Privacy Policy
Last Updated: September 11, 2026
Introduction
Endurance HQ is operated by Endurance HQ LLC, a Delaware limited liability company ("Endurance HQ", "we", "our", or "us"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our event management platform, public event sites, participant and volunteer experiences, and related services (the "Service").
Endurance HQ sometimes determines why and how personal information is used, such as for accounts, subscriptions, support, security, and our own business operations. When an event organizer uses the Service to collect or manage participant, volunteer, staff, sponsor, vendor, or audience data, the organizer generally determines the purposes of that processing and Endurance HQ processes the information on the organizer's behalf. Please also review the applicable organizer's notices and our Terms of Service.
1. Information We Collect
1.1 Information You Provide to Us
We collect information you provide directly when you:
- Create an Account: Name, email address, phone number, profile information
- Register for or Participate in Events: Name, contact details, date of birth, demographic and address information, emergency contacts, medical or allergy information, eligibility and requirement responses, team information, waiver acceptance, signatures, results, and race-day activity
- Volunteer, Staff, Speak, Sponsor, Sell, or Work with an Event: Contact information, role, availability, assignments, credentials, business details, payment or tax records, and related communications
- Create and Operate Events: Organization details, event plans, contacts, tasks, schedules, permits, financial records, content, files, images, video, sponsor and vendor information, and communications
- Make Purchases or Payments: Order, registration, donation, membership, billing, tax, refund, payout, and transaction details. Stripe processes complete payment-card information; Endurance HQ does not store complete card numbers.
- Use Communications or Community Features: Email and text-message content, replies, questions, comments, support requests, survey responses, photos, videos, and other content you submit
- Connect or Import Data: Files, records, messages, calendars, contacts, rosters, results, and account metadata that you select, import, or authorize from another service
1.2 Information Collected Automatically
When you access our Service, we automatically collect:
- Device Information: Device type, operating system, browser type, IP address
- Usage and Interaction Data: Pages and event content viewed, features used, searches, clicks, saves, scans, notification interactions, purchase attribution, referring URLs, and timestamps. Depending on the feature, this data may be associated with an account, event pass, email address, organization, browser session, or pseudonymous identifier.
- Location Data: General location based on IP address and, when you grant device permission, precise or approximate device location for maps, navigation, check-in, inventory, sponsor-hunt, geofence, or similar location-aware features
- Optional Live GPS Data: If you expressly enable participant GPS tracking, we collect precise coordinates, altitude, accuracy, speed, heading, timestamps, and optional battery level at the interval you choose. The event may display your latest position or route to organizers, event staff, crew, spectators, or public event surfaces. Revoking tracking stops future collection but does not automatically delete points already recorded.
- Push Notification Data: Browser permission status, push-subscription endpoint and encryption keys, event or account association, notification preferences, and delivery or interaction records
- Offline Storage: Data cached locally in IndexedDB for offline functionality (participant lists, check-in queues, event schedules)
- Cookies and Similar Technologies: Session cookies, authentication tokens, preference settings
1.3 Information from Third-Party Services
We integrate with third-party services that may collect or share information:
- Clerk (Authentication): Account creation, login data, OAuth provider information
- Stripe (Payments and Financial Connections): Payment transaction details, fraud prevention data, and financial account data an organizer explicitly authorizes for bookkeeping
- Resend (Email): Email delivery status, open rates, bounce notifications
- Twilio (SMS and MMS): Message content, phone numbers, inbound replies, media, consent and opt-out signals, delivery status, and carrier or validation data
- Vercel (Hosting, Storage, Analytics, and AI Gateway): Hosted files and application data, traffic and performance data, and information routed through an AI feature you choose to use
- Google Services (Optional Connections): Connected account identity and, depending on the scopes a user approves, selected Drive files, Gmail messages and attachments, Calendar events, Sheets content, or YouTube channel, live-broadcast, and chat details
- Event and Business Integrations: Registration, timing, results, mapping, accounting, CRM, task-management, social, and other connected services may provide records an authorized user directs us to import or synchronize
- Other Users and Public Sources: Event organizers, household registrants, team members, staff, volunteers, integrations, and public event websites may provide information about participants, contacts, businesses, or events
1.4 Sensitive and Special-Category Data
Some features process information treated as sensitive or "special category" data, including health and medical conditions, allergies, dietary or accessibility needs, emergency information, date of birth, precise location, financial account data, and information about minors. Depending on the feature and applicable law, we process this information:
- To provide a registration, accommodation, safety, tracking, finance, or other feature you or an authorized organizer requests
- With consent when consent is the required basis, including separate consent where a consumer health privacy law requires it
- To protect a person's vital interests or support emergency response
- As otherwise permitted or required by applicable law
You are not required to provide sensitive information unless it is necessary for a feature you request or an organizer makes it a disclosed condition of participation. You may withdraw consent where processing relies on consent, though withdrawal may limit the related feature or safe participation. Organizers generally control sensitive event data they collect and are responsible for lawful collection, notice, consent, access, and use.
