Privacy Policy — PaceTrack
PaceTrack

Privacy Policy

Last updated: July 30, 2026

1. General Provisions

1.1. This Privacy Policy (hereinafter — "Policy") defines the procedure for processing personal data of users of the PaceTrack service located at pacetrack.cc (hereinafter — "Service").

1.2. The personal data operator is Usachev Kirill Valerievich (TIN 501708810054) (hereinafter — "Operator"). Contact: admin@pacetrack.cc.

1.3. This Policy has been developed in accordance with Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data" and other applicable regulatory acts of the Russian Federation.

1.4. By registering in the Service and checking the consent box, you confirm that you have read this Policy and consent to the processing of personal data under the terms set out herein.

2. What Data We Collect and for What Purposes

2.1. Coach (User) Data

Data: name, email address, password hash, profile photo (if uploaded), Google and/or Yandex account identifiers (when signing in via OAuth).
Purpose: registration and identification in the Service, sending notifications about athletes' payment statuses, delivering technical and informational messages.
Legal basis: subject's consent (Art. 6 Pt. 1 Para. 1 of 152-FZ), performance of a contract (Art. 6 Pt. 1 Para. 5 of 152-FZ).
Retention period: until the coach deletes their account or the Operator does so.

2.2. Athlete Data

Athlete data (name, email) is entered by the coach independently. The Operator processes this data on behalf of the coach.
An athlete may independently register in the Service via Google or Yandex. Upon registration, the following data is processed: name, email address, profile photo (if uploaded), OAuth provider identifiers. Athlete registration is voluntary and does not affect the receipt of payment reminders.
Purpose: sending athletes payment reminders on the coach's behalf; providing the athlete with access to their account upon registration.
Legal basis: instruction from the operator (coach); consent of the athlete, which the coach is obliged to obtain independently before entering data into the Service; for registered athletes — consent given at registration.
Retention period: data entered by the coach — until deleted by the coach or until deletion of the coach's account; data of a registered athlete — until they delete their account or upon request to the Operator.

2.3. Sports Club Data

A coach may create a sports club in the Service. In this case, the following data is processed: club name (if specified), club logo (if uploaded), list of club coaches (email, name).
Purpose: facilitating collaborative work among coaches within a club, identifying the club in communications with athletes.
Legal basis: subject's consent (Art. 6 Pt. 1 Para. 1 of 152-FZ).
Retention period: until the club is deleted by its owner.

2.4. Voluntary Donations

When making a donation via YooMoney, the following data is processed: payment amount, transaction identifier.
The Operator does not receive or store bank card details — these are processed exclusively by YooMoney LLC.
Retention period: 5 years (in accordance with tax accounting requirements).

2.5. Technical Data

During use of the Service, the following data is automatically recorded in server logs: IP address, browser type, pages visited, session times.
Purpose: ensuring security, diagnosing errors, protecting against abuse.
Retention period: 90 days.

2.6. Data from Connected Training Services

An athlete may choose to connect a third-party service to their account — Strava, Garmin Connect, Polar Flow, WHOOP, or Wahoo — via OAuth authorization on that service's own site (the Operator never receives or sees the password for it).
Data: workout parameters (distance, duration, pace/speed, heart rate, GPS track, splits/segments); for Garmin Connect, Polar Flow, and WHOOP, also recovery, sleep, and load metrics.
Collection method: API requests and webhook notifications from the connected service, after the athlete has given consent when connecting it.
Purpose: displaying workouts and recovery metrics in the athlete's personal account. Data received through the Strava integration is displayed exclusively to the athlete themselves. Data from Garmin Connect, Polar Flow, WHOOP, and Wahoo is displayed to the athlete and, within the coaching access framework of the platform, to their coach.
Additionally, an athlete may explicitly import a one-time copy of their gear list (name, mileage, and replacement threshold when available) from Strava or Garmin Connect into PaceTrack gear records in the Gear section. After that import, no link to the source service is stored — it is a copy of the athlete's own data in the Service; the coach sees PaceTrack records, not the original Strava/Garmin gear data.
Legal basis: the athlete's consent, given when connecting the integration (and when confirming a gear import).
Retention period: when the Strava integration is disconnected, or when access is revoked on Strava's side, all previously imported Strava workout data is automatically and permanently deleted from the Service; one-time PaceTrack gear copies remain (they can be deleted manually in Gear or upon request). For all other services (Garmin Connect, Polar Flow, WHOOP, Wahoo), previously imported workouts are retained as part of the athlete's training history and can be deleted upon request (see Section 6) or upon account deletion. The integration can be disconnected and consent withdrawn at any time in the "Apps" section of the athlete's account — this stops further synchronization and revokes the access token with that service.

