Legal
Privacy Policy
Effective date: 1 January 2025 ยท Last updated: 1 April 2025
Contents
Summary: RaceHub collects only the data needed to run events and process registrations. We do not sell your data. You can request deletion of your account and data at any time.
1. Information We Collect
We collect information you provide directly when you create an account, register for an event, or contact us. This includes:
- Identity data: full name, date of birth, gender, nationality, IC/passport number
- Contact data: email address, phone number
- Health data: blood type, medical conditions (used solely for race-day safety)
- Emergency contact details
- Payment data: transaction references only โ we do not store card numbers or banking credentials
- Usage data: pages visited, events browsed, registration history
- Device data: IP address, browser type, operating system (collected automatically)
2. How We Use Your Information
RaceHub uses your personal data to operate and improve the platform. Specifically, we use your data to:
- Process event registrations and payments
- Share necessary participant data with event organisers for race-day administration
- Send race confirmations, bib assignments, and results notifications
- Issue digital finisher certificates
- Respond to support enquiries
- Detect and prevent fraud
- Comply with legal obligations under Malaysian law (PDPA 2010)
4. Data Security
We implement industry-standard security measures to protect your personal data, including encrypted data transmission (HTTPS/TLS), hashed passwords using bcrypt, database access controls, and regular security reviews.
No method of electronic storage is 100% secure. We encourage you to use a strong, unique password for your RaceHub account and to notify us immediately if you suspect unauthorised access.
5. Data Retention
We retain your account data for as long as your account is active. Registration records are retained for 7 years for accounting and legal compliance purposes.
Health and emergency contact data is retained only for the duration of an event plus 90 days. You may request early deletion by contacting us.
6. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Withdraw consent for optional data uses (e.g. marketing)
- Request deletion of your account and associated data (subject to legal retention requirements)
- Lodge a complaint with the Personal Data Protection Commissioner
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email of any material changes at least 14 days before they take effect.
Continued use of RaceHub after changes take effect constitutes acceptance of the updated policy.
Questions about this policy?
If you have any questions, concerns, or requests regarding your personal data, please contact our Data Protection Officer.
Contact DPO