Introduction
This Privacy Policy explains what personal data The Racing Line collects, why we collect it, who we share it with, how long we keep it, and what control you have over it. It covers our mobile application on iOS and Android (the "App"), our website at theracingline.app (the "Website"), and the accounts, subscriptions and affiliate programme we operate through them.
The Racing Line offers accounts, paid subscriptions and an affiliate programme, so we do collect personal data. Earlier versions of this policy stated that we did not; that is no longer accurate and this version replaces it in full.
We do not sell your personal data, and we do not share it with third parties for their own independent marketing.
1. Who We Are
The Racing Line Software is the data controller for the personal data described in this policy. We are based in the United Kingdom, and we process personal data in accordance with the UK GDPR and the Data Protection Act 2018. Where the EU GDPR applies to a user in the European Economic Area, we apply the equivalent standard.
You can reach us about anything in this policy through the contact form on our Website.
2. The Data We Collect
Account data. When you create an account we store:
- Email address: required, used to sign you in and to send service messages.
- Name: the name you enter on your profile.
- Profile picture: optional, if you upload one.
- Date of birth and gender: optional, entered by you on the profile page and left blank unless you choose to provide them. If you select "other" for gender you may add a short free-text description.
- Country: a country-level code only (for example "GB"), derived from your connection by our hosting provider so we can show the right currency and pricing. We do not store the IP address it came from for this purpose.
- Social media username: only if you supply one, for affiliate and partnership purposes.
- Account metadata: the date you accepted our terms, which platform you signed up on, the app version in use, and your marketing and event email preferences.
Subscription and billing data. If you subscribe, we store your subscription status, the platform you bought on, the product and transaction identifiers issued by the store, renewal and expiry dates, cancellation and payment-failure flags, and, for web subscriptions, your Stripe customer and subscription identifiers. We never see or store your card number. Card details are handled entirely by Stripe, Apple or Google, on their own pages rather than ours.
When Apple or Google tells us about a purchase, renewal or cancellation, we keep their notification in full. As well as the transaction identifiers, it records the price and currency you paid and the country the store recorded for the purchase.
App preferences. The series you follow, your visibility and display settings, and your notification preferences, so they sync between your devices.
Support and error reports. If you report incorrect session data from the App, we store your description of the problem, the session it relates to, and a snapshot of your email address so we can follow up.
Technical and security data. To keep the service working and to protect it from abuse, we process:
- IP addresses and browser or device user-agent strings: used for rate limiting, bot protection, and diagnosing abuse. Your IP address is also recorded against a promotional-code redemption reported by the iOS app.
- Device integrity keys: for Apple App Attest and Google Play Integrity, which confirm that requests come from a genuine, unmodified copy of our App.
- Sync diagnostics: where an account is flagged for troubleshooting a sync fault, a temporary log of what each device sent, including the platform and user-agent.
- A content-protection identifier: a per-account index used to trace unauthorised copying of our race data, as described in our Terms and Conditions.
Advertising and attribution data. This is collected only if you accept advertising cookies in our consent banner. Nothing in this group runs, and no advertising cookie is written, unless and until you accept. It consists of:
- A visitor identifier stored in the trl_aid cookie. It is a random value that does not contain anything about you, but it is not anonymous: if you go on to create an account, we link it to that account so we can tell that the visit and the sign-up were the same person.
- Advertising click identifiers and campaign tags from the link you arrived on (Meta, Google or TikTok click identifiers and any UTM parameters), together with the full landing page address and the page that referred you. We record Google and TikTok click identifiers so that we can measure those channels if we advertise on them; at present we do not, and those identifiers are not shared with anyone.
- A hashed form of your IP address and user-agent, recorded against the visit rather than the original values.
- Meta matching identifiers: your Meta browser and click cookies, stored together with your IP address and user-agent in unhashed form, because Meta requires them in that form to match a conversion to an advert.
What we send to Meta. Where you have consented on the Website, we report events to Meta both from your browser and from our own servers. Page views, sign-ups and clicks through to the app stores are reported, and so are subscription events (starting a trial, subscribing, renewing and cancelling), including the amount paid and the currency. Your email address and your account identifier are hashed before they are sent; your IP address and user-agent are sent unhashed. Hashing is not anonymisation: a hashed email is still your personal data under UK GDPR, and Meta uses it precisely because it can be matched back to you. We never send your name, date of birth, gender, address or phone number.
