GT7 EngiRace

Privacy Policy of GT7 EngiRace

Effective as of 18 July 2026

This English translation is provided for convenience. The French version remains the legally binding version. These documents are governed by French law.

1. Data controller

The data controller for personal data processed through GT7 EngiRace is:

DUPIN Valentin, sole proprietor Address: 271 bis chemin des craoux, 84310 Morières-lès-Avignon, France SIREN: 851 134 445 [FULL SIRET]: [PLACEHOLDER SIRET COMPLET] Email: valentin@dislo.fr

GT7 EngiRace is operated by DUPIN Valentin as the website publisher.

2. Data Protection Officer (DPO)

No DPO has been appointed, as this is not mandatory for the current processing activities. For any privacy-related question, users may contact the data controller directly at valentin@dislo.fr.

3. Personal data collected

We collect only the data necessary to provide, secure and improve the service, manage accounts and payments, and handle community contributions.

The categories of data collected include:

Account identity data: Clerk user ID (userId), email address, and possibly a display name depending on the authentication provider. Payment data: no card data is stored by us; payments are processed by Stripe. We only retain technical references such as the stripe_customer_id, transaction identifiers and credit history. Account and credit data: IA credit balance, purchase history, consumption history, credit/debit operations. Generated setups: car, track, objective, tuning parameters, generated outputs, generation history. BYOK personal API key: API key provided by the user for Google Gemini, OpenAI or Anthropic, stored encrypted on the server; it is never stored in plain text. Setup feedback: like/dislike, free-text comment, related setup reference. App feedback: bug report, idea, compliment, free-text message, category, optional contact email. Security and anti-spam data: IP hash used for rate limiting and abuse prevention. Technical data: server logs, timestamps, request traces, diagnostic data. Limited browsing data: technical cookies necessary for the service to function.

We do not intentionally collect sensitive personal data within the meaning of Article 9 GDPR, unless a user voluntarily provides such data in a feedback message, in which case it is used only to handle the relevant request.

4. Sources of data

Data comes from:

the user directly, when creating an account, purchasing credits, using the service or submitting a message; automatically, during browsing; our technical providers, when necessary to provide the service, secure access or confirm a transaction.

5. Purposes and legal bases

We process personal data for specific, explicit and legitimate purposes.

DataPurposeLegal basisRetention period
Account identity (userId, email)Account creation and managementPerformance of a contractWhile the account is active, then deletion or anonymisation subject to legal obligations
Payment data / stripe_customer_idPayment processing, purchase management and transaction evidencePerformance of a contract; legal obligationInvoicing data: 10 years; technical references: as long as necessary for service administration
Credit balance and historyManagement of purchased, offered and consumed IA creditsPerformance of a contractWhile the account is active, then limited retention for evidence/accounting
Generated setupsProvision of the tuning recommendation service and user historyPerformance of a contract; legitimate interest in traceabilityWhile the account is active, or deleted upon request subject to legal retention obligations
Encrypted BYOK API keyAllow the user to use their own API key for IA generationPerformance of a contractAs long as the feature remains active, then deletion upon request or account closure
Setup/app feedbackService improvement, support, bug fixing, feature prioritisationLegitimate interestUp to 24 months after receipt, unless longer retention is needed for evidence or litigation
IP hash for anti-spamFraud prevention, abuse limitation and spam controlLegitimate interestShort technical period, strictly necessary
Server logs / timestampsSecurity, diagnostics, incident prevention, technical auditLegitimate interest; security obligation6 to 12 months depending on sensitivity, unless longer retention is needed after an incident
Technical cookiesSession, language preference, site operationLegitimate interest / exemption from consent for strictly necessary cookiesDepending on the cookie, usually session duration or up to 6 months for preferences
Analytics cookies (Google Analytics)Audience measurement, visit statistics, service improvementConsent (or legitimate interest depending on configuration and applicable CNIL requirements)Up to 13 months (CNIL recommendation)

6. Recipients of personal data

Personal data is accessible only to authorised personnel of the controller and, where applicable, to technical service providers acting on our behalf.

Main recipients and processors include:

Clerk: authentication and account management, mainly in the USA. Stripe: payment processing and fraud prevention, in the USA/EU depending on the flow. Turso: database hosting. Vercel: application hosting and technical logs. Google Analytics (Google LLC): audience measurement and visit statistics (measurement ID G-MXPLMK3VCM). Google Gemini / Google AI Studio: AI-related processing when the service uses Google’s platform. OpenAI / Anthropic: only if the user uses their own BYOK API key with one of these providers; in that case, these providers act under their own policies and the user may have a direct contractual relationship with them.

We may also disclose data to third parties where required by law, upon request of a competent court or authority, or to assert our legal rights.

7. International transfers outside the EEA

Some providers may involve transfers of data outside the European Economic Area, including to the United States.

We ensure such transfers are properly safeguarded under the GDPR and CNIL guidance, including by:

using the European Commission’s Standard Contractual Clauses (SCCs) where required; implementing additional safeguards when necessary; reviewing provider security and compliance commitments; limiting transfers to what is strictly necessary.

