Privacy Policy
Last updated: 14 July 2026
1. Who we are
The time-monkey.com platform (the "Platform") is operated by the service provider named in the Terms of Use ("we"). For platform account data, security, fraud prevention, fiscal/accounting obligations and our own site analytics we act as the data controller. For the personal data of participants of a specific competition, the competition organizer is the controller and we process that data on the organizer's behalf as a processor. Contact: .
2. Data we collect
- Competition registration data: name, date of birth, gender, address, country/region/city, e-mail, phone, club, licence, and answers to additional questions defined by the organizer (e.g. emergency contact, equipment sizes, transport, meals).
- Health notes you voluntarily enter at registration (special category data) — processed solely for your safety at the competition, based on your explicit consent given by entering them; you may always leave the field empty.
- Account data: name, e-mail, password (stored hashed), language.
- Payment data: amount, currency, payment status, invoice/offer number and transaction identifier. Card data is processed exclusively by Stripe — we never see or store it.
- Registration security records (fraud prevention): IP address, browser/device information and the time you accepted the terms.
- Results and start lists: bib number, times, ranking — published publicly as an integral part of the sporting competition.
- Technical data and cookies: server logs (IP, time, page), Google Analytics (visit statistics) and Hotjar (anonymised usage analytics). These tools may set cookies.
- Communication: e-mails we send you (registration confirmations, invoices/offers, notifications) and a log of their delivery.
3. Purposes and legal bases
- processing your registration and participation, collecting the entry fee — performance of a contract (Art. 6(1)(b) GDPR);
- invoicing, fiscalization and accounting — legal obligation (6(1)(c));
- fraud prevention, payment-abuse defence (including unjustified chargebacks) and Platform security — legitimate interest (6(1)(f));
- publication of start lists and results — legitimate interest of the organizer and of public sport (6(1)(f));
- health notes — explicit consent (Art. 9(2)(a));
- promotional messages — consent given at registration, withdrawable at any time;
- site analytics — legitimate interest / consent where applicable.
4. Who we share data with
- The organizer of the competition you register for (controller of that data);
- Stripe (card payments; EU entity, possible US transfers under SCC/DPF);
- hosting provider (EU servers) and e-mail delivery provider;
- Google (Analytics) and Hotjar (usage analytics);
- accounting service and public authorities (tax administration — fiscalization) where required by law;
- banks and card schemes in payment-dispute procedures — we submit registration evidence (entered data, IP, timestamps, accepted terms, service delivered).
We never sell personal data.
5. Retention
- invoices and fiscal records — 11 years (legal obligation);
- registration data and security records — 6 years after the competition (complaint, chargeback and legal-claim periods);
- competition results — permanently, as a sporting archive (on request your name can be anonymised where no overriding interest in publication exists);
- user account — until you delete it;
- analytics — per the tool's settings (GA/Hotjar).
6. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection to processing based on legitimate interest. Consent may be withdrawn at any time. Send requests to ; for a specific competition's data you may also contact the organizer directly. You may lodge a complaint with the Croatian DPA (AZOP, azop.hr) or your local supervisory authority.
7. Account deletion
You can delete your account yourself: My account → Delete account (password confirmation required), or by request to . Deleting the account removes account data; data we are legally required to keep (issued invoices, fiscal records) and published sporting results are retained per section 5.
8. Security
We use TLS encryption in transit, role-based access control, change logging, backups and restricted access to production systems. Passwords are stored only as cryptographic hashes.
9. Changes
We will notify you of material changes through the Platform. Continued use after a change constitutes acceptance.