Accounts created in the App. When you create an account in the App, we also report that sign-up to Meta from our servers, so we can measure whether our advertising is working. This is not covered by the Website cookie banner, because it does not involve cookies or your browser: we send a hashed form of your email address and your account identifier, the platform you signed up on, and a country code — nothing else, and nothing about what you do inside the App. Legal basis: our legitimate interests in measuring the advertising we pay for. You can object at any time using section 8, and we will stop reporting for your account and exclude it from future sends.
App usage data. So we can see where people get stuck — for example how many users finish setting up and how many stop at the subscription screen — the App records a short, fixed list of things you do. This is not advertising data, it is never sent to Meta, and it does not depend on the cookie banner, which covers the Website only. It consists of:
- An installation identifier: a random value the App creates the first time you open it and stores on your device. It is not your advertising identifier, it is not taken from Apple's IDFA or Google's advertising ID, and it is not shared with anyone outside our own systems. It survives until you delete or reinstall the App.
- A fixed list of app events. Only these: opening the App for the first time, opening it again, finishing onboarding, creating your account, adding your first series, granting notification permission, reaching the subscription screen, its outcome (subscribing at either price, or closing it and coming back later), and starting a trial. Each one records the time, the platform, the app version and a country code — nothing else. Repeat opens are counted so we can see whether people keep using the App.
- The link to your account. Events recorded before you sign up are kept against the installation identifier alone. If you then create an account, we associate them with it, so that a journey which began before sign-up can be understood as one person's. That means these records are personal data, and everything in section 8 applies to them.
What the App does not record. No screen recording, no screenshots, no keystrokes, no free text you type, no contacts, no location beyond a country code, and no automatic capture of every tap. The list above is the whole list, it is enforced by our servers — anything not on it is rejected rather than stored — and we check that no email address or similar detail is smuggled into it.
Affiliate data. If you apply to the affiliate programme we additionally store your requested code, your social platform handles, any message you send us, and the payout details you give us: either a PayPal email address or a bank account name, sort code and account number.
Data from sign-in providers. If you sign in with Google or Apple, we receive your email address and basic profile details from them so we can create or match your account.
3. Why We Use Your Data, and Our Legal Basis
- To provide your account and the service: signing you in, syncing your followed series and settings, sending race notifications you have asked for. Legal basis: performance of our contract with you.
- To take payment and manage subscriptions: processing purchases, renewals, cancellations, refunds and access entitlements. Legal basis: performance of our contract with you.
- To keep the service secure: rate limiting, bot protection, app-integrity checks, fraud prevention, and protecting our race data from unauthorised copying. Legal basis: our legitimate interests in securing the service and protecting our data.
- To support you: answering enquiries and acting on the data errors you report. Legal basis: performance of our contract, and our legitimate interest in improving accuracy.
- To understand how the service is used: the app events in section 2, so we can find the points where people give up and fix them, and measure whether new releases help. We look at these as rates and groups — "62% of new users never finish onboarding" — not to follow an individual around; our own staff tools deliberately cannot show one person's activity. Legal basis: our legitimate interests in operating and improving the service. You can object at any time using section 8, and we will stop recording them for you.
- To measure and improve our advertising: connecting an advert click to a later sign-up or subscription, and reporting conversions to advertising platforms. Legal basis: your consent, given through the cookie banner, which you can withdraw at any time — except the reporting of App sign-ups described in section 2, which relies on our legitimate interests and carries a right to object instead.
- To send marketing emails: our sale and event emails go only to people who have opted in. Legal basis: your consent. There is one exception: when you register, we send a single email about the introductory offer that is running on your account, whether or not you opted in. It is sent once, only ever once, and carries an unsubscribe link. Legal basis: our legitimate interest in telling a new registrant about the offer they signed up under.
- To run the affiliate programme: assessing applications, tracking referrals and paying commission. Legal basis: performance of our contract with the affiliate.
