Legal

Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your information.

Last updated: October 26, 2025

Data Protection

We use industry-standard security measures

Transparency

Clear about what data we collect

Your Control

You control your personal data

Contact Us

Questions? We're here to help

1. Information We Collect

Personal Information

When you create an account, we collect your email address and username. You may optionally provide additional profile information such as your name, bio, avatar, racing achievements, team affiliations, and career highlights. Authentication is handled securely through Supabase Auth with support for Google OAuth, email OTP (one-time password), and magic links.

Website Content & Media

We store all content you create for your websites, including text, structured data (race results, achievements, stats), and media files. Images and videos are uploaded to Supabase Storage with automatic optimization and CDN delivery. Gallery limits apply based on your subscription plan (Free: 20 images, Pro: 50 images, Max: 100 images, with optional +50 image add-on available).

Usage Data & Analytics

With your consent (GDPR/CCPA compliant), we collect analytics data through Google Analytics 4 and Vercel Speed Insights. This includes page views, device type, browser information, geographic location (city-level), session duration, and feature usage patterns. Analytics are used solely to improve platform performance and user experience. You can opt out at any time through cookie preferences.

Technical & Security Information

For security and abuse prevention, we use your IP address for rate limiting (e.g., limiting login attempts, preventing spam signups). IP addresses are processed in-memory and not permanently stored. Browser user agent information is collected only when errors occur to help diagnose issues. Google reCAPTCHA is used on signup forms to prevent bot abuse. All authentication sessions use secure HTTP-only cookies with PKCE flow. Database access is protected by Row-Level Security (RLS) policies that ensure users can only access their own data.

Payment & Subscription Data

For paid subscriptions (Pro £9/mo, Max £19/mo), we use Stripe for payment processing. RaceXa does not store credit card numbers. We retain subscription metadata (plan type, status, billing dates) in our Supabase database to manage access to features. All payment information is handled exclusively by Stripe in compliance with PCI DSS standards.

AI-Generated Content

When using Alice AI content assistant (Paid plan feature), your field labels, existing content context, and generation prompts are sent to Google Gemini API to generate suggestions. Alice is accessible via sparkle buttons in the editor, batch AI fill, floating chat widget, and full-page chat interface (/alice). We do not train AI models on your data. AI requests are processed in real-time and not stored beyond standard server logs.

Content Moderation & Safety

To protect users and maintain platform integrity, we automatically scan uploaded content using third-party moderation services:

  • OpenAI Moderation API - Scans text and images for sexual content, violence, hate speech, harassment, and self-harm before save/publish operations
  • Google Web Risk API - Checks URLs for malware, phishing, unwanted software, and social engineering threats

Flagged content is analyzed in real-time and may be blocked from publication. Moderation scans are necessary for platform safety and are not used to train AI models or for purposes beyond content policy enforcement.

2. How We Use Your Information

Service Provision & Hosting

We use your information to provide, maintain, and improve our website builder. Your account data is stored in Supabase (PostgreSQL database) with automated backups. Websites are hosted on Vercel's global CDN for optimal performance. Media files are served through Supabase Storage with automatic image optimization. All infrastructure uses enterprise-grade SSL/TLS encryption and Row-Level Security (RLS) policies enforce data isolation between users.

Communication & Support

We send transactional emails through Resend for essential account activities (email verification, password resets, subscription confirmations). We may also send product updates, feature announcements, and promotional content about new website templates or platform improvements. Marketing emails include an unsubscribe link. Transactional emails cannot be opted out as they are necessary for account security.

Platform Improvement & Analytics

With consent, we analyze usage patterns through Google Analytics 4 and Vercel Speed Insights to identify performance bottlenecks, popular features, and areas for improvement. Analytics are anonymized where possible and aggregated for reporting. We use this data to prioritize new templates, optimize page load times, and improve editor UX for the motorsport community.

Security & Fraud Prevention

We process technical information to detect and prevent abuse, spam, unauthorized access, and fraudulent accounts. Google reCAPTCHA analyzes signup behavior to block bots. Rate limiting prevents API abuse. Session tokens expire after 7 days and use secure HTTP-only cookies with SameSite protection.

3. Information Sharing

Public Content

Content you publish on your motorsport websites is publicly accessible via your chosen username (racexa.com/[username]/[template]). Published sites are indexed by search engines (Google, Bing). Gallery images are served through Supabase CDN with public URLs once published. Unpublished sites remain private and are only accessible to you when logged in.

