Privacy Policy
1. Who is responsible
Sparta Enterprise LTD (Company No. 514437144, registered address: Mivtsa Harel 14, Ariel, Israel — operator of PeakIQ and the Race Prep product at https://hyrox.peakiq.ai) is the controller of the personal data described here. Contact for anything in this policy, including exercising your rights: support@peakiq.ai.
Two other parties have their own responsibilities: FastSpring (Bright Market, LLC), our payment reseller and Merchant of Record, processes your payment as a controller of the checkout transaction under its own privacy policy (we never receive your card number). Garmin processes your data in Garmin Connect under Garmin's own privacy policy; we receive data from Garmin only after you authorize the connection on Garmin's consent screen.
2. What we collect, from where, and why
| Category (what) | Source | Used for (why) | Legal basis (GDPR/UK GDPR) |
|---|---|---|---|
| Predictor inputs: race, division, races completed, training days, recent 5K time or pace, optional display name | You (free predictor) | Computing your predicted finish range and Race Card | Legitimate interests (providing the tool you asked to use) |
| Funnel usage events: pages/steps viewed, device answer, goal adjustments, an anonymous session ID | Your browser (first-party only) | Understanding and fixing the product funnel; measuring which advertising creative a purchase came from | Legitimate interests (product analytics and fraud-resistant attribution) |
| Attribution: creative ID (?c=) and UTM parameters, stored with session and, on purchase, the order | Ad link you clicked | Knowing which ad led to a purchase | Legitimate interests |
| Email address (prediction email, waitlists, exit-poll opt-in) | You | Sending exactly what you asked for | Consent (withdraw any time via support) |
| Order and payment metadata: FastSpring order ID/reference, product, amount, currency, status (paid/pending/failed/refunded/chargeback), purchase email, live/test flag | FastSpring webhooks | Creating your entitlement, receipts, refunds, fraud and reconciliation. We never receive card numbers. | Contract; legal obligation (financial records) |
| Account data: email, hashed credentials/sign-in links, claim tokens (stored hashed), session tokens | You; our auth provider (Supabase) | Sign-in, binding your purchase to your account, security | Contract |
| Athlete intake: race and date, division, race history, goal time, running performance, weekly availability and training days, equipment access, station experience, constraints, pain/niggle flags, consent record | You | Building and adapting your training plan; making it more conservative when you flag pain | Contract; for pain/health-related fields, explicit consent (Art. 9(2)(a)) collected in-product |
| Garmin connection data: your Garmin user ID, OAuth tokens (server-side only), device name, sync-verification status | Garmin, after your authorization | Delivering workouts to your watch and receiving your activities | Contract; the connection itself happens only on your action |
| Training and activity data: pushed workouts (names, steps, targets), completed activities (type, times, duration, distance, laps, heart-rate and pace samples, device model), derived per-lap pace/HR, station logs (loads, reps), RPE | Your Garmin device via Garmin's push API; you (manual logs) | Matching completed sessions to your plan, weekly adaptation, updating your prediction, race review | Explicit consent for health-related data (heart rate, recovery-relevant metrics, pain flags), collected before Garmin connection; contract for the rest |
| Support communications | You (email) | Helping you; quality and dispute records | Legitimate interests / contract |
| Operational logs: webhook receipts, delivery/audit logs, error and alert records | Our systems | Reliability, security, detecting silent failures, evidencing what happened | Legitimate interests (security and integrity) |
We collect no precise location, no contacts, no photos. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
3. Automated processing
Predictions, training plans, and weekly adaptations are computed by deterministic, versioned rules (documented decision logic — not a black-box model, and no LLM makes training, safety, or account decisions). These are product features you purchase, you can deviate from any session, and a human (support) reviews anything on request. We do not make automated decisions with legal or similarly significant effects about you.
