Privacy Policy
Version: 1.0 · Effective: 2026-07-25 · Last Updated: 2026-07-25
Notice: This is the master Privacy Policy for Aquaduct Data Strategies LLC and its Runner’s Review product. Aquaduct Cascade is an internal data-feed service operated by the Company that supplies race data to Runner’s Review; it is not a product that users interact with directly. Product-specific data practices are detailed in the applicable product annex referenced in Section 13. Where a product annex and this master policy differ, the product annex controls for that product.
1. Introduction and Scope
Aquaduct Data Strategies LLC (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our products and services.
This Policy applies to the products operated by the Company and the internal services that support them:
- Runner’s Review — iOS race discovery and review application
- Aquaduct Cascade — Internal data-feed service that supplies race data to Runner’s Review (not a user-facing product)
This Policy does not apply to third-party websites, applications, or services that may be linked from our products. We encourage you to review the privacy policies of those third parties before using them.
By using our products, you acknowledge you have read and understood this Privacy Policy.
2. Data Controller Identity
The data controller responsible for your personal information is:
| Attribute | Value |
|---|---|
| Legal Name | Aquaduct Data Strategies LLC |
| EIN | 99-1207154 |
| Address | 6650 Rivers Ave STE 100, Charleston, SC 29406 |
| legal@aquaductdata.com | |
| Phone | (803) 670-0335 |
For product-specific data practices, see the relevant product annex (Section 13).
3. Categories of Personal Information We Collect
We collect personal information in the following categories. The specific types collected depend on which product(s) you use — see your product’s annex for details.
3.1 Identifiers
- Name, email address, username, or other account identifier
- Apple ID or other social sign-in identifier (if you use Sign in with Apple)
- User-generated profile information (profile image, preferences)
- Device identifiers (for app functionality and security)
3.2 Precise Geolocation Data
- Precise GPS coordinates (Runner’s Review only, when location permission is granted)
- Location is used for proximity-based search functionality and is not persistently stored or tracked beyond the active session
3.3 User-Generated Content
- Reviews, ratings, and text submissions
- Photos and images you upload (stored in Google Cloud Storage)
- Feedback and survey responses
3.4 Internet or Network Activity
- App usage logs and feature interaction data
- Error and diagnostic data
3.5 Health and Activity Data
- Running activity logs (Runner’s Review only) — distance, pace, route information you voluntarily enter or log
- Apple HealthKit data is not collected. Runner’s Review does not request HealthKit permissions and does not access health data from Apple Health.
3.6 Information Collected Automatically
- IP address and general network location (not GPS)
- Browser type and operating system
- Session timestamps and activity logs
- Firebase App Check tokens (for security verification — Runner’s Review)
4. Legal Basis for Processing
We rely on the following legal bases to process your personal information:
| Basis | Description | Applicable When |
|---|---|---|
| Contract performance | Processing necessary to provide the service you requested | Account creation, service delivery, app functionality |
| Legitimate interests | Processing for our reasonable business interests that do not override your rights | Security, fraud prevention, product improvement, analytics |
| Consent | Where you have provided explicit consent | Location access, optional analytics, marketing communications |
| Legal obligation | Processing required to comply with applicable law | Tax records, legal holds, regulatory compliance |
Note: These bases apply to our current United States operations. This policy does not cover EU/EEA (GDPR) processing; we do not target or serve EU/EEA residents.
5. How We Use Your Information
We use personal information we collect to:
- Provide and operate our services — Account creation, authentication, feature delivery, customer support
- Improve our products — Analyze usage patterns, diagnose errors, test new features, improve search relevance
- Ensure security and prevent fraud — Authenticate users, detect abuse, enforce our Terms of Service
- Communicate with you — Send account-related notifications, respond to support requests, provide service updates
- Comply with legal obligations — Respond to lawful requests from government authorities, maintain required records
- Enable search and discovery — Use precise location data to return relevant nearby results (Runner’s Review)
We do not sell your personal information to third parties for their own marketing purposes.
6. Data Sharing and Third Parties
We share personal information with third-party service providers only to the extent necessary to operate our services. We do not sell or rent personal information to third parties for their own marketing.
