Privacy Policy

Last updated: September 7, 2026

Important: This Privacy Policy explains how RaceTagger collects, uses, and protects your information when you use our race photography analysis service, including our website, desktop application, and related services.

1. Introduction

RaceTagger ("we," "our," or "us") is a race photography analysis service operated by Federico Pasinetti, based in Italy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at racetagger.cloud, our desktop application for Windows and macOS, and any related services (collectively, the "Service").

We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Italian data protection laws (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018).

Data Controller: Federico Pasinetti, operating as RaceTagger. Contact: privacy@racetagger.cloud

2. Information We Collect

2.1 Account Information

When you register for our Service, we collect:

  • Email address (required for account creation and authentication)
  • Name (if provided)
  • Password (stored as a secure hash, never in plain text)
  • Account creation date and last sign-in timestamp
  • Communication and marketing preferences, including your marketing consent choice (see Section 2.7)

2.2 Payment Information

When you purchase token packages, we collect billing information through our payment processor, Stripe, Inc. We do not store credit card numbers or full payment details on our servers. We retain:

  • Transaction records (amount, date, token package purchased)
  • Billing country and tax identification details (for VAT/tax compliance via Stripe Tax)
  • Stripe customer and payment identifiers

2.3 Image and Photography Data

Our core service processes your photographs for race number detection and participant identification. When you use our analysis features:

  • Desktop App (Local Processing): When using local ONNX models, image processing occurs on your device. However, downscaled copies of image regions may be uploaded to our cloud infrastructure for AI analysis via Google Cloud (see the next bullet and Section 4.1).
  • Desktop App (Cloud Processing): When using Gemini cloud models, downscaled image crops and contextual regions are transmitted for analysis. Only downscaled JPEG copies are uploaded — at most 1920 pixels on the long side, and typically 1440 pixels for RAW files. Full-resolution originals leave your computer only if you start the optional "Upload HD Originals" action in the results page, which uploads them to our gallery storage (Cloudflare R2, Section 4.1); otherwise your original files and RAW files never leave your computer.
  • Image Metadata: We read EXIF/IPTC metadata from your photos (camera model, date taken, GPS if present) to support analysis. We can write metadata back to your files (race number, participant name) at your request.
  • Analysis Results: Race numbers detected, confidence scores, participant matches, scene classifications, and visual tags are stored in our database linked to your account.
  • Uploaded image storage: Downscaled copies you submit for cloud analysis are stored in our Storage under a non-guessable file path, retained for 90 days (see Section 5). Anyone who obtains the exact path to a file can read it directly, without signing in — we do not currently restrict access with a signed, expiring URL. We are evaluating moving this bucket to private access with signed URLs.

2.4 Biometric Data (Face Recognition)

For selected professional championships and other sport categories where it is enabled, our Service includes a face recognition feature that identifies participants from facial features in photographs. Under GDPR Article 9, facial recognition data constitutes special category (biometric) data.

Race numbers are the primary identifier. Face recognition is used only as a supplementary method, on scenes where a race number is not visible or not legible (portraits, pit garage, podium). It is active only for sport categories where the feature is enabled, and only when the preset being used contains at least one reference photo; there is no separate switch to turn it off for an individual analysis — you control it by not adding reference photos to a preset, or by removing them.

Three distinct data flows exist, and they are treated differently:

(a) Photos you analyse. Face detection and matching run locally on your device using on-device ONNX models. The facial feature vectors computed from the photographs you analyse are kept only on your device, for the duration of the analysis, and are deleted when the analysis is complete. They are never transmitted to our servers.

(b) Reference photos you upload to a preset. When you add a reference photo of a known participant to one of your own presets, both the photograph and the facial feature vector computed from it are stored on our servers (Supabase, EU region) for as long as that preset exists, so that the same preset can be used across analyses and devices. You can delete them at any time by removing the photo from the preset — this removes both the file in storage and the database row, including the descriptor. For this flow, you are the data controller for the person depicted and RaceTagger processes the reference photo and descriptor as your processor: you are responsible for having a lawful basis — ordinarily the explicit consent of the person photographed, under Article 9(2)(a) — before uploading it. See our Data Processing Agreement for the details of this relationship.

