Trust & Privacy

How we look after your data.

This page is maintained by the Sunday Run Club team to answer common security and privacy questions about the SRC app and website. It is editable project content — not an independent certification or audit.

Accounts & access

You can sign in with email and password or with Google. Passwords are never stored by us in plain text — authentication is handled by our backend provider.

Admin tools (member lists, attendance dashboards, email sending) are restricted to club organisers via a server-side role check. Being signed in is not enough to reach admin features.

Data access rules

Database access is gated by row-level security. By default you can only read and edit your own profile, your own runs, and your own shoes.

The leaderboard only shows runners who have opted in to appear on it. You can opt out at any time from your profile.

What we collect

When you sign up: your name, email address, and (optionally) phone, location, Instagram/Strava handles, and a profile photo.

When you use the club: event signups, Sunday-run check-ins, logged runs, and — if you connect Strava — activities synced from your Strava account.

How we use it

We use your data to run the club: event communications, attendance, the leaderboard you opted into, and order fulfilment for shop purchases. We don't sell your data.

Transactional emails (event confirmations, account magic links) are sent only to the address tied to your account or signup.

Your choices

You can edit your profile, hide yourself from the leaderboard, and unsubscribe from non-essential emails using the link in any email we send.

To delete your account or request a copy of your data, email info@sundayrunclub.co.za.

Reporting a security issue

If you think you've found a security or privacy problem with the SRC app, please email info@sundayrunclub.co.za with the details. Please don't publicly disclose it before we've had a chance to look.

The SRC app is built on the Lovable Cloud platform, which provides authentication, database, and hosting infrastructure. Platform-level features are operated by Lovable; how we configure and use them — and everything described on this page — is our responsibility as the app owner. Nothing on this page should be read as a certification or independent audit.

Questions? Get in touch.