FYI: Your IRONMAN Athlete Profile, Including Photos, is Being Scraped by Third Parties
This story has been updated to reflect additional reporting.
Back in 2024, IRONMAN transitioned away from using Active as their race registration system. It now utilizes TicketSocket, a white-label provider of both race registration and customer relationship management systems. Essentially, it allowed everything to remain IRONMAN-branded throughout your registration and customer interactions with IRONMAN.
That platform is where everything that you do with IRONMAN lives. It’s where you register for races. It’s where you submit for your Flex90 benefits (if you have them). It’s where you can upload profile photos. And it’s where (almost) all of your race results wind up living — some stuff pre-2013 did not survive the data merge. (We here at Slowtwitch are empathetic to minor data losses as a result of large-scale platform migration.)
Those datapoints also talk backwards to one another; for instance, your profile photo uploaded in the race registration platform works downstream to the IRONMAN race tracking app.
All of this is meant to live solely within the IRONMAN ecosystem — race results, timing splits, your photos, everything. IRONMAN, in fact, asserts exclusive intellectual property rights on these items under the Terms of Service on their website:
You acknowledge that the content included on the Site, including but not limited to, text, graphics, logos, button icons, images, audio clips, video clips, software, and the selection and arrangements thereof, is and will remain the sole and exclusive property of WTC or its licensors and is protected by both U.S. and international copyright laws. Absent the express written consent of WTC, the content on the Site may be used for personal, non-commercial use only. Any other use, including the reproduction, modification, distribution, republication or display of any of the content on the Site is strictly prohibited and an infringement of copyright or proprietary rights in the information, and of these Terms of Use. (emphasis added)
It also specifically spells out that you can’t reproduce this content elsewhere — with some specific language on how it is done.
You agree not to, and warrant and represent that you will not assist any third-party in engaging in any activity or attempting in any way, to reproduce, in whole or in part, any content provided by the Site through any method (including, without limitation, through crawling, copying, caching, or framing), unless such access is expressly permitted in a written agreement executed by WTC. You may not, for instance, (a) incorporate the information, content, or other material in any database, compilation, archive, API or cache; (b) deep-link to the Site for any purpose; (c) access the Site manually or with any robot, spider, web crawler, extraction software, automated process, device, program, or algorithm to scrape, copy, or monitor any portion of the Site; (d) take any action that imposes an unreasonable or disproportionately large load on the infrastructure of the Site; or (e) attempt to gain unauthorized access to any portion or feature of the Site by hacking, password mining, or any other illegitimate means. You agree not to use the Site, or any services made available through the Site for commercial purposes and agree not to share or transfer your account login information (if any) with any third party. For avoidance of doubt, “commercial purposes” includes non-profit purposes. (emphasis added).
It was under these terms and conditions that IRONMAN asked Christophe Balestra to shut down his popular aggregation site, The Obsessed Triathlete (aka OBSTRI). That site pulled timing data for athletes and awarded scoring for it. It also allowed for other key features like fantasy triathlon for professional races, etc. According to Balestra in a post he made on this site in 2022, he had made IRONMAN aware of the existence of OBSTRI that fall. He said at the time that IRONMAN had asserted intellectual property and the European Union’s General Data Protection Regulation claims, and that it would not be worth fighting those claims to continue operation of the site.
Fast forward to 2026, and there are two new data aggregators in town. But this time, it’s not just your race timing data that’s being captured. Your IRONMAN profile photos are also included.
First, there’s ProTriNews. As you can probably imagine, based on the focus of their podcast and associated content, they’re pretty solely focused on picking up on professional triathlon. According to Kyle Glass of PTN, the genesis of the site was having information for their podcast. “We needed to have a place to have statistics and comparisons directly in front of us. We’d heard that other resources might be shutting down, and that got us started on the work.”
They’ve also picked up on Fantasy Triathlon and their own ranking system. On the surface, not necessarily a bad thing; in fact, it’s not hard to make an argument that this isn’t dissimilar from any of the services that, say, an ESPN or other large sports entity uses when it comes to statistics, analytics, or games.
If you scratch slightly below the surface, though, it becomes a little murkier as to how this data might be getting pulled. Let’s take, for instance, one pro athlete and their image on the PTN site. Here’s the top end of Sam Long’s profile from the PTN site.

