Privacy Policy
Last updated: October 2, 2026
1. General Provisions
1.1. This Privacy Policy (hereinafter — "Policy") defines the procedure for processing personal data of users of the PaceTrack service located at pacetrack.cc (hereinafter — "Service").
1.2. The personal data operator is Usachev Kirill Valerievich (TIN 501708810054) (hereinafter — "Operator"). Contact: admin@pacetrack.cc.
1.3. This Policy has been developed in accordance with Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data" and other applicable regulatory acts of the Russian Federation.
1.4. By registering in the Service and checking the consent box, you confirm that you have read this Policy and consent to the processing of personal data under the terms set out herein.
2. What Data We Collect and for What Purposes
2.1. Coach (User) Data
Data: name, email address, password hash, profile photo (if uploaded), Google, Yandex, and/or Apple ID account identifiers (when signing in via OAuth). Regardless of the registration method, the User always has both sign-in options available at the same time — by email and password, and via the linked OAuth account; a password can be set or changed at any time using the password-reset function, including for an account originally created via OAuth. When signing in with Apple ID, the email address may be a relay address ("Hide My Email") if the coach or athlete chose to hide their real email on Apple's side.
Purpose: registration and identification in the Service, sending notifications about athletes' payment statuses, delivering technical and informational messages.
Legal basis: subject's consent (Art. 6 Pt. 1 Para. 1 of 152-FZ), performance of a contract (Art. 6 Pt. 1 Para. 5 of 152-FZ).
Retention period: until the coach deletes their account or the Operator does so.
2.2. Athlete Data
Athlete data (name, email) is entered by the coach independently. The Operator processes this data on behalf of the coach.
An athlete may independently register in the Service via Google, Yandex, or Apple ID, or create an account with an email and password — including without being linked to a coach: an athlete can use their personal account on their own (payment-tracking features by a coach are not used in that case) and can find a coach through the Service's directory, or unlink from a coach, at any time. Upon registration, the following data is processed: name, email address, profile photo (if uploaded), OAuth provider identifiers (if that sign-in method is chosen). Regardless of the registration method, the athlete always has both sign-in options available at the same time — by email/password and via OAuth; if registered via OAuth, a password can be set at any time using the password-reset function. Athlete registration is voluntary and does not affect the receipt of payment reminders.
Purpose: sending athletes payment reminders on the coach's behalf; providing the athlete with access to their account upon registration.
Legal basis: instruction from the operator (coach); consent of the athlete, which the coach is obliged to obtain independently before entering data into the Service; for registered athletes — consent given at registration.
Retention period: data entered by the coach — until deleted by the coach or until deletion of the coach's account; data of a registered athlete — until they delete their account or upon request to the Operator.
2.3. Sports Club Data
A coach may create a sports club in the Service. In this case, the following data is processed: club name (if specified), club logo (if uploaded), list of club coaches (email, name).
Purpose: facilitating collaborative work among coaches within a club, identifying the club in communications with athletes.
Legal basis: subject's consent (Art. 6 Pt. 1 Para. 1 of 152-FZ).
Retention period: until the club is deleted by its owner.
2.4. Payment for Services and Voluntary Donations
When topping up the account balance to pay for the Service, and when making a voluntary donation via YooMoney, the following data is processed: payment amount, transaction identifier.
The Operator does not receive or store bank card details — these are processed exclusively by YooMoney LLC.
In addition, the Operator keeps internal records of the movement of funds on the user's account balance: credits, charges for services and what they were for, and the remaining balance.
Purpose: settlements for the Service, maintaining the account balance, tax accounting.
Retention period: 5 years (in accordance with tax accounting requirements).
2.5. Technical Data
During use of the Service, the following data is automatically recorded in server logs: IP address, browser type, pages visited, session times.
Purpose: ensuring security, diagnosing errors, protecting against abuse.
Retention period: 90 days.
2.6. Data from Connected Training Services
An athlete may choose to connect a third-party service to their account — Strava, Garmin Connect, Polar Flow, WHOOP, or Wahoo — via OAuth authorization on that service's own site (the Operator never receives or sees the password for it).
Data: workout parameters (distance, duration, pace/speed, heart rate, GPS track, splits/segments); for Garmin Connect, Polar Flow, and WHOOP, also recovery, sleep, and load metrics.
Collection method: API requests and webhook notifications from the connected service, after the athlete has given consent when connecting it.
Purpose: displaying workouts and recovery metrics in the athlete's personal account. Data received through the Strava integration is displayed exclusively to the athlete themselves. Data from Garmin Connect, Polar Flow, WHOOP, and Wahoo is displayed to the athlete and, within the coaching access framework of the platform, to their coach.
