Privacy Policy
Last updated: 1 June 2026
1. Data controller
RUNSHOEINDEX ("we", "us", "our") is the data controller for the personal data processed through runshoeindex.com. We are a UK-based, community-powered running shoe deal platform where runners submit and vote on deals, compare prices across UK retailers, and set price drop alerts.
If you have any questions about how we handle your data, you can contact us at hello@runshoeindex.com.
2. What data we collect
- Account data: If you create an account, we collect your email address and a hashed password.
- Profile data: A username and, optionally, a display name and avatar. We also store a reputation score derived from your activity on the platform.
- Content you submit: Deals you post, comments you write, votes you cast, and deals you mark as "got this". This content is associated with your profile and may be shown publicly.
- Price alert preferences: The shoes and target prices you configure for alerts.
- Usage data: Standard web server logs (IP address, browser user-agent, pages visited, timestamps). These are used only for security and debugging and are not used to profile individuals.
- Analytics data: If you consent to analytics cookies, Google Analytics 4 collects anonymous usage data such as pages visited, session duration, and general location (country level). Google Analytics does not store your IP address.
3. Lawful basis for processing
Under UK GDPR, we rely on the following lawful bases to process your personal data:
- Consent (Article 6(1)(a)): Analytics cookies (Google Analytics) are only set after you give explicit consent via our cookie banner. Price alert emails are only sent after you explicitly opt in.
- Contract (Article 6(1)(b)): Processing your account, profile, and preferences, and storing the deals, comments, and votes you submit, is necessary to provide the service you signed up for.
- Legitimate interest (Article 6(1)(f)): Server logs for security monitoring and debugging, and moderating community-submitted content. These are proportionate and do not override your rights.
4. How we use your data
- To send you price alert emails you have explicitly requested.
- To display the deals, comments, and votes you submit to the community.
- To save your preferences across sessions.
- To maintain account security and moderate community content.
- To diagnose technical issues and improve the service.
- To understand how the site is used (via anonymised analytics, only with your consent).
We do not sell your data. We do not share your data with third parties except as required to operate the service (e.g. our email delivery provider) or as required by law.
5. Cookies and local storage
We use cookies and browser storage to make the site work and, with your consent, to understand how it is used. You can manage your preferences at any time via the "Cookie Settings" link in the footer.
Essential cookies (always active)
These are strictly necessary for the site to function. No consent is required under PECR.
| Name | Purpose | Duration |
|---|---|---|
| sb-*-auth-token | Keeps you signed in (Supabase session) | Session |
Analytics cookies (consent required)
These are only set if you click "Accept All" or enable analytics in Cookie Settings.
| Name | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics: distinguishes unique visitors | 2 years |
| _ga_Y3N91TNRWW | Google Analytics: maintains session state | 2 years |
Local storage (not cookies)
We also use your browser's local storage to remember your preferences. This is not sent to any server.
| Key | Purpose |
|---|---|
| rsi-cookie-consent | Records your cookie consent choices |
6. Affiliate links
When you click through to a retailer, you leave RUNSHOEINDEX and are subject to that retailer's own privacy policy. The retailer may track your visit via their affiliate system (e.g. a referral parameter in the URL). This allows us to earn a small commission if you make a purchase, at no extra cost to you. We have no control over the data practices of third-party retailers.
Some affiliate links are operated through affiliate networks acting on our behalf. When you click such a link, a referral or click identifier may be passed to the network so that a qualifying purchase can be attributed to us. We name each network we work with in the third-party processors list below once a programme is live.
7. Third-party processors
We use the following third-party services to operate RUNSHOEINDEX. Each acts as a data processor on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Authentication and database storage | United States |
| Cloudflare | Hosting and CDN | United States |
| Resend | Transactional email delivery | United States |
| Google Analytics | Anonymous usage analytics (consent-gated) | United States |
8. International data transfers
Some of our third-party processors are based in the United States. Where data is transferred outside the UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office, or the processor being certified under a recognised framework. You can contact us for more detail on the safeguards in place.
9. Data retention
We retain account data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days. Server logs are retained for up to 90 days. Analytics data in Google Analytics is retained for 14 months and is not linked to your personal identity.
10. Your rights
Under UK GDPR you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (e.g. via Cookie Settings or by unsubscribing from alerts)
To exercise any of these rights, email us at hello@runshoeindex.com. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data has been handled unlawfully.
11. Children's privacy
RUNSHOEINDEX is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Security
We use industry-standard security practices: HTTPS everywhere, hashed passwords (never stored in plain text), and least-privilege database access. No system is 100% secure; if you believe your account has been compromised, contact us immediately.
13. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to account holders by email. Continued use of the service after changes constitutes acceptance.
14. Contact
Questions about this policy? Contact us or email hello@runshoeindex.com.