Thunder Sporting Events
Privacy Policy
Effective: 27 May 2026 · Last updated: 16 June 2026
This Privacy Policy explains how Thunder Sporting Events (“Thunder”, “we”, “us”) collects, uses, shares, and protects personal data across our public events, our website thunder.qa, our social accounts, and our athlete/coach/organization platform (collectively, the “Services”).
The data controller is Thunder For Organizing Sporting Events, at City Plaza, Building 59, Floor 3, Office 20, Lusail, Qatar. Contact: info@thunder.qa · +974 6006 3181.
We operate in the State of Qatar, and this policy is governed by Qatari law — in particular the Personal Data Privacy Protection Law (PDPPL), Law No. (13) of 2016, and its executive regulations. This policy explains your rights and our duties under that law.
1. Who this policy covers
Thunder serves two kinds of users: the general public who register for and follow our events, and organizations (sport federations, clubs, schools and academies) who use our platform to manage their athletes — including coaches and, in some organizations, minors. Sections that concern minors and organizations are called out below.
2. Information we collect
- Identity & contact — full name, date of birth, gender, nationality, email, phone, emergency contact, and (for organization members) guardian contact details.
- Registration & medical — event entries, team/club affiliation, and any medical disclosures you provide for safe participation.
- Payment — handled by our payment processor; we do not store full card numbers.
- Race & performance — timing, results, splits, and rankings captured by official timing systems.
- Wearable & wellness (optional) — if you connect a wearable, training and health-related metrics such as heart rate, HRV, sleep, recovery, training load, and body composition.
- Fitness assessments & talent flags (organizations) — fitness-test results and derived talent indicators recorded by coaches.
- Academic calendar (organizations) — term/exam dates and, optionally, an uploaded school-calendar document.
- Photos — profile photos and event photography and video.
- Communications — messages via email, our contact forms, and our Facebook/Instagram accounts.
- Account & device — sign-in identifiers (passwordless magic-link) and basic technical data needed to run the site.
3. How we use your information
- Run events: registration, race packs, bib allocation, timing, results, leaderboards, and certificates.
- Provide the platform: athlete dashboards, coaching and training analysis, organization administration, and (where enabled) AI-assisted summaries.
- Communicate with you: confirmations, results, briefings, and — where you have opted in — coaching summaries and digests.
- Talent development: with consent, surface athlete performance to sport entities for talent discovery (see §6).
- Safety, legal, and operational compliance for public events in Qatar.
4. Legal bases for processing
Under the PDPPL we process personal data on the basis of your consent — the law’s primary basis — and otherwise only where there is a lawful purpose: performing a contract (your registration or membership), meeting a legal obligation, and our legitimate operational purposes consistent with the law. Wearable/health data and minors’ data are “special-nature” personal data under the PDPPL (which lists data on children and health among special-nature data) and receive heightened protection and we process them only with an appropriate basis — for wearable/health data, your opt-in connection of a wearable; for a minor’s data, the explicit guardian consent described in §10. We do not represent that any regulatory permission for special-nature processing has been obtained.
5. Who we share data with
We use trusted service providers (processors) to run the Services. They act on our instructions and only receive the data they need:
- RaceResult — timing and results.
- Fatora — payment processing (Qatar).
- Terra — connecting your wearable/training accounts (transfers wellness data; United States).
- An AI provider (OpenAI-compatible) — generating coaching/federation summaries from athlete names and training metrics, and extracting dates from an uploaded academic-calendar document (United States by default).
- Email delivery (Google / Gmail) — sending transactional and opted-in emails (United States).
- Meta (Facebook/Instagram) — when you interact with our social accounts.
- Sport entities / federations — athlete performance for talent discovery, with consent (see §6).
