Privacy / Policy
Privacy Policy
20 August 2026
1. Our Privacy Commitment
Runner Geeks is committed to protecting your personal data. We built our AI-powered photo search platform with privacy by design principles. Our four core commitments:
- Data Minimization — We only collect data that is strictly necessary to provide face photo search services.
- No Data Selling — We never sell your personal data to third parties.
- No Targeted Advertising — We do not use personal data for behavioral advertising.
- Full Transparency — Every data processing activity is clearly explained in this policy.
2. Information We Collect
2.1 Data You Provide
| Data Type | Purpose | Required? |
|---|---|---|
| Email address | Account registration, login, search notifications | Yes |
| Display name | User profile | Yes |
| Profile photo | Account personalization (optional) | No |
| Photo (one-off search) | Used as face search query | Conditional |
| Face ID reference photos (5 photos) | Face template for search and auto-surfacing on event pages | Conditional |
| Order & payment details | Process photo purchases, transaction history | Conditional |
| Destination bank / e-wallet account | Seller balance withdrawal | Conditional |
2.2 Automatically Collected
| Data Type | Purpose |
|---|---|
| IP address (anonymized) | Internal analytics, security |
| Browser User-Agent | Display optimization |
| Pages visited | Usage analytics |
| Referer URL | Traffic source analytics |
| Access time | Analytics, audit log |
| Device type | Responsive optimization |
2.3 Face Recognition Pipeline Data
Runner Geeks uses a face recognition pipeline to find your photos in race event collections. Here is the processing flow:
What IS stored:
- Face data from your photo (used for search)
- Face ID reference photos (5 angles) and their embeddings, while the Face ID is active
- Face data from event collection photos (created during indexing)
- Bounding box and face landmarks (for result previews)
- Photo metadata (source URL, event, timestamp)
What is NOT stored: We never store your original photos — only numerical face templates.
- Original event collection photos — platform only stores source URLs
- One-off search photos after embedding is created (deleted from system)
- Raw biometric data — data is a numerical representation, not an image
Face ID & auto-surfacing:
Once a Face ID is saved, event pages run the search with the face data we already have on our servers. Your face photos are not re-uploaded from your browser. While a Face ID is active, this automatic search always runs on event pages.
2.4 Data from Event Organizers
Race event organizers may upload photo collections to the platform. Data received from organizers includes:
- Large volumes of event photos (thousands to millions)
- Photo metadata (timestamp, location, BIB number if available)
- Event name, date, and location
Organizers warrant that they have the legal right or permission to upload such photos.
2.5 Role Request Data
When you apply for the photographer or event organizer role, we store the following application data:
- Application reason
- Portfolio URL (portfolio_url) — for photographers
- Organization name (organization_name) and organization website (website) — for event organizers
- Terms of service acceptance (accepted_terms)
- Admin notes (admin_notes) and processing time (processed_at) after review
- Creation time (created_at)
Role request data is stored for as long as your account is active and is deleted automatically together with your account (ON DELETE CASCADE).
3. Legal Basis
We process your personal data under the following legal bases pursuant to the UU PDP:
| Legal Basis | UU PDP Article | Processing Example |
|---|---|---|
| Explicit consent | Article 20(1) | Photo upload, account creation |
| Legitimate interest | Article 20(2) | Usage analytics, platform security |
| Contract performance | Article 20(1) | Photo search processing |
4. Processing Purposes
We process your personal data for the following purposes:
Primary Purposes:
- Providing face recognition-based photo search services
- Automatically surfacing the User's photos on event pages (auto-surface) based on Face ID
- Displaying Face ID stats: matches found, events scanned, and profiles waiting for processing
- User account registration and management
- Displaying relevant search results
- Sending search result notifications (email)
- Processing photo purchases, payments, fund settlement, and balance withdrawal
Supporting Purposes:
- Internal analytics to improve service quality
- Platform security and abuse prevention
- Compliance with legal obligations
- Audit logs for accountability
What we DON'T do:
- No targeted advertising
- No selling data to third parties
- No marketing profiling
- No sharing of face data between users
5. Storage & Retention
We retain your data only as long as necessary for the stated purposes. Retention periods are as follows:
| Data Type | Duration | Basis |
|---|---|---|
| Email, name | While account is active | Service delivery |
| One-off search photo | Discarded after embedding is created | Data minimization |
| Face ID reference photos | While the Face ID is active | User consent |
| Face data | Account active + 90 days | Repeated searches |
| Search results | 30 days | Search history |
| Page visits | 12 months (aggregate) | Analytics |
| Server logs | 90 days | Security |
| Email logs | 90 days | Delivery |
| Order & payment details | 7 years | Tax & bookkeeping compliance |
After account deletion, all related data will be deleted or anonymized within 90 days. Exception: transaction history (orders, payments, and wallet balances) is retained to meet bookkeeping and tax requirements.
6. User Rights
The UU PDP grants you the following rights as a data subject:
6.1 Right of Access
You have the right to know what personal data we process. Send requests to privacy@runnergeeks.id. We will respond within 3×24 hours.
6.2 Right to Rectification
You may correct inaccurate data via account settings or by contacting support@runnergeeks.id.
