1. Our commitment to privacy
2. About Carrot.run
With Carrot.run you can upload your run times, connect with friends, join and create private leagues, and collect and unlock exclusive items by using our mobile app (“App”, together “Carrot.run”). When you use Carrot.run we will process your personal data. This may include sensitive data about you, such as your location. All personal data is collected, processed and secured in compliance with the General Data Protection Regulation (GDPR). We, Carrot.run, are controller of the personal data we process about you in relation to the use of our App.
Carrot.run Data Protection Officer
1 Widcombe Street,
3. How do we process your personal data?
3.1 Creating an account
You can create an account to upload your run times, connect with friends, join and create private leagues, and collect and unlock exclusive items upload your times, create and join leagues, and follow others. When you register for an account we ask you to provide some basic information about yourself, such as:
Date Of Birth
You can also use your Facebook or Google account to register. If you do so, we may gain access to public profile information from such third party service providers. We process this data as it is necessary to deliver Carrot.run to you (legal basis: the performance of the agreement).
3.2 Using Carrot.run
As a registered user, you can start using Carrot.run. It is up to you how you use Carrot.run. You can upload your run times to collect and unlocks exclusive items. You can join and create private leagues. You can connect and compete with friends - giving them kudos for their performances.
We process the following data:
Your personal info, such as your full name, date of birth, gender, hometown and e-mail address
Your added content, such as run times and likes
Whom you follow and who follows you
Technical information to make Carrot.run work well, such as your IP-address, device type, browser type and screen size
We process this data as it is necessary for the performance of the agreement.
You can delete all of your added content whenever you like by deleting your entire account. When you do, it will no longer be visible to others and be 'soft deleted' from our servers within 7 days. All personal information will be dissociated and deleted, but all historical run times will remain in the system; this enables tracking, improving and historical reference. At no point will Carrot.run will able to associate these runs with the users, after such 'soft deletion' has occurred.
3.3 Improving, securing and optimising Carrot.run
Carrot.run is constantly in development. We need certain data to optimise your experience and to improve the services. This concerns, for example, the following data:
How you interact with the App, such as search terms, screens and messages
Device information, such as hardware model, OS version, unique ID, browser type and WiFi information
Hometown location data (at a city level)
Information collected by cookies and similar technologies
The legal basis for this processing is our legitimate interest to improve the App, by analysing how the App is used, what problems are encountered and what improvements are necessary. We will limit this processing as much as possible, for instance by masking sensitive data.
3.5 Social Media
If you follow us on social media or communicate with us or about us on social media, we may have access to a part of your public profile data. Carrot.run also follows social media channels and may have access to public profile information by doing so.
We do this in order to increase our social media activity, respond to queries, and analyse customer satisfaction. The legal basis for this is our legitimate interest to improve our services.
3.6 Customer satisfaction surveys
Carrot.run conducts customer surveys in several ways. If you contact support or make a purchase, you may receive an invitation to participate in a customer satisfaction survey. For this purpose we process information such as your e-mail address, the reason for sending you a survey and the results of the survey.
We use the results to improve the quality of our services and products. The legal basis is the performance of the agreement with you.
You can subscribe to our mailings. For this, we need your name and email address. The legal basis for this is your consent. You can unsubscribe at any time by clicking on the ‘unsubscribe’ button in each email. If you are no longer subscribed, we will remove your name and email address from our mailing list.
You may also receive mails which are necessary for the performance of the agreement with you, such as a confirmation of your account creation, password reset request or changes to our legal documentation.
You can contact our support department for any issues related to our services. When you do, we process your account details and the contents of your issue, in order to answer your request, on the basis of the performance of the contract with you.
3.9 Contracting partners
We sometimes make use of contracting partners, such as IT service providers. We may need to process some personal data of our contacts with such partners. We do this for the performance of the contract with these partners.
3.10 Protection of rights
Lastly, we may need to process your data to protect our rights or the rights of third parties and to enforce our Terms of Service or policies, for instance to protect our intellectual property rights when they are violated. We may also share your data as part of a business sale, merger, investment, change in control or transfer of Carrot.run. The legal basis for this are our legitimate business interests.
4. How do we share your personal data?
We have never sold your personal data to third parties for commercial purposes, and we have no intentions to do so in the future. We only share your personal data when necessary for offering our services, as described here.
We provide personal data to third parties who process personal data on our behalf. We enter into a processing agreement with our processors in which we legally bind our processors to process your personal data in accordance with the GDPR.
We share data, for instance, with:
Hosting IT service providers to store our user data
Companies which help us analyse usage of the App
In addition, we may be required by law to provide your information to a third party
Other parties may also be involved in the performance of the agreement with you as an independent or joint controller. We will inform you about it when this is the case.
Your personal data will only be stored or processed outside the European Union (and the EEA) by us or by third parties if this is in accordance with the applicable regulations for the transfer of personal data to countries outside the European Union. This means that we will only transfer your personal data to countries outside the European Union if the European Commission has decided that the third country in question ensures an adequate level of protection, or if other appropriate safeguards are put in place, such as the use of unchanged standard data protection clauses that have been approved by the European Commission.
5. How do we secure your data?
Carrot.run takes the protection of personal data seriously and takes appropriate measures to prevent misuse, loss, unauthorised access, unwanted disclosure and unauthorised alteration. We strictly follow our partner, Amazon Web Services (AWS) data security processes. All our data is hosted by AWS and as such is secured within their world-leading platform. A breach of security would mean a breach of AWS security. Any such breach will be communicated to all Carrot.run users within immediate knowledge, via Newsletter communication.
6. What rights do you have?
Account information can be changed directly within your account. You can delete your account through your account settings. Also, when you have given us consent for certain processing activities, you can withdraw this consent at any time.
You have the right to access, correct or erase your data. You can also ask us to restrict the processing or transfer your personal data and you have the right to object to the processing of your personal data.
To exercise these rights, contact us at firstname.lastname@example.org. You can also submit a complaint to the Personal Data Authority.