Privacy Policy
Last updated: February 22, 2026
1. Data Controller
Daniel Kappler
Email: [email protected]
If you have questions about this privacy policy or how we process your data, please contact us at the email address above.
2. What Data We Collect
Account Data
When you create an account, we collect your email address, display name, and authentication credentials. If you sign in via a third-party provider, we receive the profile information shared by that provider.
Telemetry & Lap Data
Our desktop telemetry client captures lap times, sector times, and session data directly from iRacing. This data is uploaded to SpecTrace to power leaderboards, session results, and performance tracking.
Usage Data
We collect basic analytics data such as pages visited, feature usage, browser type, and device information to improve the service.
Payment Data
Payments are processed by Stripe. We do not store your full credit card number. Stripe processes your payment information in accordance with their own privacy policy. We receive only a transaction reference, subscription status, and the last four digits of your card.
3. Legal Bases (Art. 6 GDPR)
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b)) — Processing necessary to provide you with the SpecTrace service (account data, telemetry data, session data).
- Legitimate interest (Art. 6(1)(f)) — Analytics and service improvement, fraud prevention, and ensuring platform security.
- Consent (Art. 6(1)(a)) — Where applicable, for optional cookies and marketing communications. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — Where we are required to retain data for tax or legal compliance.
4. Cookies
We use essential cookies to keep you logged in and maintain your session. We may also use analytics cookies to understand how the service is used. You can manage cookie preferences in your browser settings.
5. Third-Party Services
- iRacing — We integrate with iRacing to capture telemetry data. Your iRacing data is subject to iRacing's own terms and privacy policy.
- Stripe — Payment processing. See Stripe's Privacy Policy.
- Hosting providers — Our infrastructure is hosted on cloud providers within the EU/EEA or with appropriate safeguards in place.
6. Data Retention
We retain your account data for as long as your account is active. Telemetry and lap data is retained for the duration of your account. If you delete your account, your personal data will be removed within 30 days, except where retention is required by law (e.g., invoicing records retained for up to 10 years for tax purposes).
7. Your Rights
Under the GDPR, you have the right to:
- Access — Request a copy of the personal data we hold about you.
- Rectification — Request correction of inaccurate data.
- Erasure — Request deletion of your personal data ("right to be forgotten").
- Restriction — Request restriction of processing in certain circumstances.
- Data portability — Receive your data in a structured, machine-readable format.
- Objection — Object to processing based on legitimate interests.
- Withdraw consent — Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at [email protected].
8. Right to Lodge a Complaint
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
9. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by email or through the application. The "last updated" date at the top indicates the latest revision.