(c) Official presets maintained by RaceTagger. For a small number of professional championships, RaceTagger itself maintains reference photos and facial feature vectors of professional drivers, sourced and curated by us rather than uploaded by a customer. For this data, RaceTagger is the data controller. These reference templates of professional drivers are processed by RaceTagger on the basis of our legitimate interest in providing accurate identification for professional, publicly-competing drivers; a data protection impact assessment covering this processing is maintained. Drivers or their teams may request removal at any time by writing to privacy@racetagger.cloud.

2.5 Desktop Application Telemetry

Our desktop application collects the following technical data to improve performance and diagnose issues:

  • Application usage: App launches, session duration, feature usage, application version, OS platform and version
  • System information: CPU architecture, available RAM, hostname, and operating system username. For anti-abuse device checks specifically, your username is truncated to 15 characters server-side before being stored or used. As of desktop app version 1.1.13, the app itself also truncates your OS username (15 characters) and hostname (20 characters) before sending them, for every payload that carries them — device checks, application-launch logs, and execution telemetry — in addition to the server-side truncation described above. Server-side, that same 15/20-character cap currently applies only to anti-abuse device checks; for application-launch logs (see "Application usage" above) it exists as a database-level rule not yet deployed — until it is, those records keep whatever the app already truncated to before sending, per the previous sentence.
  • Device identifier: A SHA-256 hashed machine ID derived from your hardware. We do not store the raw hardware identifier.
  • Error reports: When errors occur, we collect sanitized stack traces, error messages, and diagnostic context designed to strip file paths, email addresses, and usernames before transmission. You can turn this off in the desktop app's Settings ("Automatic Error Reporting").
  • Execution telemetry: Analysis settings, model selected, number of images processed, processing duration, and token consumption per execution.
  • Analysis log files (JSONL): Every time you run an analysis, a JSONL log of that run is uploaded to our servers to support troubleshooting, retained for 12 months. As of desktop app version 1.1.13, you can turn this off in Settings → Privacy & AI ("Upload analysis logs for troubleshooting", on by default) — turning it off keeps every analysis log on your computer only, nothing is sent. When upload is on, the log is sanitized before it leaves your device: an absolute file path found anywhere in it is rewritten to a path relative to the folder you selected for that analysis, or to just its file name when it falls outside that folder — never a full local path — and fields that identify your computer (hostname, OS username, and similar) are redacted outright rather than truncated. This is different from error reports: it happens on every run, not only when you submit an error report.

You can disable non-essential telemetry (application usage) in the desktop app settings. As of desktop app version 1.1.13, automatic error reporting and analysis log upload can also be turned off from Settings → Privacy & AI — each is on by default, and each is a separate toggle from the AI training consent described in Section 3.3.

2.6 Website Analytics and Cookies

Our website uses the following analytics and tracking technologies, subject to your consent:

  • Google Analytics 4: Page views, sessions, and user engagement metrics. Configured with IP anonymization enabled and ad personalization signals disabled.
  • Microsoft Clarity: Session recordings, heatmaps, and click tracking for UX improvement. May record mouse movements, scrolls, and clicks on our website.
  • Meta Pixel and Conversions API: Conversion tracking for advertising campaigns, both from your browser (Pixel) and, for certain conversion events, from our servers directly to Meta (Conversions API). We apply PII sanitization to the Pixel to prevent transmission of personal data (emails, phone numbers, names) to Meta in the clear; the server-side Conversions API instead sends a SHA-256 cryptographic hash of your email address and account identifier. A hashed email is still personal data under GDPR even though it is not human-readable.

Our website loads fonts (Inter, Roboto Mono, JetBrains Mono, Barlow Condensed) via Next.js' font system: they are downloaded once at build time and served from our own domain, not from Google's servers, so visiting our website does not connect your browser to Google Fonts regardless of your cookie choices.

The analytics and marketing technologies above are loaded only after you provide consent through our cookie banner. You can change your preferences at any time via the cookie settings on our website. See our Cookie Policy for full details, including how a change to this policy causes the consent banner to reappear.

