LEGAL RECORD
Privacy Notice.
How ROAD CO. UK LIMITED handles personal data across the website, web app, iOS app, public registry, Teams, moderation and email services.
DATA CONTROL / UK GDPR / ROAD CO. UK LIMITED
Effective and last updated: 19 July 2026 · Version: ROAD-PRIVACY-2026-07-19 · Website: www.roadco.uk · App: app.roadco.uk
1. Controller and scope
ROAD CO. UK LIMITED (company number 16903248) is the controller of personal data processed through the ROAD public website, account-based web application, iOS application, public registry pages, team features, moderation tools and related emails. Our registered office is 51 Nelson Road, Gorleston, Great Yarmouth, England, NR31 6AT. Email: contact@roadco.uk.
This notice covers members, team applicants and participants, visitors to public ROAD pages, people who request a MARK, people named in reports or blocks, email recipients, and anyone who contacts ROAD. ROAD has not appointed a data protection officer.
2. What ROAD does
ROAD is an account-based commitment and documentary-record service. Members create a MARK and profile, issue a time-based ROAD, file dated statements and optional supporting material, choose visibility, participate in teams, and use reporting, blocking, correction, restriction and account-deletion tools.
Some ROAD pages are intentionally public. Public content can be viewed without an account and can be indexed, copied, downloaded or shared outside ROAD. ROAD is not a private diary unless the relevant ROAD and entry visibility settings are Private.
3. Data we collect
- Account and authentication: email address, account identifier, Supabase-managed authentication credentials, session and security data, password-reset events, account status and confirmation that the member is at least 18.
- Identity and profile: MARK, handle, avatar, optional identity image, discipline or domain, country and region, visibility, website and social links, optional public contact email and enquiry settings.
- ROAD and entry content: title, declaration or rules, classification, duration and dates, statements, session titles, record status, timestamps, visibility, corrections and registry identifiers.
- Supporting material: uploaded images; approved external or YouTube links; titles, notes and context; measures such as distance, duration, steps, sets, repetitions, weight, score or custom measures; and related storage paths.
- Optional location: latitude, longitude, accuracy and capture time after a member deliberately chooses device location, or a location label entered manually. ROAD does not request continuous or background location.
- Health- and fitness-related content: exercise measures and any injury, rehabilitation, recovery, sobriety, health, disability or similar information a member deliberately places in a ROAD, entry, team field, image or supporting record.
- Teams: applicant or coach name, discipline, region, athlete count, proposed team name, application reasons, role, membership, invitations, messages, tasks, completion and linked records.
- Safety and administration: reports, reasons and details, blocks, moderation status, reviewer notes and actions, rights requests, deletion scheduling and execution status, ownership checks and audit records.
- Marketing preference: email address, opt-in or opt-out state, source, wording or version and timestamps.
- Technical and request information: request metadata received by ROAD or its providers, which can include IP address, browser or device information, request time, delivery, error or security events. ROAD stores an HMAC-derived administrator-login IP bucket and removes those attempt records after 24 hours.
- Public MARK request: email, requested or issued MARK, privacy acknowledgement, separate marketing choice, timestamps and request status. The current flagship homepage does not submit this form, but the legacy endpoint remains part of the service.
4. Where data comes from
Most data comes directly from the member or correspondent. ROAD also creates identifiers, timestamps, public visibility projections, audit records and moderation or deletion status as the service operates. Team leaders can provide invitation or application information. Other members can identify a person or content in a report or block. Authentication, hosting, storage and email providers return service metadata.
If you provide information about another person, you must have a lawful reason, give them this notice where appropriate, and avoid supplying private or sensitive information ROAD does not need.
5. Purposes and lawful bases
- Contract: create and secure an account; issue and display a MARK; operate ROADs, entries, evidence, visibility and Teams; send requested transactional messages; and provide member-requested features.
- Legitimate interests: secure ROAD; prevent spam, fraud and abuse; screen public text; investigate reports; maintain an attributable registry and technical audit trail; diagnose failures; answer business correspondence; and establish, exercise or defend legal claims. ROAD must balance these interests against affected people’s rights.
