Legal
Privacy policy
How this service handles personal data. Last updated 23 September 2026.
Who is responsible
DEKA Results API is an independent data product operated from Belgium. It is not affiliated with, endorsed by, or operated by Spartan or DEKA. For anything on this page, including requests to access or delete data, write to [email protected].
If you hold an account
An account exists so you can hold an API key, see your usage and pay for a plan. What is stored is what those three things need and nothing beyond them.
- Name and email address
- To identify the account, address you in the dashboard, and contact you about your keys or billing.
- Password
- Stored only as an Argon2id hash. The password itself is never written down, so it cannot be read out of the database or recovered by us.
- Google account identifier
- Only if you sign in with Google. See the section below.
- Session records
- A hash of the session token, the browser's user-agent string, and an expiry date. Sessions last 30 days. The token itself is not stored.
- API keys
- A hash of the key, its first characters, and the name you gave it. The key itself is shown once and never stored, which is why we cannot recover a lost one.
- Usage counters
- Requests, rate-limited requests and errors per key per day. Counts only — never the queries you ran or the data you received.
- Billing identifiers
- A Stripe customer and subscription id, your plan, and its status.
There is no advertising, no profiling, no behavioural tracking, and no third-party analytics on this site. Nothing about you is sold or shared for anyone else’s marketing.
Signing in with Google
Signing in with Google is optional and sits beside the ordinary email and password form. If you use it, Google tells us three things: a permanent identifier for your Google account, your email address, and your name. That is the whole of the openid email profile scope, and we request nothing else — no contacts, no calendar, no Drive, no access to anything in your Google account.
The identifier is what the account is keyed on, not the email address. Google documents it as permanent for the life of the account, whereas an email address can be changed by its owner or reassigned by a workspace administrator to a different person entirely — and that person should not inherit your API keys.
Revoking access at your Google account permissions stops future sign-ins. It does not delete the account here; email us for that.
Payments
Payments are handled by Stripe. Card numbers are entered on Stripe’s own checkout, never on this site, and never reach our servers. We receive only the identifiers and subscription status listed above. Stripe’s handling of your payment details is covered by Stripe’s privacy policy.
Cookies
One cookie, named deka_session. It holds your sign-in session, is marked httpOnly so no script can read it, and expires after 30 days or when you sign out. It is strictly necessary to keep you signed in, does nothing else, and is not used to track you — which is why this site has no cookie banner rather than why it should have one.
If you are an athlete whose results appear here
This is the section worth reading if you arrived by searching your own name. This service collects race results that event organisers and their timing providers have already published publicly, and reorganises them into one consistent model. It holds your name, the country and home town shown on the published result, the gender and age category the event recorded, and your finishing times, positions and splits.
It does not hold your email address, phone number, postal address, date of birth or any account credential, and it never attempts to collect them. Where an age band is shown, it is the band the event published, not a date of birth we inferred.
You did not enter into an agreement with us, so if you want your results removed, ask and we will remove them. Write to [email protected] with enough detail to identify the right person — a link to one of your results is ideal, because names are not unique. We will confirm when it is done and suppress the record so a later crawl does not restore it.
Removing a result here does not remove it from the event organiser’s own site. That request has to go to them.
Where the data lives, and for how long
Everything runs on a single rented server in Germany, with Cloudflare in front of it. The database is not reachable from the internet. Payments go to Stripe, and Google receives a sign-in request only at the moment you choose to sign in with Google. There are no other processors.
- Account records
- Kept while the account exists, and deleted on request.
- Sessions
- 30 days, then deleted automatically. Changing your password deletes all of them immediately.
- Revoked API keys
- The hash is kept so a revoked key stays revoked.
- Usage counters
- Aggregated per day; the dashboard shows the last 30.
- Race results
- Kept indefinitely — a results archive whose history expires is not an archive — unless removal is requested.
Your rights
Under the GDPR you may ask for a copy of what is held about you, ask for it to be corrected or deleted, object to how it is processed, or complain to a supervisory authority. In Belgium that is the Gegevensbeschermingsautoriteit. Write to [email protected] and you will get an answer within 30 days. There is no charge, and you do not need to give a reason for a deletion request.
Changes
If this policy changes in a way that affects you, the date at the top changes and account holders are emailed. Silent rewrites are not a thing we do.
See also the terms of service and the crawler policy, which explains how this service reads public sources and how to ask it to stop.
