Privacy Policy — WeRun Maldives Pvt Ltd
Last updated: 11 September 2025
Contact: hello@werunmaldives.com
WeRun Maldives Pvt Ltd (“WeRun,” “we,” “our,” “us”) is committed to protecting your personal information.
1) What we collect
-
Account & profile: name, email, phone, date of birth, gender (optional), emergency contact.
-
Event data: registrations, categories, bib numbers, run times, results, photos/videos.
-
Payments: cardholder name, masked PAN (last 4), transaction ID, and token references from our payment processor. We do not store full card numbers, CVV, or 3-D Secure data on our servers. (PCI-DSS baseline controls apply to environments that store/process/transmit card data.
-
Technical data: IP address, device/browser info, cookies, analytics.
2) How we use information
-
Register you for events; issue confirmations and receipts.
-
Publish non-sensitive event results (e.g., name, category, time) where events indicate results will be public.
-
Process payments and fraud checks, including EMV® 3-D Secure (Mastercard Identity Check) where supported.
-
Operate, secure, and improve our site/app; comply with law.
3) Payments & processors
-
Card payments are processed through our acquiring bank via Mastercard payment gateway services (e.g., MPGS) or an equivalent PCI-validated processor. The processor acts as our payment service provider and tokenizes card data for reuse where you opt to save a card. (Mastercard Rules & security standards govern participants processing Mastercard transactions.)
-
Security capabilities & transmission policy: Card details are transmitted over TLS/SSL directly to our processor; we follow gateway and PCI guidance to protect payment data. We do not store full card numbers or CVV on WeRun systems. (PCI DSS; typical acquirer website disclosure requirements.
4) Stored cards (tokenization)
If you choose “save card,” you explicitly consent to us and our processor storing payment credentials (as a token) for future one-time fees or scheduled charges you authorize (e.g., future event registrations). You may remove a saved card anytime from your account or by contacting us. (Card brands require clear disclosure and consent for stored credentials.)
5) Sharing
We share data only with service providers under contract (payments, hosting, analytics, email/SMS, results timing/photography) and as required by law. We don’t sell personal data.
6) International transfers
Our providers may process data in multiple jurisdictions subject to contractual safeguards.
7) Data retention
Account, registration, and transaction records are retained as legally required and for legitimate business needs (tax/audit, dispute handling). Saved card tokens are retained until you delete them or your account is closed.
8) Your rights
You can access, correct, delete, or export your data; withdraw marketing consent; and request deletion of saved cards. Contact hello@werunmaldives.com.
9) Cookies & analytics
We use necessary cookies and optional analytics. You can manage preferences in your browser or our banner (where available).
10) Changes
We’ll post updates here with a new “Last updated” date.