Privacy Policy
1. Introduction
Welcome to Ultra-Go. We respect your personal privacy and are committed to maintaining transparent data processing practices. This Privacy Policy outlines what information we collect across our website (the "Site") and the Ultra-Go mobile application (the "App"), how we handle and protect that information, and your legal rights under the European Union General Data Protection Regulation (GDPR) and Belgian law.
2. Information We Collect
A. Waitlist Registration Data (Website)
When you register for the Ultra-Go waitlist on our Site, we collect your email address. This information is gathered with your explicit consent to notify you about early access invitations, beta availability, and product announcements. Waitlist email management is handled via our newsletter processor, Kit (ConvertKit).
B. Mobile Application Data Processing (Free & Pro Tiers)
Depending on your subscription tier, Ultra-Go processes your training, physiological, and race logistics data as follows:
- Free Tier Users (On-Device Storage): For users on the Free tier, data is processed and stored strictly locally on your physical device (using `@react-native-async-storage/async-storage`). We do not host, sell, or transmit Free tier profile or race data to external cloud databases.
- Pro Tier Subscribers (Cloud Sync & Backup): For users subscribed to the Pro tier, your application data is securely backed up and synchronized across your authorized devices via encrypted cloud servers.
The application data scope across both Free and Pro tiers includes:
- Runner Profile Metrics: Name, biological sex, body weight (kg/lbs), height (cm/in), sweat rate category, salt loss type, gut training level, hourly target intake overrides (carbohydrates, fluids, sodium, calories), and measurement unit preferences (metric vs. imperial, Celsius vs. Fahrenheit).
- Fuel Pantry Inventory: Custom food items, brands, product types (gels, drink mixes, solids, electrolytes, capsules), and detailed macro/micro-nutrient values (calories, carbohydrates, sodium, caffeine, potassium, magnesium, calcium, and fluid mixing volumes).
- Course & Strategy Configurations: Parsed `.gpx` trackpoint data, manual course metrics (distance, elevation climb/descent), aid station lists, cutoff times, resource availability, drop bag item manifests, segment carry plans, hourly intake schedules, and environmental targets (temperature and humidity).
- Crew Management Inputs: Dedicated crew viewpoint names, physical access addresses, GPS coordinates, aid station handoff instructions, and crew packing checklist items.
C. Client-Side File Processing
When you import a `.gpx` course file into the App, the file is parsed locally in JavaScript memory on your device (`gpxParser`) to extract track distance and elevation coordinates. For Free users, parsed data remains exclusively in local device storage. For Pro users, parsed course configurations are securely synchronized to your cloud account.
D. Web Analytics & Cookies (Consent Mode v2)
On our Site, we use cookies and statistical tools, specifically Google Analytics (G-9XM78NDLNN), to analyze website visitor traffic and optimize user experience.
In full compliance with European Union ePrivacy and GDPR requirements, our Site implements Google Consent Mode v2. By default, all analytical storage (`analytics_storage`), advertising consent (`ad_storage`), and user data personalization consent parameters are set to 'denied' for all visitors until you explicitly choose to accept cookies via our interactive consent banner. Your consent choice is stored locally in your browser (`localStorage.getItem('cookieConsent')`).
3. Legal Basis for Processing (GDPR)
Under Article 6 of the GDPR, our legal bases for processing personal data are:
- Consent (Art. 6(1)(a) GDPR): For collecting your email address via the waitlist form and for activating optional Google Analytics tracking cookies via our consent banner.
- Performance of a Contract / App Functionality (Art. 6(1)(b) GDPR): For processing your physiological, race strategy, and cloud synchronization data (for Pro subscribers) to deliver pacing calculations, multi-device syncing, and crew itineraries.
- Legitimate Interests (Art. 6(1)(f) GDPR): For maintaining website technical security, preventing abuse, and addressing user support inquiries.
4. How We Use Your Information
We use collected data solely for the following purposes:
- To manage your waitlist placement and deliver product news, beta invitations, and release updates (managed via Kit).
- To compute hourly nutrition targets, pacing timelines, drop bag alerts, and crew packing manifests within the mobile App.
- To provide multi-device cloud synchronization and remote data backup for Pro Tier subscribers.
- To measure aggregate, anonymized website traffic statistics and landing page performance (only when Google Analytics consent is granted).
- To respond directly to support inquiries sent to our contact address.
5. Pro Tier & Cloud Synchronization Security
For users who subscribe to the Pro Tier, cloud synchronization features operate using robust security measures:
- Encryption: All synchronized data (runner profiles, pantry items, race plans, and crew notes) is encrypted during transmission using TLS/SSL protocols and stored using encrypted cloud database architecture at rest.
- Access Control: Your synced data is strictly linked to your authenticated user account and cannot be accessed by unauthorized third parties.
6. Third-Party Service Processors
We do not sell, rent, lease, or trade your personal information to any third parties or advertisers. We only engage reputable service processors who adhere to strict data protection standards:
- Kit (ConvertKit): Email marketing platform used to store waitlist subscriber emails and dispatch updates. Data handling is governed by Kit's Privacy Policy.
- Google Analytics: Web analytics provider used to aggregate anonymous Site usage metrics when consent is granted.
- Cloud Infrastructure Providers: Encrypted database services used to host and synchronize Pro Tier user backups securely.
7. Data Retention & Erasure
- Waitlist Email Data: Retained for the duration of the waitlist program or until you unsubscribe. You can withdraw consent and delete your email instantly by clicking "Unsubscribe" in any email footer or contacting us.
- Free Tier Local App Data: Retained on your physical device under your exclusive control. You can permanently erase all stored profile, pantry, and race data at any time by clearing the App's storage/cache in your OS settings or by uninstalling the App.
- Pro Tier Cloud Data: Retained in secure cloud storage while your account remains active. Pro users can request full cloud account data deletion directly through the App settings or by emailing info@pietersimons.com.
8. Your GDPR & EU Privacy Rights (Belgium & EU)
If you reside in the European Economic Area (EEA) or Belgium, you hold the following rights under the GDPR regarding personal data processed by us:
- Right of Access (Art. 15 GDPR): The right to request confirmation of whether we process your personal data and obtain a copy of held data.
- Right to Rectification (Art. 16 GDPR): The right to request correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): The right to request deletion of your waitlist email or Pro tier cloud account data from our servers.
- Right to Restrict Processing (Art. 18 GDPR): The right to request restriction of processing under specific legal conditions.
- Right to Data Portability (Art. 20 GDPR): The right to receive your personal data in a structured, commonly used machine-readable format.
- Right to Object (Art. 21 GDPR): The right to object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent (Art. 7(3) GDPR): The right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, please submit your request to info@pietersimons.com. You also have the right to lodge a complaint with a supervisory authority, such as the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données).
9. Data Security Measures
We apply appropriate technical and organizational security measures to protect website interactions, subscriber lists, and Pro tier cloud databases against unauthorized access, alteration, disclosure, or destruction.
10. Children's Privacy
Our Site and App are not directed to children under the age of 16. We do not knowingly collect or solicit personal data from children. If you become aware that a child has provided us with personal information without parental consent, please contact us immediately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our legal obligations, app features, or data processing practices. Any updates will be posted on this page with an updated "Last Updated" timestamp.
12. Contact Information
For any privacy-related questions, data access requests, or regulatory inquiries, please contact us at:
Email: info@pietersimons.com