PRIVATE BETA
MyRacingPath is in private beta and not open to the public. These policies apply to you now: they are not drafts. We update them as the product changes, and we will tell you before any material change takes effect.
PRIVACY POLICY
Last updated: 21 August 2026
1. Who we are
- MyRacingPath is operated by MY RACING PATH LTD, a company registered in England and Wales (company number 17355031), whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
- MY RACING PATH LTD is the data controller for personal data collected about you through the service.
- We are registered with the UK Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018, registration number ZC223123.
- MyRacingPath currently markets to and serves users in the United Kingdom. The platform does not actively target users in the European Union or European Economic Area. If, in future, MyRacingPath offers services to EU users at a scale that triggers Article 27 of the EU GDPR, an EU representative will be appointed and details published here. EU or EEA users who happen to use the service can in any event contact us at support@myracingpath.com and may lodge a complaint with their local supervisory authority.
- A correspondence address is available on request via support@myracingpath.com.
- For any data protection questions, contact us at support@myracingpath.com.
2. What data we collect
Account information
Name, email, date of birth, country of residence, password (hashed), profile photo (optional). Your date of birth is what enforces the minimum age of 13 at sign-up and switches on the under-18 protections in section 10.
Racing information
Racing history, championships entered, sessions and results you log, equipment owned, goals, team membership, and any racing budget or season costs you choose to record.
Performance and AI data
Skill Score assessments, reaction time results, your conversations with our AI features (the Race Engineer, the career agents, interviews), the facts those features extract from your conversations to remember you by, any Path Agent drafts you work on, and any AI review you request of your saved path. Nothing changes your saved path unless you press Save: section 5 explains that.
Health data
None. The app does not ask for or store health information. An earlier version had an injury log; that feature was removed in July 2026 and no injury data is held for any account.
Safeguarding data
If something typed into an AI feature, or something an AI feature writes back, trips our safety checks: the flagged excerpt, its category, the automated triage outcome, whether the account belonged to someone under 18 and their age at the time, and a record of who we alerted. Section 8 explains how long this is kept, and our Safeguarding Policy explains why.
Sponsorship outreach data
If you use the sponsorship agent: the local businesses you search for and save as prospects, the outreach messages it drafts and the ones sent from your own connected Gmail address, replies to those messages (which we screen for scams and manipulation), and an encrypted token for the Gmail connection, which is deleted when you disconnect it or delete your account.
Payment information
Processed by Stripe. We receive confirmation of payment and subscription status but do not store full card details.
Technical data
IP address, device type, browser, operating system, pages viewed, features used, timestamps.
Communication data
Emails you send us and feedback you submit in the app.
Parent data (where applicable)
Email address, approval decisions for an under-18 driver's team seat, consents given.
Launch notification list
If you ask to be told when MyRacingPath opens, we store your email address, the fact that you consented, and which page you asked from. Nothing else: no name, no age, no date of birth. You do not need an account to join the list, and joining it does not create one.
3. How we collect data
- Directly from you when you create an account, complete surveys, use our features, communicate with us, or ask to be told when the app opens.
- Automatically through cookies and similar technologies (see our Cookie Policy).
- From third parties only where specifically stated: Stripe (payment confirmation), authentication providers (if you use Google sign-in), and your own Gmail mailbox if you connect it for sponsorship outreach (we read replies to messages the agent sent, nothing else).
4. Why we collect data (purposes and legal basis)
- To provide the MyRacingPath service and personalised AI career recommendations: Article 6(1)(b) UK GDPR (contract performance).
- To process payments: Article 6(1)(b). Any paid plan covering an under-18 driver is bought and held by a parent or guardian, either as an individual plan in their own name or as a Team they manage with the driver on a driver seat, so for those plans the payment contract is with the parent or guardian and we process the payer's account and payment data to perform it. The driver's own use of the service still runs on the driver's account.
- To send service-related communications such as confirmation emails, renewal reminders, and security notifications: Article 6(1)(b).