Service Providers & Infrastructure

We share data with trusted third-party service providers who operate our infrastructure:

  • Supabase Inc. - Database hosting, authentication, file storage (PostgreSQL, Auth, Storage)
  • Vercel Inc. - Website hosting, CDN, serverless functions, analytics
  • Stripe Inc. - Payment processing, subscription management (PCI DSS compliant)
  • Google LLC - AI content generation (Gemini API), analytics (GA4), spam prevention (reCAPTCHA), URL safety (Web Risk API)
  • OpenAI - Content moderation for text and images (Moderation API)
  • Resend - Transactional email delivery (account verification, password resets)

All providers are bound by data processing agreements (DPAs) and operate under GDPR-compliant Standard Contractual Clauses (SCCs). They are prohibited from using your data for purposes beyond providing services to RaceXa.

Analytics & Performance Monitoring

With your consent, anonymized usage data is shared with Google Analytics 4 and Vercel Analytics to measure platform performance and user engagement. IP addresses are anonymized, and personal identifiers are removed before transmission. You can opt out via cookie preferences or browser extensions.

No Data Sales

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We do not participate in data broker activities or advertising networks beyond standard analytics (Google Analytics, Vercel Analytics).

4. Data Security

We implement enterprise-grade security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of internet transmission or electronic storage is 100% secure.

Infrastructure Security

  • Encryption in Transit: All connections use TLS 1.3 encryption (HTTPS)
  • Encryption at Rest: Database and file storage encrypted with AES-256
  • Secure Authentication: PKCE OAuth flow, HTTP-only session cookies, 7-day token expiration
  • Database Security: PostgreSQL Row-Level Security (RLS) policies enforce user data isolation
  • API Protection: Rate limiting, request validation, CORS policies

Application Security

  • Input Validation: All user inputs sanitized and validated with Zod schema validation
  • Content Moderation: Automated scanning for malicious URLs, prohibited content, and policy violations
  • Spam Prevention: Google reCAPTCHA v3 on signup, rate limiting on API endpoints
  • Session Management: HTTP-only cookies with SameSite protection, 7-day expiration

Infrastructure Providers

  • Hosting: Vercel (SOC 2 Type II certified, ISO 27001 compliant)
  • Database: Supabase on AWS (SOC 2 Type II, GDPR compliant)
  • Payment: Stripe (PCI DSS Level 1 certified)

Monitoring & Response

We maintain error tracking and automated dependency updates to protect against emerging threats. In the event of a data breach affecting your account, we will notify you within 72 hours as required by GDPR Article 33.

Your Responsibility: Use a strong, unique password. Enable two-factor authentication when available. Do not share your account credentials. Log out from shared devices. Report suspicious activity to security@racexa.com.

5. Your Rights and Choices

Account Access & Management

You can access, review, and update your personal information through your account dashboard. This includes profile details, username, email, bio, avatar, and website content. For data not accessible through the dashboard, contact privacy@racexa.com with your request.

Data Portability (GDPR Article 20)

You have the right to export your data in machine-readable format (JSON). Contact privacy@racexa.com to request a complete data export, which includes: account information, website content, media file URLs, subscription history, and consent records. We will provide the export within 30 days.

Marketing Communications & Consent

You can opt out of promotional emails by clicking the unsubscribe link in any marketing email or by updating your email preferences in account settings. Opting out does not affect transactional emails (account verification, password resets, subscription confirmations) which are necessary for account security and service operation.

Cookie & Analytics Control

You can manage cookie preferences at any time by clicking "Cookie Settings" in the footer. You can accept or reject functional and analytics cookies. Strictly necessary cookies (authentication, security) cannot be disabled as they are essential for the platform to function. You can also use browser settings or install the Google Analytics Opt-out Browser Add-on.

Account Deletion (Right to Erasure)

You can delete your account at any time through Settings → Account → Delete Account. Upon deletion, we will permanently remove:

  • Your personal profile information (email, username, bio, avatar)
  • All website content and media files from Supabase Storage
  • Published websites (they will become inaccessible)
  • Subscription data (after current billing period)

Retention exceptions: We may retain anonymized analytics data, aggregated usage statistics, financial records for tax compliance (7 years), and data required by law or pending legal proceedings.

GDPR Rights (EU/UK Users)

Under GDPR, you have the right to: access your data (Article 15), rectify inaccurate data (Article 16), erasure/deletion (Article 17), restrict processing (Article 18), data portability (Article 20), object to processing (Article 21), and withdraw consent (Article 7). To exercise these rights, email privacy@racexa.com with your request and proof of identity.