Relevant services include Clerk, Stripe, Vercel, Google Analytics, Google Gemini and, where applicable, OpenAI or Anthropic for BYOK use. Where transfers rely on contractual safeguards, users may request a copy or summary by contacting the data controller.

8. Retention periods

We retain data only for as long as necessary for the purposes pursued, then delete or anonymise it.

The main retention periods are:

Active user account: for the duration of service use. Billing data and accounting records: 10 years from the end of the fiscal year, in accordance with applicable legal obligations. Credit and transaction history: account lifetime + period necessary for proof, fraud prevention and complaint handling. Generated setups: while the account is active, unless the user requests deletion or temporary retention is needed as evidence of a transaction. Setup feedback and app feedback: up to 24 months. Technical logs / server logs: generally 6 to 12 months. Anti-spam IP hash: strictly as long as necessary for filtering and security. Encrypted BYOK API key: as long as the feature is active, then deleted upon request or account closure. Technical cookies: session duration or, for some preferences, up to 6 months. Google Analytics cookies: up to 13 months (CNIL recommendation). Cookie consent records: kept for a reasonable period for proof and to avoid repeated requests.

These periods may be extended in the event of a dispute, complaint, audit or legal retention requirement.

9. Data security

We implement appropriate technical and organisational measures to protect data against loss, unauthorised access, disclosure, alteration or destruction.

Main measures include:

HTTPS encrypted communications; server-side encryption of BYOK API keys using AES-256-GCM; logical segregation of data; access limited to authorised persons only; access logging and anomaly monitoring; secret management and environment variable protection; backups and continuity measures where applicable.

No security measure can provide absolute protection. In the event of a personal data breach likely to result in a high risk to individuals’ rights and freedoms, we will notify affected users and, where required, the CNIL.

10. Cookies and other trackers

The site uses:

strictly necessary cookies/trackers required for operation, including:

  • Clerk session cookies: authentication and session maintenance;
  • NEXT_LOCALE language cookie: language preference storage;

audience measurement cookies/trackers via Google Analytics 4 (Google LLC), to analyse site traffic and improve the service. Relevant cookies (e.g. _ga, _ga_*, _gid) are described in the Cookies Policy.

These trackers are essential to the service or its proper use and generally do not require prior consent when they are strictly necessary. Analytics cookies require consent where required by the CNIL; you may refuse them via your browser settings (see Cookies Policy). We do not use advertising marketing cookies (Meta Pixel, targeted advertising, etc.). A cookie consent banner may be implemented later to formalise analytics cookie management.

11. Minors

GT7 EngiRace is intended for adults. We do not target minors and do not intentionally collect personal data from minors.If a parent or legal guardian believes that a minor has provided us with personal data without authorisation, they may request deletion by writing to valentin@dislo.fr.

12. Your rights

Under the GDPR and the French Data Protection Act, you have the following rights:

right of access; right to rectification; right to erasure; right to restriction of processing; right to object, especially where processing is based on legitimate interests; right to data portability where applicable; right to withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal.

These rights may be limited where processing is necessary to comply with a legal obligation, to establish, exercise or defend legal claims, or where another legal exemption applies.

13. Exercising your rights

To exercise your rights or ask any question about your personal data, please contact us at:

  • valentin@dislo.fr
  • We may ask for proof of identity if needed, only to verify your identity where there is reasonable doubt.
  • We will respond within one month of receiving your request. This period may be extended by two additional months in complex cases or where there are numerous requests, in accordance with the GDPR. If extended, you will be informed of the reasons for the delay.

14. Complaint to the CNIL

If you believe, after contacting us, that your rights are not respected or that our processing does not comply with applicable law, you may lodge a complaint with the CNIL:

Website: www.cnil.fr

15. Link with the Terms and Conditions and contributor charter

This privacy policy must be read together with:

the site’s Terms and Conditions; the applicable contributor charter for community presets, JSON imports and user-generated content; any additional policy displayed on the website.

If there is a conflict between a specific policy and this privacy policy, the specific policy prevails for the relevant processing, unless mandatory law provides otherwise.

16. Community contributions

The site may allow users to share community presets, set car limitations or import JSON files. In this context, data published by users may be visible to others depending on the sharing settings selected. Users must not include unnecessary personal data in their contributions.The controller may moderate, hide or remove any content that is unlawful, contrary to the Terms and Conditions, or contrary to the contributor charter.

17. Changes to this policy

We may update this privacy policy to reflect:

legal or regulatory changes; technical changes to the website; changes in our providers or processing practices.

The applicable version is the version in force on the date you access the website, or, where required by law, the version brought to the user’s attention for consent or prior information.

18. Contact

For any question regarding this privacy policy or your personal data:

  • DUPIN Valentin271 bis chemin des craoux, 84310 Morières-lès-Avignon, FranceEmail: valentin@dislo.fr