Privacy
Privacy Policy
Last updated: 3 September 2026
kliva.run is a trail-race calendar and race-planning tool. This policy explains what personal data we collect, why, where it is stored, and the choices and rights you have. It is written in English and applies to every language version of the site.
Who we are
kliva.run (“we”, “us”) operates the website at kliva.run and its progressive web app. For any privacy question or request, contact us at contact@kliva.run.
Data we collect
We only collect what the features you use actually need:
- Account & identity. When you sign in with Google, Strava, or a one-time email code, we receive and store your email address and a display name. Signing in with Strava also gives us your public Strava athlete profile (name, avatar). We never see your Google or Strava password.
- Profile you set. A display name and an optional avatar image you upload.
- Content you create. The races and editions you save or bookmark, and any GPX route files you upload for a race plan.
- Watch pairing. When you send a race plan to a Garmin watch, we generate a short pairing token tied to your account and that plan, and store it so the watch can fetch the plan. It carries no data beyond what is needed to deliver that plan to your device.
- Usage & device data. Basic server logs (such as IP address and request metadata) for security and reliability, and — only with your consent — aggregated product-analytics data (see Cookies & analytics).
How we use your data
- To provide the service: authenticate you, save your races, build and deliver race plans, and sync them to your watch.
- To operate securely and prevent abuse.
- With your consent, to understand how the product is used so we can improve it.
- To contact you about a request you made to us.
We do not sell your personal data, and we do not use it for advertising profiling.
Where your data is stored
The site is hosted on Vercel. Account and race data are stored in a Neon (PostgreSQL) database. Uploaded files — GPX routes and profile avatars — are stored on Cloudflare R2. Data may be processed on servers located in the European Union and the United States by these providers.
Cookies & analytics
We use a small number of strictly necessary cookies and local storage to keep you signed in and to remember your language and consent choice. These are always on because the site cannot work without them.
Optional analytics load only after you accept in the consent banner. When accepted, we use Contentsquare for aggregated, privacy-conscious product analytics (heatmaps and session insight, with input masked by default), and we show an embedded lodging map from Stay22 on race pages. If you decline, none of these load. You can change your choice at any time.
Who we share data with
We share data only with the processors that make the service run, each under their own privacy terms:
- Google and Strava — sign-in.
- Resend — sending one-time login codes and notification emails.
- Vercel — hosting; Neon — database; Cloudflare — file storage and content delivery.
- Garmin — when you choose to sync a race plan to your watch.
- Contentsquare and Stay22 — only with your analytics consent.
How long we keep it
We keep your account data for as long as your account exists. Pairing tokens are short-lived and expire after they are used or after a short period. Server logs are retained for a limited time for security. When you delete something (an avatar, a saved race, your account), we remove it from our active systems.
Your rights
Depending on where you live (including under the EU GDPR and the Swiss FADP), you have the right to access, correct, export, or delete your personal data, and to withdraw consent for optional analytics. You can update your profile and remove uploaded content from your account, or contact us at contact@kliva.run to make a request. You also have the right to lodge a complaint with your local data-protection authority.
Children
kliva.run is not directed at children under 16, and we do not knowingly collect their personal data.
Changes to this policy
We may update this policy as the service evolves. We will change the “last updated” date above, and for material changes we will make the update visible on the site.