1.5 Connected Financial Account Data
An authorized organizer may optionally connect a U.S. financial account through Stripe Financial Connections to import transactions into the organizer's bookkeeping ledger. Stripe hosts the authentication and consent flow. Endurance HQ requests transaction access only and receives:
- Institution name, account display name, account type, and the last four digits
- Transaction dates, descriptions, amounts, currency, and posting status
- Stripe identifiers and refresh status needed to maintain the connection
Endurance HQ does not receive the organizer's bank login credentials or full account number through this feature.
1.6 Artificial Intelligence Inputs and Outputs
The Service includes optional artificial-intelligence features for assistance, search, extraction, transcription, translation, classification, drafting, research, and analysis. When you or an authorized user invokes one of these features, we may process the prompt and relevant text, files, images, screenshots, connected-service content, public-source content, and existing workspace or event context through Vercel AI Gateway and model providers such as OpenAI. We also retain the resulting output, usage metadata, review decisions, and related audit records as needed to provide and improve the requested workflow.
Do not submit personal information to an AI feature unless you are authorized to do so. AI output may be incomplete or inaccurate and should be reviewed by an appropriate person before it is used for operational, safety, financial, legal, eligibility, or other consequential decisions. As stated in Section 2.6, Google user data is not used to train generalized artificial-intelligence or machine-learning models.
1.7 Organizer-Provided and Organizer-Controlled Data
Event organizers may create records directly or import them from registration, timing, spreadsheet, mailbox, or other systems. Organizers are responsible for having a lawful basis to provide that information, giving required notices, honoring applicable rights, and limiting access to authorized users. If your request concerns an event record, we may direct the request to the organizer or assist the organizer in responding.
2. How We Use Your Information
We use the information we collect to:
2.1 Provide and Improve the Service
- Create and manage user accounts
- Process event registrations and payments
- Generate QR codes for check-in systems
- Send confirmation emails and race day information
- Manage volunteer shifts and assignments
- Enable offline functionality via local storage
- Provide maps, optional location-aware tools, live tracking, results, media, commerce, membership, fundraising, sponsor, vendor, and community features
- Provide organizer-requested AI, translation, search, extraction, import, and automation features
- Provide customer support and respond to inquiries
- Monitor and improve platform performance
2.2 Communicate with You
- Send registration confirmations and race day updates
- Notify volunteers of shift assignments and check-in status
- Deliver organizer-authored email, SMS, MMS, push, inbox, and race-day communications and process replies
- Send important service announcements and updates
- Respond to support requests and feedback
- Send marketing communications (with your consent)
2.3 Ensure Security and Compliance
- Detect and prevent fraud, abuse, and security incidents
- Enforce our Terms of Service
- Comply with legal obligations and law enforcement requests
- Protect the rights and safety of users and the public
2.4 Analytics and Research
- Analyze usage patterns and trends
- Measure event, registration, sponsor, content, campaign, notification, store, and race-day engagement
- Conduct research to improve features
- Generate aggregate, anonymized statistics
- A/B test new features and improvements
2.5 SMS/Text Messaging Communications
Endurance HQ provides SMS and MMS tools to event organizers and also sends limited platform messages. Messages may identify Endurance HQ, a specific event, or an event organization as the sender. We use Twilio and participating mobile carriers to transmit messages and process replies, delivery events, and opt-out signals.
Types of messages:
- Event registration confirmations
- Race day updates, schedule changes, and course alerts
- Volunteer shift reminders (24 hours and one hour before)
- Emergency and safety notifications
- Event cancellation or postponement notices
- Two-way replies and organizer support
- Promotional, fundraising, sponsor, store, or community messages only when the sender has the consent required for that subject
Consent and frequency: Message frequency varies by event, program, and your activity. Consent must identify the sender and message subject and is not a condition of a purchase, registration, or volunteer opportunity. An organizer that imports or adds a phone number and marks it eligible for messaging represents that it obtained and can document the required consent. Promotional messages require the separate level of consent required by law and provider policy.