2.7 Marketing and Communication Data

If you give explicit marketing consent (an unchecked-by-default checkbox at signup, separate from accepting this Privacy Policy and the Terms of Service), we collect:

  • Your email address and marketing consent status
  • Email engagement metrics (opens, clicks) via our email service provider, Brevo
  • UTM parameters from your signup (source, medium, campaign) for attribution purposes

Marketing consent defaults to declined and is not retroactive: if you registered before this consent field existed, we treat you as not consenting to marketing until you actively opt in, even if you were previously receiving our newsletter. Your account is always synced to our email platform (Brevo) for service and transactional email regardless of marketing consent; you are only added to the marketing/newsletter list, and only receive newsletter broadcasts, if you have given marketing consent. You can withdraw consent at any time via the unsubscribe link in any marketing email, or by contacting us; an unsubscribe or complaint is also recorded in our suppression list and honored across future sends.

3. How We Use Your Information

3.1 Legal Bases for Processing (GDPR Article 6)

We process your personal data on the following legal bases:

Processing ActivityLegal BasisGDPR ArticleYour Control
Account creation & authenticationContract performanceArt. 6(1)(b)Account deletion
Image analysis & race number detectionContract performanceArt. 6(1)(b)Per-execution
Payment processing & invoicingContract + Legal obligationArt. 6(1)(b)(c)N/A (required)
Face recognition — reference photos in your presetsContract (RaceTagger as processor) + Art. 9(2)(a) explicit consent, obtained by you from the person depicted (you are the controller)Art. 6(1)(b), Art. 9(2)(a)Add/remove reference photos
Face recognition — official driver presets maintained by RaceTaggerLegitimate interest; a data protection impact assessment covering this processing is maintainedArt. 6(1)(f)Removal on request
AI model training with your imagesLegitimate interestArt. 6(1)(f)Right to object / opt-out in settings
Desktop app telemetryLegitimate interestArt. 6(1)(f)Settings toggle (usage telemetry only)
Error reporting & analysis logsLegitimate interestArt. 6(1)(f)Settings toggle (desktop app 1.1.13+)
Website analytics (GA4, Clarity)ConsentArt. 6(1)(a)Cookie banner
Advertising tracking (Meta Pixel & Conversions API)ConsentArt. 6(1)(a)Cookie banner
Marketing emails & newslettersConsentArt. 6(1)(a)Opt-in checkbox (unchecked by default) + unsubscribe link
Tax compliance & financial recordsLegal obligationArt. 6(1)(c)N/A (required)

3.2 Service Delivery

We use your data to provide, maintain, and improve the Service, including: analyzing your photographs using AI models, matching detected race numbers to participant databases, generating analysis results and visual tags, managing your token balance and purchase history, and delivering email notifications about your analysis results.

3.3 AI Model Improvement

By default, we may use anonymized analysis data and image crops to train and improve our AI models for race number detection, scene classification, and related features, on the basis of our legitimate interest in improving the Service. Only images an admin has curated into the training dataset (see Section 4.1, Roboflow) are actually used; you may object and opt out at any time by emailing privacy@racetagger.cloud, and we will cease using your data for training purposes going forward. (A self-service toggle for this in your account settings is planned but not yet built — until then, opting out goes through this email.)

3.4 Security and Abuse Prevention

We monitor for abusive use of our Service, including device fingerprinting for rate limiting and fraud prevention. This processing is based on our legitimate interest in maintaining service integrity and protecting our users.

4. Data Sharing and Third-Party Processors

We do not sell, rent, or trade your personal data. We share data with the following categories of processors, each bound by data processing agreements:

