1. Who we are
ODDS Running is a social product for run clubs, operated by Goc Ventures Group LLC, a Florida limited liability company. The service consists of an iOS app, an Android app, this marketing website, and a backend hosted on InsForge. For EU and UK users this entity is the data controller under GDPR / UK GDPR.
2. What we collect — account & identity
Email address (required), password (hashed by InsForge, never stored in plaintext), and if you sign in with Apple or Google, the stable identifier and email returned by that provider. Optional profile fields: username, display name, bio, Instagram handle, gender, avatar image, and the optional Running fields — a running goal, your next race, a Strava handle, and a home club. Optional fields can be removed at any time in Settings. Profile visibility is a setting you control in Settings → Privacy: Public (anyone can see your activity, runs, and badges), Friends (the default — only your friends can), or Private (no one can); it also governs what run club organizers see about you (section 9). Consent record: when you create an account, and each time you accept an updated version of the Terms or this Policy, we record the timestamp and the document version you accepted plus an append-only history entry (version, when you acted, when our server recorded it, which screen it came from, and the app version and OS that rendered it). We keep a copy of every published version of both documents so the text you agreed to can be reproduced. The history is kept for 5 years after account deletion. Email list preferences: two optional marketing lists (weekly runs digest; ODDS news & updates), both off by default, each with its own opt-in and opt-out timestamps.
3. What we collect — location
Exact latitude and longitude, foreground only, only when you actively tap 'find runs near me', create an event, pick a meeting point on the map when posting a run partner request, or check in to a run with your location. We do not request 'always' permission and we do not run background location. Coordinates are stored on events you create and on run-partner posts (the meeting point you drop on the map); radius-search queries are transient, and a run-partner post's coordinate is deleted when the post auto-expires after 4 hours or you cancel it. Checking in to a run: a run club chooses which ways its runners can check in, and can change them at any time — holding your phone to the club's NFC sticker, confirming you're at the meeting point with your location, a one-tap check-in, or the host marking you present. We record that you checked in, when, which way was used, and who did it (you, or the host who marked you present), and we keep a history of check-ins and undone check-ins for each run. Sticker check-in reads only the sticker's link and serial number; no location is read. Location check-in happens only when you tap it, and only at clubs that have turned it on: your phone reads your location once and sends it to our server, which works out how far you are from the run's meeting point. We keep only that distance and how accurate your phone said the reading was. Your coordinates are discarded straight away and never stored, logged, or shown to anyone. We also check whether your phone reports the reading as simulated.
4. What we collect — device data
Push notification token (APNs on iOS, FCM on Android) so we can send notifications you opted into — event reminders, vibe checks on your event, friend requests, and announcements from clubs you follow or run with; each category has its own toggle in Settings → Notifications. A random per-install UUID stored locally — this is not Apple's IDFA or Google's AAID; we use it only to dedupe anonymous search analytics. App and OS version with API requests for bug fixes. IP and User-Agent on public web forms (event proposals, waitlist) for rate-limit and abuse prevention. We do not collect IDFA / AAID and we do not show an App Tracking Transparency prompt because we have nothing to track across apps.
5. What we collect — your content
Events, RSVPs and check-ins, vibe checks (comments and emoji reactions), direct messages, friend relationships, badges you earn, event proposals, and waitlist signups. When you RSVP "going" to an event, your username and profile photo (if you set one) are shown to other ODDS users on that event — friends first, then everyone else — unless your Profile visibility (Settings → Privacy) is Friends (the default) or Private, in which case only your friends see you there and everyone else sees just the going count. Your friends also see that you're going in their Activity feed; people who aren't your friends never do. Other users see nothing beyond username and photo. The first time you tap "I'm going" the app tells you who will see it, and you can change the setting before anything is saved. Separately, the organizers of the club hosting that run see your RSVP and check-in on their roster regardless of this setting — exactly what they see is in section 9. Direct messages are stored on our servers and are not end-to-end encrypted — treat them as private email, not as a sealed letter.
6. What we do NOT collect
No Google Analytics, Meta Pixel, Sentry, PostHog, Mixpanel, Amplitude, Segment, or Vercel Analytics. No advertising SDKs, retargeting pixels, or data brokers. No access to your contacts, calendar, mic, SMS, or camera roll beyond the photo you pick for your avatar. No background or 'always' location. No Apple Health, HealthKit, Google Fit, Health Connect, or any other health or fitness data — the app never asks for that permission. No IDFA / AAID. No sale of personal information, ever.