6.1 Third-Party Service Providers
The following third parties may receive or process your personal information on our behalf:
| Provider | Service | Data Shared | Products |
|---|---|---|---|
| Google Cloud Platform (GCP) | Cloud infrastructure, database hosting (Cloud SQL), object storage (GCS), machine learning (Cloud Vision) | Account data, photos, activity logs | Runner’s Review |
| Google Firebase | App security (Firebase App Check), push notifications | App Check tokens, device identifiers | Runner’s Review |
| Apple Inc. | Sign in with Apple, App Store distribution, TestFlight | Apple ID, email (if shared by user) | Runner’s Review |
6.2 Legal Disclosures
We may disclose your personal information if required by law, court order, or government authority, or if we believe disclosure is necessary to: (a) comply with a legal obligation; (b) protect the rights or safety of the Company, our users, or the public; (c) detect, prevent, or address fraud or security issues.
6.3 Business Transfers
If the Company is involved in a merger, acquisition, asset sale, or reorganization, your personal information may be transferred as part of that transaction. We will provide notice (per Section 12) before your information is transferred and becomes subject to a different privacy policy.
6.4 What We Do Not Do
- We do not sell personal information as defined under the CCPA or similar state laws
- We do not share personal information with third parties for their own direct marketing purposes without your consent
- We do not share Runner’s Review location data with advertising networks
7. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer period is required by law.
| Data Category | Retention Period | Notes |
|---|---|---|
| Account data (active users) | Duration of account + 90 days after deletion request | Extended if required by legal hold |
| Transaction and billing records | 7 years | Required for tax and accounting compliance |
| Activity logs and app usage data | 12 months rolling | Aggregated/anonymized after retention period |
| Photos and user-uploaded content | Until user deletes or account is closed | Stored in GCS; deletion is irreversible |
| Precise location data | Session only — not persistently stored | Runner’s Review proximity search |
| Security and fraud prevention logs | 24 months | Required for fraud detection efficacy |
| Legal hold data | As required by legal obligation | Overrides normal retention schedule |
To request deletion of your data, see Section 9 (User Rights).
8. Security Practices
We implement reasonable administrative, technical, and physical safeguards to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our practices include:
- Encryption in transit: All connections to our services use TLS/HTTPS
- Encryption at rest: Sensitive data is encrypted at the database and storage layer (GCS, Cloud SQL)
- Access controls: Access to personal data is restricted to personnel who need it to operate the service; authentication is enforced via Firebase App Check (Runner’s Review)
- Incident response: We maintain procedures for identifying and responding to data security incidents
- Third-party security: We select service providers with their own documented security programs (GCP is SOC 2 certified)
No security system is impenetrable. We cannot guarantee the absolute security of data transmitted to or stored by our services. If you believe your account or data has been compromised, contact us immediately at legal@aquaductdata.com.
9. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
9.1 Right to Access
You may request a copy of the personal information we hold about you. We will respond within 45 days (CCPA) of a verifiable request.
9.2 Right to Correction
You may request that we correct inaccurate or incomplete personal information. Some corrections can be made directly within the product (account settings).
9.3 Right to Deletion
You may request deletion of your personal information. We will honor deletion requests subject to exceptions for legal obligations, fraud prevention, and completing transactions.
9.4 Right to Portability
You may request a machine-readable export of your personal information in cases where processing is based on your consent or performance of a contract.
9.5 Right to Opt Out of Sale/Sharing
We do not sell personal information. If our practices change, you will be provided with an opt-out mechanism before any such sale begins.
9.6 Right to Non-Discrimination
We will not discriminate against you for exercising any rights under this Policy or applicable law. You will not receive different prices, service tiers, or reduced quality as a result of exercising your privacy rights.
9.7 How to Submit a Rights Request
To exercise your rights, contact us at:
- Email: legal@aquaductdata.com (subject: “Privacy Rights Request”)
- Mail: Aquaduct Data Strategies LLC, 6650 Rivers Ave STE 100, Charleston, SC 29406
We aim to respond to all verifiable requests within 30 days. CCPA requests receive a response within 45 days as required by law (see Section 10.4 for CCPA-specific timelines). We may require verification of your identity before processing a request to protect against unauthorized access.