Message and data rates may apply. Check with your mobile carrier for details about your text messaging plan.
Opting out: Reply STOP to withdraw consent from the sender or messaging program associated with that message. You may receive one confirmation. Depending on the sending number and event, you may need to opt out separately from a different event or organization sender. Reply START or follow the disclosed enrollment method if you later choose to re-enroll.
Help: Reply HELP to any message for assistance, or contact us at tyler@endurancehq.app.
Mobile data: We do not sell mobile numbers or SMS consent, and we do not share them with third parties for those third parties' own marketing. We disclose them as needed to the applicable sender, Endurance HQ's communications providers, carriers, and vendors that support message delivery and compliance. See our SMS Terms for complete program details.
2.6 Connected Google Services
Authorized users may optionally connect Google Drive, Gmail, Google Calendar, Google Sheets, or YouTube for an event, organization, workspace, mailbox, or personal chat participation. We receive the connected account identity, approved scopes, connection status, and the records the user selects or makes available within configured filters. Access depends on the connection:
- Google Drive: We access files the connected account selects or authorizes under the approved scope, store imported copies and metadata, generate previews, and refresh a linked copy when requested. When an authorized user requests it, we may also create or copy an event document in Drive.
- Gmail: Within the connected mailbox and configured filters, we may read and store threads, message bodies, snippets, headers, senders, recipients, labels, dates, and attachments; search and classify messages; associate them with event or CRM records; and perform user-requested reply, draft, send, archive, or label actions.
- Google Calendar: We may read calendar and event details, descriptions, times, locations, organizers, attendees, and changes; synchronize eligible meetings into event or CRM records; and maintain a Google notification channel for updates.
- Google Sheets: We may read spreadsheet metadata, sheet names, and cell content for connected search, roster, list, import, and operations workflows. The connection is read-only unless a separate interface clearly requests additional access.
- YouTube Live: We read the connected YouTube channel identity and, when an authorized organizer requests it, create, configure, and bind live broadcasts and ingestion streams for an event. We store the channel details and event broadcast configuration needed to maintain that connection. Connecting a channel does not start a broadcast.
- YouTube chat: When an organizer connects a broadcast's chat, we receive and display its messages, author channel identities, display names, profile images, timestamps, and moderation events. Posting requires the sender's separate YouTube authorization and uses that person's channel. Authorized organizers may remove messages or block authors through YouTube. We do not use these connections to read or modify unrelated videos, comments, or subscriptions.
- YouTube retention and control: Cached YouTube messages, moderation records, and private sending receipts are scheduled for deletion after 24 hours. Disconnecting a personal YouTube connection revokes its Google authorization and removes its private sending receipts; messages already posted on YouTube remain there. You can also revoke access through your Google Account connections or request deletion using the contact details below.
- Use and Sharing: We use Google user data only to provide and secure the connected features the authorized user requests. A requested AI feature may process selected Google content to produce that user's output, but Google user data is not sold, used for advertising, or used to train generalized artificial-intelligence or machine-learning models. We share it only with providers needed to operate and secure those requested features.
- Storage and Control: Connection records and credentials remain while needed to maintain the connection. Imported files, synchronized messages, meeting records, derived tasks, CRM records, summaries, and other outputs may remain after disconnection until an authorized user deletes them or requests deletion, subject to Section 4. Authorized users can pause, disconnect, or revoke a connection and use available feature-specific deletion controls.
Endurance HQ's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
2.7 Connected Financial Account Data
We use permissioned transaction data only to create and maintain the connected workspace or organization's bookkeeping ledger, including importing new posted transactions, applying amount or date corrections, and removing transactions that the financial institution marks void.
- No money movement: The bank feed does not authorize Endurance HQ to initiate payments, transfers, or withdrawals.
- No unrelated use: We do not use connected account data for advertising, credit decisions, or training generalized artificial intelligence models.
- Storage and access: We store the connected account identifiers and imported ledger entries with our database provider. Only users authorized to access that workspace or organization's finances can view them.
