Privacy & Data-Sharing Policy
Version 2026-08-13
Apex Paceprocesses your personal information to provide athletic training and analytics. This notice explains what we collect, why, on what basis, who we share it with, and your rights under South Africa’s Protection of Personal Information Act (POPIA). For storage technologies specifically, see our Cookie Policy.
Who is responsible
Apex Pace is the responsible party, operated as a sole proprietorship in South Africa. Contact our Information Officer at privacy@apexpace.co.za. You may also lodge a complaint with the Information Regulator (South Africa). Our PAIA manual explains what records we hold and how to request access to them.
What we collect and why
Items marked special personal informationare health or biometric data, which POPIA protects more strictly. We process these only where you have given consent — we ask for it when you first sign in and record your answer, so you can see what you agreed to. You can say no and keep using Apex Pace; the features that rely on that data simply stay empty.
Account identity
Your email, password (securely stored), display name, date of birth, timezone, and an optional short bio.
Purpose: Create your account, sign you in, and personalise the app. Basis: Contract necessity — required to provide the account. Retention: Kept while your account is active; removed when you delete it.
Physiology (special personal information)
Sex/gender, height, weight, resting/max/threshold heart rates, FTP, and threshold pace.
Purpose: Calculate your training zones, load, and performance analytics. Basis: Consent (special personal information — POPIA s27(1)(a)). Retention: Kept while active; removed on delete; pseudonymised on archive.
Activities and GPS routes
Per-workout summaries plus a per-second stream of GPS location (latitude/longitude), heart rate, power, cadence, speed, elevation, and temperature.
Purpose: Show your history, route maps, and detailed analysis. Basis: Contract necessity — recording and analysing your activities is the service. The heart-rate and other biometric channels in the stream are covered by your health-data consent. Retention: Kept while active; removed on delete; pseudonymised on archive.
Original activity files (special personal information)
The raw FIT/TCX/GPX files you upload or sync, which contain full GPS and biometric data.
Purpose: Re-process activities and let you re-download your originals. Basis: Consent (special personal information — they carry biometric data). Retention: Kept while active; deleted from object storage on account delete.
Daily health metrics (special personal information)
Wellness data synced from a connected device: heart-rate variability, sleep, resting heart rate, steps, stress, body battery, and training readiness.
Purpose: Track recovery and readiness. Basis: Consent (special personal information — POPIA s27(1)(a)). Retention: Kept while active; removed on delete; pseudonymised on archive.
Wellness check-ins (special personal information)
Daily questionnaire answers including illness symptoms, injury or pain location and severity, menstrual phase and hormonal symptoms, fatigue, mood, and nutrition.
Purpose: Monitor your wellness and surface alerts to a coach you have linked. Basis: Consent (special personal information, including reproductive-health data). Retention: Kept while active; removed on delete; pseudonymised on archive.
Training notes and plans
Free-text day notes, planned workouts, goals, events, and tags.
Purpose: Plan and review your training. Basis: Contract necessity, with your health-data consent covering any health detail you choose to record. Retention: Kept while active; removed on delete; pseudonymised on archive.
Coaching relationships
Links between you and any coaches or squads you join, and in-app notifications.
Purpose: Let coaches you authorise see your training and message you. Basis: Contract necessity / consent (you choose who to link). Retention: Kept while the link exists; you can unlink a coach at any time.
Connected-device credentials
Your device login for a service you link (e.g. your Garmin email and password), stored encrypted.
Purpose: Sync your activities and health data from your device account. Basis: Consent — you initiate the link. Retention: Kept until you unlink the device or delete your account.
Security and audit records
Administrative and security logs, which include the IP address of sensitive actions.
Purpose: Protect accounts and investigate abuse. Basis: Legitimate interest / legal obligation (security). Retention: Kept for 12 months, then deleted automatically. These records are not removed when you delete your account — they are what shows the deletion happened — but they identify you by a one-way code, not your email.
Where your data comes from
Most data you enter or record yourself. If you link a Garmin account, we also receive activities, original files, and daily health metrics from Garmin as a source of your data.
Who we share with
Garmin Connect
At link time your Garmin login is sent to Garmin to authenticate. Apex Pace then syncs your activities, original files, and daily health metrics from Garmin, and can push planned workouts to your Garmin calendar.
