Privacy Policy of GT7 EngiRace
Effective as of 18 July 2026
This English translation is provided for convenience. The French version remains the legally binding version. These documents are governed by French law.
1. Data controller
The data controller for personal data processed through GT7 EngiRace is:
DUPIN Valentin, sole proprietor Address: 271 bis chemin des craoux, 84310 Morières-lès-Avignon, France SIREN: 851 134 445 [FULL SIRET]: [PLACEHOLDER SIRET COMPLET] Email: valentin@dislo.fr
GT7 EngiRace is operated by DUPIN Valentin as the website publisher.
2. Data Protection Officer (DPO)
No DPO has been appointed, as this is not mandatory for the current processing activities. For any privacy-related question, users may contact the data controller directly at valentin@dislo.fr.
3. Personal data collected
We collect only the data necessary to provide, secure and improve the service, manage accounts and payments, and handle community contributions.
The categories of data collected include:
Account identity data: Clerk user ID (userId), email address, and possibly a display name depending on the authentication provider. Payment data: no card data is stored by us; payments are processed by Stripe. We only retain technical references such as the stripe_customer_id, transaction identifiers and credit history. Account and credit data: IA credit balance, purchase history, consumption history, credit/debit operations. Generated setups: car, track, objective, tuning parameters, generated outputs, generation history. BYOK personal API key: API key provided by the user for Google Gemini, OpenAI or Anthropic, stored encrypted on the server; it is never stored in plain text. Setup feedback: like/dislike, free-text comment, related setup reference. App feedback: bug report, idea, compliment, free-text message, category, optional contact email. Security and anti-spam data: IP hash used for rate limiting and abuse prevention. Technical data: server logs, timestamps, request traces, diagnostic data. Limited browsing data: technical cookies necessary for the service to function.
We do not intentionally collect sensitive personal data within the meaning of Article 9 GDPR, unless a user voluntarily provides such data in a feedback message, in which case it is used only to handle the relevant request.
4. Sources of data
Data comes from:
the user directly, when creating an account, purchasing credits, using the service or submitting a message; automatically, during browsing; our technical providers, when necessary to provide the service, secure access or confirm a transaction.
5. Purposes and legal bases
We process personal data for specific, explicit and legitimate purposes.
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Account identity (userId, email) | Account creation and management | Performance of a contract | While the account is active, then deletion or anonymisation subject to legal obligations |
| Payment data / stripe_customer_id | Payment processing, purchase management and transaction evidence | Performance of a contract; legal obligation | Invoicing data: 10 years; technical references: as long as necessary for service administration |
| Credit balance and history | Management of purchased, offered and consumed IA credits | Performance of a contract | While the account is active, then limited retention for evidence/accounting |
| Generated setups | Provision of the tuning recommendation service and user history | Performance of a contract; legitimate interest in traceability | While the account is active, or deleted upon request subject to legal retention obligations |
| Encrypted BYOK API key | Allow the user to use their own API key for IA generation | Performance of a contract | As long as the feature remains active, then deletion upon request or account closure |
| Setup/app feedback | Service improvement, support, bug fixing, feature prioritisation | Legitimate interest | Up to 24 months after receipt, unless longer retention is needed for evidence or litigation |
| IP hash for anti-spam | Fraud prevention, abuse limitation and spam control | Legitimate interest | Short technical period, strictly necessary |
| Server logs / timestamps | Security, diagnostics, incident prevention, technical audit | Legitimate interest; security obligation | 6 to 12 months depending on sensitivity, unless longer retention is needed after an incident |
| Technical cookies | Session, language preference, site operation | Legitimate interest / exemption from consent for strictly necessary cookies | Depending on the cookie, usually session duration or up to 6 months for preferences |
| Analytics cookies (Google Analytics) | Audience measurement, visit statistics, service improvement | Consent (or legitimate interest depending on configuration and applicable CNIL requirements) | Up to 13 months (CNIL recommendation) |
6. Recipients of personal data
Personal data is accessible only to authorised personnel of the controller and, where applicable, to technical service providers acting on our behalf.
Main recipients and processors include:
Clerk: authentication and account management, mainly in the USA. Stripe: payment processing and fraud prevention, in the USA/EU depending on the flow. Turso: database hosting. Vercel: application hosting and technical logs. Google Analytics (Google LLC): audience measurement and visit statistics (measurement ID G-MXPLMK3VCM). Google Gemini / Google AI Studio: AI-related processing when the service uses Google’s platform. OpenAI / Anthropic: only if the user uses their own BYOK API key with one of these providers; in that case, these providers act under their own policies and the user may have a direct contractual relationship with them.
We may also disclose data to third parties where required by law, upon request of a competent court or authority, or to assert our legal rights.
7. International transfers outside the EEA
Some providers may involve transfers of data outside the European Economic Area, including to the United States.
We ensure such transfers are properly safeguarded under the GDPR and CNIL guidance, including by:
using the European Commission’s Standard Contractual Clauses (SCCs) where required; implementing additional safeguards when necessary; reviewing provider security and compliance commitments; limiting transfers to what is strictly necessary.