Now, if you’ve seen this look from Sam before, it should be familiar. Here’s Sam’s profile photo on the Professional Triathlete Organisation’s (PTO) athlete database.

A quick check of the source code from the PTN website gives you the answer as to where the image came from: they pull it directly from the PTO (who, perhaps infamously, have similarly restrictive Terms and Conditions about images and media rights).

We brought this up with the PTN team. PTN’s Talbot Cox admitted that yes, they did an initial scrape of various sources during the initial buildout, working to transform that data into the site they made. He also noted that yes, they do pull a feed of non-real time results data for pro athletes.
He was quick to point out that both IRONMAN and the PTO had themselves scraped certain athlete photos from other sources in the build out of their respective websites covering professional athletes, such as those of Thor Bendix Madsen and Marty Andrie on the IM Pro Series site. The PTN team did also mention that all professional athletes can claim their profiles on the site and change these images out (for example, Trevor Foley now uses a photo of Will Ferrell as his character Ricky Bobby from Talladega Nights), and build these profiles out to include links to sponsors and coverage of their races.
But it’s not just PTN who is aggregating data, and it’s also not just about pro data. There’s now Triathlon Lab, run by the ONYERLEFT team. They’re also picking up where OBSTRI left off with professional triathlon results and fantasy triathlon. But they also scraped and aggregated age-group athlete data — including your IRONMAN profile photo.
Here’s an example of this, with yours truly and my admittedly pathetic IRONMAN results.

Opening the element inspector, and it reveals the image source URL, which is highlighted below.

When I then do the same thing on my IRONMAN profile, it reveals that the image files are, in fact, the same. My image is being pulled off of an IRONMAN source and embedded into the Triathlon Lab site.

At the time of our original writing in this report, there were over 1,000,000 age group athlete records within the Triathlon Lab application, with an unknown number of embedded athlete photos included.
Following the publication of this article, the Triathlon Lab team reached out to Slowtwitch. They asserted that our reporting reflected a prior iteration of the site, and that their site no longer was scraping or publishing athlete profile photos. For example, my results no longer appear at all on the site. After reviewing approximately 1000 different age group records in the database, it would appear that any age-group photos are self-added by users who have registered for the site. But the site still does aggregate and consolidate user data into a single, unique profile.
This is decidedly different than other race data aggregation sites. Compare this with, say, Athlinks. Athlinks accounts require a registration process in order to claim and aggregate results into a single profile. Unless you choose to opt into using Athlinks, results are scattered into individual records; said otherwise, if I register and race 20 events, those 20 results are separate and not consolidated into a single unique Ryan Heisler. Athlinks also allows you to make your athlete data hidden, or to make your profile private, if you wish to keep everything aggregated there. These are the exact type of safeguards that are generally necessary under data protection laws.
Tags:
IRONMANPTOContinue the discussion at forum.slowtwitch.com
7 more replies



