Privacy Policy
We Will Never Sell Your Data
Your personal data is not a product. We will never sell or rent your data to any third party; share your data with advertisers or data brokers; use your data to build advertising profiles; license your data to analytics companies or data aggregators; trade your data in exchange for services; or allow any human to review your personal data outside of what is necessary to operate the service (e.g., resolving a dispute you have submitted).
This is not a policy we reserve the right to change quietly. Any future change to how we use your data will be communicated directly to you with at least 14 days' notice before it takes effect (see Section 13).
The only time your data leaves SimToCircuit is to operate the service itself — specifically, to process your subscription through Stripe. That is described in full in Section 4.
What We Collect
Account Data: Your email address (for login, account recovery, and transactional notifications) and your password — we never see or store your password; it is hashed and held by our authentication provider before it reaches us.
Billing Reference: When you subscribe, Stripe generates an ID that links your account to your subscription status. We store only this reference — not your card number, billing address, or any payment details. All payment information is entered directly into Stripe and never passes through our systems.
Payout Info (if applicable): If you receive prize payouts, Stripe Connect handles collection of your banking details directly. We do not receive or store this information.
Racing Activity: Race entries, RSVPs, and check-in timestamps (for scheduling and attendance); iRacing session and subsession IDs (for result verification and race record-keeping); penalties, disputes, and club affiliations (for league administration and accountability).
Technical Data: Session tokens stored in secure, HTTP-only cookies — not accessible to JavaScript or any client-side code. Server logs (IP address and request timestamps only), not linked to your profile, automatically deleted after 30 days.
How We Use It
Email address: Login, account recovery, transactional notifications. Subscription identifier: Verify your active membership and manage billing via Stripe. Racing activity: Leaderboards, scheduling, dispute resolution, league rules enforcement. Session tokens: Keep you logged in securely. Server logs: Security monitoring and troubleshooting.
We do not use your data for advertising. We do not send marketing emails. Penalty and dispute decisions are made by human administrators, not automated systems.
Payment Processing
We do not handle your payment information. When you subscribe, you enter your payment details directly into a Stripe-hosted interface. That information goes to Stripe and stays with Stripe.
What we receive from Stripe is a subscription status and a customer reference ID — nothing that could be used to identify or charge your payment method. Stripe operates under PCI-DSS standards and their own privacy policy at stripe.com/privacy.
Infrastructure
SimToCircuit is hosted on industry-standard cloud infrastructure and uses Stripe for payment processing. We use these platforms to build and run the service — they are infrastructure providers, not parties we share your data with for their own purposes.
All data is stored in data centers in the United States. Stripe processes payments under their own compliance standards and data residency practices.
Data Retention
Account data (email, credentials): 7 years, or until you request deletion — legal and operational compliance. Subscription reference (Stripe ID): 7 years — financial record-keeping. Race activity (entries, results, penalties, disputes): 7 years, or until you request deletion — leaderboard integrity and dispute resolution. Session tokens: Until logout or expiry — active session management only. Server logs: 30 days — security monitoring.
If you request account deletion, personal data (email, credentials, racing activity) is purged within 30 days. Subscription reference records required for financial compliance are retained for the full 7-year period.
Security
Your connection to SimToCircuit is always encrypted — we serve exclusively over HTTPS and all data in transit is protected by TLS. Your password is hashed by our authentication provider before it reaches our systems — we never see it. Session tokens are stored in secure cookies that are inaccessible to JavaScript and cannot be stolen by cross-site scripting attacks. When you log out or your session expires, your session tokens are immediately cleared. Our database is not publicly accessible. Payment card data never enters our systems — Stripe handles all PCI-DSS scope.
To report a security concern, open a ticket in our official Discord server.
Cookies
We use cookies only to keep you logged in. No tracking cookies, no analytics, no advertising of any kind. If you log out or your session expires, the cookies are cleared.
Your Rights
You may request to access a copy of the personal data we hold about you; correct inaccurate or incomplete data; delete your account and personal data (financial reference records retained per law); or export your data in a portable format.
Open a ticket in our official Discord server with your account email and what you're requesting. We will respond within 2 business days and may verify your identity before acting.
Note: Account deletion is permanent and ends your access immediately. Membership fees already paid are non-refundable.
Breach Notification
If we discover unauthorized access to your personal data, we will notify you by email within 72 hours — describing what happened, what data was affected, and what we are doing to address it.
Third-Party Services
SimToCircuit may reference or link to external platforms such as iRacing, Twitch, or Discord. This policy does not cover their data practices. Please review their respective privacy policies.
Minors
This service is not intended for users under 18. We do not knowingly collect data from minors. If you believe someone under 18 has created an account, open a ticket in our official Discord server and we will delete it promptly.
Changes to This Policy
Material changes — new data collected, new uses, or changes to your rights — will be communicated by email and/or in-app notice at least 14 days before taking effect. Minor clarifications may be made without advance notice.
Version history: v1.0 — 2026-05-25 — Initial release.
Contact
Privacy requests and security concerns are handled through our official SimToCircuit Discord server. Open a support ticket and we will respond within 2 business days.