CCPA Rights (California Users)

California residents have the right to: know what personal information is collected (this policy), request deletion of personal information, opt out of data sales (we don't sell data), and non-discrimination for exercising privacy rights. Submit CCPA requests to privacy@racexa.com.

Response Time: We respond to verified data rights requests within 30 days (GDPR) or 45 days (CCPA). Complex requests may require an additional 30-day extension with notice.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze platform usage, and provide personalized content. This section explains what cookies we use, why we use them, and how you can control them.

What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help us remember your preferences, understand how you use our platform, and improve your experience. We also use similar technologies like localStorage and sessionStorage.

Cookie Categories

Strictly Necessary Cookies (Always Active)

These cookies are essential for the website to function and cannot be disabled. They enable core features like authentication and security.

  • sb-*-auth-token - Session authentication (Supabase, 7 days)
  • _GRECAPTCHA - Anti-bot protection (Google, 6 months)
Functional Cookies (Optional)

These cookies enable enhanced features and remember your preferences.

  • racexa-theme - Dark/light mode preference (localStorage)
Analytics & Performance Cookies (Requires Consent)

These cookies help us understand how visitors use our website anonymously.

  • _ga, _gid, _gat - Google Analytics (2 years / 24 hours / 1 minute)
  • Vercel Analytics - Performance monitoring (session only)

Data Collected: Page views, device type, browser, geographic location (city-level), referrer, session duration. No personally identifiable information unless you are logged in.

Third-Party Services

We use the following third-party services that may set their own cookies:

How to Control Cookies

RaceXa Cookie Preferences

You can manage your cookie preferences at any time by clicking "Cookie Settings" in the footer of any page. You can:

  • Accept or reject different categories of cookies
  • View detailed information about each cookie
  • Change your preferences at any time
Browser Controls

You can also control cookies through your browser settings:

  • Chrome: Settings → Privacy and security → Cookies
  • Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Cookies and site permissions

Note: Blocking all cookies will prevent you from using certain features, including logging in.

Third-Party Opt-Out Tools

Your Rights Regarding Cookies

Under GDPR and CCPA, you have the right to:

  • Be informed about what cookies we use (this policy)
  • Consent to or refuse non-essential cookies
  • Withdraw your consent at any time
  • Request deletion of data collected through cookies
  • Opt out of analytics and tracking

Cross-Border Data Transfers

Some of our third-party services (Google, Vercel) are based in the United States. When you consent to analytics cookies, your data may be transferred internationally. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

For complete cookie information, including detailed purposes, durations, and provider privacy policies, please see our dedicated Cookie Policy.

7. International Data Transfers

RaceXa operates globally to serve the international motorsport community. Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our infrastructure providers operate.

Data Locations

  • Database & Storage: Supabase on AWS (multiple regions, primary: EU)
  • Website Hosting: Vercel global CDN (nearest edge location to user)
  • Email: Resend (US-based)
  • Analytics: Google Analytics (US), Vercel Analytics (US)
  • Payments: Stripe (US and EU data centers)
  • AI Processing: Google Gemini API (US), OpenAI Moderation API (US)
  • Security: Google Web Risk API (US)
8. Children's Privacy

Our service is not directed to children under 13 years of age (or 16 in the EEA/UK). We do not knowingly collect personal information from children without verifiable parental consent. Users aged 13-17 must obtain parental or guardian consent before creating an account.

If we become aware that we have collected personal information from a child under 13 without parental consent, we will take immediate steps to delete that information from our servers. If you believe a child has provided us with personal information, please contact us at privacy@racexa.com.

Parents & Guardians: You have the right to review, modify, or delete your child's personal information. Contact privacy@racexa.com with verification of guardianship.

9. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, legal requirements, or service features. The "Last updated" date at the top of this page indicates when the policy was last modified.

Notification of Changes

  • Material Changes: We will notify you by email and/or prominent notice on the platform at least 30 days before changes take effect
  • Minor Updates: Non-material changes (clarifications, formatting) will be posted without notice
  • Consent: Continued use of the service after changes take effect constitutes acceptance of the updated policy
10. Contact Us

If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

General Privacy Inquiries

Email: privacy@racexa.com

Security Issues

Email: security@racexa.com

For reporting security vulnerabilities

Postal Address

RaceXa Data Protection
[Company Address - To Be Updated]
United Kingdom