- Legal obligation: respond where law requires preservation, disclosure, restriction, erasure, safeguarding or regulatory action.
- Consent: optional direct marketing and the designated sensitive classifications described below. A device permission is requested before camera, photo-library or location access, but operating-system permission is not by itself the UK GDPR lawful basis for every later use.
6. Sensitive classifications
Injury rehabilitation, surgery recovery, addiction recovery, sobriety, physical therapy and health reset can reveal health or recovery information. ROAD asks for a separate, unticked, explicit-consent choice before a member creates or changes a ROAD to one of those classifications. The choice is recorded for that ROAD and is separate from accepting the Terms.
A designated sensitive ROAD starts Private. Its identity is excluded from public surfaces until the member completes a separate sharing confirmation. New filings start Private and require their own disclosure choice. Making the ROAD identity public does not publish private or withheld historical entries, images, notes, location or evidence.
A member can return the ROAD to Private and withdraw consent through the ROAD controls. Withdrawal stops new filings and further sharing while preserving sealed records and any limited data ROAD must retain lawfully. Do not enter diagnoses, treatment, medication or other special-category information in ordinary free-text, image or team fields; those fields do not currently provide the designated explicit-consent flow.
7. Visibility
- Public: profiles, ROADs, entries, images, measures, links and related material can appear on Pulse, Discover, Archive, public profiles, public ROAD and record pages, certificates, downloads and shared links. A public ROAD can make the associated profile public for attribution.
- Withheld: the existence of an entry and limited support-signal information can remain visible. Withheld does not mean deleted, anonymous or inaccessible to ROAD administration.
- Private: excluded from ROAD’s public projections, but stored to provide the account and accessible to authorised administrators where necessary.
- Teams: applications, membership, tasks, messages and records are disclosed under authenticated team roles and database access rules. A task record issued publicly can also appear on public ROAD surfaces.
Public information can be copied, cached, indexed, downloaded, screenshotted or reshared. ROAD cannot reliably retrieve copies held outside its systems.
8. Images, location and links
Camera and photo-library access are used only after a member chooses to capture or select an image. ROAD validates and re-encodes supported proof and identity images on the server, which is intended to remove EXIF and embedded GPS metadata. The visible image can still reveal people, places or documents.
Device location is optional and user-triggered; manual location text is available instead. ROAD does not use background location, HealthKit, Motion and Fitness APIs, contacts, microphone or native video capture. External links open at the member’s direction and the destination then applies its own privacy practices.
9. Storage technologies
ROAD uses Supabase authentication cookies, a signed administrator cookie lasting no more than 12 hours, a local preference named road_registry_view, temporary Teams draft data in session storage, and a public-site session flag that avoids replaying the opening sequence in the same browser session. ROAD does not currently use advertising cookies, analytics pixels, device fingerprinting or cross-service tracking.
Details and controls are in the Storage Technologies Notice. ROAD will add any consent mechanism PECR requires before introducing non-essential tracking.
10. Recipients and processors
- Supabase: authentication, Postgres database and object storage.
- Vercel: website and web-application hosting, delivery and server functions.
- Resend: transactional email, delivery metadata, and marketing only where a valid preference and lawful route exist.
- Apple: iOS application distribution and App Store services under Apple’s own terms.
- Members and the public: according to Public, Withheld, Private and Teams rules.
- Advisers, regulators, courts, law enforcement or a successor: only where reasonably necessary and lawful, with appropriate protection.
ROAD does not sell personal data and does not share it for third-party advertising or cross-company tracking. A provider’s own account, billing or service-generated data can be processed by that provider under its own notice.
11. International transfers
Supabase, Vercel and Resend can use infrastructure, support or subprocessors outside the United Kingdom, including in the EEA, United States, Singapore and other published locations. The exact location depends on ROAD’s provider configuration; do not assume all data remains in the UK.
Where ROAD initiates a restricted transfer, it must identify a lawful mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum, and complete any assessment the law requires. Provider terms describe available mechanisms, but the source code does not prove ROAD’s account-level project region, DPA acceptance or completed transfer assessment. Contact ROAD for the current verified arrangement relevant to your data.