6.3 Right to Erasure
You may request deletion of your account and personal data via the Accounts → Privacy → Request deletion page, or email privacy@runnergeeks.id. The request is reviewed by our team before it is processed.
6.4 Right to Restriction
Under certain conditions, you may request restriction of data processing. Contact privacy@runnergeeks.id.
6.5 Right to Data Portability
You have the right to receive your personal data in a commonly used structured format. Send requests to privacy@runnergeeks.id.
6.6 Right to Withdraw Consent
You may withdraw consent at any time without affecting the lawfulness of prior processing. Do so via account settings or email privacy@runnergeeks.id.
6.7 Right to Complain
If you believe your rights have been violated, you may file a complaint with the Ministry of Communication and Digital Affairs (Kominfo) at kominfo.go.id.
8. International Data Transfers
We limit international data transfers to the maximum extent possible. The following services may involve data transfers:
| Service | Location | Data | Safeguards |
|---|---|---|---|
| Google / Firebase (auth) | Global (GCP) | Email at login | SCC, TLS encryption |
| Cloudflare (CDN) | Global edge | Static content (anonymous) | Edge caching, TLS |
| AI Processing | Local | No transfer | 100% on-premise |
Local AI Processing:
All face recognition processing (detection, embedding, vector search) runs 100% on our own servers. No facial data is sent to third-party APIs for AI processing. AI models run locally with no external connection.
9. Third-Party Data Sharing
We share your personal data only in the following limited situations:
What IS shared:
- Email provider (SendGrid) — For notification emails. Data: email address.
- Cloudflare — For CDN and edge security. Data: anonymized IP address.
- Event organizers — Only photo metadata and search results belonging to the requesting user, upon user request.
- Third-party payment provider (e.g., Midtrans) — To process photo purchase payments. Data: order number, payment amount, payment method.
- Organizers & photographers (settlement) — For disbursing photo sale revenue. Data: photo sale summary, withdrawal destination account.
What is NOT shared:
- We never share face data with third parties.
- We never share data with advertising companies.
- We never share data with government entities unless required by law.
- We never share data between users.
- Full payment data (card number, etc.) — only handled by the payment provider, never stored by us.
10. Data Security
We implement technical and organizational security measures to protect your personal data:
| Layer | Technology | Details |
|---|---|---|
| Transit encryption | TLS 1.3 | All HTTPS connections |
| At-rest encryption | AES-256 | Database server |
| Authentication | JWT (15 min access, 30 day refresh) | Time-based tokens |
| Authorization | Role-based (user, organizer, admin) | Every endpoint verified |
| Audit log | Activity + IP + User-Agent | All operations logged |
| Firewall | Cloudflare WAF + OS firewall | Edge + server level |
| Embedding | Numerical data (not image) | Cannot be reconstructed into photo |
| Input validation | All endpoints | Prevent SQL injection/XSS |
AI Model Security:
Face recognition models run on our servers with no outbound internet connection. No facial data is sent to external cloud AI services. Models are downloaded once during deployment and run fully offline.
Security Incident Procedure:
In the event of a data breach affecting personal data, we will:
- Identify and secure the breach source within 1×24 hours
- Notify affected data subjects within 3×24 hours
- Report to Kominfo as required by UU PDP
- Conduct forensic investigation and remediation
11. Children's Privacy
Runner Geeks services are not intended for children under 13. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13 without parental consent, we will delete such data promptly. If you believe your child has provided us with personal data, contact privacy@runnergeeks.id.
12. Policy Changes
This privacy policy may be updated from time to time. We will notify users of material changes via email or platform announcement.
Minor changes: Do not require special notice (e.g., grammar fixes, added examples).
Material changes: Requires 14 days notice before effective date.
Change History
| Version | Date | Changes |
|---|---|---|
| v1.0 | July 15, 2026 | Initial policy |
| v1.1 | August 4, 2026 | Added transaction, payment, fund settlement, and withdrawal data |
| v1.2 | August 20, 2026 | Face ID feature and auto-surfacing on event pages; unified payment checkout (Snap and 3D Secure credit cards); account deletion request flow |
13. Contact & Complaints
13.1 Contact Us
If you have questions, concerns, or wish to exercise your rights, contact us:
| Purpose | Response | |
|---|---|---|
| Privacy questions | privacy@runnergeeks.id | 3×24 hours |
| Account support | support@runnergeeks.id | 2×24 hours |
| Purchase/payment help | billing@runnergeeks.id | 2×24 hours |
| Data Protection Officer | dpo@runnergeeks.id | 1×24 hours |
Address: Runner Geeks, Indonesia
13.2 Complaint Procedure
- Contact our DPO at dpo@runnergeeks.id — we will respond within 24 hours.
- We will investigate and provide a written response within 7 business days.
- If unsatisfied with our response, you may contact support@runnergeeks.id for escalation.
- If still unresolved, you have the right to file a complaint with Kominfo: kominfo.go.id
13.3 Data Protection Officer
We have appointed a Data Protection Officer (DPO) who can be contacted for all privacy and personal data related inquiries:
Email: dpo@runnergeeks.id
This document was last updated: 20 August 2026