Privacy Policy
MatchRox (“MatchRox,” “we,” “us,” or “our”) helps HYROX athletes find doubles partners, align on strategy, and prepare for race day. This Privacy Policy explains what personal information we collect through the MatchRox iOS app and related services (the “Service”), how we use it, who we share it with, and the choices and rights you have.
MatchRox is not intended for children under 18. If you are under 18, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
Account & profile: name, email, password, date of birth, gender (optional), city/region, profile photo, HYROX division, age group, and goal race times.
Athlete data: running pace, race history, splits, preferred roles, communication style, availability, favorited partners, and notes.
Messages & invites: content of invites, acceptances, declines, and in-app messages between you and other athletes.
Payments: if you subscribe, your payment is processed by Apple via the App Store. We receive a subscription status, not your full payment details.
Support communications: anything you send us at support@matchrox.com.
1.2 Information Collected Automatically
Device and app data: device model, iOS version, app version, language, time zone, crash logs, and diagnostic data.
Usage data: screens viewed, features used, search filters, matches viewed, invites sent, and in-app interactions.
Approximate location: derived from IP address for fraud prevention and regional event surfacing.
Precise location: only with your permission (“While Using”), to show nearby athletes, gyms, and races.
Identifiers: a MatchRox user ID, and (with your ATT consent) Apple’s IDFA for measurement.
1.3 Information from Third Parties
Apple Health (HealthKit): with your explicit permission, workouts, running pace. Health data is treated as sensitive and is never used for advertising, never sold, and never used to train third-party AI models.
Founding gyms: if you join MatchRox through a founding gym, the gym may share your name, email, and basic athlete info so we can pre-populate your profile (with your consent).
HYROX public results: we may ingest publicly posted race results to enrich athlete profiles with verified times.
2. How We Use Your Information
We use your information to:
Create and secure your account, verify your identity, and prevent fraud or abuse.
Power the Doubles Synergy Engine — match you with compatible partners, generate fit scores, role splits, pacing targets, and race-day plans.
Enable messaging, invitations, and shared planning with athletes you connect with.
Surface nearby athletes, gyms, and events based on your location and preferences.
Process subscriptions, free trials, and Race Strategy Pack purchases.
Send transactional notifications (invites, messages, race reminders) and, with consent, product updates.
Measure and improve the Service — analytics, debugging, and feature research.
Comply with legal obligations and enforce our Terms of Service.
3. Pre-Release Versions (Private Alpha and Public Beta)
MatchRox is launching in two sequential pre-release phases: a Private Alpha (invitation-only) and a Public Beta. During pre-release, we may collect additional diagnostic, telemetry, and crash data to identify and fix defects. Pre-release versions may be modified, suspended, or discontinued without notice and may behave differently from the generally-available product. Your participation is governed by the MatchRox End User License Agreement (EULA), which includes confidentiality obligations for Private Alpha participants.
4. How We Share Information
4.1 With Other Athletes
Your profile is visible to other MatchRox athletes so they can match with you. You control what’s visible — see Section 7. Certain fields (email, phone, exact location, full date of birth) are never shown to other athletes.
4.2 With Your Doubles Partner
When you accept an invite, you and your partner share a planning workspace. Your partner can see fields you approved for sharing (e.g., pacing data, availability, race strategy, messages).
4.3 With Service Providers
We share limited data with vendors who help us run the Service under written contracts that restrict their use of your data. Categories include cloud hosting, analytics, crash reporting, customer support, email/push delivery, and payment processing.
4.4 With Founding Gyms
If you join through a founding gym, we share aggregate participation metrics with that gym. Individual profile is shared only with your explicit consent.
4.5 Legal and Safety
We may disclose information to comply with law, respond to valid legal process, protect the rights, safety, or property of MatchRox, our users, or the public, and investigate fraud or abuse.
4.6 Business Transfers
If MatchRox is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy.
4.7 What We Do Not Do
We do not sell your personal information.
We do not share your personal information for cross-context behavioral advertising.
We do not use Apple Health data for advertising, marketing, or to train third-party AI models.
5. Apple Health (HealthKit) Data
If you choose to connect Apple Health, MatchRox may access limited workout information, such as activity type, workout date, duration, and distance. We do not access broader health metrics such as heart rate, cadence, zones, or sleep through this integration. Apple Health data is collected only with your separate HealthKit permission and is used only for workout tracking, accountability features, and related athlete-profile functionality.
It is never displayed publicly, never sold, never used for advertising, and never used to train third-party AI models. If you choose to enable sharing, it is shared only with your active partners. You can disconnect Apple Health at any time through your device settings and stop sharing within the MatchRox app.
