Last updated October 27, 2025
42cal Race Directory Privacy Policy
How 42cal collects, protects, and uses your personal data in the race directory.
Privacy policy contents
42cal ("we," "us," or "our") operates a race directory at 42cal.com that helps runners discover and bookmark marathon races worldwide. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the 42cal race directory.
We process personal data in accordance with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA). When you use our services, you agree to the practices described below.
Note: This privacy policy applies specifically to the 42cal race directory at 42cal.com. For the MarathonOS training app privacy policy, please visit /privacy-marathonos.
The 42cal race directory collects the following personal data:
- Account information: Email address, name, and authentication identifiers when you create an account via Clerk authentication.
- Bookmarked races: Race IDs and metadata for races you bookmark or save to your dashboard.
- Browsing activity: Pages viewed, search queries, and race filters you apply (stored via PostHog analytics with IP anonymization).
- Technical data: Device type, browser, IP address (anonymized for analytics), and session timestamps.
- Support communications: Emails or support tickets you send to us.
We do NOT collect:
- Fitness or health data
- Payment or credit card information (we do not process payments for the race directory)
- Location data beyond IP-based geolocation for analytics
- Workout or training data
We use your personal data to:
- Create and manage your account on the 42cal race directory
- Store and display your bookmarked races on your dashboard
- Personalize race recommendations based on your preferences
- Send transactional emails (account confirmation, password resets)
- Improve the race directory with analytics (via PostHog with IP anonymization)
- Respond to support requests and technical issues
- Comply with legal obligations
We do not sell your personal data or use it for targeted advertising. We do not share your data with third parties except as described in the "Data Sharing" section below.
The 42cal race directory uses Supabase (PostgreSQL) as our primary data store with infrastructure hosted in the United States. We apply the following safeguards:
- Encryption: All data is encrypted in transit using HTTPS/TLS and at rest via cloud provider-managed keys.
- Row-Level Security: Supabase Row-Level Security ensures each user can access only their own bookmarked races.
- Authentication: We use Clerk for secure authentication with industry-standard security practices.
- No data resale: We do not transfer personal data to data brokers or advertisers.
Despite our safeguards, no system is completely secure. We maintain an incident response plan and will notify affected users and regulators of data breaches as required by law.
We only share your data when necessary to operate the 42cal race directory or when required by law:
- Service providers: Infrastructure vendors such as Supabase, Vercel, and Clerk process data on our behalf under data processing agreements and cannot use it for their own purposes.
- Analytics: PostHog collects anonymized usage data with IP truncation to help us improve the race directory.
- Legal compliance: We may disclose data if required by law, subpoena, or to protect the rights, property, or safety of 42cal users.
We never sell personal data, rent contact lists, or share your bookmarked races with third parties.
Depending on your location, you have the following rights over your personal data:
- Access: Request a copy of your data at any time. We provide exports in JSON or CSV within 30 days.
- Portability: Transfer your bookmarked races to another service by requesting a structured export.
- Correction: Update your email or profile details in your account settings.
- Deletion: Permanently delete your account and all associated data. We erase account data within 30 days of a verified request.
- Opt-out (CCPA): California residents can opt out of any data sharing that qualifies as a "sale" or "sharing." 42cal does not sell personal information, but you may still submit a request via support@42cal.com.
- Complaint: EU users can lodge a complaint with their local supervisory authority if they believe our processing violates GDPR.
To exercise any of these rights, email support@42cal.com with the subject "Privacy Request - Race Directory." We may need to verify your identity before fulfilling requests.
The 42cal race directory relies on trusted vendors to deliver the platform:
- Clerk: Provides authentication and user management services with SOC 2 Type II compliance.
- Supabase: Provides SOC 2 Type II compliant database hosting with row-level security and audited access logs.
- Vercel: Hosts the 42cal race directory within ISO 27001 certified infrastructure.
- PostHog: Supplies privacy-first product analytics with IP anonymization and respect for Do Not Track signals.
We retain data only as long as needed to provide the race directory:
- Active accounts: Bookmarked races and profile data are retained indefinitely while your account remains active.
- Deleted accounts: All personal data is permanently erased from our production systems within 30 days of deletion request confirmation.
- Inactive accounts (no login for 3+ years): We will email you before deleting inactive account data.
- Backups: Encrypted database backups are retained for up to 90 days for disaster recovery, then securely purged. Deleted data may remain in backups during this period.
42cal is based in the United States. If you access the race directory from the European Economic Area (EEA), United Kingdom, or other regions with laws governing data collection, we transfer personal data to the U.S. under standard contractual clauses (SCCs) and other appropriate safeguards.
The 42cal race directory is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If we learn that a child has provided us with personal data, we will delete it within 30 days. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@42cal.com.
We may update this Privacy Policy to reflect changes in our products, legal requirements, or industry practices. When we make material changes, we will notify you via email and update the "Last updated" date at the top of this page. Continued use of the 42cal race directory after any changes constitutes acceptance of the revised policy.
For questions, requests, or concerns about this Privacy Policy, reach out to us:
- Email: support@42cal.com
- Website: https://www.42cal.com