Personally, I don’t care and think Ironman needs to be doing this kind of stuff. And if they aren’t they need to enable others to do so.
Also known as “The Snap”
And I will argue that “minor data losses” does not fully capture the wealth of content that now only exists on archive.org (IF you can find it)
Yeah, some of it was bullshit chit-chat, but that was what the Slowtwitch Community was back then, and it was fun, and there was quality in there, and if one was to reference “hey! Someone said this in 2015, but it’s ABSOLUTELY relevant today!!!” they’re out of luck
Or maybe it’s me?
I am generally OK with anything about me related to racing completely in the public domain effectively as freeware (other than personal contact details). As far as I am concerned, if someone enters a race, they are putting themselves out in public related to everything about their racing. Let’s think about an Olympic athlete. Every microsecond of their performance, the details, the imagery, their personal images are all in the public domain. I actually don’t see why age groupers deserve any special treatment. If you don’t want your activities in an public race published in any media, just don’t race. Just train on your own and keep your exercise private. And I think everything about athletes racing should be transposable across anywhere on the internet. The only thing private should be our personal address, date of birth etc etc. But the actual sport stuff should be public domain.
That’s why we all joke that race results are forever.
One has zero expectation of privacy in entering an Ironman. I can’t imagine any reasonable person being more upset that their race results are publicly available outside of Ironman’s website than our personal information (address, family history, phone number, etc.) being used for targeted ads. Hell, flock cameras use facial recognition. If someone wants to use the race times that are already public, more power to them. It’s a badass app that makes racing that much better for all of us.
True. Event at Challenge races the best in the world have to strip naked in front of the port-o-potty.
Here’s where I draw the line on this:
1.) If it’s pro triathlon, I don’t have any issue – so long as everyone’s allowed to take a feed of it.
2.) if somebody were taking my race data to do aggregate analysis, like the Coach Cox site? Go for it.
3.) it’s when you take my stuff, take my photo that’s meant for use in a single location, and then you create a single identifiable record, that I have a problem with it – especially when the IM Terms of Service make it clear that you’re not allowed to do so.
I’ve very sympathetic to photojournalism, having shot photography at sporting events from 1999-2017 all around the world. I’ll still go out to some events and shoot. And I’ve even jumped into a finisherpix event a couple times in the last couple years when I had nothing to do that day. – holy hell those are not fun. Talk about trigger finger fatigue.
But I was never one to get hyped up about someone stealing my photos, etc. as I didn’t really care about credit personally. But I know a lot of photogs who absolutely will die, or rather, crucify anyone else who offends them, on that hill.
In the grand scheme of things, while I agree it seems you are technically accurate, if I scroll their listings on the offending site, all I see are the pro photos. None of the agrs. Probably because none bother to add a photo to their IM profile? So are you upset as the potential photographer of said pros, that your work for hire for that pro (or IM) is now being syndicated on this site?
When I do a google image search of a pro, who’s photo shows up on the site, I get the exact same image on google, as I can find on Ironman. Are you upset that image is being “scraped” by google? Do you really feel there’s some value lost there as the photographer?
If so, what is it? If the entire website was populated with 3000 photos, you might say, it’s a nice reference that adds value to their site the photographer isn’t being compensated for. But the residuals from that tiny thumbnail, if fairly calculated is virtually zero. It’s only when photographers have an inflated sense of what that syndicated photo is worth that suddenly photogs start grabbing their torches and pitchforks.
I’ll just add a little more – the value of a google image search to society far outweighs the value of a photographer of their photo. Would we really be happy if the solution to all of this is telling google to shut down google image search because every photographer in the world can send them an invoice for $10,000 for copyright infringement for each violation? Google says, F-this, and just shuts it down. Happy now? Are we better off?
It’s not you
A big chunk of knowledge was lost, a bigger chunk was mangled to the point you can’t follow it
The Library of Alexandria held thousands of years of history, and stood for 600 years. What kind of endurance website can’t even manage a tenth of that?
I think I can see where you’re coming from, but what’s the difference from someone going to a 3rd party site and seeing the photo you uploaded to IM compared to someone looking at the results of IMLP 2 years later and seeing that same photo? The Ironman app is publicly available, it’s not behind a paywall or the requirement that a username be created.
Thought I’d chip in on this, given I’m some part of the problem.
Aggregate analysis was why I started collecting Ironman results. I used to just put up blog posts with analysis for Ironman races. Putting all the data online came about as a project to keep me busy during Covid lockdowns (and having a site lots of people visit isn’t a bad thing when your income comes from coaching Ironman athletes).
In the case of my data collection, I take completed results sets and don’t dig any further. So, the personal information I hold is a name, country and age group with a result. I did all of this quite naively but have learned a lot more about GDPR rules in the UK as a consequence. I regularly get requests to remove personal information and I always remove an individuals personal data on request (GDPR article 17 requires this).
I recently had to put my site behind Cloudflare because I started receiving 300,000 requests per day from bots in China (I can’t afford the kind of hosting to handle that sort of traffic). I would assume all the data Ironman holds is getting hit many time over that.
our events cut off at 17 hours, best we can do sorry.
General thread reply:
The Triathlon Lab team reached out after our initial publication. Our story has been updated to reflect changes that they have made to their site, which includes no longer scraping and publishing athlete photos.
Welcome back to contributing and thanks for chiming in.
The Cloudflare thing is a big heartburn element for lots of us…ours tend to be from Singapore vs China but it’s largely the same issue.
And yeah. GDPR. Everyone’s favorite.
Yes, Thorsten was doing this for over a decade and many people on this forum are sycophants of his as many are sycophants of other more nepharious people in Triathlon.
I’ve rarely seen an anti-Thorsten post, but you could have made this post about him. Since he was the one doing it the longest but I think they sent him a letter so he stopped.