·Privacy

Privacy Policy

Last updated 9 September 2026

The short version

SendOff stores what you type into it: your email address, your race, and what your crew logs. There is no analytics, no advertising, no third-party trackers, no cookies, and nothing is sold to anybody.

There is one thing worth knowing before you put a race in, and it is under the repository is public.

What is collected

Your account

Your email address, and your password stored only as a salted hash. The password itself is never stored and cannot be recovered, only reset. Also your role and your plan.

Your profile, if you fill one in

A display name, fueling goals, hour bands, and the notes you want a crew to have.

A race

Its name, location, start time, activity, course (segments, aid stations, and the elevation from any GPX file you upload), cutoffs, and the racers' names and bib numbers.

What the crew logs

Arrival and departure times at each aid station, calories, fluid, sodium, whether those were measured or estimated, gear taken or dropped, free text notes, and anything typed into the issues and meds fields. Those last two are worth calling out on their own: a crew uses them for how a racer is doing and what they have taken, so they can hold health information about a named person. They are stored exactly like the rest of the race, which on a public race means publicly. Also which account logged each one.

Access

Which email addresses may see or edit each race, and which account each racer is linked to.

Feedback you send

What you wrote, and, gathered automatically so a report is useful: the page you were on, the race, the version of the app, whether the device was offline, how many unsent writes were waiting, and your browser's user agent. Your email address if you were signed in, or one you typed if you were not.

If you ask for an invite or a password reset

Your name, your email address, and anything you wrote in the request.

Technical

Your IP address is used to rate limit feedback and invite requests. It is held as a counter against your address for one hour and then it is gone. SendOff keeps no other logs of its own. Cloudflare and GitHub keep theirs.

Where it is stored

Cloudflare Workers KVaccounts, profiles, access lists, invite and reset tokens, share links, feedback
Cloudflare D1races and logged splits
GitHubraces and logged splits, as files in a repository
Your own browseryour session, a copy of the races you have opened so they still work with no signal, and any feedback waiting to send

The repository is public

SendOff's race data is currently kept in a public GitHub repository, which is also what serves the pages people watch. That has consequences which are not obvious from using the app:

Unlisted does not mean sealed, encrypted or access controlled. An unlisted race is kept off the public list and out of search engines, and its address carries a random suffix so it cannot be guessed, but the file behind it sits on a public host and can be read by anybody who has that address. Do not put anything in a race that you would mind a stranger reading. SendOff called this setting private until 9 September 2026, and stopped because unlisted is what it actually does.

Moving off this is in progress and is the next piece of work after the September 2026 race. Until it is finished, treat a race page as something a stranger could read.

Who else sees something

Cloudflare
Hosts the service, stores the data, and routes the email. They can see everything SendOff holds.
GitHub
Hosts the repository and serves the public pages.
Google Fonts
Serves the typefaces. Loading any SendOff page sends your IP address and browser details to Google.
Esri
Serves the map tiles behind a course map. Opening a race page that draws a map sends your IP address and the map coordinates to Esri, which reveals roughly where the race is.

That is the whole list. No analytics, no advertising networks, no social pixels, no session recording.

What is not done

No cookies are set. Your sign-in session lives in your browser's local storage rather than a cookie, which is why there is no cookie banner: there is nothing to consent to. Nothing is sold, rented, or shared for advertising. There is no profiling and no automated decision-making.

Sensitive information

No location is ever taken from your device. SendOff never asks your browser for your position and never reads it. Nothing in the app calls the browser's location interface at all.

The only coordinates in SendOff are in a course file that whoever set the race up chose to upload, and that file describes a route rather than a person. It is worth understanding what that still implies: a course, a start time and a logged arrival together say roughly where a named racer was, and on a public race that is readable by anybody.

The other sensitive thing SendOff can hold is health information, and only because a crew typed it. The notes, issues and meds fields are free text, and crews use them for how a racer is doing and what they have taken. SendOff does not require any of it, does not ask for it, and cannot tell whether a note is about a shoe or a stomach. It is stored like the rest of the race and it is readable by everyone the race is readable by.

None of it is sold, shared for advertising, or used to build a profile of anybody. If you would rather it were not in a public file, keep it out of the fields, or wait for the storage move described above.

On your device

Signing in stores a session that lasts seven days. Opening a race stores a copy of it so the page still works when the signal goes, which for a crew at an aid station is the point. Feedback written with no signal is held until it can be sent. Signing out deletes all of it, and so does clearing your browser's data for the site.

How long things are kept

Sign-in sessions7 days
Password reset links2 days
Account invites14 days
Share links30 days by default
Invite and access requests90 days
Feedback180 days
Rate limit counters1 hour
Races and logged datauntil deleted

Your rights: getting a copy, a correction, or a deletion

Write to info@sendoff.run. Your account, your profile and your races can be deleted on request.

You can ask to see what is held about you, to get a copy of it in a portable form, to have it corrected, or to have it deleted. Ask at info@sendoff.run from the address on the account, or say which account you mean. Every request is answered within 45 days. If it needs longer you will be told why inside those 45 days, and the extension will not be more than a further 45.

If a request is refused you will be told why, and you can appeal by replying to that answer. An appeal is decided within 60 days. If the appeal is refused as well, you will be told how to complain to the Texas Attorney General.

Anything already published to the public repository is harder, and it is worth being straight about that. Removing it from the current files is done within 30 days of the request. Removing it from the repository's history means rewriting that history, which cannot be done for one person on demand because it rewrites the whole repository. Within the same 45 days you will be told which of the two your request needs and, where it needs the second, the date it is expected by. It will not be left at "eventually".

Children

SendOff is not aimed at children and accounts are not knowingly given to anybody under 13. No age is asked for at sign up, because sign up is invite only and every invite is sent by hand.

A racer in a race can be a child, because a child can run a race and a crew logs for them. What is held then is a name, a bib number and the splits, entered by an adult on the crew rather than by the child, and there is no account for that child.

If you believe a child under 13 has an account, or that something about a child is in a race and should not be, write to info@sendoff.run and it will be removed. A parent or guardian can ask for that without having the account.

Where it is processed, and by whom

SendOff itself is run from the United States, in Texas. Two companies process data on its behalf, and no others:

Cloudflare, Inc. (US)runs the worker that answers requests, and holds accounts, profiles, access lists, tokens, share links and feedback. Also serves traffic from whichever of its locations is nearest the person asking, worldwide.
GitHub, Inc. (US, a Microsoft company)holds races and logged splits as files in a public repository, and serves the pages people watch.

Both are United States companies operating globally, so your data is stored in the United States and may pass through or be cached in other countries as it is served. Nobody else is given it. There is no advertising network, no analytics provider and no data broker in this list because there are none.

Changes

This will change, and most of all when the storage move above is finished. The date at the top says when it last did.

Contact

info@sendoff.run