4.1 Sub-Processors

ProviderPurposeData SharedLocation
Supabase (PostgreSQL)Database, Auth, StorageAccount data, analysis resultsEU (Frankfurt)
Google Cloud Vertex AIAI image analysis (Gemini) — desktop app, website demo, our private API, and entry-list PDF parsing. This EU-only guarantee covers these photo/PDF pipelines specifically — see the next row for our calendar-research tooling, which is not a photo pipeline and is not EU-pinnedDownscaled image crops, PDF text, promptsEU only, never a global or non-EU endpoint. The "eu" multi-region for crop re-analysis, visual tagging, and PDF parsing, with europe-west4 as an automatic fallback only if "eu" itself is unavailable; europe-west1 for default photo analysis, the website demo, and our private API
Google Cloud Vertex AI (calendar research)Internal tooling only — automated championship calendar sync (session-context-ai-sync) via Gemini with Google Search grounding, to keep event/session schedules current. Never touches a customer photo and is not a fallback for photo analysisPublic championship/event/session metadata only (names, rounds, dates, venues, official URLs) — used to build the search query and to write the resulting calendar back. No customer photos or personal dataGlobal Vertex endpoint (not EU-pinned) — Google Search grounding for this model is not confirmed to work on an EU-only Vertex location
Google AI StudioInternal admin tooling only, all gated to admins — not used in any customer-facing analysis flow, and not a fallback from Vertex AI anywhere else in the product. Four callers: gemini-proxy (ad-hoc model testing), analyze-multimodal (multi-modal detection test lab), the business-analytics AI-insights summarizer, and sync-calendar-results (race-calendar research via Gemini with Google Search grounding)Whatever an admin submits while testing a model (may include image or text content) for the first two; aggregated internal business metrics (no customer photos or personal data) for the third; only race-calendar metadata (championship name, event/session names, dates, venue, official results-source URL) for the fourth — no customer photos or personal data. Restricted to Gemini 2.5/3 modelsUS
OpenRouter, Inc.Internal admin tooling only, gated to admins — candidate AI model screening (run-regression-benchmark, and the Management Portal's /api/benchmark-run route that triggers it) against our curated internal regression test set, to evaluate models outside the Gemini family before any production adoption decision. Never used in a customer-facing analysis flow, and never a fallback from Vertex AIA regression test-set image (curated internal QA photos, not customer uploads) and the analysis prompt, routed to whichever third-party model the admin selects for the screening runVaries by the model selected — OpenRouter forwards each request to that model's own hosting provider, so no single, fixed data residency applies
Stripe, Inc.Payment processing, TaxBilling info, transactionsUS (SCCs)
Brevo (Sendinblue)Email marketing & transactionalEmail, preferencesEU (France)
Cloudflare (R2)Image storage (galleries)Gallery imagesEU/US (Cloudflare Inc.) — DPF + SCCs
Vercel, Inc.Website hostingIP, request logsUS (SCCs)
Google AnalyticsWebsite analyticsAnonymized usage dataUS (SCCs)
Microsoft ClarityUX analyticsSession recordingsUS (SCCs)
Meta PlatformsAd conversion tracking (Pixel + server-side Conversions API)Sanitized events; SHA-256 hashed email/user ID for server-side eventsUS (SCCs)
Roboflow, Inc.(a) Real-time AI image analysis (RF-DETR object detection) for the sport categories configured to use it, instead of Google Cloud Vertex AI — see 4.2; and (b) AI model training dataset management (admin-curated, training-consented images only)(a) A signed URL to the uploaded photo, for inference only; (b) downscaled image copies, filenameUS (SCCs)

4.2 International Data Transfers

Where data is transferred outside the European Economic Area (EEA) — for example billing data to Stripe, an admin's test prompt to Google AI Studio, or a photo sent to Roboflow for real-time analysis, all as described in Section 4.1 — we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the Data Privacy Framework (DPF) where the recipient participates in it, or the data processor's adherence to an adequate level of protection as determined by the Commission. Most of your photographs and analysis data are not part of this: for the sport categories configured to use Google Cloud Vertex AI (the large majority), your photos are processed exclusively in the EU (Section 4.1), so they are not transferred outside the EEA in the first place. The categories configured to use Roboflow's RF-DETR model instead are the exception — those photos are sent to Roboflow (US) for that real-time analysis, under the SCCs referenced above. You may request a copy of the applicable safeguards, or ask which category applies to you, by contacting us.

4.3 Legal Disclosures

We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of RaceTagger, our users, or the public.

