Last updated: January 30, 2025
Version: 2.0
Effective Date: February 1, 2025
PeakRunner Pty Ltd ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect your personal data when you use our mobile application and services.
Key Points:
Data Controller:
PeakRunner Pty Ltd
Australia
Privacy Officer:
privacy@peakrunner.com
Support:
support@peakrunner.com
For EU residents: Contact your local supervisory authority: https://edpb.europa.eu/about-edpb/board/members_en
You provide:
Profile data:
With your explicit consent, we collect from:
Apple Health (iOS):
Google Health Connect (Android):
We also write data back:
How we obtain consent:
During onboarding, you see a "Health Data Permissions" screen explaining what we collect, why, and how to revoke access. You explicitly choose "Grant Health Permissions" or "Skip for Now."
How to withdraw consent:
Settings > Privacy > Revoke Health Data Access
Legal Basis:
Explicit consent (GDPR Article 6.1.a and Article 9.2.a)What we collect (with your explicit consent):
When you connect your Garmin Connect™ account, we access data from your Garmin devices via Garmin's Activity API — completed activities and their detailed tracks: activity type, start time, duration, distance, pace/speed, heart rate, elevation, cadence, calories, GPS route, and the Garmin device model. On connect we import up to 14 days of activity history. We also use Garmin's Training API to send planned workouts from your PeakRunner training plan to your Garmin device.
How we obtain consent:
You authorize the connection through Garmin's OAuth2 sign-in and choose which permissions to grant on Garmin's consent screen. You can disconnect at any time in Settings > Connected Services, or revoke access from your Garmin Connect account; we process Garmin's deregistration and stop receiving your data.
How we use it:
To match your Garmin activities to planned sessions, generate AI coaching feedback and performance metrics, and sync planned workouts to your watch.
Processing and storage (including third-party AI):
Garmin data is stored in Microsoft Azure (Cosmos DB), encrypted at rest (AES-256), and processed by Microsoft Azure OpenAI to produce AI coaching insights (see Sections 6.1 and 8). Your Garmin data is not used to train Microsoft's models, is not sold, and is not shared with advertisers. Retention follows Section 9.
Legal Basis: Explicit consent (GDPR Article 6.1.a and Article 9.2.a)
During active runs only:
Important: Location is ONLY tracked during active run sessions, not when app is closed or in background.
Location Privacy Controls:
How to manage: Settings > Privacy > Location Privacy
Permissions:
Legal Basis:
Consent and contract performanceEach tracked run includes:
Automatically collected:
Legal Basis: Legitimate interests (security, fraud prevention)
We do NOT store credit card numbers.
We receive from Stripe:
Legal Basis: Contract performance
Purpose: Service improvement (anonymized data)
Legal Basis: Legitimate interests
Important: Once anonymized, this data is no longer personal data under GDPR and may be retained indefinitely
Consent (Article 6.1.a):
Contract Performance (Article 6.1.b):
Legitimate Interests (Article 6.1.f):
Legal Obligation (Article 6.1.c):
⚠️ GDPR Article 22 Disclosure
What the AI does:
How it works:
Significance:
Your rights:
Human Oversight: Our support team can review AI recommendations upon request.
How we improve our AI models:
What data is used for AI improvement:
What data is NOT used:
Your control:
We do NOT sell your personal data.
Stripe (https://stripe.com/privacy)
Microsoft Azure (https://privacy.microsoft.com)
Azure OpenAI (https://privacy.microsoft.com)
Expo (https://expo.dev/privacy)
Google Maps API (https://policies.google.com/privacy)
Google Sign-In (https://policies.google.com/privacy)
Data: Email, name, profile photo (only if you sign in with Google)
Microsoft OAuth (https://privacy.microsoft.com)
Data: Email, name (only if you sign in with Microsoft)
Apple Sign In (Apple Privacy Policy)
Data: Email (optional relay), name (only if you sign in with Apple)
Apple Health (iOS)
Google Health Connect (Android)
Garmin Connect (https://www.garmin.com/privacy/connect/)
⚠️ We are not responsible for third-party practices:
When you interact with third parties through PeakRunner (OAuth providers, health platforms, payment processors), their privacy policies and terms apply to their services. We encourage you to review their policies:
Third-party risks you should know:
Our responsibility ends where theirs begins:
What you should do:
We may disclose data to:
We will notify you of legal requests unless prohibited by law.
Processing Locations:
Standard Contractual Clauses (SCCs):
Your rights:
Encryption:
Access Controls:
Infrastructure:
Note: No system is 100% secure. We strive to protect your data but cannot guarantee absolute security.
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account | Duration of service | Ongoing service delivery |
| Deleted account | 30 days | Account recovery period |
| Health data | 7 years after deletion | Medical data standards |
| Activity history | While account active | Training analysis |
| AI interactions | While account active | Personalized coaching |
| Payment records | 7 years | Legal/tax requirements |
| Audit logs | 6-12 months | Security and compliance |
| Backups | 90 days | Disaster recovery |
| Anonymized analytics | Indefinitely | Product improvement |
We may retain certain data beyond the standard periods in these situations:
Important: These exceptions apply only when legally required or necessary for legitimate purposes. We minimize retention wherever possible.
What gets deleted immediately:
What may persist (anonymized):
What may persist (with identifiers) temporarily:
Content you shared with others:
Third-party data:
To delete account:
Right to Access (GDPR Article 15)
Right to Rectification (Article 16)
Right to Erasure (Article 17)
Right to Restriction (Article 18)
Right to Data Portability (Article 20)
Right to Object (Article 21)
Right to Withdraw Consent
Important: Withdrawal doesn't affect prior lawful processing
Re-consent Rate Limiting:
Right to Lodge Complaint:
Right to Know:
Right to Delete:
Right to Opt-Out of Sale:
Right to Non-Discrimination:
How to exercise: privacy@peakrunner.com or [PHONE NUMBER TO ADD]
Verification: We may request info to verify identity
Authorized Agents: May designate agent with written authorization
Minimum Age: 13 years old
For users aged 13-17, we provide enhanced privacy protections:
Default Privacy Settings:
Important: Users can change these settings, but we recommend keeping enhanced protections until age 18
Health Data Restrictions:
Parental Rights (Ages 13-15):
Age Verification:
If your child under 13 created an account:
Supervising teens (13-17):
Red flags to watch for:
Location (When In Use):
Health (HealthKit):
Notifications:
Camera (Optional):
Location (Fine/Coarse):
Health Connect:
Notifications:
Camera (Optional):
Internet/Network:
Health Data Sync:
Location:
Push Notifications:
Mobile App:
Local Storage:
Analytics:
Website (if applicable):
We may update for:
Material changes (affect rights significantly):
Non-material changes:
In merger/acquisition/sale:
Your responsibility:
Our commitment:
For analytics and AI improvement:
By creating an account, you acknowledge:
Thank you for trusting PeakRunner with your fitness journey and personal data.