SimCoach powered by Race Stint

RACE STINT PRIVACY NOTICE

Last updated: 14/08/2026 Version: 1.2 (Beta — registered office updated)

This Privacy Notice explains how Code State Ltd ("Code State", "we", "us" or "our") collects, uses, shares and protects your personal data when you use the Race Stint service, including the racestint.app website, the Race Stint mobile and web dashboard, and the Race Stint Windows Agent (collectively, the "Service").

We are the data controller for the personal data described in this notice.

We take your privacy seriously. If you have any questions, please contact us at [email protected].


1. WHO WE ARE

Code State Ltd Registered in England and Wales, Company No. 12856318 Registered office: 128 City Road, London, EC1V 2NX

Email: [email protected] Website: https://racestint.app

Race Stint is a telemetry-driven endurance race strategy platform for sim racing, currently supporting Le Mans Ultimate and iRacing. We are the controller of your personal data, which means we decide how and why your data is processed.


2. PERSONAL DATA WE COLLECT

We collect the following categories of personal data:

2.1 Account data (you provide this)

  • Name (or display name) and email address
  • Password (stored as a salted hash; we never see your plain-text password)
  • Two-factor authentication secret and recovery codes
  • Team name, team logo, and team membership details
  • Subscription tier and billing status (Silver / Gold / Founding Member)

2.2 Sim racing and telemetry data (the Windows Agent collects this)

The Race Stint Windows Agent reads telemetry data from a Supported Sim while you play. The interface used depends on which sim you are running:

  • Le Mans Ultimate — the Agent reads from a memory-mapped file populated by the open-source community plugin rFactor2SharedMemoryMapPlugin64.
  • iRacing — the Agent reads from the official iRacing SDK (IRSDK) memory-mapped file (Local\IRSDKMemMapFileName) published by iRacing for use by third-party applications.

In both cases, the Agent does not communicate with the sim publisher's servers or modify the sim itself. Data collected includes:

  • Lap times, sector times, and stint timings
  • Fuel consumption and fuel level data
  • Tyre temperatures, pressures, wear, and compound information (including left-side asymmetry data where the sim provides it)
  • Vehicle, track, weather, session, and event metadata
  • Driver inputs aggregated to lap and stint level (throttle, brake, steering)
  • Position, speed, and corner-by-corner performance metrics
  • Incident data (off-tracks, spins, contact)

This telemetry is associated with your Race Stint account so that we can produce strategy, post-race debriefs, and team analytics. We do not transmit your telemetry data to the sim publishers, and we do not receive any data from them.

2.3 Diagnostic and technical data

  • Windows Agent version, operating system version, and crash reports
  • Device identifier (a random ID generated by the Agent, not your Windows username)
  • IP address (used by Cloudflare for security and rate limiting)
  • Browser type, device type, and language for the web dashboard
  • Server logs of API requests and errors

2.4 Communications data

  • Emails you send to us and our replies
  • Bug reports and feedback you submit through the "Send Diagnostics" feature or other channels
  • Any chat content you send to the live race chat or post-race debrief features (Gold tier)

2.5 Marketing and preference data

  • Whether you have consented to receive product and marketing emails
  • Email engagement data (opens, clicks) where Resend reports it to us
  • Cookie preferences set on the website

We do not intentionally collect special category data (health, ethnicity, political opinions, etc.) and ask you not to include such data in support messages or feedback.


Under the UK GDPR we must have a lawful basis for processing your personal data. Below is what we do with your data and the lawful basis for each activity.

Purpose Data used Lawful basis
Create and manage your account Account data Contract
Authenticate you (login, 2FA) Account data, IP address Contract
Ingest telemetry, calculate strategy, generate stint plans, deliver the dashboard Telemetry, account data Contract
Build community baselines per car / track / compound (anonymised and aggregated) Telemetry only Legitimate interests (improving the Service for all users)
Generate post-race debriefs and live race chat using Anthropic's Claude AI models (Gold tier) Telemetry, chat content Contract
Diagnose bugs and improve the Service Diagnostic data, crash reports Legitimate interests (running and improving a reliable Service)
Send transactional emails (signup, 2FA, password reset, billing, beta updates, important Service announcements) Email address, account data Contract / legitimate interests
Send occasional product update and marketing emails Email address, preference data Consent (you can withdraw at any time via the unsubscribe link or by emailing us)
Take payment for paid subscriptions Account data, billing data Contract
Protect the Service against fraud, abuse, and bots (Cloudflare WAF and Turnstile) IP address, device data, technical signals Legitimate interests (security)
Comply with legal obligations Any Legal obligation
Enforce our Terms, EULA, and acceptable use, or pursue legal claims Any Legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we are satisfied they are not. You have the right to object to processing based on legitimate interests — see Section 8.


4. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. We share it only with the service providers ("processors") below, who process data on our behalf under written contracts that meet UK GDPR requirements.

