ProviderServiceLocationSafeguards
Vercel Inc.Website hostingUnited StatesStandard Contractual Clauses (SCCs)
Supabase Inc.Database, authenticationSingaporeStandard Contractual Clauses (SCCs)
Stripe Inc.Payment processing (PCI-DSS)United StatesStandard Contractual Clauses (SCCs)

4.3 Competent authorities

Your data may be passed on to administrative or judicial authorities upon legal request (tax, judicial, etc.).

4.4 Sports federations

Some events are affiliated with sports federations (FFA, FFTRI, etc.). In this case, your data and results may be passed on to these federations in accordance with their rules.

5. Data transfers outside the European Union

Some of our providers are located outside the European Union:

ProviderCountryTransfer mechanism
VercelUnited StatesStandard Contractual Clauses (Decision 2021/914)
StripeUnited StatesStandard Contractual Clauses (Decision 2021/914)
SupabaseSingaporeStandard Contractual Clauses (Decision 2021/914)

These transfers are covered by appropriate safeguards in accordance with Chapter V of the GDPR. You can obtain a copy of these safeguards by contacting us.

6. Data retention periods

Type of dataRetention period
Event registration dataUntil deleted by the Organizer or at your request (after the event)
User account dataLifetime of the account + 3 years after the last activity
Organizer account dataDuration of the contract + 3 years
Billing data10 years (legal obligation - French Commercial Code, Art. L123-22)
Payment data (held by Stripe)According to Stripe's policy and legal obligations
Technical and security logs12 months
Analytics cookies13 months maximum

When these periods expire, the data is deleted or anonymized.

7. Data security

We implement appropriate technical and organizational measures to protect your data:

Technical measures:

  • Encrypted communications (HTTPS/TLS 1.3)
  • Encryption of sensitive data at rest
  • Secure authentication (2FA available via Supabase)
  • Role-based access control (Row Level Security)
  • Regular, geographically distributed backups
  • Monitoring and intrusion detection

Organizational measures:

  • Access to data limited to what is strictly necessary
  • Staff awareness and training
  • Incident management procedures
  • Regular security testing

Payments:

  • 100% of payments processed by Stripe (PCI-DSS Level 1 certified)
  • No bank card data stored by RaceUp

8. Your rights over your data

In accordance with the GDPR (Articles 15 to 22), you have the following rights:

8.1 Right of access (Art. 15)

You can obtain confirmation that data concerning you is being processed and access this data as well as information about the processing.

8.2 Right to rectification (Art. 16)

You can request the correction of inaccurate data or the completion of incomplete data.

8.3 Right to erasure (Art. 17)

You can request the erasure of your data in the following cases:

  • The data is no longer necessary for the purposes
  • You withdraw your consent (if that was the legal basis)
  • You object to the processing (legitimate interest)
  • The processing is unlawful
  • Erasure is required by a legal obligation

Exceptions: This right does not apply when the processing is necessary to comply with a legal obligation (e.g. keeping invoices for 10 years) or for the establishment, exercise or defence of legal claims.

8.4 Right to restriction (Art. 18)

You can request the restriction of processing in certain situations (contested accuracy, unlawful processing, etc.).

8.5 Right to data portability (Art. 20)

You can receive your data in a structured, commonly used and machine-readable format (JSON, CSV) and transmit it to another controller.

8.6 Right to object (Art. 21)

You can object at any time, on grounds relating to your particular situation, to the processing of your data based on legitimate interest.

Where processing is based on your consent, you can withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

8.8 Right to set post-mortem instructions

You can set instructions regarding the retention, erasure and communication of your data after your death.

8.9 How to exercise your rights

To exercise your rights, contact us:

By email: contact@raceup.org (or dpo@raceup.org)

By post: Timothy ALCAIDE - DPO, 11 rue du Professeur Jean Granier, 34070 Montpellier, France

We will reply within one month of receiving your request. This period may be extended by two months for complex requests.

You may be asked for proof of identity to verify your identity.

9. Complaints to the CNIL

If you consider that the processing of your data infringes your rights, you can lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL):

CNIL

3 Place de Fontenoy - TSA 80715

75334 PARIS CEDEX 07, France

Phone: +33 1 53 73 22 22

Website: https://www.cnil.fr

10. Minors' data

Sports events may be open to minors according to the conditions set by each Organizer.

For minors under 16, consent must be given by the holder of parental authority. The legal representative making the registration is responsible for the information provided.

11. Changes to this policy

We reserve the right to modify this privacy policy. Any change will be published on this page with a new update date.

In the event of a substantial change affecting your rights, we will inform you by email or by a notification on the platform.

12. Contact

For any question about this policy or your personal data:

Email: contact@raceup.org

Post: Timothy ALCAIDE, 11 rue du Professeur Jean Granier, 34070 Montpellier, France


Last updated: 13 January 2026

This privacy policy complies with Regulation (EU) 2016/679 (GDPR) and amended French Law No. 78-17 of 6 January 1978 (loi Informatique et Libertés).


← Back to legal documents

© 2026 RaceUp. All rights reserved.

Made with ❤️ for athletes