Role: Independent controller (your own Garmin account). When: Only if you choose to link a Garmin account. Processed outside South Africa.
CartoDB
When you open an activity map, your browser requests map tiles for the area of your route, which discloses your route location to CartoDB.
Role: Processor for map rendering (basemaps.cartocdn.com). When: Only when you have allowed the Functional cookie category. Processed outside South Africa.
Resend
Your email address and the contents of the message we are sending you — account emails such as password resets, invitations, and notifications. We do not send marketing.
Role: Processor for outbound email delivery. When: Whenever we send you an email. Processed outside South Africa.
Zoho Mail
If you email us — including the Information Officer address — your message and your address are received and stored in our Zoho mailbox.
Role: Processor for our own inbound mailboxes. When: Only if you write to us. Processed outside South Africa.
We do not use any analytics, advertising, tracking, or AI services, and we never sell or rent your data. Our database and file storage run on our own infrastructure; email is delivered and received through the providers listed above.
Garmin Connect, CartoDB, Resend, Zoho Mail are located outside South Africa, so using Apex Pace means your information is transferred there. We rely on your consent and on the necessity of providing the features you use (POPIA s72(1)(b) and (c)). We have not put binding transfer agreements in place with these providers, and we would rather say so than imply a protection that is not there.
Your rights and how to use them
- Access. View your profile in the app. Settings → Danger zone → Download your data gives you a ZIP of your profile, activities, health metrics, check-in answers and consent history. For an activity's full second-by-second recording, download its original file from the activity page — we serve that wherever we still hold the file.
- Correction. Edit your profile and settings directly; for anything you cannot change yourself, email the Information Officer.
- Deletion / erasure. Settings → Danger zone → Delete account (on the desktop app) removes your data, including files in object storage. One record survives: an entry showing that the deletion happened, which identifies you by a one-way code rather than your email, and is itself deleted after twelve months.
- Archive (pseudonymise). Settings → Danger zone → Archive removes direct identifiers (name, email, photo, exact date of birth) while retaining your training history in pseudonymised form. You can opt in to let that pseudonymised data improve our own models; choose Delete instead if you want nothing kept.
- Object / restrict. Unlink any coach, opt out of aggregate statistics, or change cookie settings in the footer at any time.
- Withdraw consent. Unlink a device, opt out of aggregate statistics, or change your cookie settings at any time. For health data specifically, withdrawing means deleting or archiving your account — both remove the data. Turning it off per-feature from inside the app is not available yet, and we would rather say so than imply otherwise. Withdrawal does not affect processing already carried out.
- Complain. Contact the Information Officer at privacy@apexpace.co.za, or lodge a complaint with the Information Regulator (South Africa).
Aggregate statistics
Your anonymised training data may contribute to aggregate statistics across the platform. This is managed by a toggle in your Athlete settings, where you can opt out at any time. It is separate from cookie consent.
How long we keep things
Your training history has no automatic expiry: activities, health metrics and check-in answers stay until you remove them, delete your account, or archive it. We would rather state that plainly than imply a tidying-up schedule that does not exist. The one category with a fixed limit is security and audit records, which are deleted after twelve months.
Deleting or archiving your account takes effect immediately in the app. We keep rolling database backups for fourteen days on the same server, so a copy of removed data can persist there for up to that long before it ages out. Backups are only ever read to restore the service after a failure.
Security
We protect your data with encryption in transit (HTTPS/TLS), access controls, hashed passwords, and encrypted storage of any linked-device credentials. No method is perfectly secure, but we take measures appropriate to the sensitivity of the data we hold.
Direct marketing
We do not send unsolicited electronic marketing. If we ever introduce marketing, we will only send it where POPIA section 69 permits — with your prior opt-in, and always with an easy way to opt out.
Changes
We may update this notice. The version date at the top changes when we do, so you can tell whether you are reading the same version you read last time. We do not currently notify you in the app when this page changes — if that matters to you, check back here.
Changes to what we store in your browser are different: those bump the cookie-policy version, which asks you to make your choices again rather than carrying forward a decision you made against an older description.