7. How we use your data
Operating the service (sign-in, RSVPs, feed, messaging) on the basis of our contract with you. Sending transactional email (verification, reset, RSVP confirmation) as part of the contract. Showing who's going to an event (username and profile photo of "going" RSVPs, friends first) as part of the contract, limited by your Profile visibility setting (default: Friends). Giving a club's organizers the roster, check-ins, and attendance history for their own runs (section 9) as part of the contract — the club's run is the thing you RSVP'd to. Sending push notifications you opted into, including announcements from clubs you follow or run with (Settings → Notifications → Club announcements). Showing events near you only after you grant location permission. Recording that you checked in to a run, how, who did it, and a history of check-ins and undone check-ins, as part of the contract. Confirming you're at the meeting point when you choose to check in with your location — read once at your tap and reduced on our server to a distance and accuracy — as part of the contract; you can use another way the club offers instead. Preventing abuse on public forms as a legitimate interest. We do not make automated decisions that produce legal or similarly significant effects on you.
8. Who we share with
Infrastructure providers acting on our instructions only: InsForge (backend host — auth, database, file storage), Vercel (web hosting), Resend (email delivery — account notices and the marketing lists you opt into; sees your email address, message content and delivery events), Apple APNs (iOS push delivery), Google FCM (Android push delivery), and Apple / Google as OAuth identity providers if you choose them. Run club organizers are a separate case, described in section 9. We do not share with advertisers, ad networks, data brokers, or attribution providers. We may disclose data when required by law (subpoena, court order); we will not disclose more than necessary and will notify you unless legally prohibited.
9. Run club organizers
Run clubs on ODDS Running are run by independent organizers — not our employees, and not processors acting on our instructions. When you interact with a club, its organizers see some of your data through the organizer tools in the app and the web console. This is the complete list. For a club run you RSVP to (whatever your Profile visibility setting): your username and profile photo, your RSVP status (going / thinking / not going) and when you set it, whether and when you checked in and how (sticker, location, one-tap, or host) — for a host check-in, which host; for a location check-in, your distance from the meeting point rounded to 10 m — the history of check-ins and undone check-ins for that run, how many of that club's previous runs you RSVP'd to and checked in at, and whether this is your first run with them. In the club's people list (their view of everyone who has run with the club or follows it): the same identity fields, your total runs (and how many of them were checked in each way), RSVPs, and no-shows with that club, when you first and last ran with them, whether you follow them, and a label we compute from that history — newcomer (first run within 30 days), regular (3+ check-ins in the last 60 days), lapsed (2+ RSVPs and nothing in 45 days), follower (follows, never RSVP'd), or occasional. The web console lets an organizer download this list as a CSV file. Only if your Profile visibility is Public: the running goal and home club you entered in Settings → Running; for Friends and Private profiles these are hidden from organizers. If your Profile visibility is Private: you are left out of the club's people list, its CSV, and its history-based announcement audiences (regulars, lapsed, everyone); you still appear on the roster of any run you RSVP to, and you still receive announcements sent to a run you RSVP'd to or a club you follow unless you turn off Club announcements in Settings → Notifications. Organizers never see your email address, phone number, location (a location check-in shows them only your rounded distance from their own meeting point), direct messages, or activity with other clubs. Organizers may use this only to run their club and communicate with their runners on ODDS Running, and are bound by Terms section 7. Deleting your account removes you from every organizer view, but not from a CSV an organizer already downloaded — that copy is theirs to delete under the same Terms. Report misuse to privacy@oddsrunning.com.
10. International transfers
Data is stored and processed in the United States. If you access the service from the EU, UK, or elsewhere outside the US, your data is transferred to the US. We rely on the EU–US Data Privacy Framework (where applicable to our processors) and Standard Contractual Clauses with processors that have not self-certified.