- To send marketing communications: Article 6(1)(a) consent. You can withdraw at any time.
- To tell you once that MyRacingPath has opened, if you joined the launch notification list: Article 6(1)(a) consent. We email you a single time for that purpose. We do not add you to any other list, we do not sell or share the address, and every message carries an unsubscribe link. You can withdraw at any time by emailing us or using that link.
- To prevent fraud, protect the security of our service, and retain safeguarding records, including after an account is deleted: Article 6(1)(f) legitimate interests, balanced against user rights.
- To comply with legal obligations including tax, accounting, and regulatory requirements: Article 6(1)(c).
- To protect vital interests in case of safeguarding concerns: Article 6(1)(d) and Schedule 1 Part 2 paragraph 18 of the Data Protection Act 2018.
5. Automated decisions and profiling
- We use automated processing to generate your Skill Score and your Race Engineer responses.
- Your Racing Path is yours, and nothing changes it without you pressing Save. You build it in the path editor: you choose every championship, and the app supplies facts and costs from its catalogue. On the Max plan you can also talk to the Path Agent, which works on a draft copy beside you; the draft touches nothing until you save it, and you can ask the AI for a second opinion on a saved path at any time, which changes nothing on its own. Families do make real spending decisions on plans like this, so we are not going to pretend it is trivial: anything the AI drafts or tells you about your path is an opinion for you to argue with, not a decision we have made about you.
- Nothing we do is a decision made purely by a machine that has a legal or similarly significant effect on you, which is what the UK GDPR rules on significant decisions, as amended by the Data (Use and Access) Act 2025, are about. For drivers under 18 we go further and do not make significant decisions about you by machine at all, which is what Standard 12 of the ICO's Age Appropriate Design Code asks of us.
- Before opening the beta we completed a Data Protection Impact Assessment covering all of this, written against the live system rather than from a template, and we review it whenever the service materially changes.
- You can request human review of any automated output at any time.
6. Who we share data with (sub-processors)
We share limited personal data with the following sub-processors, each bound by data processing agreements and appropriate safeguards:
| Provider | Purpose | Transfer mechanism |
|---|---|---|
| Supabase | Database and authentication hosting. | UK region (London). The data stays in the UK. Supabase's standard terms add the SCCs and the UK Addendum for any support access from outside it. |
| Vercel | Application hosting. | United States. Data Privacy Framework certified, with the SCCs and the UK Addendum in Vercel's standard terms. |
| Stripe | Payments and subscriptions. | United States. Data Privacy Framework certified, with the SCCs and the UK Addendum in Stripe's standard terms. |
| Resend | Transactional email. | United States. SCCs and the UK Addendum in Resend's standard terms. |
| Anthropic | The AI models behind every AI feature. | United States. SCCs and the UK Addendum in Anthropic's standard commercial terms. |
| Sign in with Google if you choose it, plus Places and Maps lookups when you search for a sponsor company. Not used for any AI feature. | United States. Data Privacy Framework certified, with the SCCs and the UK Addendum in Google's standard terms. | |
| PostHog | Product analytics. EU region, no session recording, and it only runs if you accept analytics cookies. | EU region. The analytics stay in the EEA, which the UK's adequacy regulations cover. PostHog is a US company, so its standard terms add the SCCs and the UK Addendum for any support access from outside the EEA. |
| Sentry | Error reports when something breaks. There is no session recording, so we never record or replay your screen. | EU region (Germany). The reports stay in the EEA, which the UK's adequacy regulations cover. Sentry is a US company, so its standard terms add the SCCs and the UK Addendum for any support access from outside the EEA. |
| Upstash | Rate limiting. It holds short-lived counters keyed to your IP address or account id and nothing else. Each counter expires automatically, most within minutes and all within 24 hours. | UK region (London). The counters stay in the UK. Upstash is a US company, so its standard terms add the SCCs and the UK Addendum for any support access from outside it. |
| Vercel Analytics | Aggregate page view counts. It sets no cookies, and it only runs if you accept analytics cookies. | United States. The same Vercel entity, so the same Data Privacy Framework certification, SCCs and UK Addendum. |
Our AI features run on Anthropic's Claude models only. Nothing you type into the Race Engineer goes to any other AI provider.