Additionally, an athlete may explicitly import a one-time copy of their gear list (name, mileage, and replacement threshold when available) from Strava or Garmin Connect into PaceTrack gear records in the Gear section. After that import, no link to the source service is stored — it is a copy of the athlete's own data in the Service; the coach sees PaceTrack records, not the original Strava/Garmin gear data.
Legal basis: the athlete's consent, given when connecting the integration (and when confirming a gear import).
Retention period: when the Strava integration is disconnected, or when access is revoked on Strava's side, all previously imported Strava workout data is automatically and permanently deleted from the Service; one-time PaceTrack gear copies remain (they can be deleted manually in Gear or upon request). For all other services (Garmin Connect, Polar Flow, WHOOP, Wahoo), previously imported workouts are retained as part of the athlete's training history and can be deleted upon request (see Section 6) or upon account deletion. The integration can be disconnected and consent withdrawn at any time in the "Apps" section of the athlete's account — this stops further synchronization and revokes the access token with that service.
2.7. PaceTrack Athlete Mobile App
When using the mobile app, the following additional data is processed:
- Location (GPS). The app requests precise location access, including in the background (when the screen is locked or the app is minimized), solely while a workout recording is active — to build the route and calculate distance/pace. Location is not tracked when no workout recording is in progress.
- Bluetooth. The app may connect to a heart rate sensor and/or a pace sensor (footpod) over Bluetooth to receive readings during a workout. Data is transmitted directly from the sensor to the user's device, does not pass through the Operator's servers in real time, and is stored as part of the workout data.
- Camera and microphone. Used only at the user's explicit action — to attach a photo or record a voice message in the chat with the coach.
- Push notifications. The device token for push notifications is sent to the Operator's server to deliver notifications (new messages, workout feedback, etc.) and is deleted upon signing out of the account.
Storage and deletion of this data follow the same rules as other athlete data (see Section 6).
2.8. Public Profile and Training Feed
The Service includes a public athlete profile and training feed: name (or username), profile photo, city, workouts and related statistics (distance, pace/speed, time, heart rate, elevation gain, power), overall career statistics, as well as other users' reactions (likes, comments) and the ability to follow a profile (including with follow-approval, if the athlete enabled that requirement).
Visibility of the profile, default visibility of workouts, and career statistics are enabled by default; the athlete may turn off profile visibility entirely, or change the visibility of an individual workout, at any time in profile settings — once turned off, the profile, workouts, and statistics stop being shown to other users. The athlete can also enable protection for the exact start and finish location of a workout (automatic trimming of the GPS track near a home address within a set radius) to avoid revealing their exact place of residence when publishing a route.
The Service also provides a feature for finding athletes who trained nearby at the same time ("who I crossed paths with"): this automatically matches athletes' workout GPS tracks by route geometry and time; the result of a match is the name of the athlete found, without exposing anyone's exact tracks.
Purpose: the Service's social features — publicly showcasing workouts and achievements, follows, reactions, and finding athletes with similar workouts.
Legal basis: the athlete's consent, expressed through profile visibility settings.
Retention period: until the athlete disables the relevant visibility setting or deletes their account.
2.9. Participation in Challenges
An athlete may voluntarily join a challenge — a competition with standings and rankings organized by a coach, a club, or the Service administration, including with participants from different clubs (cross-club challenges) and/or with sponsor support. Participation involves processing: name, email, workout results and metrics, participation status, and ranking.
This data is available to: the challenge organizer (the coach, club, or Service administration, including for exporting a list of winners with name and email for prize-awarding purposes); assigned judges (arbiters), who may review participants' workouts to check the integrity of the standings; and, if the challenge has a sponsor, the sponsor through a separate sponsor cabinet (a list of participants with name and email, the leaderboard, and participants' workouts for moderation and results purposes).
Purpose: organizing, judging, and finalizing the results of the challenge.
Legal basis: the athlete's voluntary decision to join the challenge.
Retention period: until the challenge ends and results are finalized; after that, the results are retained as part of the athlete's training history in the Service.
2.10. Partner Services (for example, shoe fitting)
An athlete may choose to use a partner service connected to the Service (for example, a sports shoe-fitting service). Before contacting a partner's service, the athlete is shown a notice of what data the partner will receive.
Data: contact details (name, email, phone if provided, city), a workout summary (volume, period, distances), and, if the athlete voluntarily fills out the intake form, information about injuries or conditions relevant to the fitting. The partner's access to the athlete's workout data is granted independently of the athlete's general profile privacy settings and may include recent workouts, including non-public ones, to the extent necessary for the consultation.
