Our Commitment to Your Privacy
This page outlines how we collect, use, and protect your personal data, ensuring full transparency about our privacy practices.
Version 1.0 — 4 September 2026
This notice covers Cairn, event management software provided by Creed Apps (“we”, “us”, “ours”).
1. The most important thing on this page
Cairn holds two different kinds of information, and different people are responsible for each.
Your account. Your name and email address, and the record of your activity in the app. We are responsible for this.
The event’s data. Participants, crew, checkpoints, timings, welfare notes — everything an organiser puts into Cairn to run their event. The event organiser is responsible for this. We only hold and process it on their instructions, under a written agreement with them. We do not decide what goes in, who sees it, or how long it stays.
In data protection language: we are the controller of your account, and a processor for the event’s data.
What this means in practice: if you want to know what an event holds about you, or want it corrected or deleted, ask the organisation running that event. If they need our help to answer you, we will give it.
2. What we collect, and why
| What | Why | Basis |
|---|---|---|
| Name, email address | To create your account and let you sign in | Performing our contract with you |
| Which events and role you hold | To show you the right thing and stop you seeing what you should not | Performing our contract with you |
| Activity records — what you logged and when | So an event has an accurate, attributable record; and so we can investigate faults | The organiser’s legitimate interest in an accurate event record |
| Technical logs — errors, sign-ins | To keep the service working and secure | Our legitimate interest in a service that works |
We do not use your information for advertising, we do not profile you, and we do not sell it. Cairn shows no ads.
3. Location
Cairn does not track your location. It asks which checkpoint you are at and you answer by tapping — the app never reads your device’s GPS to decide where you are. Where you say you are is recorded, because an event needs to know; where you actually are is not collected at all.
4. Where it is stored
The event’s data is stored in the United Kingdom. Participants, crew, checkpoints, timings, welfare notes — all of it sits in Cairn’s database in Google’s London region (europe-west2), and the server functions that act on it run in the same place.
Sign-in details are stored in the United States. Cairn uses Firebase Authentication to sign you in, and Google runs that service only from US data centres — there is no option to run it anywhere else. It holds your email address, an internal user reference, and the times you signed in. It holds nothing about an event, a participant, or anything you logged.
Google is certified under the UK Extension to the EU–US Data Privacy Framework, and our agreement with Google incorporates the UK International Data Transfer Addendum. Those are the legal mechanisms covering that transfer.
Our subprocessors:
- Google (Firebase / Google Cloud) — database and server functions in the United Kingdom; sign-in service in the United States.
The app’s files are delivered through Google’s global content delivery network. It serves the same files to everyone and holds no personal information.
We will tell organisers before adding or changing a subprocessor.
5. How long it is kept
Event data is kept for as long as the organiser tells us to, and deleted or returned when their agreement with us ends or when they ask. Retention is their decision, not ours — ask them.
Your account is kept while you have access to at least one event, and deleted when you ask us to.
6. Who else sees it
Other people working on the same event, according to the role the organiser gave you. A checkpoint crew member sees what they need to log a participant; a lead sees more; an organiser sees the event.
Outside that: nobody, except our subprocessors above, and where the law requires it.
7. Your rights
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to what we are doing with it, or ask us to restrict it.
For your account, ask us: info@creedapps.uk. We will reply within one month.
For an event’s data, ask the organisation running that event — see section 1.
If you are unhappy with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk.
8. Children
Cairn is for event crew and organisers, and is not intended for anyone under 16. Participant records are entered by organisers and may relate to entrants of any age permitted by the event.
9. Changes
If we change this notice materially we will tell affected organisers, and the version and date above will change.
10. Contact
If you have questions about this Privacy Policy or your data Contact Us