11. Retention
Account, profile, events, RSVPs, check-ins and check-in history, messages, friends, and vibe checks are retained while your account is active and deleted when you delete your account. A check-in history entry naming a host who later deletes their account keeps the entry but drops the host. Activity pings auto-expire after 4 hours. Anonymous search logs aggregate into a 7-day rolling view; raw rows are kept up to 90 days for abuse detection. Push tokens are replaced on every device re-registration. Event-proposal IP and User-Agent are kept 90 days for rate-limit then nulled. Server logs roll on a ~30-day window. Backups are purged on the same cadence after account deletion (excluding any rolling backup window — typically ≤30 days residual). Organizer CSV exports (section 9) leave our systems when downloaded; the organizer must delete them when they stop leading the club or when we ask.
12. Your rights
You have the right to access, correct, delete, restrict, port, and object to processing of your data, and to withdraw consent at any time — revoke location or push permission in your device settings, or turn off any push category in Settings → Notifications. Account deletion is available in-app under Settings → Account → Delete account. Request other rights at privacy@oddsrunning.com. EU and UK users can lodge a complaint with their local supervisory authority — we'd appreciate the chance to address concerns directly first.
13. California (CCPA / CPRA)
Categories collected: identifiers (email, username, OAuth subject, device UUID, IP on web forms), customer records (profile fields), internet/network activity (search queries, request logs), geolocation (precise, only with foreground permission; for a location check-in we keep only the derived distance from the meeting point, not the coordinates), sensory data (avatar photos), and sensitive personal information (precise geolocation). We use sensitive PI strictly for the purposes in section 7 and do not infer characteristics about you. Disclosed for a business purpose to run club organizers (section 9): identifiers (username), customer records (profile photo; goal and home club if your profile is Public), and your RSVP, check-in (including how you checked in, which host checked you in, and for a location check-in your rounded distance from the meeting point), and follow activity with that club. No sale. No share for cross-context behavioral advertising. Rights honored at privacy@oddsrunning.com or via in-app account deletion. Authorized agents accepted with verified power-of-attorney.
14. Security
All traffic is TLS-encrypted in transit. Passwords are hashed by InsForge. Auth tokens are stored in iOS Keychain (hardware-backed where available) and Android EncryptedSharedPreferences. The database is encrypted at rest. Access to production data is restricted and logged. Direct messages are not end-to-end encrypted. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant supervisory authorities within the windows required by law (72 hours under GDPR).
15. Children
ODDS Running is for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it immediately. Parents and guardians who believe a minor has registered should contact privacy@oddsrunning.com.
16. Cookies
The marketing site sets no cookies. We do not use analytics, advertising, or tracking cookies and we do not show a consent banner because there is nothing to consent to. The staff-only /admin area keeps its session token in localStorage. The native apps do not use web cookies. Full inventory at /cookies.
17. Marketing email
Transactional email (verification codes, password resets, RSVP confirmations, event reminders you opted into) is sent on the basis of our contract with you. Marketing email is opt-in only, in two lists you control separately: the weekly runs digest and ODDS news & updates. Every marketing email carries a one-click unsubscribe link scoped to that list, standard one-click unsubscribe headers, our postal address, and a line saying why you're receiving it. Opt-outs take effect immediately in our system and within 10 business days at the very latest; you can also toggle each list in Settings → Email. Service notices (a material change to these documents, account-deletion confirmation, security or breach notification) go to every account and cannot be unsubscribed from. We comply with the US CAN-SPAM Act, EU ePrivacy Directive, and Canada's CASL.
18. Changes to this policy
Every version of this Policy and the Terms is published with a version (its effective date), the date it was announced, and a plain-English summary of what changed. For material changes (new data category collected, new third party, new use that changes the legal basis) we publish the new version at least 30 days before it takes effect; during that window you'll see an in-app banner with the summary and we email it to the address on your account. When it takes effect, the app asks you to review and accept the new version before you continue, and we record which version you accepted and when. If you don't accept, you can stop using ODDS and delete your account; the version you last accepted governs until then. We never treat continued use alone as acceptance. For non-material changes (clarifications, typo fixes, address updates, a rename) we update the 'Last updated' date above without changing the version. Past versions are available on request.
19. Contact
Privacy questions: privacy@oddsrunning.com. Postal: Goc Ventures Group LLC, 92 SW 3rd St Apt 2907, Miami, FL 33130, United States. DMCA notices: /dmca.