Legal · privacy
Privacy Policy
1. Controller
The controller of your personal data within the meaning of the EU General Data Protection Regulation (GDPR) is Ville Löfgren / Pace-ly (enskild firma), Härkevägen 9, 832 96 Frösön, Sweden, contact support@pace-ly.com. We have not appointed a Data Protection Officer because we are not required to under Article 37 GDPR.
2. What we collect and why
The table below describes the categories of personal data we process today. It is illustrative of how and why we process data, not an exhaustive field list. As the Service gains features we may process further data of the same kinds and for the same purposes described here; where a change materially affects you we will update this table and, where required, notify you or ask you to re-accept this Policy (see section 10).
| Category | Source | Legal basis | Retention |
|---|---|---|---|
| Account identifiers: Discord ID, name, avatar URL, email | Discord OAuth on first sign-in | Art. 6(1)(b): performance of the contract (operating your account) | Until account deletion + 30 days |
| Billing data: Stripe customer ID, subscription status, period dates | Stripe webhooks; we never see your card number | Art. 6(1)(b): contract; Art. 6(1)(c): bookkeeping obligation | 7 years from end of fiscal year (Bokföringslagen 7:2) |
| Telemetry: throttle, brake, steering, suspension, tyre, etc. (in-sim only) | Pace-ly Client reads the simulator’s shared memory and uploads it | Art. 6(1)(b): to provide the analysis service | While your account is active, until you delete it |
| Lap video clips: short in-sim video of a single lap, which may include the game’s audio, uploaded so it can be played back alongside your telemetry | Pace-ly Client records and uploads it when you choose to capture a lap | Art. 6(1)(b): to provide the video-analysis feature you enable | Until you delete the clip, free its storage slot, or delete your account |
| AI chat transcripts and driver feedback | You, by chatting with Pace-ly | Art. 6(1)(b) | While your account is active, until you delete the thread or your account |
| Driver profile: handle, display name, bio, avatar/banner URLs, optional iRacing customer ID. Shown to other users according to your profile-visibility setting | You, via profile settings | Art. 6(1)(b): providing the profile and team features you enable | Until you clear the fields or delete your account |
| Team data: memberships and roles, join requests, invitations, shared setups and shared telemetry, competition entries and results | You and your team’s admins, by using the Teams features | Art. 6(1)(b) | Until you leave the team or delete the content; removed with account deletion |
| Team chat messages | You, by posting in your team’s channels | Art. 6(1)(b) | Until deleted by you or a team admin; removed with account deletion |
| Technical data: IP address, user-agent, request logs | Your browser and the live-client connecting to our edge | Art. 6(1)(f): legitimate interest in security and abuse prevention | Up to 90 days |
| Consent records: timestamp, IP, document version, hash | Captured when you accept ToS/Privacy | Art. 6(1)(c): to demonstrate compliance with GDPR Art. 7(1); Art. 6(1)(f) / Art. 17(3)(e): retaining proof of acceptance to establish or defend legal claims | Kept after account deletion in pseudonymised form (IP and user-agent removed), retaining only proof of which document version you accepted and when, for no longer than necessary to establish or defend legal claims (typically the statutory limitation period) |
3. Recipients and sub-processors
We share personal data only with the sub-processors listed at /subprocessors. In summary:
- Discord Inc.: identity provider for OAuth sign-in (US, SCCs).
- Stripe Payments Europe Ltd.: payment processing (Ireland, intra-EEA).
- Anthropic PBC: AI inference for the race-engineer feature (US, SCCs). Anthropic does not train on API inputs by default.
- Cloudflare Inc.: edge hosting, D1 database, R2 telemetry and video storage. We configure R2 to keep EU users’ data in EU jurisdictions (SCCs apply). Cloudflare Email Routing also forwards mail sent to our support address to the operator’s mailbox.
- Resend (Plus Five Five, Inc.): sends our transactional and support e-mail (e.g. when you use the contact form). Receives the e-mail’s name, address and content (US, SCCs).
4. International transfers
Where personal data leaves the EEA (Anthropic, Discord, Cloudflare US), transfers rely on the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where applicable, supplementary technical measures (encryption in transit, encryption at rest). DPAs are stored and available on request to support@pace-ly.com.
5. Your rights under GDPR
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). For access/portability you can use the self-service download at /account/privacy; for everything else email support@pace-ly.com. We respond within one month (Art. 12(3)).
When you delete your account we erase your personal data as described in the table above, with two limited exceptions the law permits us to keep: billing records held by Stripe (required by the Swedish Bokföringslag) and a pseudonymised record of which legal-document versions you accepted (retained to establish or defend legal claims under Art. 17(3)(e), with your IP and user-agent removed).
You may withdraw any consent you have given at any time without affecting the lawfulness of past processing. You may lodge a complaint with the Swedish supervisory authority Integritetsskyddsmyndigheten (IMY) at imy.se, or with the DPA of your habitual residence.
6. Automated decision-making and AI
Pace-ly uses an AI model (Anthropic Claude) to generate setup advice and driving observations. This is not automated decision-making within the meaning of Article 22 GDPR: no legal or similarly significant effect is produced for you, and the output is advisory only, requiring your own action to apply. See /ai-disclosure for the full disclosure.
7. Security
Data is encrypted in transit (TLS) and at rest (Cloudflare-provided encryption for D1 and R2). Access to production systems is restricted to the founder. See /legal-security for our security and vulnerability disclosure policy.
8. Children
The Service is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has used the Service, please contact support@pace-ly.com and we will delete the account.
9. Cookies
The Service uses a single strictly-necessary session cookie set by our authentication system. We do not use analytics, advertising or tracking cookies. See /cookies.
10. Changes to this Policy
We may update this Policy. The version and date are shown above. For material changes affecting your rights we will notify you by email or in-product banner.