- Disconnecting: An organizer can disconnect the bank feed from Finance. This ends future access and removes the live connection. Ledger entries already imported remain as bookkeeping records until an authorized user deletes them or requests deletion.
- Deletion requests: Contact the privacy addresses below to request deletion of connected financial data. We will disconnect the account, delete data from our systems unless we have a legal basis to retain it, and coordinate the request with Stripe when required.
2.8 Precise Location and Live Tracking
Location-aware features require device permission. A one-time location request may center a map, help navigate to an event place, record where an operational scan occurred, or detect proximity to an event location. Continuous live GPS tracking is a separate feature that requires an affirmative in-product tracking grant.
When live tracking is enabled, we use position points to show progress, latest location, and route history for the event. The feature is designed to make that information available through the event's live or participant-facing experience, which may be public or shared with organizers, staff, crew, and spectators. You can pause tracking, revoke the in-product grant, or turn off device permission. Because recorded points may already have been displayed, cached, or used for event operations, contact us or the event organizer to request deletion of prior location history.
2.9 Automated Features and Human Review
We use rules, algorithms, and AI to assist with imports, matching, classification, recommendations, risk or readiness indicators, content generation, translations, scheduling, and other workflows. Event organizers remain responsible for reviewing outputs and for decisions about eligibility, lottery or waitlist operation, safety, staffing, refunds, awards, and other event matters. We do not use personal information for targeted advertising across unrelated websites or to make solely automated decisions that produce legal or similarly significant effects on behalf of Endurance HQ without any right or safeguard required by applicable law.
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
3.1 With Event Organizers and Authorized Users
When you interact with an event, we make relevant information available to the event organizer and users the organizer authorizes, which may include event staff, volunteers, timing providers, medical and safety personnel, sponsors, vendors, contractors, or other operational partners. Access depends on role and feature. Event organizers are responsible for their own use and disclosure of event data.
3.2 With Service Providers
We share information with trusted third-party service providers who help us operate the Service:
- Clerk: User authentication and account management
- Stripe: Payment processing, fraud prevention, and permissioned financial account connections
- Resend: Transactional email delivery
- Twilio: SMS, MMS, phone-number, reply, and delivery services
- Neon (PostgreSQL): Database hosting
- Vercel: Application hosting, CDN, file storage, analytics, performance monitoring, and AI Gateway
- Vercel Connect: Secure Google authorization and short-lived access tokens for optional organizer connections
- OpenAI and Other Model Providers: Optional AI features invoked by an authorized user
- General Translation: Localization and organizer-requested translation features
- External Image Hosts (optional): If you choose to host or link images through third-party services such as Imgur or Cloudinary, those services receive the image requests directly. We do not share your account or personal information with them; they are not our service providers and are governed by their own privacy policies.
3.3 With Event Participants, the Public, and Transaction Partners
Information may be shown to other users or the public when the feature is designed for publication or sharing. Examples include event pages, schedules, results, participant profiles or bios, questions, photos and videos, sponsor interactions, prize or draw fulfillment, fundraising acknowledgments, and optional live GPS tracking. Organizers control many publication settings, and you should review the applicable event's choices before submitting content.
If you buy from, donate to, join, message, scan, enter a promotion with, or otherwise interact with an event, sponsor, vendor, fundraiser, photographer, or other transaction partner, we may provide the information needed to complete that interaction. We do not transfer SMS consent as permission for another party's marketing.
3.4 Connected Services and User-Directed Disclosures
We disclose information to a connected service when an authorized user enables an integration, imports or exports data, sends a message, publishes content, or otherwise directs the Service to interact with that provider. The receiving provider's terms and privacy policy apply to its independent processing.
3.5 For Legal, Safety, and Security Reasons
We may disclose your information if required by law or in response to:
- Legal process (subpoenas, court orders)
- Law enforcement or regulatory requests
- Protection of our rights, property, or safety
- Emergency situations involving public safety
3.6 Business Transfers
If Endurance HQ is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice before your information becomes subject to a different privacy policy.
3.7 With Your Consent
We may share your information for other purposes with your explicit consent.
4. Data Retention
We retain personal information for the period reasonably necessary for the purposes described in this Privacy Policy. The period depends on the type of record, the event organizer's instructions, the duration of an account or customer relationship, safety and operational needs, consent and opt-out evidence, dispute and fraud prevention, backup cycles, and tax, accounting, contractual, and legal requirements.
