BiblyBibly

Legal

Privacy Policy

How Bibly Limited collects, uses, and protects your personal data under the Hong Kong Personal Data (Privacy) Ordinance.

Effective 25 April 2026 · Version 1.0

This Privacy Policy explains how Bibly Limited (“Bibly”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data when you use the Bibly race registration platform — including the websites at bibly.run and bibly.events, our mobile applications, and any related services (collectively, the “Service”).

Bibly is a Hong Kong-based platform built for runners and race organisers. We are committed to handling your personal data lawfully, fairly, and transparently in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”) and the six Data Protection Principles (“DPPs”) set out in Schedule 1 of the PDPO.

1. Who we are

Bibly Limited is a private company incorporated in Hong Kong and operates as the data user (as defined in section 2(1) PDPO) responsible for the personal data we collect through the Service.

  • Registered entity: Bibly Limited
  • Registered office: [Hong Kong address — to be added]
  • General contact: hello@bibly.run
  • Privacy contact: legal@bibly.run

2. Scope of this policy

This policy applies to all personal data processed by Bibly when you:

  • browse our websites or use our mobile applications;
  • create a Bibly account, runner profile, or organiser account;
  • register for, enter, or pay for an event listed on Bibly;
  • list, manage, or promote an event as a race organiser;
  • subscribe to our newsletter or marketing communications;
  • contact our support team or otherwise communicate with us.

Where Bibly processes data on behalf of a race organiser (for example, the participant list for that organiser’s event), the organiser is the data user for their participant data and their own privacy notice will also apply. Bibly remains the data user in respect of your Bibly account, your runner profile, and any data we use for our own purposes (such as fraud prevention or platform analytics).

3. Personal data we collect

3.1 Information you give us

  • Identity data: first and last name, preferred name, date of birth, gender, nationality.
  • Contact data: email address, mobile number, postal address, country of residence.
  • Account data: username, password (stored hashed), profile photo, communication preferences.
  • Race entry data: event(s) entered, distance/category, estimated finish time, team or club affiliation, T-shirt size, dietary requirements, accommodation preferences.
  • Emergency and safety data: emergency contact name and number, blood type (where an organiser requires it), medical conditions or allergies you choose to disclose.
  • Identification data: HKID, passport, or other government-issued ID number where an organiser is legally required to verify identity (for example, for international events).
  • Payment data: billing name and address, last four digits and brand of payment card. Full card numbers are processed directly by our payment processors and are never stored on Bibly servers.
  • User-generated content: photos, comments, race reviews, and any content you post publicly on the Service.
  • Correspondence: support tickets, emails, and chat messages you send us.

3.2 Information we collect automatically

  • Device and technical data: IP address, device identifiers, browser type and version, operating system, language, time zone, screen size, app version.
  • Usage data: pages or screens visited, features used, search terms, clicks, time on page, referral source, crash logs.
  • Approximate location: derived from your IP address (city / country level) to show you locally relevant events.
  • Precise location: only if you grant permission in our mobile apps (for example, to show events near you).
  • Cookies and similar technologies: see Section 11 below.

3.3 Information from third parties

  • Race organisers who upload participant data to Bibly for an event you have registered for.
  • Payment processors (Stripe, and others) who confirm your payment status and provide fraud signals.
  • Social and fitness platforms (such as Strava, Facebook, or Google) if you choose to log in or link your account — only the data you authorise.
  • Analytics and advertising partners who help us measure and improve the Service.

3.4 Sensitive data

We try to limit our collection of sensitive data. Where you choose to provide health-related information (such as medical conditions, allergies, or blood type) for race-day safety, we treat it with additional safeguards — restricted access, encryption at rest, and disclosure only to your event’s medical team and the relevant race organiser. You are not required to provide sensitive data unless an organiser specifies it as a condition of entry.

4. Purposes for which we use your data

Under DPP1 we collect personal data only for purposes directly related to a function or activity of Bibly, and only the data necessary for those purposes. We use your personal data for the following purposes:

  • Provide the Service: create and operate your account, process race entries, issue bib numbers, deliver tickets and confirmations, list events.
  • Process payments: charge entry fees, issue refunds, prevent fraud, comply with anti-money-laundering and tax obligations.
  • Race-day operations: share required participant data with the relevant race organiser and timing provider so they can run the event safely.
  • Customer support: respond to enquiries, resolve disputes, and improve our help resources.
  • Service improvement: analyse usage, debug, run A/B tests, develop new features, and secure the platform against abuse.
  • Communications: send transactional messages (entry confirmations, race-day instructions, payment receipts) and — only where you have opted in — marketing emails about Bibly and partner events.
  • Legal and compliance: meet our obligations under Hong Kong law, respond to lawful requests from regulators or law enforcement, and enforce our terms.

We will not use your personal data for any new purpose materially different from the above without your prescribed consent (DPP3, section 2(3) PDPO).

5. Consent and choices

Providing personal data to Bibly is voluntary. However, some data is necessary for us to provide the Service — for example, we cannot register you for an event without your name, contact details, and payment information. If you do not provide such required data, we may be unable to complete your registration.

Marketing: we will only send you direct marketing messages if you have opted in. Every marketing email contains a one-click unsubscribe link. You can also turn marketing off at any time in your account settings or by emailing legal@bibly.run. We do not sell or rent your personal data to third parties for their direct marketing.

