Privacy Policy
Last updated: July 2026
Who we are
Race Day Vault is a platform that lets sports event organizers make event photos available to participants, who can find them by searching for their bib number or, where enabled, by facial recognition.
The platform is operated by João Ascenso, sole trader, tax ID (NIF) 214674185, with professional address in Leiria, Portugal ("we").
Who is responsible for your data
For most of the processing described in this policy, we are the controller.
The exception is event photos and the biometric data derived from them: there, the controller is the event organizer, who decides to publish the photos and enable the features. We act as a processor, handling that data on the organizer's behalf and under their instructions.
Where minor participants take part in events, the organizer must ensure compliance with the rules applicable to the processing of their data.
What data we process
- Event photos — uploaded by the organizer and their photographer team;
- Searches and downloads — the bib number searched and the download type, not linked to athletes' names, emails or other personal data;
- Photo purchases — the email provided at checkout, the photos purchased and the amount paid. Payments are processed by Stripe; we do not store card data;
- Organizer and photographer accounts — email and, for organizers, name;
- Organizer applications — name, contact details, billing information (tax ID and address) and event information;
- Biometric data — only in events with face search enabled (see the dedicated section below).
Purposes and legal bases
- Making photos and bib search available — providing the service the organizer contracted; the legal basis for publishing the photos is determined by the organizer, as controller;
- Delivering purchases and resending download links — performance of the purchase contract;
- Invoicing and accounting — compliance with legal obligations;
- Authentication and contact for organizers and photographers — performance of the contract;
- Reviewing organizer applications — pre-contractual steps; rejected applications are deleted within a maximum of 6 months;
- Event statistics (searches and downloads) — legitimate interest, without identifying athletes;
- Face search — explicit consent (see the next section).
Facial recognition and biometric data
In events where the organizer enables this option, faces present in the event's photos are analyzed so athletes can search with a selfie. Because this involves biometric data, it requires the participants' explicit consent (Art. 9 GDPR), which the organizer, as controller, undertakes to obtain — for example through an opt-in at race registration.
The selfie you submit is analyzed on the spot and never stored; submitting it requires your consent, which you can withdraw at any time. The facial data derived from the photos is processed on infrastructure in the European Union and deleted together with the event.
Data sharing and providers
We do not sell personal data or share it for advertising purposes. We use specialized technology providers for hosting, photo storage, payment processing, communications and search features. These providers only process data under our instructions and under appropriate contracts.
International transfers
Data is processed, wherever possible, on infrastructure in the European Union. Where transfers outside the EU occur, they take place under adequate safeguards: EU-U.S. Data Privacy Framework certification or the European Commission's Standard Contractual Clauses.
Data retention
- Photos and face search data: deleted when the event is archived (date set by the organizer, maximum 6 months) or earlier if the organizer deletes them;
- Organizer and photographer accounts: for as long as the account exists; deleted within 30 days of a request;
- Rejected applications: maximum 6 months;
- Purchase and billing records: kept for the period required by tax and accounting law (generally 10 years);
- Search and download statistics: without data identifying athletes, kept with the event.
Cookies
We only use strictly necessary cookies: a session cookie for organizer and photographer authentication, and a functional cookie that remembers your language choice. Public event pages do not use tracking or advertising cookies.
Your rights
Under GDPR you have the right to access your data, rectify it, request its erasure, restrict or object to its processing, and to the portability of the data you provided. Where processing is based on consent, you can withdraw it at any time, without affecting processing already carried out.
Photo removal — if you appear in a photo and want it removed, contact info@racedayvault.com stating the event and bib number. We forward the request to the organizer, who can remove the photo immediately; if the organizer does not respond within a reasonable time, we remove it ourselves.
To exercise any of these rights, write to info@racedayvault.com — we reply within one month at most. Where applicable, this period may be extended as provided for in the GDPR, in which case you will be informed of the extension. For event photos, where the organizer is the controller, we forward and follow up on your request.
Security
We apply appropriate technical and organizational measures to protect the data: encryption in transit, original photos stored in private space with no public access, per-account and per-event access controls, and certified infrastructure providers. In the event of a personal data breach that puts data subjects at risk, we will notify the supervisory authority and, where required, the affected individuals.
Updates to this policy
We may update this policy whenever necessary. The updated version will be made available on this page with the revision date indicated.
Contact and complaints
For privacy questions or to exercise your rights: info@racedayvault.com.
You also have the right to lodge a complaint with the supervisory authority: CNPD — Comissão Nacional de Proteção de Dados (Portugal).