- Accounts and Customer Records: Generally retained while the account, organization, or customer relationship is active and afterward as needed for support, security, disputes, and legal obligations
- Event, Registration, Volunteer, Results, Waiver, and Communications Records: Retained under the event organizer's instructions and for operational, historical, safety, compliance, and legal needs. Organizers may retain exported copies independently.
- Payments, Orders, Donations, Memberships, Tax, and Bookkeeping: Retained for applicable transaction, accounting, tax, chargeback, fraud, and legal periods
- SMS Consent and Opt-Out Records: Retained as needed to document consent, honor revocation, prevent unwanted messages, and meet legal, carrier, and provider requirements
- Connected Services: Connection credentials and sync metadata are retained while the connection is active and for a limited period afterward. Imported or synchronized records may remain after disconnection until deleted or no longer needed.
- Precise Location: Retained for event operations, live and historical event features, safety, and organizer instructions. Revoking live tracking stops future collection but does not itself delete prior points.
- Local and Offline Data: Remains on the device until the application clears it, it expires under the applicable cache rule, or the user clears browser or application storage
- Deidentified or Aggregated Data: May be retained where it can no longer reasonably be linked to an individual
You may request deletion by contacting tyler@endurancehq.app or christian@trailrunnerhq.com. We may retain information when required or permitted by law, when needed to complete a requested transaction, maintain security, honor an opt-out, establish or defend claims, or comply with an organizer's lawful retention instruction. Deletion from active systems may not immediately remove information from backups, archives, public caches, recipient inboxes, organizer exports, or third-party systems.
5. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
5.1 General Rights (All Users)
- Access: Request a copy of the personal information we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request eligible information in a portable format
- Opt-Out: Unsubscribe from marketing communications
5.2 U.S. State Privacy Rights
Residents of California, Colorado, Connecticut, Delaware, Oregon, Texas, Virginia, and other states may have additional rights where the applicable law covers Endurance HQ or the event organizer, including:
- Know and Access: Confirm processing and obtain categories, specific information, sources, purposes, and categories of recipients
- Correct, Delete, and Port: Correct inaccuracies, request deletion, and receive eligible information in a portable format
- Opt Out: Opt out of sale, targeted advertising, or profiling in furtherance of decisions with legal or similarly significant effects, when applicable. Endurance HQ does not sell personal information or use it for cross-context behavioral advertising.
- Limit Sensitive Information: Limit or withdraw consent for certain uses or disclosures of sensitive personal information, including health information and precise geolocation, where applicable
- Appeal and Non-Discrimination: Appeal a denied request and receive equal service without unlawful retaliation for exercising a privacy right
5.3 European and United Kingdom Rights
- Right of Access and Rectification: Access personal data and correct inaccurate data
- Right to Erasure: "Right to be forgotten" under certain conditions
- Right to Restriction: Limit how we use your data
- Right to Object: Object to processing for direct marketing or legitimate interests
- Right to Portability: Receive your data in a machine-readable format
- Right to Withdraw Consent: Withdraw consent for processing at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority
5.4 Exercising Your Rights
Contact tyler@endurancehq.app or christian@trailrunnerhq.com and identify the right you want to exercise, the relevant event or organization, and the email address or phone number associated with the record. We may verify your identity or authority before completing a request. Authorized agents may submit requests where permitted by law.
For organizer-controlled event data, we may refer your request to the applicable organizer or act on its documented instructions. You may also contact the organizer directly. We will respond within the period required by applicable law and explain any denial. Where an appeal right applies, reply to the decision with the subject "Privacy Appeal" and explain why you believe it should be reconsidered.
You can also use available account, event-pass, volunteer, notification, or connection settings; use email unsubscribe links; reply STOP to the relevant SMS sender; revoke live GPS tracking; or withdraw browser permissions. These controls may not delete historical records, which require a separate deletion request.
6. Security Measures
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. Depending on the Service feature, these safeguards include:
- Encryption: Encrypted network connections and provider-managed encryption for hosted data
- Authentication: Secure authentication via Clerk with multi-factor authentication support
- Payment Security: Payment-card processing through Stripe; Endurance HQ does not store complete card numbers
- Access Controls: Role-based permissions and event or organization scoping
- Application Safeguards: Signed or scoped access tokens, audit records, validation, rate limits, and other feature-specific controls
- Offline Security: Browser same-origin protections for locally cached data
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Protect your credentials and device, limit permissions to people who need them, and notify us promptly if you suspect unauthorized access.
