Aquaduct Data Strategies LLC

Privacy Policy

Version: 1.0  ·  Effective: 2026-07-25  ·  Last Updated: 2026-07-25

Notice: This is the master Privacy Policy for Aquaduct Data Strategies LLC and its Runner’s Review product. Aquaduct Cascade is an internal data-feed service operated by the Company that supplies race data to Runner’s Review; it is not a product that users interact with directly. Product-specific data practices are detailed in the applicable product annex referenced in Section 13. Where a product annex and this master policy differ, the product annex controls for that product.

1. Introduction and Scope

Aquaduct Data Strategies LLC (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our products and services.

This Policy applies to the products operated by the Company and the internal services that support them:

This Policy does not apply to third-party websites, applications, or services that may be linked from our products. We encourage you to review the privacy policies of those third parties before using them.

By using our products, you acknowledge you have read and understood this Privacy Policy.

2. Data Controller Identity

The data controller responsible for your personal information is:

AttributeValue
Legal NameAquaduct Data Strategies LLC
EIN99-1207154
Address6650 Rivers Ave STE 100, Charleston, SC 29406
Emaillegal@aquaductdata.com
Phone(803) 670-0335

For product-specific data practices, see the relevant product annex (Section 13).

3. Categories of Personal Information We Collect

We collect personal information in the following categories. The specific types collected depend on which product(s) you use — see your product’s annex for details.

3.1 Identifiers

3.2 Precise Geolocation Data

3.3 User-Generated Content

3.4 Internet or Network Activity

3.5 Health and Activity Data

3.6 Information Collected Automatically

We rely on the following legal bases to process your personal information:

BasisDescriptionApplicable When
Contract performanceProcessing necessary to provide the service you requestedAccount creation, service delivery, app functionality
Legitimate interestsProcessing for our reasonable business interests that do not override your rightsSecurity, fraud prevention, product improvement, analytics
ConsentWhere you have provided explicit consentLocation access, optional analytics, marketing communications
Legal obligationProcessing required to comply with applicable lawTax records, legal holds, regulatory compliance

Note: These bases apply to our current United States operations. This policy does not cover EU/EEA (GDPR) processing; we do not target or serve EU/EEA residents.

5. How We Use Your Information

We use personal information we collect to:

  1. Provide and operate our services — Account creation, authentication, feature delivery, customer support
  2. Improve our products — Analyze usage patterns, diagnose errors, test new features, improve search relevance
  3. Ensure security and prevent fraud — Authenticate users, detect abuse, enforce our Terms of Service
  4. Communicate with you — Send account-related notifications, respond to support requests, provide service updates
  5. Comply with legal obligations — Respond to lawful requests from government authorities, maintain required records
  6. Enable search and discovery — Use precise location data to return relevant nearby results (Runner’s Review)

We do not sell your personal information to third parties for their own marketing purposes.

6. Data Sharing and Third Parties

We share personal information with third-party service providers only to the extent necessary to operate our services. We do not sell or rent personal information to third parties for their own marketing.

6.1 Third-Party Service Providers

The following third parties may receive or process your personal information on our behalf:

ProviderServiceData SharedProducts
Google Cloud Platform (GCP)Cloud infrastructure, database hosting (Cloud SQL), object storage (GCS), machine learning (Cloud Vision)Account data, photos, activity logsRunner’s Review
Google FirebaseApp security (Firebase App Check), push notificationsApp Check tokens, device identifiersRunner’s Review
Apple Inc.Sign in with Apple, App Store distribution, TestFlightApple ID, email (if shared by user)Runner’s Review

We may disclose your personal information if required by law, court order, or government authority, or if we believe disclosure is necessary to: (a) comply with a legal obligation; (b) protect the rights or safety of the Company, our users, or the public; (c) detect, prevent, or address fraud or security issues.

6.3 Business Transfers

If the Company is involved in a merger, acquisition, asset sale, or reorganization, your personal information may be transferred as part of that transaction. We will provide notice (per Section 12) before your information is transferred and becomes subject to a different privacy policy.

6.4 What We Do Not Do

7. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer period is required by law.

Data CategoryRetention PeriodNotes
Account data (active users)Duration of account + 90 days after deletion requestExtended if required by legal hold
Transaction and billing records7 yearsRequired for tax and accounting compliance
Activity logs and app usage data12 months rollingAggregated/anonymized after retention period
Photos and user-uploaded contentUntil user deletes or account is closedStored in GCS; deletion is irreversible
Precise location dataSession only — not persistently storedRunner’s Review proximity search
Security and fraud prevention logs24 monthsRequired for fraud detection efficacy
Legal hold dataAs required by legal obligationOverrides normal retention schedule

To request deletion of your data, see Section 9 (User Rights).

8. Security Practices

We implement reasonable administrative, technical, and physical safeguards to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our practices include:

No security system is impenetrable. We cannot guarantee the absolute security of data transmitted to or stored by our services. If you believe your account or data has been compromised, contact us immediately at legal@aquaductdata.com.

9. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

9.1 Right to Access

You may request a copy of the personal information we hold about you. We will respond within 45 days (CCPA) of a verifiable request.