- To meet our legal obligations: keeping accounting and tax records, and responding to lawful requests. Legal basis: compliance with a legal obligation.
Optional profile fields such as date of birth and gender are provided at your choice; leaving them blank does not affect your use of the service. Where we rely on legitimate interests, we have considered the impact on you and you can object at any time; see section 8.
4. Cookies and Similar Technologies
Our Website uses cookies. The App does not use browser cookies, but it does store equivalent identifiers on your device: for sign-in, for the app-integrity checks in section 12, and the installation identifier described in section 2. None of the App's stored identifiers are used for advertising.
What we do depends on where you are. Cookie law differs by country, so the Website works out your location from your connection and applies the rules for that place. There are two behaviours:
- United Kingdom, the EEA, and most of the world: nothing beyond the essential and security cookies below runs until you choose Accept all. Closing, ignoring or scrolling past the banner is not acceptance, and nothing advertising-related is loaded while you do nothing. If we cannot work out where you are, this is the behaviour you get.
- United States, Canada outside Quebec, Australia, New Zealand and Japan: advertising cookies run when the page loads, we tell you so at that point, and you can switch them off in one click, either on that notice or through the Do Not Sell or Share My Personal Information link in the footer.
Global Privacy Control. If your browser sends a Global Privacy Control signal, we treat it as an instruction to switch advertising cookies off, we honour it before any advertising cookie is set, and we tell you on screen that we have done so. You do not need to do anything else, and we honour it wherever you are, not only in the places that require it.
Essential cookies. These are always on, because the site cannot work without them. No consent is required for them, and they are not used for advertising:
- Authentication cookies set by Supabase, which keep you signed in. Access tokens are short-lived and refresh automatically.
- trl_consent: records your cookie choice so we do not ask again. Lasts 180 days.
- trl_pending_email: set when we send you a confirmation email, so that if you open a link that has already expired we can tell you which address it was sent to. It holds that address, cannot be read by scripts in your browser, and expires after 24 hours.
- Cloudflare Turnstile: used on the sign-in and registration pages to tell humans from bots. Turnstile does not track users across sites.
- trl-funnel-id: a random value written to your browser's local storage only when you start the sign-up flow, so we can count how many people who begin signing up go on to create an account. It is created nowhere else on the Website, is sent only to our own servers, is not shared with anyone, and is deleted from your browser when you finish signing up.
- Administrator session cookies: used only by our own staff accounts for two-factor administration.
Advertising cookies. These are set only after you choose Accept all on the cookie banner. If you choose Essentials only, none of them are written and the Meta Pixel is never loaded:
- trl_aid: the visitor identifier described in section 2, lasting 90 days and refreshed on each visit. It is also mirrored into your browser's local storage.
- _fbc: records the Meta advert you clicked, so a later sign-up can be matched to it. We set this one ourselves and it lasts 90 days.
- _fbp: a Meta browser identifier, set by Meta's own pixel script rather than by us.
- The Meta Pixel: loaded from Meta only after consent, and used to report page views and sign-ups.
Content embedded from other companies. Some pages include content served directly by someone else, which can set their own cookies as soon as that page loads:
- YouTube: used to play race streams and video clips.
- Google Maps: used to show the map on circuit pages.
We do not receive anything from these embeds and we do not use them to advertise, but they do let YouTube and Google see your IP address and which page you were viewing, under their own privacy policies. To be straight with you: these currently load whether or not you accept advertising cookies. We are changing that so they load only with your agreement. In the meantime, your browser's third-party cookie settings will block them.
Changing your mind. Once you have made a choice, a Cookie settings button stays in the corner of our public pages, including this one. You can use it at any time to reopen the banner and switch advertising cookies off again, and refusing is always as easy as accepting. We do not repeat the banner inside the signed-in app, because the choice has already been made by then; if you are signed in and want to change it, this page is the quickest route. When you turn them off we delete the advertising cookies listed above, along with the browser-storage copy of your visitor identifier, and stop sending events to Meta. Withdrawing consent does not by itself erase what was collected while consent was in place. To have that erased, ask us using section 14.