Withdrawal: you may withdraw consent for any optional processing at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. How we share your data

We share personal data only where necessary and only with parties bound by appropriate confidentiality and data-protection obligations. The categories of recipients are:

  • Race organisers and timing providers for events you have registered for — to produce the start list, allocate bib numbers, manage check-in, record results, and contact you about the event.
  • Payment processors (e.g. Stripe) — to process card transactions and detect fraud.
  • Cloud and infrastructure providers (e.g. hosting, storage, email delivery, error monitoring) acting strictly on our instructions as data processors.
  • Analytics, attribution, and advertising partners (e.g. Google Analytics, Meta Pixel) as described in Section 11.
  • Professional advisers (auditors, lawyers, insurers) where reasonably required.
  • Authorities where disclosure is required by law, court order, or in response to a lawful request from a regulator or law-enforcement agency.
  • Acquirers in connection with a merger, acquisition, or restructuring — subject to this policy continuing to apply to your data.

We do not sell your personal data.

7. Data security

DPP4 requires us to take all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use. We maintain a layered set of technical and organisational measures, including:

  • encryption in transit (TLS 1.2+) for all connections to the Service;
  • encryption at rest for databases and backups;
  • hashed and salted password storage (bcrypt/argon2);
  • role-based access control and the principle of least privilege for staff and contractors;
  • multi-factor authentication for administrative access;
  • network segmentation, firewalls, and intrusion-detection logging;
  • regular vulnerability scanning, dependency patching, and periodic penetration testing;
  • documented backup and disaster-recovery procedures;
  • vendor due-diligence and contractual data-protection clauses with all processors.

No system is perfectly secure. In the unlikely event of a personal-data breach that is likely to result in real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner for Personal Data (“PCPD”) without undue delay, in line with the PCPD’s Guidance on Data Breach Handling and Notifications.

8. How long we keep your data

Under DPP2(2) personal data must not be kept longer than is necessary for the purpose for which it is used. The table below summarises our standard retention periods. We may retain data for longer where we are required by law or where it is reasonably necessary for the establishment, exercise, or defence of legal claims.

Category of dataRetention period
Account profile dataWhile your account is active + 24 months after closure
Race entry records7 years after the event date (tax & accounting)
Payment & invoicing records7 years (Inland Revenue Ordinance)
Marketing preferencesUntil you unsubscribe + 24 months
Support correspondence3 years from resolution
Server, security & audit logsUp to 12 months
Cookies & analytics identifiersSee Section 11 (max 24 months)

9. Your rights under the PDPO

Under DPP6 and Part V of the PDPO you have the right to:

  • Ascertain whether we hold personal data about you;
  • Access the personal data we hold about you, and request a copy (a “Data Access Request”);
  • Correct personal data that is inaccurate (a “Data Correction Request”);
  • Object to or withdraw consent for direct marketing — without charge and at any time;
  • Be informed of the kinds of personal data held and the main purposes of use;
  • Lodge a complaint with the PCPD if you believe your rights have been breached.

To exercise any of these rights, email legal@bibly.run with the subject line “PDPO Request”. We may need to verify your identity before responding. We will respond to a Data Access or Correction Request within 40 days as required by section 19(1) PDPO. A reasonable fee may be charged for compliance with a Data Access Request, in line with section 28 PDPO.

Account deletion: you may close your Bibly account at any time from your settings or by emailing us. We will delete or anonymise your personal data subject to the retention periods in Section 8 and any legal hold.

10. Cross-border data transfers

Bibly is operated from Hong Kong, but some of our service providers (cloud hosting, email delivery, analytics, payment processing) are located outside Hong Kong, including in the European Economic Area, the United Kingdom, the United States, and Singapore.

Where personal data is transferred outside Hong Kong, we take reasonable steps to ensure the recipient affords a level of protection comparable to that under the PDPO — through contractual data-protection clauses, the recipient’s own certifications (such as ISO 27001 or SOC 2), and limiting transfers to what is necessary. We monitor guidance issued by the PCPD on cross-border data transfers and update our safeguards accordingly.

11. Cookies and similar technologies

We and our partners use cookies, local storage, SDKs, and similar technologies to operate the Service, remember your preferences, measure performance, and (with your consent) deliver relevant marketing. The categories we use are:

  • Strictly necessary — required for the Service to function (login session, security, load balancing). Always on.
  • Functional — remember your language, region, and display preferences.
  • Analytics — help us understand how the Service is used (for example, Google Analytics). Set only with your consent in regions that require it.
  • Marketing — used by us and partners (for example, Meta, Google Ads) to measure campaigns and show relevant ads. Set only with your consent.

You can manage cookies through our cookie banner, your browser settings, or — for advertising IDs on mobile — your device’s privacy controls. Disabling certain cookies may affect the functionality of the Service.

12. Children and minors

The Service is intended for users aged 13 and above. Users under 18 must obtain consent from a parent or legal guardian before creating a Bibly account or registering for an event. Some events (for example, marathons or trail-running events) have higher minimum-age requirements set by the organiser — check the event listing before registering.

If you are a parent or guardian and believe your child has provided personal data to us without your consent, please contact legal@bibly.run and we will delete the data unless we are required to retain it by law.

13. Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The “Effective” date at the top of this document indicates when it was last revised. Where changes are material, we will notify you in advance by email or through a prominent notice in the Service. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact us and complaints

Questions, comments, or requests under this policy should be sent to our privacy team:

Bibly Limited — Privacy Team
Email: legal@bibly.run
General: hello@bibly.run
Address: [Hong Kong address — to be added]

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong under section 37 PDPO:

Unit 1303, 13/F, Dah Sing Financial Centre, 248 Queen’s Road East, Wanchai, Hong Kong
Hotline: +852 2827 2827 · Fax: +852 2877 7026
Enquiry: enquiry@pcpd.org.hk
Complaints: complaints@pcpd.org.hk
Website: www.pcpd.org.hk