4. Who processes data for us
| Provider | Role | What they handle |
|---|---|---|
| Supabase | Database & authentication platform (processor) | All product data listed above; sign-in emails for magic links |
| Vercel | Hosting/serverless platform (processor) | Traffic to the site and APIs (incl. IP addresses in transient logs) |
| Postmark (ActiveCampaign) | Transactional email (processor) | Email address and email contents we send you |
| Garmin | Independent service you connect | Your Garmin account and device data, under Garmin's policy |
| FastSpring | Merchant of Record (independent controller of checkout) | Payment details, tax location, order data. FastSpring's checkout pages set their own cookies/analytics under FastSpring's policy. |
Advertising platforms (Meta): if you arrive from an ad, the platform knows you clicked under its own policy. On our pages, advertising measurement is strictly opt-in: nothing loads until you choose "Allow" on the measurement banner. If — and only if — you allow it, we (a) load the Meta Pixel (Meta Platforms Ireland Ltd/Meta Platforms Inc., an independent controller under Meta's privacy policy), which sets Meta cookies and reports page view, lead, checkout-start and purchase events, and (b) on a completed purchase, send a matching server-side event via the Meta Conversions API containing a hashed (SHA-256) form of your email, the order value, and an order identifier used only to de-duplicate the browser event. If you decline (or make no choice), no pixel loads and no server event is sent — the purchase itself is unaffected. You can clear your choice by clearing site data for this domain. Meta may process this data outside the EEA under its own safeguards.
5. International transfers
Our providers process data in the United States and/or the EEA. Where personal data of EEA/UK users is transferred internationally, we rely on the safeguards in each provider's data-processing terms (EU Standard Contractual Clauses and, where applicable, the EU–US / UK–US Data Privacy Framework). Copies of the relevant provider terms are available via the providers or from us on request.
6. Cookies and similar technologies
Our own pages use browser storage (not advertising cookies) for: your session ID (analytics/attribution), your sign-in session, your consent choices, referral-code and purchase-recovery state. These are necessary for the product to function or are first-party measurement of our own funnel. Two third-party scripts can load: FastSpring's checkout library (only when you open checkout; FastSpring applies its own cookie practices) and the Meta Pixel — only after you explicitly allow measurement cookies on the banner (see Section 3). Declining the banner keeps our pages free of advertising cookies; every product feature, including checkout, works identically either way.
7. How long we keep data
- Account, intake, plans, activities, predictions, logs you created: kept while your account exists; deleted immediately and permanently when you delete your account in Settings.
- Order, entitlement and payment-event records: retained after deletion as financial/audit records (with your account link removed), for as long as tax and accounting law requires.
- Garmin tokens: removed when you disconnect Garmin or delete your account.
- Claim links: expire automatically after 14 days.
- Unclaimed funnel data (predictor inputs/events under an anonymous session ID) and operational logs: retained for product-integrity purposes and periodically reduced; not linked to an identity unless you purchase or submit your email.
8. Security
Data is encrypted in transit (TLS); database access is locked to server-side service credentials (row-level security denies direct client access); Garmin and payment secrets exist only server-side; payment webhooks are signature-verified; access and admin actions are audit-logged; claim tokens are stored hashed. No internet service can promise absolute security — if we learn of a breach affecting you, we will notify you and the relevant authorities as the law requires.
9. Your rights
Depending on where you live (EEA/UK GDPR, Israel's Privacy Protection Law, and various US state laws), you have rights to access, correct, delete, receive a portable copy of, object to, or restrict the processing of your personal data, and to withdraw consent at any time (this stops future processing based on consent — for training data it means disconnecting Garmin and/or deleting your account, and the paid features that depend on that data will stop working).
Built-in, no ticket needed: Settings → Export my data (JSON by email), Settings → Disconnect Garmin (stops all new device data; access tokens are removed), Settings → Delete account & data (permanent, immediate). Anything else — or if you have no account — email support@peakiq.ai; we verify identity via your account/order email and answer within 30 days (usually much faster).
You may also complain to a supervisory authority: your local EEA data-protection authority, the UK ICO (ico.org.uk), or the Israeli Privacy Protection Authority. We'd appreciate the chance to fix it first.
10. Children
The Service is for adults (18+). We do not knowingly process children's data; if you believe a minor has an account, contact us and we will delete it.
11. Changes
We will update this policy when the product's actual data practices change (for example, adding an advertising pixel or a new processor), with the new version and date shown above and notice for material changes. The policy always aims to describe what the system actually does — not more, not less.