Purpose: the partner's consultation on product fitting; the subsequent purchase takes place on the partner's side, outside the Service — in that respect, the partner acts as an independent data controller.
Legal basis: the athlete's separate consent, given when contacting a specific partner's service; this consent is independent of the athlete's general profile privacy settings and is given separately for each partner.
Retention period on the Operator's side: as part of the athlete's workout data (see Sections 2.6–2.7); the retention period on the partner's side is governed by that partner's own privacy policy. The current list of partners is published in the relevant section of the Service.
2.11. Event participants without an account
A person may register for a coach or club event without creating a Service account. In that case we process their name, email, an optional comment, and an IP address hash.
Purpose: event registration, email confirmation, reminders, a calendar file, and running the event.
The name, email, and comment are shared with the event organizer (the coach or the club).
Legal basis: separate consent given at registration. Consent can be withdrawn with “Delete my data” on the personal registration page: the name and email are then anonymized.
Retention: 12 months after the event ends, then the registration is anonymized.
2.12. Availability marks, including health information
An athlete or their coach may mark calendar days when the athlete is not training, or is training only in selected sports.
Data: start and end dates, the kind of mark (“unavailable” or “selected sports only”), the selected sports; optionally a reason (vacation, travel, illness, injury, family, other) and a free-text comment; who created or changed the mark and when.
The reasons “illness” and “injury”, and the comment, may contain health information. They are optional: a mark works without a reason.
Purpose: so the coach and the PaceTrack Bot AI coach can plan around days the athlete is unavailable, and so the Service can warn about workouts that fall on those days.
Who can see them: the athlete; coaches with a confirmed link, including every coach in the club; and, for AI-coach subscribers, the AI-coach supervisor. Each of them can create, change, or delete a mark. If a coach creates or changes a mark, the athlete is notified. A coach whose link has ended loses access.
AI features: dates, mark type, reason, and comment are used by the Service’s AI when planning — the week assistant, the AI chat, and the AI coach — and are passed to external AI apps that the coach connected to their own account with a personal token, within that coach’s access.
The reason and comment are not included in in-app notifications, email, push notifications, Telegram messages, or the action log: notifications name only the person, the dates, and the kind of mark.
Legal basis: the athlete’s consent. If a coach enters a reason or a comment, the coach is responsible for having the athlete’s consent, as in section 2.2.
Retention: until the athlete or a coach deletes the mark, or until the athlete’s account is deleted — then every mark is deleted permanently.
2.13. Wellbeing diary
An athlete may log how they feel each day: scores from 1 to 5 (sleep quality, overall feeling, stress, muscle soreness, mood), sleep duration, weight, notes about nutrition and the day, and “sick” and “injured” flags with a short comment.
Purpose: the athlete sees their own trend; a coach sees only the metrics the athlete has opened to coaches in visibility settings.
Who can see it: the athlete sees every entry. Confirmed coaches and the AI-coach supervisor see only metrics marked “to coaches”. One visibility setting applies to every coach. A coach whose link has ended loses access.
AI features: the athlete’s own assistant sees every part of the diary. The coach’s AI features, the virtual coach, and plan review see only metrics opened to coaches.
Scores, weight, sleep duration, and note text are not copied into notifications, email, push, Telegram messages, or the action log.
Legal basis: consents the athlete has already given by using the Service. There is no extra consent dialog on the first entry; a note under the form explains that a coach sees only the metrics that are open.
Retention: until the athlete deletes the entries in their profile, or until the athlete’s account is deleted — then the entries are deleted permanently. Visibility settings stay when entries are deleted.
3. Cookies and web analytics
3.1. The Service uses necessary cookies to keep an authenticated user's session and to protect forms. Without them it is impossible to sign in to the Service or to submit forms.
3.2. To analyse visits and improve the Service we use the Yandex Metrica web analytics service (YANDEX LLC). Metrica sets its own cookies (for example, _ym_uid, _ym_d) and receives technical information: IP address, browser and device details, addresses of pages visited and referrers, time, and actions on pages.
3.3. Webvisor is enabled on the site. It is a Metrica feature that records a visitor's actions on pages (navigation, scrolling, clicks, and input in form fields, except fields that Metrica treats as confidential, such as passwords), so that we can analyse how convenient the interface is.
3.4. Data collected by Metrica is processed by YANDEX LLC under its terms: yandex.ru/legal/metrica_termsofuse and yandex.ru/legal/confidential. We receive aggregated statistics and session recordings in the Metrica interface.
3.5. You can disable cookies in your browser settings (without the necessary cookies it is impossible to sign in to the Service) or opt out of Metrica data collection with the official blocker: yandex.ru/support/metrica/general/opt-out.html. Opting out of analytics does not prevent you from using the Service or registering for events.
