Legal
Last updated: 16 Sep 2026
HyPair is a mobile app that helps athletes find doubles partners for hybrid races — HYROX and Tryka. This policy explains exactly what personal data we collect, why we collect it, who we share it with, and what rights you have over it. Questions? Email us at hello@hypair.app.
HyPair is operated by HyPair Ltd (registered as HYPAIR LIMITED, Company No. 819983), a private limited company incorporated in Ireland. When this policy refers to "HyPair", "we", "us" or "our", it means HyPair Ltd.
For the purposes of the EU General Data Protection Regulation (GDPR), HyPair Ltd is the data controller for all personal data collected through the HyPair app and website (hypair.app).
Contact: hello@hypair.app · HyPair Ltd · Ireland
Legacy waitlist data — before the app launched, joining the waitlist at hypair.app collected your email address and which race format you were training for (HYROX or Tryka). The waitlist was retired once both iOS and Android launched, and all historical waitlist entries were deleted on 14 Sep 2026. No waitlist data is currently collected or stored.
Account data — when you register, we collect your email address and a password. Passwords are stored as a secure one-way hash (bcrypt) and are never stored or transmitted in plain text.
Profile data — to help you find race partners, you provide: first and last name, date of birth, gender, profile photo, city/country, training pace, personal best times, race formats you compete in, training frequency, and a short bio. Date of birth is used for an age check and gender for HYROX/TRYKA competition category matching. All profile fields beyond name, email, date of birth, and gender are optional.
Event data — races you have registered for, your preferred format (doubles/mixed doubles), and your target wave time.
Matching and messaging data — partner requests you send or receive, the outcome (accepted/declined), and messages exchanged with matched athletes inside the app.
Usage and analytics data — which screens you visit, errors and crashes, basic device information (OS version, device type), and in-app activity events tied to your account (e.g. onboarding progress, match requests sent/received, and safety actions like blocking or reporting another user). We use this to fix bugs, understand where users get stuck, and enforce our Terms of Service. We do not sell this data.
Push notification token — if you grant permission, we store a device token to send you match alerts and chat notifications. You can revoke this at any time in your device settings.
Device location — if you tap the "Nearby" filter on the Events screen and grant location permission, we request a one-time, approximate (not precise) location fix from your device to sort/filter events by distance from you. We do not store this location or track it in the background — it's used only in the moment, on your device, to filter the list you're viewing. You can deny or revoke location permission at any time in your device settings; the app works fully without it.
Gym owner data — if you set up a gym profile, we collect your gym's business name, address, phone number, website, and Instagram handle.
Athlete data entered by a gym owner — a gym owner organising an event can manually add a non-app athlete's name, pace, and race format for their own event management. This is data about a third party, not about you if you're the athlete in question and haven't created an account — if you believe a gym has added your details and want them removed, contact hello@hypair.app.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the matching and messaging service you signed up for | Contract performance (Art. 6(1)(b)) |
| Sending transactional emails (verification, reset, match alerts) | Contract performance (Art. 6(1)(b)) |
| Improving the app, fixing bugs, preventing abuse | Legitimate interests (Art. 6(1)(f)) |
We do not sell your personal data. We do not share it with advertisers. We share data only with the following data processors, all of whom are bound by data processing agreements:
| Processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage (profile photos) | US (data hosted in Switzerland) | Standard Contractual Clauses (SCCs) |
| Resend Inc. | Transactional email — verification, password reset, match notifications | US | Standard Contractual Clauses (SCCs) |
| Vercel Inc. | Hosting of the hypair.app website, plus cookieless Web Analytics (aggregate page-view counts only — no personal data, no cookies, no cross-site tracking) | US (CDN globally distributed) | Standard Contractual Clauses (SCCs) |
| Porkbun LLC | Email routing (hello@hypair.app), DNS, security | US | Standard Contractual Clauses (SCCs) |
| Expo / EAS (Expo Inc.) | Mobile app distribution and push notification delivery | US | Standard Contractual Clauses (SCCs) |
| Sentry (Functional Software, Inc.) | Crash and error reporting — tied to the screen/action where an error occurred, not directly to your name or email | US | Standard Contractual Clauses (SCCs) |
| Other app users | Your public profile (name, photo, bio, pace, race formats) is visible to other authenticated athletes browsing for partners. Your email address is never shared with other users. | N/A | N/A |
Several of our processors are based in the United States. The US does not have an EU adequacy decision for all transfers. Where we transfer personal data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, which provide equivalent protection to data held within the EU.