5. Who We Share Data With
We use the following service providers, who process personal data on our instructions under a written data-processing agreement:
- Supabase: our database, authentication and file storage. Holds account data, preferences and uploaded profile pictures.
- Vercel: hosting for the Website and our scheduled jobs. Processes request data including IP addresses, and supplies the country-level location we use for pricing.
- Cloudflare: DNS, content delivery, web application firewall and the Turnstile bot check. Processes request data including IP addresses.
- Stripe: payment processing for web subscriptions. Stripe collects your payment details directly and acts as an independent controller for its own fraud-prevention and regulatory purposes.
- Apple: App Store distribution, in-app purchases, subscription notifications, App Attest device checks, and Sign in with Apple.
- Google: Google Play distribution, in-app purchases, subscription notifications, Play Integrity device checks, and Google sign-in.
- Resend: delivery of our transactional and marketing emails. Processes your email address and message content.
- Backblaze B2: object storage for race calendar data and media assets.
- Mixpanel: product analytics inside the mobile App only. The App's own analytics component sends usage events to Mixpanel; this is separate from the app-usage data in section 2, which stays in our database. Mixpanel is not used on the Website and is not used for advertising.
- Meta Platforms: advertising measurement. On the Website this happens only where you have accepted advertising cookies; sign-ups made in the App are additionally reported from our servers as described in section 2, on the basis of our legitimate interests. We send the identifiers described in section 2, together with sign-up and subscription events and their value. For the data we send, Meta acts as a joint controller with us under its Controller Addendum, and as an independent controller for what it then does with it. Beyond those two paths, we do not send Meta anything.
- Web3Forms: delivery of messages submitted through our contact form. The form sends your name, email address and message straight to Web3Forms, which emails it to us. We do not store it in our own database.
- YouTube and Google Maps: embedded video and maps, as described in section 4. These see your IP address when a page containing them loads.
We may also disclose personal data where we are legally required to, where it is necessary to establish or defend legal claims, or in connection with a sale or reorganisation of our business, in which case you will be told beforehand.
6. International Transfers
Several of the providers listed above are based in, or process data in, the United States and other countries outside the United Kingdom. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum, the European Commission Standard Contractual Clauses, or an adequacy decision, together with the safeguards those providers have in place. You can ask us for details of the safeguards that apply to a particular transfer.
7. How Long We Keep Data
- Account data: kept while your account is open. When you delete your account it is anonymised as described in section 9.
- Deleted-account email record: when you delete your account we keep a record of the email address that was used, purely so we can tell you that the address was previously registered if you try to sign up again. This is automatically deleted after 90 days.
- Payment, subscription and commission records: retained after account closure for as long as UK tax and accounting law requires, currently six years from the end of the relevant financial year.
- Support and error reports: kept while the reported issue is open and for a reasonable period afterwards so we can spot recurring data problems.
- Security and rate-limiting records: short-lived. Bot-check tokens and app-attestation challenges expire within minutes; rate-limit counters expire within hours.
- Advertising and attribution records: the trl_aid cookie lasts 90 days from your last visit. The matching records on our servers, including the Meta matching identifiers in section 2, are kept for as long as your account is open — we do not yet run a time-based purge for open accounts, though they are now deleted automatically when you delete your account (section 9). We are still working on a fixed period; in the meantime we will delete them on request, and you can ask at any time without closing your account.
- App usage data: the individual app events in section 2 are deleted automatically 13 months after they are recorded, by a job that runs every night. We keep that long so we can compare one racing season with the previous one. The summary of which stages an installation has reached, and the daily totals we chart, are kept while your account is open; they are a few rows per installation and contain no new information about you.
- Sync diagnostic logs: only created for accounts we are actively troubleshooting, and deleted once the fault is resolved.
Where no fixed period is stated, we keep personal data only for as long as it is needed for the purpose it was collected for, and you can ask us to erase it sooner.
8. Your Rights
You have the following rights over your personal data. There is no charge, and we will respond within one month.
- Access: you can see and check the personal data on your account at any time on the profile page in the App or on the Website. You can also ask us for a copy of everything else we hold about you.
- Rectification: you can correct your name, date of birth, gender, email address and profile picture directly on the profile page. If anything else is wrong, tell us and we will fix it.