7. Cookies and Tracking Technologies
7.1 Types of Cookies We Use
- Essential Cookies: Required for authentication (Clerk), security, and fraud prevention during payment (Stripe)
- Functional Cookies: Remember preferences and settings (language, theme)
- Service Worker: Enables offline functionality and background sync
We do not use personal information for cross-context behavioral advertising. We use Vercel Web Analytics and Speed Insights and our own first-party product, event, content, campaign, notification, purchase-attribution, and interaction analytics. Depending on the feature, analytics may be aggregated or associated with an account, organization, event pass, email address, browser session, or pseudonymous identifier. We use this information to operate and improve the Service, measure requested features, prevent abuse, and provide organizer reporting. We do not sell it for advertising.
7.2 Local Storage
We use browser local storage and IndexedDB to:
- Store email addresses for race day portal access
- Cache participant lists for offline check-in
- Queue offline mutations (check-ins, updates) for sync
- Store race day schedules and event information
7.3 Managing Cookies
Most browsers allow you to control cookies, permissions, local storage, and site data. Disabling or clearing these technologies may sign you out or impair offline, notification, mapping, and other Service features. Where applicable law requires consent for a non-essential technology, we will request it through the relevant interface.
8. Children's Privacy
The Service is not directed to children under 13, and a child under 13 may not independently create an account or submit personal information to us. Some events allow minors to participate. In those cases, a parent, legal guardian, or other authorized adult may provide a minor participant's registration, contact, age, health, emergency, waiver, results, media, and event-activity information to the organizer through the Service.
Event organizers are responsible for determining whether minors may participate, obtaining verifiable parental or guardian authorization when required, providing required notices, limiting collection to what is appropriate for the event, and complying with child privacy, publicity, waiver, and safety laws. Endurance HQ processes organizer-controlled minor data to provide the requested event services and does not knowingly use a child's personal information for cross-context behavioral advertising.
A parent or guardian may contact tyler@endurancehq.app or christian@trailrunnerhq.com to request access, correction, or deletion. Include the relevant event and enough information for us to verify authority. We may coordinate the request with the event organizer and may retain information where law or a permitted exception requires it.
9. International Data Transfers
Endurance HQ is based in the United States. Your information may be transferred to and processed in the United States or other countries where our service providers operate. These countries may have different data protection laws than your country of residence.
Where applicable law requires a transfer mechanism, we use appropriate safeguards that may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Applicable data-privacy frameworks or other legally recognized transfer mechanisms
10. Third-Party Websites and Services
The Service may contain links to third-party websites (event websites, sponsor sites, social media, image hosting services). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information.
This includes:
- External image hosting services (Imgur, Cloudinary)
- Social media platforms linked from event pages
- Sponsor websites
- Lodging and travel booking sites
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top
- Sending an email to registered users (for significant changes)
- Displaying a prominent notice in the Service
The revised policy becomes effective on the stated date. If a change requires consent under applicable law, we will request consent separately. We encourage you to review this Privacy Policy periodically.
12. Privacy Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you may contact us at:
Privacy Contact
Endurance HQ LLC (a Delaware limited liability company)
Email: tyler@endurancehq.app, christian@trailrunnerhq.com
Legal: tyler@endurancehq.app, christian@trailrunnerhq.com
General Support: tyler@endurancehq.app, christian@trailrunnerhq.com
Privacy Policy Summary
Key Points:
- We collect information to provide event, participant, volunteer, commerce, communication, mapping, and organizer services
- Optional live tracking may collect precise GPS data and share it on event-directed surfaces
- Optional AI and connected-service features process the content an authorized user submits or selects
- We use service providers such as Clerk, Stripe, Resend, Twilio, Vercel, and AI model providers
- We do not sell your personal information
- Connected financial account data is used only for organizer-requested bookkeeping and can be disconnected from Finance
- Event organizers generally control event participant and volunteer data
- You may have rights to access, correct, delete, port, limit, opt out, withdraw consent, or appeal
- We use reasonable safeguards, but no system is completely secure
- Offline functionality may store event data locally on your device
- Contact tyler@endurancehq.app or christian@trailrunnerhq.com for data protection inquiries
By using Endurance HQ, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.