5. Data Retention

We retain your data for the following periods:

  • Account data: For the duration of your account, plus 30 days after deletion request to allow for recovery, plus up to a further 7 days for the data to age out of routine database backups.
  • Analysis results and execution logs: For the duration of your account. Deleted upon account deletion.
  • Analysis log files (JSONL, Section 2.5): 12 months from upload. We are rolling out a scheduled job to delete data past this period automatically; until it is fully live, older files are deleted manually on request.
  • Payment and transaction records: 10 years from the date of transaction, as required by Italian tax law (D.P.R. 600/1973).
  • Error reports and telemetry: 12 months from the date of collection. We are rolling out a scheduled database job to delete data past this period automatically; until it is fully live for your data, older records are deleted manually on request.
  • Uploaded images for AI analysis (Section 2.3): 90 days. We are rolling out an automated process to remove images past this period; until it is fully live, removal beyond 90 days is available on request.
  • Facial feature vectors and reference photos (Section 2.4): for reference photos in your own presets, until you delete the photo or the preset, or until you delete your account. For official driver presets maintained by RaceTagger, reviewed at least yearly.
  • Website analytics data: up to 14 months (Google Analytics), up to 1 year (Microsoft Clarity cookies — see the Cookie Policy for the duration of each individual cookie).
  • Marketing consent records: For the duration of your subscription, plus 3 years as proof of consent.
  • Image uploads for AI training: Retained only for the period necessary to complete model training. Deleted within 90 days of training completion or upon withdrawal of consent.
  • Platform infrastructure logs (Vercel, Supabase): governed by each provider's own log retention, up to 30 days under their standard configuration. RaceTagger does not extend or separately archive these logs.

6. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR. You may exercise these rights by contacting us at privacy@racetagger.cloud or through your account settings where applicable:

6.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data. We will respond to your request within 30 days.

6.2 Right to Rectification (Article 16)

You may request correction of inaccurate personal data or completion of incomplete data. You can update your email and profile information directly in your account settings.

6.3 Right to Erasure (Article 17)

You may request deletion of your personal data. Upon receiving a valid erasure request, we will delete your account and associated data within 30 days, including the images and reference face photos you have uploaded to our Storage, except where retention is required by law (payment records, retained by our payment processor Stripe for tax compliance), is not attributable to you individually (official driver reference photos maintained by RaceTagger, described in Section 2.4(c), are not personal data of yours and are not affected by your account deletion), or would break aggregate records shared with other users (your account identifier may remain in the affected-user list of a platform-wide error report, since removing it would corrupt the affected-user count for other, unrelated accounts). Deleted data may persist in routine backups for up to a further 7 days. Account deletion can be initiated through your account settings or by contacting us.

6.4 Right to Restriction of Processing (Article 18)

You may request that we restrict processing of your data in certain circumstances, such as while we verify the accuracy of contested data or assess whether our legitimate interests override your rights.

6.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON). You can export your data through your account settings; the export includes your account and subscriber profile, token balance and transactions, purchases, executions and analysis results, uploaded image metadata (file names and storage paths, not the image files themselves), application launch history, the metadata and URLs of reference face photos in your own presets (not the facial feature vectors used for matching — contact us if you need those), and your recent error reports. Token transactions, purchases, executions, analysis results, and uploaded images are capped at your 1,000 most recent each, error reports at your 500 most recent, and application launches at your 100 most recent; if you have more than that, the export response says so and you can contact privacy@racetagger.cloud for a complete export. RaceTagger Assistant conversations are not included in the export, because no such data is stored yet — the feature is still in development (see Section 14).

6.6 Right to Object (Article 21)

You may object to processing based on legitimate interests (such as telemetry collection, AI training, or the official driver presets described in Section 2.4(c)). We will cease processing unless we demonstrate compelling legitimate grounds. You may also object to direct marketing at any time, and we will comply without exception.

6.7 Right to Withdraw Consent (Article 7)

Where processing is based on consent (analytics cookies, marketing emails, advertising tracking), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at www.garanteprivacy.it, or with the supervisory authority in your EU Member State of residence.

7. Cookies and Tracking Technologies

7.1 Essential Cookies

These cookies are strictly necessary for the operation of our website and cannot be disabled:

  • Authentication session cookies (Supabase Auth)
  • Cookie consent preferences (racetagger_consent in localStorage), including the version of this Cookie Policy you consented to

7.2 Analytics Cookies (Require Consent)

These cookies help us understand how visitors interact with our website:

  • Google Analytics (_ga, _ga_*): Measures page views, sessions, and user engagement. IP anonymization is enabled. Cookie duration: 2 years. Data retention within Google Analytics: up to 14 months.
  • Microsoft Clarity (_clck, _clsk, CLID): Records session replays, heatmaps, and click behavior. Cookie durations range from 1 day (_clsk) to 1 year (_clck, CLID) — see the Cookie Policy for the duration of each cookie.