12. Retention and deletion
- Account, profile, ROAD, entry, team and support data is kept while needed to provide the account and until deleted, anonymised, restricted or no longer required under the criteria below.
- Administrator-login attempt buckets are removed after 24 hours. Provider logs and backups follow the provider configuration and contract, which ROAD must verify and document before launch.
- A signed-in member can request account deletion in Settings without giving a reason. ROAD verifies ownership by email, schedules deletion seven days later and permits revocation during that period.
- The deletion job removes stored identity and evidence images, evidence and later-addition data, entry support content, memberships and access, the authentication user, direct profile fields and core ROAD or entry text. Retained record structures are made Private or anonymised. A completion email is attempted after successful deletion.
- ROAD can retain limited deletion-request, moderation, security or non-public registry audit data where necessary for legal claims, safety, abuse prevention or another legal duty.
Retention decisions consider purpose, sensitivity, account status, risk, legal limitation periods, erasure rights and preservation duties. ROAD’s operational register must record fixed periods or review dates for provider logs, reports, marketing evidence, support, Teams records and backups before production launch.
13. Account deletion
Use Settings → Account deletion in the signed-in app. ROAD emails a confirmation link, then shows the scheduled date and lets the member revoke during the seven-day cooling-off period. If the in-app route is unavailable, use the process in Data Rights & Account Deletion or email contact@roadco.uk.
Identity verification can be required. ROAD will explain any limited information it must lawfully retain. “Add-only” and “immutable” product language does not override statutory data-protection rights.
14. Marketing
Marketing uses a separate, unticked choice. ROAD records the wording or version, source and timestamp. Members can withdraw in Settings or by email. Every campaign must identify ROAD and contain a simple working unsubscribe route that does not require login. A suppression record can be retained to honour the choice.
The app has self-service subscribe and unsubscribe controls and token-based email unsubscribe support. The legacy public MARK-request list does not yet have a complete campaign unsubscribe workflow; ROAD must not use that list for marketing until every message has a working unsubscribe and the suppression process is tested. Transactional account, security, moderation and deletion messages are not marketing merely because they concern ROAD.
15. Security
ROAD uses authenticated sessions, database row-level access policies, separate administrator controls, signed cookies, rate-limiting, validation, public-text screening, visibility projections, image validation and re-encoding, and security and moderation logs. Access to production systems should be limited to people who need it.
No internet service is completely secure. Use a unique password, protect your device and email account, and report suspected unauthorised access promptly through Contact & Site Information.
16. Your rights
Depending on the circumstances, you may have rights to be informed, access data, correct inaccuracies, erase data, restrict processing, receive certain data in a portable format, object to legitimate-interest processing or direct marketing, and withdraw consent. ROAD does not use solely automated decisions with legal or similarly significant effects.
Use Settings or follow Data Rights & Account Deletion. ROAD can verify identity and can lawfully limit a request where an exemption applies; if so, it will explain the decision where permitted. Rights requests are normally answered within one calendar month, subject to lawful extensions.
17. Complaints
Send a data-protection complaint to contact@roadco.uk with “Data protection complaint” in the subject. ROAD will acknowledge it within 30 days, take appropriate steps to investigate, keep you informed and provide an outcome without undue delay. Complaint handling is separate from any rights request made at the same time.
You can complain to the Information Commissioner’s Office at ico.org.uk or seek a judicial remedy. Contacting ROAD first is encouraged but does not remove those rights.
18. Adults only and online safety
ROAD accounts are for adults aged 18 and over. Signup records a self-declaration but does not collect date of birth and is not a highly effective age-assurance measure. ROAD must therefore maintain and review the children’s access assessment and any resulting children’s risk assessment required by the Online Safety Act.
If you believe a child has an account or personal data about a child appears on ROAD, use the urgent route in Reporting & Safety.
19. Changes and contact
ROAD will review this notice when its product, providers, disclosures or legal duties change. Material changes will be dated and brought to members’ attention before a new use begins where required. Consent is not inferred merely from continued use where the law requires a fresh choice.
ROAD CO. UK LIMITED
51 Nelson Road
Gorleston
Great Yarmouth
England
NR31 6AT
contact@roadco.uk