10. California Residents (CCPA / CPRA Disclosures)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.
10.1 Categories Collected
In the preceding 12 months, we have collected the following categories of personal information (as defined by Cal. Civ. Code § 1798.140):
| CCPA Category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, user ID, Apple ID, device ID |
| Personal information under Cal. Civ. Code § 1798.80 | Yes | Name, email address |
| Characteristics of protected classifications | No | — |
| Commercial information | Yes (Runner’s Review) | Subscription and in-app purchase records (Compete / Director tier) |
| Biometric information | No | — |
| Internet or other electronic network activity | Yes | App usage logs and feature interaction data |
| Geolocation data | Yes (Runner’s Review) | Precise GPS for proximity search |
| Sensory data (audio, video, etc.) | Yes (partial) | Photos uploaded by users (Runner’s Review) |
| Professional or employment information | No | — |
| Education information | No | — |
| Inferences drawn from the above | No | — |
| Sensitive personal information | Yes (partial) | Precise geolocation (Runner’s Review); account credentials |
10.2 Purposes for Collection
We collect personal information for the business and commercial purposes described in Section 5 of this Policy.
10.3 Categories of Third Parties to Whom We Disclose
We disclose personal information to third-party service providers as described in Section 6.1. We do not sell or share personal information for cross-context behavioral advertising as defined by the CPRA.
10.4 Your CCPA Rights
As a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell
- Delete personal information we have collected about you (subject to exceptions)
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information — note: we do not currently sell personal information
- Limit use of your sensitive personal information — we do not use sensitive PI beyond what is necessary to provide our services
- Non-discrimination for exercising these rights
To submit a CCPA rights request: Email legal@aquaductdata.com with the subject line “CCPA Rights Request.” We respond to verifiable requests within 45 days. We may request information to verify your identity.
Authorized Agents: California residents may use an authorized agent to submit rights requests on their behalf. We may require written authorization or power of attorney before processing a request submitted by an agent.
11. Children’s Privacy
Our products and services are not directed to children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13.
If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly. If you believe we may have collected information from a child under 13, please contact us at legal@aquaductdata.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, products, or applicable law. We will notify you of material changes by:
- Updating the “Last Updated” date at the top of this document
- Posting a notice in the applicable product (in-app or on-site notification)
- Sending an email notification to registered users when we have your email address
Your continued use of our products after the effective date of an updated Policy constitutes your acceptance of the changes. If you do not agree with the changes, you should stop using the affected product and contact us to delete your account.
Material change means a change that significantly affects how we collect, use, or share your personal information, or that meaningfully reduces your rights.
13. Product-Specific Annexes
For full disclosure of data practices specific to each product, please review the applicable annex:
| Product | Annex | Key Additions |
|---|---|---|
| Runner’s Review | legal.aquaductdata.com/annexes/runners-review | Apple Sign-In, precise location, GCS photos, Firebase App Check, Google Cloud Vision |
| Aquaduct Cascade | legal.aquaductdata.com/annexes/aquaduct-cascade | Internal data-feed service supplying race data to Runner’s Review; no direct end users |
14. Contact for Privacy Requests
For privacy-related questions, rights requests, or to report a concern:
| Contact Type | Details |
|---|---|
| Privacy Email | legal@aquaductdata.com (subject: “Privacy Request”) |
| Mailing Address | Aquaduct Data Strategies LLC, 6650 Rivers Ave STE 100, Charleston, SC 29406 |
| DMCA Takedowns | See legal.aquaductdata.com/dmca |
| Cookie Policy | See Cookie Policy |
We aim to respond to all privacy requests within 30 days. CCPA verifiable requests receive a response within 45 days as required by law (with a possible 45-day extension if we notify you of the extension).
15. Version and Effective Date
| Attribute | Value |
|---|---|
| Version | 1.0 |
| Effective Date | 2026-07-25 |
| Last Updated | 2026-07-25 |
| Status | In effect |
| Scope | United States only. EU/EEA (GDPR) provisions are not included and do not apply. |
Document History
| Date | Version | Changes |
|---|---|---|
| 2026-03-21 | 1.0-draft | Initial draft |
| 2026-07-12 | 1.0 | Finalized for launch. Removed the inactive EU/EEA GDPR scaffold (no attorney review; US-only operations) and the private issue link. |
| 2026-07-25 | 1.0 | Brought into force: effective date set and status changed from draft to in effect. No change to data practices, disclosures, or terms. |
This Privacy Policy was prepared by Aquaduct Data Strategies LLC. If you have legal questions, consult a qualified attorney licensed in South Carolina.
© 2026 Aquaduct Data Strategies LLC. All rights reserved.