2.7. PaceTrack Athlete Mobile App

When using the mobile app, the following additional data is processed:

  • Location (GPS). The app requests precise location access, including in the background (when the screen is locked or the app is minimized), solely while a workout recording is active — to build the route and calculate distance/pace. Location is not tracked when no workout recording is in progress.
  • Bluetooth. The app may connect to a heart rate sensor and/or a pace sensor (footpod) over Bluetooth to receive readings during a workout. Data is transmitted directly from the sensor to the user's device, does not pass through the Operator's servers in real time, and is stored as part of the workout data.
  • Camera and microphone. Used only at the user's explicit action — to attach a photo or record a voice message in the chat with the coach.
  • Push notifications. The device token for push notifications is sent to the Operator's server to deliver notifications (new messages, workout feedback, etc.) and is deleted upon signing out of the account.

Storage and deletion of this data follow the same rules as other athlete data (see Section 6).

3. Cookies

The Service uses cookies exclusively to maintain the session of an authenticated user (session cookies). Marketing and analytics cookies are not used. Disabling cookies in the browser makes it impossible to log in to the Service.

4. Transfer of Data to Third Parties

The Operator transfers personal data to the following third parties solely for the purpose of providing the Service:

  • YooMoney LLC — processing of voluntary donations. YooMoney is an independent operator with respect to payment data.
  • Mail service (SMTP) — sending notifications to coaches and athletes.
  • Google LLC — authenticating users who choose to sign in with a Google account. Google receives information about the fact of accessing the authentication service. Google's privacy policy: policies.google.com/privacy.
  • Yandex LLC (Yandex ID) — authenticating users who choose to sign in with a Yandex account. Yandex's privacy policy: yandex.ru/legal/confidential/.

The Operator does not sell, exchange or transfer data to other third parties without the subject's consent, except in cases provided for by Russian law.

5. Data Storage and Localization

Collection, organization and storage of personal data of Russian Federation citizens is carried out using databases located in the Russian Federation (hosting: Beget, Russia), in accordance with Art. 18.1 of 152-FZ.

6. Rights of Data Subjects

You have the right at any time to:

  • obtain information about what data is being processed and on what grounds;
  • request correction of inaccurate data;
  • request deletion of personal data ("right to be forgotten");
  • withdraw consent to data processing — withdrawal does not affect the lawfulness of processing carried out prior to withdrawal;
  • file a complaint with Roskomnadzor: rkn.gov.ru.

To exercise your rights, send a request to: admin@pacetrack.cc. Response time — 30 days.

Data imported from Strava is deleted automatically when the integration is disconnected. If your request concerns deleting data from other connected training services (Garmin Connect, Polar Flow, WHOOP, or Wahoo) — please specify the service and account. Such data is deleted within 48 hours of the request.

Self-service account deletion. You can exercise the right to deletion without contacting support — in the "Delete Account" section of your profile. A confirmation link is sent to your email (valid for 24 hours); deletion happens immediately after you confirm via that link.

  • Athlete: the profile, all workouts and plans, data from connected training services (Section 2.6) — access to those is also revoked, wellness data, and push subscriptions are permanently deleted. If the coach kept a payment record for this athlete, that record (name, payment history) is not deleted — it simply becomes unlinked from the deleted account, as if the athlete had never registered. The athlete's own chat messages are hidden from the conversation but not physically erased — this preserves the coach's side of the conversation history.
  • Coach: if the coach owns a sports club with other coaches, account deletion is unavailable until club ownership is transferred or the other members are removed (this is stated explicitly if deletion is attempted). The coach's athletes are not deleted — they become athletes without a coach and can find a new one through the directory. Clubs with no other coaches are deleted along with the account.

Before confirming, an exact list of what will be deleted is shown. The action is irreversible.

7. Data Protection

The Operator applies organizational and technical measures to protect personal data: data is transmitted over HTTPS, passwords are stored as hashes (bcrypt), access rights are differentiated, and regular backups are performed.

8. Children

The Service is not intended for persons under 18 years of age. The Operator does not intentionally collect data from minors. If such data is discovered, please notify us at admin@pacetrack.cc for deletion.

9. Changes to This Policy

The Operator may amend this Policy. The current version with the update date is available on the website at pacetrack.cc/en/privacy.php. Continued use of the Service after changes are published constitutes acceptance of the updated Policy.

10. Operator Contact Details

Usachev Kirill Valerievich

TIN: 501708810054

E-mail: admin@pacetrack.cc

Website: pacetrack.cc