Last updated 9 September 2026
The short version
SendOff stores what you type into it: your email address, your race, and what your crew logs. There is no analytics, no advertising, no third-party trackers, no cookies, and nothing is sold to anybody.
There is one thing worth knowing before you put a race in, and it is under the repository is public.
What is collected
Your account
Your email address, and your password stored only as a salted hash. The password itself is never stored and cannot be recovered, only reset. Also your role and your plan.
Your profile, if you fill one in
A display name, fueling goals, hour bands, and the notes you want a crew to have.
A race
Its name, location, start time, activity, course (segments, aid stations, and the elevation from any GPX file you upload), cutoffs, and the racers' names and bib numbers.
What the crew logs
Arrival and departure times at each aid station, calories, fluid, sodium, whether those were measured or estimated, gear taken or dropped, free text notes, and anything typed into the issues and meds fields. Those last two are worth calling out on their own: a crew uses them for how a racer is doing and what they have taken, so they can hold health information about a named person. They are stored exactly like the rest of the race, which on a public race means publicly. Also which account logged each one.
Access
Which email addresses may see or edit each race, and which account each racer is linked to.
Feedback you send
What you wrote, and, gathered automatically so a report is useful: the page you were on, the race, the version of the app, whether the device was offline, how many unsent writes were waiting, and your browser's user agent. Your email address if you were signed in, or one you typed if you were not.
If you ask for an invite or a password reset
Your name, your email address, and anything you wrote in the request.
Technical
Your IP address is used to rate limit feedback and invite requests. It is held as a counter against your address for one hour and then it is gone. SendOff keeps no other logs of its own. Cloudflare and GitHub keep theirs.
Where it is stored
| Cloudflare Workers KV | accounts, profiles, access lists, invite and reset tokens, share links, feedback |
| Cloudflare D1 | races and logged splits |
| GitHub | races and logged splits, as files in a repository |
| Your own browser | your session, a copy of the races you have opened so they still work with no signal, and any feedback waiting to send |
The repository is public
SendOff's race data is currently kept in a public GitHub repository, which is also what serves the pages people watch. That has consequences which are not obvious from using the app:
- A race marked unlisted is not sealed. The box below says exactly what that means.
- Every change made through SendOff creates a public commit. Commit messages made before 9 September 2026 contain the email address of whoever made the change, and they remain in the repository's history. Messages made after that date carry no address: what was done is recorded publicly, who did it is recorded in the database.
- Email addresses that were once stored inside the race files themselves were removed in September 2026. They remain in the repository's history.
Unlisted does not mean sealed, encrypted or access controlled. An unlisted race is kept off the public list and out of search engines, and its address carries a random suffix so it cannot be guessed, but the file behind it sits on a public host and can be read by anybody who has that address. Do not put anything in a race that you would mind a stranger reading. SendOff called this setting private until 9 September 2026, and stopped because unlisted is what it actually does.
Moving off this is in progress and is the next piece of work after the September 2026 race. Until it is finished, treat a race page as something a stranger could read.
Who else sees something
- Cloudflare
- Hosts the service, stores the data, and routes the email. They can see everything SendOff holds.
- GitHub
- Hosts the repository and serves the public pages.
- Google Fonts
- Serves the typefaces. Loading any SendOff page sends your IP address and browser details to Google.
- Esri
- Serves the map tiles behind a course map. Opening a race page that draws a map sends your IP address and the map coordinates to Esri, which reveals roughly where the race is.
That is the whole list. No analytics, no advertising networks, no social pixels, no session recording.
What is not done
No cookies are set. Your sign-in session lives in your browser's local storage rather than a cookie, which is why there is no cookie banner: there is nothing to consent to. Nothing is sold, rented, or shared for advertising. There is no profiling and no automated decision-making.
Sensitive information
No location is ever taken from your device. SendOff never asks your browser for your position and never reads it. Nothing in the app calls the browser's location interface at all.
The only coordinates in SendOff are in a course file that whoever set the race up chose to upload, and that file describes a route rather than a person. It is worth understanding what that still implies: a course, a start time and a logged arrival together say roughly where a named racer was, and on a public race that is readable by anybody.
The other sensitive thing SendOff can hold is health information, and only because a crew typed it. The notes, issues and meds fields are free text, and crews use them for how a racer is doing and what they have taken. SendOff does not require any of it, does not ask for it, and cannot tell whether a note is about a shoe or a stomach. It is stored like the rest of the race and it is readable by everyone the race is readable by.
None of it is sold, shared for advertising, or used to build a profile of anybody. If you would rather it were not in a public file, keep it out of the fields, or wait for the storage move described above.
On your device
Signing in stores a session that lasts seven days. Opening a race stores a copy of it so the page still works when the signal goes, which for a crew at an aid station is the point. Feedback written with no signal is held until it can be sent. Signing out deletes all of it, and so does clearing your browser's data for the site.
How long things are kept
| Sign-in sessions | 7 days |
| Password reset links | 2 days |
| Account invites | 14 days |
| Share links | 30 days by default |
| Invite and access requests | 90 days |
| Feedback | 180 days |
| Rate limit counters | 1 hour |
| Races and logged data | until deleted |
Your rights: getting a copy, a correction, or a deletion
Write to info@sendoff.run. Your account, your profile and your races can be deleted on request.
You can ask to see what is held about you, to get a copy of it in a portable form, to have it corrected, or to have it deleted. Ask at info@sendoff.run from the address on the account, or say which account you mean. Every request is answered within 45 days. If it needs longer you will be told why inside those 45 days, and the extension will not be more than a further 45.
If a request is refused you will be told why, and you can appeal by replying to that answer. An appeal is decided within 60 days. If the appeal is refused as well, you will be told how to complain to the Texas Attorney General.
Anything already published to the public repository is harder, and it is worth being straight about that. Removing it from the current files is done within 30 days of the request. Removing it from the repository's history means rewriting that history, which cannot be done for one person on demand because it rewrites the whole repository. Within the same 45 days you will be told which of the two your request needs and, where it needs the second, the date it is expected by. It will not be left at "eventually".
Children
SendOff is not aimed at children and accounts are not knowingly given to anybody under 13. No age is asked for at sign up, because sign up is invite only and every invite is sent by hand.
A racer in a race can be a child, because a child can run a race and a crew logs for them. What is held then is a name, a bib number and the splits, entered by an adult on the crew rather than by the child, and there is no account for that child.
If you believe a child under 13 has an account, or that something about a child is in a race and should not be, write to info@sendoff.run and it will be removed. A parent or guardian can ask for that without having the account.
Where it is processed, and by whom
SendOff itself is run from the United States, in Texas. Two companies process data on its behalf, and no others:
| Cloudflare, Inc. (US) | runs the worker that answers requests, and holds accounts, profiles, access lists, tokens, share links and feedback. Also serves traffic from whichever of its locations is nearest the person asking, worldwide. |
| GitHub, Inc. (US, a Microsoft company) | holds races and logged splits as files in a public repository, and serves the pages people watch. |
Both are United States companies operating globally, so your data is stored in the United States and may pass through or be cached in other countries as it is served. Nobody else is given it. There is no advertising network, no analytics provider and no data broker in this list because there are none.
Changes
This will change, and most of all when the storage move above is finished. The date at the top says when it last did.