Relevant services include Clerk, Stripe, Vercel, Google Analytics, Google Gemini and, where applicable, OpenAI or Anthropic for BYOK use. Where transfers rely on contractual safeguards, users may request a copy or summary by contacting the data controller.
8. Retention periods
We retain data only for as long as necessary for the purposes pursued, then delete or anonymise it.
The main retention periods are:
Active user account: for the duration of service use. Billing data and accounting records: 10 years from the end of the fiscal year, in accordance with applicable legal obligations. Credit and transaction history: account lifetime + period necessary for proof, fraud prevention and complaint handling. Generated setups: while the account is active, unless the user requests deletion or temporary retention is needed as evidence of a transaction. Setup feedback and app feedback: up to 24 months. Technical logs / server logs: generally 6 to 12 months. Anti-spam IP hash: strictly as long as necessary for filtering and security. Encrypted BYOK API key: as long as the feature is active, then deleted upon request or account closure. Technical cookies: session duration or, for some preferences, up to 6 months. Google Analytics cookies: up to 13 months (CNIL recommendation). Cookie consent records: kept for a reasonable period for proof and to avoid repeated requests.
These periods may be extended in the event of a dispute, complaint, audit or legal retention requirement.
9. Data security
We implement appropriate technical and organisational measures to protect data against loss, unauthorised access, disclosure, alteration or destruction.
Main measures include:
HTTPS encrypted communications; server-side encryption of BYOK API keys using AES-256-GCM; logical segregation of data; access limited to authorised persons only; access logging and anomaly monitoring; secret management and environment variable protection; backups and continuity measures where applicable.
No security measure can provide absolute protection. In the event of a personal data breach likely to result in a high risk to individuals’ rights and freedoms, we will notify affected users and, where required, the CNIL.
10. Cookies and other trackers
The site uses:
strictly necessary cookies/trackers required for operation, including:
- Clerk session cookies: authentication and session maintenance;
- NEXT_LOCALE language cookie: language preference storage;
audience measurement cookies/trackers via Google Analytics 4 (Google LLC), to analyse site traffic and improve the service. Relevant cookies (e.g. _ga, _ga_*, _gid) are described in the Cookies Policy.
These trackers are essential to the service or its proper use and generally do not require prior consent when they are strictly necessary. Analytics cookies require consent where required by the CNIL; you may refuse them via your browser settings (see Cookies Policy). We do not use advertising marketing cookies (Meta Pixel, targeted advertising, etc.). A cookie consent banner may be implemented later to formalise analytics cookie management.
11. Minors
GT7 EngiRace is intended for adults. We do not target minors and do not intentionally collect personal data from minors.If a parent or legal guardian believes that a minor has provided us with personal data without authorisation, they may request deletion by writing to valentin@dislo.fr.
12. Your rights
Under the GDPR and the French Data Protection Act, you have the following rights:
right of access; right to rectification; right to erasure; right to restriction of processing; right to object, especially where processing is based on legitimate interests; right to data portability where applicable; right to withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal.
These rights may be limited where processing is necessary to comply with a legal obligation, to establish, exercise or defend legal claims, or where another legal exemption applies.
13. Exercising your rights
To exercise your rights or ask any question about your personal data, please contact us at:
- valentin@dislo.fr
- We may ask for proof of identity if needed, only to verify your identity where there is reasonable doubt.
- We will respond within one month of receiving your request. This period may be extended by two additional months in complex cases or where there are numerous requests, in accordance with the GDPR. If extended, you will be informed of the reasons for the delay.
14. Complaint to the CNIL
If you believe, after contacting us, that your rights are not respected or that our processing does not comply with applicable law, you may lodge a complaint with the CNIL:
Website: www.cnil.fr
15. Link with the Terms and Conditions and contributor charter
This privacy policy must be read together with:
the site’s Terms and Conditions; the applicable contributor charter for community presets, JSON imports and user-generated content; any additional policy displayed on the website.
If there is a conflict between a specific policy and this privacy policy, the specific policy prevails for the relevant processing, unless mandatory law provides otherwise.
16. Community contributions
The site may allow users to share community presets, set car limitations or import JSON files. In this context, data published by users may be visible to others depending on the sharing settings selected. Users must not include unnecessary personal data in their contributions.The controller may moderate, hide or remove any content that is unlawful, contrary to the Terms and Conditions, or contrary to the contributor charter.
17. Changes to this policy
We may update this privacy policy to reflect:
legal or regulatory changes; technical changes to the website; changes in our providers or processing practices.
The applicable version is the version in force on the date you access the website, or, where required by law, the version brought to the user’s attention for consent or prior information.
18. Contact
For any question regarding this privacy policy or your personal data:
- DUPIN Valentin271 bis chemin des craoux, 84310 Morières-lès-Avignon, FranceEmail: valentin@dislo.fr
