Privacy policy
Last updated: 8 September 2026
Who we are
Marshal is operated by Wiltech Solutions (Pty) Ltd, a company registered in South Africa ("we", "us").
Marshal lets an event organiser see participants' live position and vitals during an organised activity. Data reaches us from a Connect IQ data field installed on a participant's own Garmin watch or bike computer.
Marshal is used worldwide. We are based in South Africa and event data is stored in the European Union, so this policy is written to South Africa's POPIA and the EU and UK GDPR, and we apply that same standard to everyone. Where the law where you live gives you more than this policy describes, you keep it.
Who is responsible for what
Two different sets of personal information pass through Marshal, and we are not in the same role for both. This decides who you go to when you want something done about your data.
| An event's participant data positions, heart rate, pace, display names |
The event organiser is the controller. They decide the event exists, who is invited, who sees the dashboard, and when it is closed and deleted. We are their processor: we hold and move that data on their instructions and for no purpose of our own. Their obligations are set out in our organiser terms. |
| Organiser account data email address, authentication, the events created |
We are the controller. We decide what is needed to run the service, keep it secure and reach account holders. |
POPIA calls a controller the responsible party and a processor the operator. The roles are the same either way.
What we collect
While a participant is recording an activity with Marshal running, their device sends us:
| Location | Latitude and longitude, and altitude |
| Health data | Heart rate — optional, and off if the participant turns it off on their own device |
| Activity data | Speed, distance, cadence and power, where the device reports them |
| Identifiers | A random identifier generated on the device, and the display name the participant enters |
| Timing | When each reading was taken and received |
We do not receive a participant's Garmin account, email address, or any other activity they record. Marshal only transmits while it is on an active data screen during a recorded activity.
For organisers who create an account, we hold the email address and authentication details provided at sign-up, the events created, and a record of which version of the organiser terms was accepted and when.
It can be switched off. In the data field's settings there is a Send heart rate toggle. Turn it off and the watch sends position and pace only — the readings are left out on the device, so no health data is transmitted, stored or seen by anyone. Nothing else about taking part changes.
Why, and on what basis
We process this information for one purpose: to show an event organiser where participants are and how they are doing, during the event.
The basis is consent — explicit consent, which is what both the GDPR (Article 9) and POPIA (section 27) require before anyone may process health data such as heart rate. A participant chooses to install Marshal, add it to a data screen, and enter an event code. The organiser is responsible for obtaining that consent before the event and for telling participants what will happen; we require this of them in the organiser terms.
Consent can be withdrawn in part or in full. In part, by turning off Send heart rate, which stops health data alone while position continues. In full, at any time and with no reason given, by removing Marshal from the data screen, clearing the event code, or uninstalling it. Nothing further is sent from that moment. To also remove what was already sent, ask the organiser to delete it — which they can do immediately.
For organiser account data, our basis is the performance of our agreement with the account holder, and our legitimate interest in keeping the service secure.
We do not sell this information, use it for advertising, or profile anyone with it.
Who can see it
- The event organiser who created the event, and anyone they give the dashboard to.
- Anyone holding the event code, but only if the organiser has switched public viewing on for that event. It is off unless they turn it on, and it stops the moment the event is closed.
- Us, only where necessary to operate, support or troubleshoot the service.
- Google, as our hosting provider (see below).
Anyone holding an event's join code can send readings to that event. Codes should be shared only with participants.
Public viewing is the organiser's decision, not ours. If it is on, the code is all anyone needs to watch — no account, and no approval from the organiser beyond having given out the code. Ask your organiser whether your event uses it.
Where it is stored
In Google Firebase Realtime Database, in Google's europe-west1 region (Belgium). Wherever a participant is, that is where their readings are held.
So for people in the EU or UK, event data stays in Europe. For everyone else — including in South Africa, where we are based — it means data crosses a border to get there, and it is reachable by us in South Africa in order to operate and support the service. Those transfers rely on Google's contractual safeguards for its cloud services, on the European Commission's standard contractual clauses, and on the consent described above.
How long we keep it
Recorded positions and vitals are deleted 48 hours after the later of: the event being closed, or the last reading received.
An organiser can delete an event's data, or all of their events and data, at any time from their portal — immediately and permanently.
An organiser's account details are kept until the account is deleted.
Children
Marshal is not designed for children, and organiser accounts are for adults. Group events do sometimes include under-18s — school sport, a youth club ride — and where they do, the organiser must obtain consent from a parent or guardian in the form their local law requires. That obligation is written into the organiser terms.
If you believe a child's data has reached us without that consent, tell us and we will delete it.
Your rights
Wherever you are, you may ask to:
- confirm whether we hold personal information about you;
- have a copy of it, in a portable form;
- have it corrected, or deleted;
- restrict or object to its processing;
- withdraw consent, at any time, without giving a reason.
These are the rights POPIA and the GDPR give, and we extend them to everyone rather than only to people the two Acts happen to cover. Withdrawing consent does not undo processing that already, lawfully, happened.
Participants: ask your event organiser first. They are the controller for the event and can delete its data immediately. You may also contact us directly using the details below and we will respond within a reasonable period, and in any event within one month. Because devices identify themselves with a random identifier rather than a name we hold, we may need the event code and the display name used in order to find your data.
If you are unhappy with how we have handled it, you can complain to a supervisory authority: the Information Regulator in South Africa, the ICO in the United Kingdom, your national data protection authority in the EU, or whichever body oversees this where you live.
Security
- All transmission uses HTTPS; the device refuses to send otherwise.
- Readings can only be sent to an event using its join code, and only while that event is open.
- Only the event's owner and anyone they authorise can read its data. Join codes cannot be listed or searched by anyone.
- Recorded data cannot be altered or deleted by other participants.
No system is perfectly secure. Marshal depends on Bluetooth, a phone, and a mobile network, any of which can fail. It is a situational-awareness tool, not a safety or emergency system, and must not be relied on to detect that someone is in trouble.
Changes
If we change this policy we will update the date above and, where the change is significant, tell account holders by email.
Contact
For any privacy question or request:
tristan@alasia.co.za
Wiltech Solutions (Pty) Ltd, South Africa
If you need our registered address — to serve a formal notice, or for a regulator — ask at the address above and we will provide it.
Supervisory authorities: South Africa — inforegulator.org.za · United Kingdom — ico.org.uk · EU — your national authority.