4.1 Our subprocessors

Provider Purpose Location of processing Safeguards
Laravel Cloud (operated by Laravel Holdings, Inc.) Application hosting, database (PostgreSQL), file storage. Runs on Amazon Web Services in the AWS EU West (London) region (eu-west-2). United Kingdom Data Processing Agreement; UK-based processing — no international transfer of primary application data.
Resend (Resend Inc.) Sending transactional and marketing emails United States Data Processing Agreement; certified under the EU-US Data Privacy Framework and the UK Extension to the EU-US DPF; Standard Contractual Clauses where applicable.
Cloudflare (Cloudflare, Inc.) DNS, CDN, Web Application Firewall, DDoS protection, and Turnstile invisible captcha on public forms Global edge network with UK and EU points of presence; controlling entity in the United States Data Processing Agreement; Standard Contractual Clauses (UK Addendum); Cloudflare is certified under the EU-US Data Privacy Framework (UK Extension).
Anthropic (Anthropic PBC) Generative AI for post-race debriefs and live race chat (Gold tier) using Claude AI models via the Anthropic API United States Data Processing Agreement; Standard Contractual Clauses (UK Addendum). Anthropic does not use API inputs or outputs to train its models. We send only the telemetry context and chat message necessary to generate the response.
Stripe (Stripe Payments Europe, Limited and Stripe, LLC) Processing payments and managing subscription billing for paid tiers Ireland and the United States Data Processing Agreement; our contracting entity is Stripe Payments Europe, Limited (Dublin, Ireland); Standard Contractual Clauses with the UK International Data Transfer Addendum for transfers to the United States; Stripe, LLC is certified under the EU-US Data Privacy Framework and the UK Extension to the EU-US DPF.

We may add or change subprocessors as the Service evolves. We will keep this list up to date and, where we are required to, notify you in advance of material changes.

4.2 Other recipients

We may share personal data with:

  • Professional advisers — accountants, lawyers, and auditors, where necessary
  • Regulators and law enforcement — where we are required to by law or where we have a legitimate basis for doing so
  • A successor business — if Code State is acquired or merges, your data may transfer to the acquiring entity, subject to the same protections

We do not currently use any third-party advertising, web analytics, or tracking services.


5. INTERNATIONAL TRANSFERS

The bulk of your personal data — including your account, telemetry, and team data — is stored in the United Kingdom on Laravel Cloud's AWS EU West (London) infrastructure.

Some personal data is transferred outside the UK — to Ireland (Stripe Payments Europe, Limited) and to our subprocessors in the United States (Resend, Cloudflare's controlling entity, Anthropic, and Stripe, LLC). Where we transfer personal data outside the UK, we rely on one or more of the following safeguards:

  • The UK Extension to the EU-US Data Privacy Framework, where the recipient is certified
  • The UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum
  • A Transfer Risk Assessment, where required

You can request a copy of the safeguards we use by emailing [email protected].


6. HOW LONG WE KEEP YOUR DATA

We keep your personal data only for as long as we need it.

Data Retention
Account data For the life of your account, plus up to 30 days after deletion to allow recovery. Backups containing your account data are retained for up to 35 days, after which they are overwritten.
Telemetry, lap, and stint data For the life of your account. After account deletion, your personal telemetry data is deleted within 30 days. Anonymised, aggregated baseline data (which cannot be linked back to you) may be retained indefinitely as part of our community baseline dataset.
Diagnostic and crash data Up to 12 months
Server logs Up to 90 days
Email communications Up to 24 months after the last interaction
Marketing consents and unsubscribes Until you re-consent or for 24 months after withdrawal, to honour your preference
Billing records 7 years, as required by UK tax law

Backups are encrypted at rest and follow the retention windows above.


7. SECURITY

We take reasonable technical and organisational measures to protect your data, including:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for the application database and backups
  • Salted, hashed password storage (we never see your password)
  • Two-factor authentication available on all accounts
  • Cloudflare WAF, DDoS protection, and Turnstile to defend against bots and attacks
  • Principle of least privilege for engineering access to production data
  • Logging and monitoring of access to production systems

No system is completely secure. If we discover a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and notify you without undue delay where required.


8. YOUR RIGHTS

Under the UK GDPR you have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure ("right to be forgotten") — ask us to delete your data, subject to exceptions
  • Restriction — ask us to limit how we process your data
  • Portability — receive your data in a structured, commonly used, machine-readable format
  • Object — object to processing based on legitimate interests, including profiling
  • Withdraw consent — where we rely on consent, you can withdraw it at any time
  • Not be subject to automated decision-making — we do not use your data for solely automated decisions that produce legal or similarly significant effects on you
  • Complain — lodge a complaint with the ICO (see Section 11)

To exercise any of these rights, email [email protected]. We will respond within one month. We may need to verify your identity before acting on a request.


9. COOKIES AND SIMILAR TECHNOLOGIES

The racestint.app website uses a small number of cookies and similar technologies. The first time you visit, you'll see a cookie banner allowing you to accept or reject non-essential cookies.

Type Examples Purpose
Strictly necessary (always on) Session cookie, CSRF token, Cloudflare security cookies (__cf_bm, cf_clearance), Turnstile challenge cookie Logging you in, keeping the Service secure, blocking bots. These cannot be turned off.
Functional (with consent) Theme/language preference, "remember me" Remembering your choices
Analytics / marketing None at present We do not currently use any third-party analytics or advertising cookies. We will update this notice and re-prompt for consent before introducing any.

You can manage cookies via the cookie banner, your browser settings, or by emailing [email protected].

The Race Stint Windows Agent does not use cookies. It uses local files to store your authentication token and configuration.


10. CHILDREN

The Service is not intended for children under 13, and you must be at least 13 years old to use it. If you are under 18, a parent or guardian must have reviewed and agreed to our Terms of Service on your behalf. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please email [email protected] and we will delete it.


11. HOW TO COMPLAIN

If you have a complaint about how we handle your personal data, please email [email protected] first so we can try to resolve it.

You also have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 Website: https://ico.org.uk


12. CHANGES TO THIS NOTICE

We may update this Privacy Notice from time to time. The "Last updated" date at the top will reflect the most recent change. Where changes are material, we will notify you by email or through the Service before they take effect.


13. CONTACT

For any privacy-related questions or to exercise any of your rights:

Code State Ltd Email: [email protected] Web: https://racestint.app/privacy Company No. 12856318 (England and Wales)