4. Transfer of Data to Third Parties
The Operator transfers personal data to the following third parties solely for the purpose of providing the Service:
- YooMoney LLC — processing of voluntary donations. YooMoney is an independent operator with respect to payment data.
- Mail service (SMTP) — sending notifications to coaches and athletes.
- Google LLC — authenticating users who choose to sign in with a Google account. Google receives information about the fact of accessing the authentication service. Google's privacy policy: policies.google.com/privacy.
- Yandex LLC (Yandex ID) — authenticating users who choose to sign in with a Yandex account. Yandex's privacy policy: yandex.ru/legal/confidential/.
- Apple Inc. — authenticating users who choose to sign in with Apple ID (Sign in with Apple). Apple's privacy policy: apple.com/legal/privacy.
- Service partners offering related services to athletes (for example, a sports shoe-fitting service) — only with the athlete's separate consent to contact a specific partner (see Section 2.10).
- Organizers, judges (arbiters), and sponsors of Service challenges — within the scope of the athlete's voluntary participation in a specific challenge (see Section 2.9).
- YANDEX LLC (Yandex Metrica) — web analytics of site visits, see section 3.
- Event organizers (coaches and clubs) — data of registered participants to the extent described in section 2.11.
The Operator does not sell, exchange or transfer data to other third parties without the subject's consent, except in cases provided for by Russian law.
5. Data Storage and Localization
Collection, organization and storage of personal data of Russian Federation citizens is carried out using databases located in the Russian Federation (data center at: 36 Berzarina St., bldg. 3, Moscow, Russia), in accordance with Art. 18.1 of 152-FZ.
6. Rights of Data Subjects
You have the right at any time to:
- obtain information about what data is being processed and on what grounds;
- request correction of inaccurate data;
- request deletion of personal data ("right to be forgotten");
- withdraw consent to data processing — withdrawal does not affect the lawfulness of processing carried out prior to withdrawal;
- file a complaint with Roskomnadzor: rkn.gov.ru.
To exercise your rights, send a request to: admin@pacetrack.cc. Response time — 30 days.
Data imported from Strava is deleted automatically when the integration is disconnected. If your request concerns deleting data from other connected training services (Garmin Connect, Polar Flow, WHOOP, or Wahoo) — please specify the service and account. Such data is deleted within 48 hours of the request.
Public profile. An athlete can turn off profile visibility entirely, or hide an individual workout, at any time — in the profile section ("Public profile" and visibility settings). Once turned off, the profile, workouts, and statistics stop being shown to other users, including in "who I crossed paths with" search results.
Consent to sharing data with partners and challenge participation. Consent to share data with a specific Service partner (Section 2.10) applies to that one instance of contacting the partner; contacting them again requires new consent. You can withdraw from a current challenge or opt out of joining new ones at any time in the challenges section; data already shared with an organizer, judges, or sponsor can be deleted on request to admin@pacetrack.cc, to the extent it remains under the Operator's control.
Self-service account deletion. You can exercise the right to deletion without contacting support — in the "Delete Account" section of your profile. A confirmation link is sent to your email (valid for 24 hours); deletion happens immediately after you confirm via that link.
- Athlete: the profile, all workouts and plans, availability marks (Section 2.12), wellbeing diary entries (Section 2.13), data from connected training services (Section 2.6) — access to those is also revoked, wellness data, and push subscriptions are permanently deleted. If the coach kept a payment record for this athlete, that record (name, payment history) is not deleted — it simply becomes unlinked from the deleted account, as if the athlete had never registered. The athlete's own chat messages are hidden from the conversation but not physically erased — this preserves the coach's side of the conversation history.
- Coach: if the coach owns a sports club with other coaches, account deletion is unavailable until club ownership is transferred or the other members are removed (this is stated explicitly if deletion is attempted). The coach's athletes are not deleted — they become athletes without a coach and can find a new one through the directory. Clubs with no other coaches are deleted along with the account.
Before confirming, an exact list of what will be deleted is shown. The action is irreversible.
7. Data Protection
The Operator applies organizational and technical measures to protect personal data: data is transmitted over HTTPS, passwords are stored as hashes (bcrypt), access rights are differentiated, and regular backups are performed.
8. Children
The Service is not intended for persons under 18 years of age. The Operator does not intentionally collect data from minors. If such data is discovered, please notify us at admin@pacetrack.cc for deletion.
9. Changes to This Policy
The Operator may amend this Policy. The current version with the update date is available on the website at pacetrack.cc/en/privacy.php. Continued use of the Service after changes are published constitutes acceptance of the updated Policy.