9.2 Right to Correction

You may request that we correct inaccurate or incomplete personal information. Some corrections can be made directly within the product (account settings).

9.3 Right to Deletion

You may request deletion of your personal information. We will honor deletion requests subject to exceptions for legal obligations, fraud prevention, and completing transactions.

9.4 Right to Portability

You may request a machine-readable export of your personal information in cases where processing is based on your consent or performance of a contract.

9.5 Right to Opt Out of Sale/Sharing

We do not sell personal information. If our practices change, you will be provided with an opt-out mechanism before any such sale begins.

9.6 Right to Non-Discrimination

We will not discriminate against you for exercising any rights under this Policy or applicable law. You will not receive different prices, service tiers, or reduced quality as a result of exercising your privacy rights.

9.7 How to Submit a Rights Request

To exercise your rights, contact us at:

We aim to respond to all verifiable requests within 30 days. CCPA requests receive a response within 45 days as required by law (see Section 10.4 for CCPA-specific timelines). We may require verification of your identity before processing a request to protect against unauthorized access.

10. California Residents (CCPA / CPRA Disclosures)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.

10.1 Categories Collected

In the preceding 12 months, we have collected the following categories of personal information (as defined by Cal. Civ. Code § 1798.140):

CCPA CategoryCollectedExamples
IdentifiersYesName, email, user ID, Apple ID, device ID
Personal information under Cal. Civ. Code § 1798.80YesName, email address
Characteristics of protected classificationsNo
Commercial informationYes (Runner’s Review)Subscription and in-app purchase records (Compete / Director tier)
Biometric informationNo
Internet or other electronic network activityYesApp usage logs and feature interaction data
Geolocation dataYes (Runner’s Review)Precise GPS for proximity search
Sensory data (audio, video, etc.)Yes (partial)Photos uploaded by users (Runner’s Review)
Professional or employment informationNo
Education informationNo
Inferences drawn from the aboveNo
Sensitive personal informationYes (partial)Precise geolocation (Runner’s Review); account credentials

10.2 Purposes for Collection

We collect personal information for the business and commercial purposes described in Section 5 of this Policy.

10.3 Categories of Third Parties to Whom We Disclose

We disclose personal information to third-party service providers as described in Section 6.1. We do not sell or share personal information for cross-context behavioral advertising as defined by the CPRA.

10.4 Your CCPA Rights

As a California resident, you have the right to:

To submit a CCPA rights request: Email legal@aquaductdata.com with the subject line “CCPA Rights Request.” We respond to verifiable requests within 45 days. We may request information to verify your identity.

Authorized Agents: California residents may use an authorized agent to submit rights requests on their behalf. We may require written authorization or power of attorney before processing a request submitted by an agent.

11. Children’s Privacy

Our products and services are not directed to children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13.

If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly. If you believe we may have collected information from a child under 13, please contact us at legal@aquaductdata.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, products, or applicable law. We will notify you of material changes by:

Your continued use of our products after the effective date of an updated Policy constitutes your acceptance of the changes. If you do not agree with the changes, you should stop using the affected product and contact us to delete your account.

Material change means a change that significantly affects how we collect, use, or share your personal information, or that meaningfully reduces your rights.

13. Product-Specific Annexes

For full disclosure of data practices specific to each product, please review the applicable annex:

ProductAnnexKey Additions
Runner’s Reviewlegal.aquaductdata.com/annexes/runners-reviewApple Sign-In, precise location, GCS photos, Firebase App Check, Google Cloud Vision
Aquaduct Cascadelegal.aquaductdata.com/annexes/aquaduct-cascadeInternal data-feed service supplying race data to Runner’s Review; no direct end users

14. Contact for Privacy Requests

For privacy-related questions, rights requests, or to report a concern:

Contact TypeDetails
Privacy Emaillegal@aquaductdata.com (subject: “Privacy Request”)
Mailing AddressAquaduct Data Strategies LLC, 6650 Rivers Ave STE 100, Charleston, SC 29406
DMCA TakedownsSee legal.aquaductdata.com/dmca
Cookie PolicySee Cookie Policy

We aim to respond to all privacy requests within 30 days. CCPA verifiable requests receive a response within 45 days as required by law (with a possible 45-day extension if we notify you of the extension).

15. Version and Effective Date

AttributeValue
Version1.0
Effective Date2026-07-25
Last Updated2026-07-25
StatusIn effect
ScopeUnited States only. EU/EEA (GDPR) provisions are not included and do not apply.

Document History

DateVersionChanges
2026-03-211.0-draftInitial draft
2026-07-121.0Finalized for launch. Removed the inactive EU/EEA GDPR scaffold (no attorney review; US-only operations) and the private issue link.
2026-07-251.0Brought into force: effective date set and status changed from draft to in effect. No change to data practices, disclosures, or terms.

This Privacy Policy was prepared by Aquaduct Data Strategies LLC. If you have legal questions, consult a qualified attorney licensed in South Carolina.

© 2026 Aquaduct Data Strategies LLC. All rights reserved.