6. Injury & Health Status Disclosure
MatchRox lets you record injury information using structured fields, such as body part and severity, so active partners can plan realistically. We do not collect medical records, diagnoses, medications, or free-text injury notes through this feature. Injury information is treated as sensitive data and is disclosed only with your explicit consent.
Opt-in only: injury fields are private by default. Nothing is disclosed to other athletes unless you choose to enable sharing.
Sharing controls: for each injury entry, you can choose whether it remains Private, visible only to you, or Shared, visible to your active partners. At this time, MatchRox does not allow you to choose specific partners or specific races for an injury disclosure. If you enable sharing for an injury entry, that entry will be visible to all of your active partners. Injury information is never displayed on your public profile or shown to potential matches during browsing.
Purpose limitation: injury disclosures are shared only with your active partners and are used solely to support race planning, training coordination, and awareness of your current physical limitations. MatchRox does not use injury information for matching, pacing recommendations, role splits, profiling, fit scores, or automated decision-making. Injury information is never used for advertising, never sold, and never used to train third-party AI models.
Withdraw anytime: you can edit, hide, or delete any injury entry at any time from Profile → Health → Injuries. If you turn sharing off or delete an injury entry, future sharing stops. Previously shared information may remain visible to active partners until it is refreshed, expires, or is removed from their active view.
Explicit consent: the first time you enable sharing of an injury entry, MatchRox will show a separate consent prompt describing what will be disclosed and that it will be visible to all of your active partners. You must affirmatively accept before any disclosure occurs.
Retention and expiry: each injury entry expires 90 days after creation. A daily background process automatically resolves expired entries and marks them as auto-expired for audit trail purposes. Injury data is permanently deleted after 1 year.
Because injury information can reveal details about your physical or mental health, it may be treated as special category data under GDPR Article 9 and as sensitive personal information under applicable U.S. state privacy laws. Where required, we rely on your explicit consent as the legal basis for processing and sharing this information, and you may withdraw that consent at any time without affecting the lawfulness of prior processing.
7. Data Retention
We retain your personal information for as long as your account is active and as needed to provide the Service. When you delete your account, we delete or anonymize your personal information within 30 days, except where we must retain it for legal, tax, fraud prevention, or dispute resolution purposes. Backups are purged within 90 days.
8. Your Choices and Rights
8.1 In-App Controls
Profile visibility: hide from the athlete directory, restrict fields, or pause matching.
Permissions: toggle Health, Location, Camera, Contacts, Notifications, and Tracking in iOS Settings.
Communications: unsubscribe from marketing emails; transactional messages cannot be disabled while your account is active.
8.2 Privacy Rights
Depending on where you live, you may have the right to:
Access a copy of your personal information.
Correct inaccurate or incomplete information.
Delete your personal information.
Port your data in a machine-readable format (JSON or CSV).
Object to or restrict certain processing.
Withdraw consent for processing based on consent.
Opt out of “sales” or “sharing” as those terms are defined under U.S. state privacy laws (MatchRox does not engage in either).
Exercise any of these rights via Settings → Privacy → Request, or email privacy@matchrox.com. We will verify your identity before acting on requests involving sensitive data.
9. International Data Transfers
MatchRox is operated from the United States and is currently offered solely to users physically located in the fifty (50) United States and the District of Columbia. Personal information is processed in the United States and may also be processed by service providers in other countries that maintain comparable safeguards.
10. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, encryption at rest for sensitive fields, access controls, and regular security reviews. No system is perfectly secure, and we cannot guarantee absolute security.
11. Children’s Privacy
MatchRox is not directed to persons under 18, and we do not knowingly collect personal information from anyone under 18. At account creation, users are required to certify that they are at least 18 years old. Accounts that we reasonably believe were created by, or are being used by, a person under 18 will be terminated. If you believe a person under 18 has provided personal information to us, contact privacy@matchrox.com and we will promptly delete it.
12. Third-Party Services
The Service may link to or integrate with third-party services (e.g., Apple Health, HYROX event websites, Apple App Store). Their privacy practices are governed by their own policies, which we encourage you to review.
13. California Privacy Notice
In the past 12 months, MatchRox has collected the following categories of personal information: identifiers, customer records, internet and device activity, geolocation, health-related information (with consent), inferences, and commercial information. We collect this information for the business purposes described in Section 2. We do not sell or share personal information for cross-context behavioral advertising. California residents have rights to know, delete, correct, limit use of sensitive personal information, and are entitled to non-discrimination for exercising these rights.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you in the app or by email before the changes take effect. The “Last Updated” date above indicates when the Policy was last revised.
15. Contact Us
Privacy Inquries: privacy@matchrox.com
Support Contact: support@matchrox.com