- Regulators and authorities — where required by law or valid legal process.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
6. Talent discovery & sport entities
Our platform lets sport entities discover athletes by performance (race history and derived metrics). For adults, this uses race and performance data already part of competing publicly. For a MINOR, the talent search shows performance in a DE-IDENTIFIED form by default — the name is hidden and the exact age is shown only as a broad age band — so a minor can be discovered by performance without their identity being exposed. A minor's identity (name and exact age) is revealed, and deeper processing (such as AI analysis or exported reports) is enabled, ONLY where a parent or legal guardian has given explicit, purpose-limited consent, or has approved a specific request — and then only to the requesting sport entity, not across the whole platform. Contact details are released only after a parent or legal guardian approves a reviewed contact request: the request is first reviewed by Thunder, then sent to the guardian, and nothing is shared unless the guardian approves.
7. International data transfers
Some processors are outside Qatar — notably Terra, our AI provider, and Google/Gmail (United States). This means some personal data, including (where applicable) wellness data and names, is processed abroad. Qatar’s PDPPL permits cross-border data flows and does not prohibit them, provided the processing remains lawful under the law and does not expose the data to serious harm; we keep the transfer limited to what the service requires and rely on the provider’s contractual and security safeguards.
8. How long we keep data
In line with the PDPPL, we do not keep personal data for longer than necessary for the purposes for which it was collected. There is no fixed statutory retention period; the periods below reflect that principle.
- Race results and registration records: retained to maintain historical results and to meet record-keeping duties.
- Wearable/wellness and assessment data: kept while your account/membership is active; you can disconnect a wearable and request deletion.
- Aggregated, anonymized statistics: may be kept indefinitely.
9. Your privacy rights
- Access — get a copy of your data. Signed-in users can instantly download their profile, race results, and registrations from “Manage your data” below; request your full record (wearable/wellness, assessments, photos, communications) via the contact below.
- Correction — fix inaccurate data.
- Deletion — request erasure (some records may be retained where the law requires).
- Withdraw consent — opt out of non-essential communications at any time (every such email has an unsubscribe link).
- Object / restrict — object to certain processing.
These rights are those granted to individuals under the PDPPL. To exercise any right, use “Manage your data” below or email info@thunder.qa; we will respond within the period required by the PDPPL and its executive regulations. If you believe we have not handled your data correctly, you may also lodge a complaint with the competent authority responsible for personal-data protection under the PDPPL.
10. Children’s data & guardian consent
A child’s personal data is special-nature data under the PDPPL and is processed only with the explicit consent of the child’s parent or legal guardian. Some events have junior categories, and some organizations (schools/academies) manage minors. A minor’s registration, fitness testing, photos, connecting a wearable or other processing of health data, and any talent-sharing each require that guardian consent, recorded per scope — and a minor cannot connect a wearable until guardian consent is on record. A guardian may, at any time, withdraw consent, request a copy of the child’s data, and request its deletion. We do not knowingly collect a child’s data without guardian consent. (Under Qatari law the age of majority is 18.)
11. Marketing emails & unsubscribe
Consistent with the PDPPL’s rules on direct marketing, non-transactional marketing emails (e.g. coaching summaries, digests) are sent only where you have given prior consent, always identify the sender, and carry a working one-click unsubscribe through which you can stop them or withdraw consent; unsubscribing is honored before the next send. Transactional emails (sign-in links, registration confirmations, results, certificates) are part of the Services and are not marketing.
12. Cookies
We use a small number of essential cookies (e.g. your language and current organization). We do not run third-party advertising or tracking pixels. You can disable cookies in your browser; some features may not work.
13. How we protect your data
We use administrative, technical, and physical safeguards, transmit data over encrypted (HTTPS) connections, and isolate each organization’s data. No system is perfectly secure, so we cannot guarantee absolute security.
14. Data breaches
If a personal-data breach occurs, we will assess it and — where, under the PDPPL, it may cause serious harm to the data or to individual privacy — notify the affected individuals and the competent authority as the law requires.
15. Changes & contact
We may update this policy; material changes will be posted here with a new date. Questions or requests: info@thunder.qa · +974 6006 3181 · City Plaza, Building 59, Floor 3, Office 20, Lusail, Qatar.