7.3 Marketing Cookies (Require Consent)

  • Meta Pixel (_fbp, _fbc): Tracks conversions from Facebook/Instagram advertising. PII is sanitized before transmission. Duration: 90 days.

7.4 Managing Your Preferences

You can manage your cookie preferences at any time through the cookie settings banner on our website. The banner also reappears automatically if we update this Cookie Policy in a way that changes what it discloses (a new version number) — a consent recorded under an older version is treated as not decided. You may also configure your browser to block or delete cookies, although this may affect website functionality.

8. Desktop Application Specific Provisions

8.1 Local Data Storage

The desktop application stores the following data locally on your device:

  • Authentication tokens for maintaining your login session
  • Application settings and preferences
  • Cached analysis configurations and participant presets
  • JSONL log files for each analysis run — these are also uploaded to our servers, see Section 2.5

8.2 Network Communications

The desktop application communicates with our servers for the following purposes:

  • User authentication and session management
  • Token balance checks and consumption tracking
  • Image analysis via cloud AI models (Section 2.3 and Section 4.1)
  • Downloading sport category configurations and participant presets
  • Application update checks
  • Telemetry, error report, and analysis log submission (Section 2.5)

8.3 Offline Capability

When using local ONNX models for analysis, the desktop app can function partially offline. However, token authorization, result storage, and certain features require an active internet connection.

9. Children's Privacy

Our Service is intended for professional and semi-professional photographers and is not directed to individuals under the age of 18. We do not perform age verification at signup beyond the account creation flow itself. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Row-Level Security (RLS) policies on customer-facing database tables
  • SHA-256 hashing of device identifiers
  • Automatic PII sanitization in error reports, analytics, and application logs, including email addresses in server-side logs (partially redacted, e.g. "f***@domain.com" — the domain remains visible)
  • Role-based access control for account-facing and payment functions. A small number of internal administrative tools do not yet have this control fully applied — we are addressing this as a priority.
  • Regular security reviews and dependency updates

While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you via email if the changes are significant
  • Display a prominent notice on our website and/or desktop application

We encourage you to review this Privacy Policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Automated Decision-Making (Article 22)

The Service uses one form of fully automated decision-making with a direct effect on you: our device-limit check, run at login, can automatically deny access to your account if it determines you have exceeded the number of devices allowed. This decision is based on the device fingerprinting described in Section 3.4.

If you believe this decision was made in error, you can request human review by contacting info@racetagger.cloud. Beyond this device-limit check, we do not carry out profiling or automated decision-making that produces legal effects or similarly significantly affects you. Race number detection, participant matching, and scene classification (Sections 2.3–2.4) are analysis outputs you review and act on yourself; they are not decisions we make about you.

13. Customers Based Outside the EEA

If you use the Service as a photographer or business based outside the European Economic Area, you remain the data controller for the photographs you submit and the people depicted in them, under the law applicable to you. RaceTagger processes that data as your processor from our infrastructure in the EEA, under the Data Processing Agreement described in Section 4 and available at /dpa. This does not change the international-transfer safeguards described in Section 4.2 for the sub-processors we ourselves use.

14. RaceTagger Assistant

We are developing an in-app conversational assistant ("RaceTagger Assistant") that can answer questions about your account and, for subscribers, take actions on your behalf inside the Service. In line with Article 50 of the EU AI Act, you are informed that this feature is an artificial intelligence system: when you interact with it, you are talking to an AI, not a human.

This feature is still in development at the time of writing. Once live, conversations with the Assistant will be processed within the EU and retained for 90 days; database tables to store them do not exist yet, which is also why Assistant conversations are not currently part of the data export described in Section 6.5. We will update this section with any change to that design before the feature launches.

15. Contact Information

For any questions, concerns, or requests regarding this Privacy Policy or our data practices:

Privacy inquiries: privacy@racetagger.cloud

General inquiries: info@racetagger.cloud

Legal matters: legal@racetagger.cloud

Abuse reports: abuse@racetagger.cloud

Data Controller: Federico Pasinetti

Website: https://racetagger.cloud


This Privacy Policy is effective as of September 7, 2026.