Legal
Privacy notice
Last updated 23 August 2026.
This notice explains what personal data Slipstream Pitlane holds about you, why, who else sees it, how long it is kept, and what you can ask us to do with it. It is written to be read, not to be got past.
On this page
1. Who is responsible
Slipstream Pitlane is the data controller for the personal data described here, and is operated from the United Kingdom. Contact: pitlane@slipstream.org.uk.
2. What we hold
Your account
- Your email address and the name you are known by.
- When your account was created, and whether it is active.
- Hashed sign-in tokens and session tokens. We store a one-way hash, never the value in the link or the cookie.
What you upload
- Your session data — the Alfano, MyChron or RaceChrono exports themselves — with their original filename, size and the time they arrived.
- The telemetry derived from them: laps, times, GPS traces, speeds, rpm, section times and the analysis built on those.
- What you tell us about a session — the class you ran, the circuit if you correct our identification, your setup sheet, and any notes or answers you give to the questions a report asks.
Session data records where a vehicle was, when, and how fast. Attached to your name, that is personal data about your movements, and we treat it that way.
Your reports and your credits
- The reports produced for you, and the requests that produced them.
- Your credit ledger — every grant, spend, refund and Market trade, with its reason and date. The ledger is append-only: entries are never edited, which is what makes a balance checkable.
What we do not hold
- No advertising or analytics trackers. There is no Google Analytics, no advertising pixel and no third-party tracking script in the members' area.
- No card details. Card payments are handled by Stripe and your card number never reaches us.
- No password — sign-in is by emailed link, so there is no password to lose.
3. Why we hold it, and our lawful basis
| What | Why | Lawful basis |
|---|---|---|
| Email, name, session tokens | To let you sign in and to keep your account yours | Performance of our contract with you |
| Session data, telemetry, setup sheets | To produce the reports you asked for | Performance of our contract with you |
| Credit ledger, report requests | To account for what you paid and what you received | Contract, and our legal obligation to keep records |
| Service and error records | To keep the service working and secure | Our legitimate interest in a service that runs |
| Emails about your reports and account | To deliver what you bought and tell you about your account | Performance of our contract with you |
| Marketing email, if we ever send any | To tell you about Slipstream | Your consent, withdrawable at any time |
4. Cookies
The members' area sets one cookie: a sign-in session
cookie. It is set only after you use a sign-in link, it holds a random
value (we store only its hash), it is marked
HttpOnly and SameSite=Lax, and it lasts up to
30 days or until you sign out.
It is strictly necessary for the service to work, so it does not require a consent banner. There are no analytics, advertising or profiling cookies, so there is nothing else to consent to.
5. Who else sees your data
We use a small number of service providers. Each processes data only on our instructions.
| Provider | What it does | What it sees |
|---|---|---|
| Render | Hosts the application and its storage | Everything the service stores, at rest on its infrastructure |
| Resend | Sends our email — sign-in links, report notifications | Your email address and the content of those messages |
| ImprovMX | Forwards email sent to our address into our inbox | Anything you send us by email |
| Google (Gmail) | Our own inbox, where your email to us arrives | Anything you send us by email |
| Stripe | Takes card payments for credits | Your card and billing details — we never see the card number |
Automated processing and AI
Your report is computed. The measurements and the choice of what to tell you are made by our own engine following explicit rules, which is why the same session always produces the same report. The standard report path makes no AI model calls at all.
An optional language pass exists which, when switched on, sends report text to an AI provider to tidy the wording. It cannot change any number or any finding.
No decision with a legal or similarly significant effect on you is made automatically.
6. Other members, and the Marketplace
Your files and reports are visible only to you when you are signed in. Other members cannot see them.
If you choose to list a session on the Marketplace, a member who buys it receives comparison rights only: they can compare their laps against yours and use that comparison in their own reports. They see your lap and section times and the session's driver label. They never receive your raw logger file or your setup sheets. Withdrawing a listing stops new purchases; members who already bought keep what they paid for.
If a report compares you against another member, their session appears in your report on the same basis — times, not files.
7. Where your data is stored
The service and its storage are hosted in the European Union (Frankfurt, Germany). Some of our providers — including our email sender and our own inbox — may process data outside the UK and EEA. Where they do, transfers rely on the safeguards the law requires, such as UK International Data Transfer Agreement clauses or an adequacy decision.
8. How long we keep it
- Your files, telemetry and reports — for as long as your account is open, because their value to you is that they are still there next season. Ask us and we will delete any of them sooner.
- Sign-in links — 15 minutes, then they stop working. Session records — up to 30 days, and removed after that.
- Transaction and credit records — kept for 6 years after the tax year they fall in, which is what UK tax law requires of business records.
- Backups — a copy of the members' database is retained as a safeguard, and deleted data disappears from backups as those are rotated.
When you close your account we delete your files, telemetry and reports, and keep only what the transaction records above require.
9. How it is protected
- Sign-in links are single-use, expire in 15 minutes, and only their hash is stored.
- Every lookup is scoped to the signed-in member, so one member cannot reach another's records by changing a web address.
- Sign-in attempts are rate-limited.
- Traffic is encrypted in transit (HTTPS).
- The members' database is backed up, and a restore has to be proven, not assumed.
No service is perfectly secure. If a breach puts your rights at risk we will tell you, and report it to the ICO within 72 hours as the law requires.
10. Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete your data, where we do not have to keep it;
- restrict or object to our use of it;
- port it — receive it in a machine-readable form, or have it sent to someone else;
- withdraw consent where consent is what we relied on.
Email pitlane@slipstream.org.uk from your account address. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
11. Children
Karting has young drivers, and this matters more here than in most notices.
A Pitlane account must be held by someone aged 16 or over. Where the driver in the data is under 16, the account must be held by their parent or guardian, who is responsible for it and for what is uploaded.
If we learn that an account is held by a child under 16, we will close it and delete its data.
12. Changes, and how to complain
If we change this notice materially we will email members before the change takes effect. The version in force is the one on this page, with its date.
If you are unhappy with how we have handled your data, tell us first — pitlane@slipstream.org.uk. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), the UK's data protection regulator.