Supabase hosts your data on AWS's eu-central-2 region (Zurich, Switzerland).
You can request a copy of the relevant SCCs by emailing hello@hypair.app.
Once your profile is approved, it's visible to any other authenticated HyPair user, not only people registered for the same event — event-based partner search is how most people will actually find you, but it isn't a hard access boundary. Only signed-in users can view profiles — unauthenticated visitors cannot access any profile data.
You control what appears on your profile by editing it in the app. You won't appear in partner search for a specific event unless you've registered for it, but your profile itself isn't restricted to only those you share an event with. If another user blocks you, your profile is hidden from them (and theirs from you) in both directions. Deleting your account removes your profile from partner search immediately.
If you are in the EEA or UK, you have the following rights. To exercise any of them, email hello@hypair.app. We will respond within 30 days.
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights. To exercise any of them, email hello@hypair.app. We will respond within 45 days.
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) — and, if you are a Quebec resident, Quebec's Act respecting the protection of personal information in the private sector ("Law 25") — give you the following rights. To exercise any of them, email hello@hypair.app. We aim to respond within 30 days.
HyPair Ltd (see Section 1) is the organisation responsible for compliance with PIPEDA and Law 25 for the personal information described in this policy; direct any privacy questions or concerns to hello@hypair.app in the first instance. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or, if you are a Quebec resident, the Commission d'accès à l'information du Québec.
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles (APPs) give you the following rights. To exercise any of them, email hello@hypair.app. We aim to respond within 30 days.
Your data may be disclosed to and stored by overseas recipients as part of our use of Supabase (see Section 4 and Section 5 above for exactly which processors and locations) — we take reasonable steps to ensure those processors handle your data consistently with the APPs, including data processing agreements. If you believe we have not handled your personal information in line with the APPs, you can complain to us at hello@hypair.app first, and if unresolved, to the Office of the Australian Information Commissioner (OAIC).
If you are in South Africa, the Protection of Personal Information Act (POPIA) gives you the following rights. To exercise any of them, email hello@hypair.app. We aim to respond within 30 days.
HyPair Ltd is the responsible party (as that term is used in POPIA) for the personal information described in this policy. If you believe we have not handled your personal information lawfully, you can complain to us at hello@hypair.app first, and if unresolved, to South Africa's Information Regulator.
HyPair is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. During registration, users must confirm they are 18 or older.
If we become aware that a user is under 18, we will delete their account and all associated data immediately. If you believe a child has created an account, please email hello@hypair.app and we will act within 48 hours.
The HyPair website (hypair.app) sets no browser cookies at all — it does not sit behind a CDN/security layer like Cloudflare, and we do not use tracking, advertising, or analytics cookies. We do use Vercel's cookieless Web Analytics to count aggregate page views — see our Cookie Policy for details.
The HyPair mobile app does not use cookies. It uses a secure session token stored in the device's secure storage (not accessible to other apps).
We may update this policy as the app evolves and as we add new processors or features. We will notify active users of any material changes via email or an in-app notice at least 14 days before the change takes effect. The "last updated" date at the top of this page always reflects the current version.
Continued use of HyPair after a notified change constitutes acceptance of the updated policy.
For any questions about this policy, your data, or to exercise your rights:
Email: hello@hypair.app
Company: HyPair Ltd · Ireland
Response time: within 30 days for all GDPR requests