- Erasure: you can delete your account yourself, in the App or on the Website. See section 9 for exactly what that does. You can also ask us to erase specific data, such as advertising, attribution or app usage records, without closing your account.
- Portability: you can ask us for a copy of the data you have given us in a structured, machine-readable format. Ask us using the contact form and we will prepare it for you.
- Objection and restriction: you can object to processing we carry out on the basis of legitimate interests, and ask us to restrict processing while an objection or a correction is being considered.
- Withdrawing consent: you can withdraw advertising consent at any time using the Cookie settings button in the corner of this page, and turn off marketing emails from your account settings or the unsubscribe link in any marketing email. Withdrawing consent does not affect processing carried out before you withdrew it.
- Complaining: if you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.
9. Deleting Your Account
You can delete your account at any time, in the App or from the profile page on the Website. It takes effect immediately. When you delete your account we:
- Cancel any subscription billed through us straight away, so you are not charged again;
- Delete your profile picture;
- Remove your name, and clear your followed series, display settings and notification preferences;
- Replace your email address on your account with a placeholder that cannot receive mail, which both removes it and frees your real address for re-registration;
- Sign you out on every device and disable the account.
Subscriptions bought through Apple or Google must be cancelled by you, in your App Store or Google Play subscription settings. We are not able to cancel those on your behalf, and deleting your account does not stop them renewing.
Deleting your account now also erases, automatically, the tracking records that used to be left behind: the Meta matching identifiers holding your IP address and user-agent, the link between your visits and your account, the advertising click records themselves, and the app usage data in section 2. This clean-up was added in August 2026; an earlier version of this policy warned that it had to be done by hand, and that is no longer the case.
It is still not a complete erasure, and we would rather say so plainly. Some records that remain are linked to you: your date of birth, gender and country if you gave them; your subscription and payment history, which we are legally required to keep; and any error reports you sent us. If you want those erased too, ask us using the contact form and we will do it by hand where the law allows.
One thing we cannot undo. Where you had consented and we already reported a sign-up or subscription to Meta, Meta has its own copy. There is no way for us to recall an event that has been sent, so we cannot delete it from their systems on your behalf. What we can do, we do: we stop sending anything further, and we erase the identifiers at our end. To have your data removed at Meta's end you need to use the privacy controls in your own Meta account.
What we keep even then. Payment, subscription and commission records are retained for the accounting periods described in section 7, because we are legally required to keep them. Your email address is also held in the separate 90-day record described in section 7.
10. Marketing and Notifications
Notifications. The App can remind you about upcoming sessions for the series you follow. You choose which reminders you get in the App, and you can turn them off there or in your device settings at any time. Your choices sync to your account so they follow you between devices, but the reminders themselves are scheduled by your own device. We do not hold a push token for your device, and we do not send notifications from our servers.
Email. We send service emails you cannot opt out of while you have an account: confirming your address, resetting your password, and telling you about changes to your subscription. Sale and event emails are sent only if you opt in. As explained in section 3, one email about the introductory offer is sent to every new registrant regardless of that setting. Every marketing email, including that one, contains an unsubscribe link, and unsubscribing stops all of them.
11. Children
The Racing Line is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has given us personal data, contact us and we will delete it. Where you provide a date of birth it is optional and is used only to understand our audience, not to restrict access.
12. Security
We protect your data with row-level security in our database, so one account cannot read another. Administrative access is limited to named staff accounts protected by two-factor authentication. Payment card details never reach our servers. Bot protection and rate limiting sit in front of our sign-in and account routes, and our App uses Apple and Google device-integrity checks to confirm requests come from a genuine copy of the App.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will tell you and the Information Commissioner's Office as the law requires.
13. Changes to This Policy
We may update this Privacy Policy as the service changes. The date at the top of this page shows when it was last revised. If we make a change that materially affects how we use your data, or that requires your consent, we will tell you directly rather than relying on this page alone.
14. Contact Us
For any privacy question, or to exercise any of the rights in section 8, please use the contact form on our Website and mark your message as a privacy request. Our Terms and Conditions govern your use of the service alongside this policy.