- We do not sell or rent your personal data to third parties.
- We may share data with law enforcement where legally required (for example under a court order or valid law enforcement request).
- We may share aggregated, anonymised data that does not identify you with partners for business purposes.
- If we are acquired or merge with another business, data may transfer to the successor entity, subject to the same protections as in this Policy.
7. International transfers
- Your account data lives in the United Kingdom. Supabase runs our database in the London region and Upstash runs our rate-limit counters in the same region, so neither leaves the country.
- PostHog holds our product analytics in the EU, and Sentry holds our error reports there too. The UK's adequacy regulations cover the EEA, so the data sitting there needs no extra safeguard.
- PostHog, Sentry and Upstash are American companies, but the data they hold for us sits in the UK or the EU as described above. Their standard terms add Standard Contractual Clauses and the UK International Data Transfer Addendum for any support access from outside it.
- The rest of our sub-processors are in the United States: Vercel, Vercel Analytics, Stripe, Resend, Anthropic and Google. Stripe, Vercel, Vercel Analytics and Google are certified under the EU-US Data Privacy Framework. Every one of them is covered by Standard Contractual Clauses and the UK International Data Transfer Addendum in their standard terms.
- Google receives your sign-in details if you choose Sign in with Google, and the Places and Maps lookups you run when searching for a sponsor company. It does not receive anything you type into an AI feature.
- You can request a copy of our transfer mechanisms by contacting us.
8. How long we keep data
- Account data: during your subscription, then 30 days after a deletion request (the soft-delete window, so you can change your mind), and in any event no more than 90 days.
- Payment records: 7 years. The Companies Act 2006 s.388 and HMRC VAT Notice 700/21 require six years from the end of the financial year the transaction falls in, so a flat seven is what guarantees we cover it. These records are kept without your name or email, linked only to the Stripe transaction.
- Safeguarding records: 7 years from case closure, and they are kept even if you delete your account. The retained record keeps the incident itself (the flagged excerpt, its category, the triage outcome and any alerts sent) together with who it concerned, including the name, email address and date of birth we held at the time, because a safeguarding record that cannot name its subject is useless to the authorities it exists for. The link to any live account is severed. See our Safeguarding Policy.
- Marketing consent logs: 2 years after withdrawal.
- Launch notification list: deleted once we have emailed you that the app has opened, or sooner on request. If we decide not to launch, the whole list is deleted. It is never held for more than 24 months.
- Race Engineer conversations: kept in your account until you delete them or delete your account, then removed with it. Anthropic holds what our models were sent under its standard commercial terms.
- Session files and associated timing data: kept for the lifetime of your account and deleted with it.
- Breach records: 6 years, and longer if a breach is still being dealt with or could still be litigated.
- After retention periods expire, data is deleted or anonymised irreversibly.
9. Your rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data (the “right to be forgotten”).
- Restrict processing.
- Object to processing based on legitimate interests or for direct marketing.
- Data portability (receive your data in a machine-readable format).
- Withdraw consent where processing is based on consent.
- Not be subject to solely automated decisions with legal or similarly significant effects.
- Lodge a complaint with the ICO (ico.org.uk) or your local EU data protection authority.
To exercise any of these rights, contact us at support@myracingpath.com. We will respond within one month, extendable by two months for complex requests, with notice.
For users under 18, a parent or legal guardian can also raise a request on their behalf by contacting support@myracingpath.com. There is no charge in most cases. Excessive or unfounded requests may incur a reasonable fee or be refused.
10. Children's privacy (ages 13 to 17)
- This policy is written for adults and older teenagers. We are working on a shorter, plainer version for younger drivers and we will link it here when it is ready. Until then, if anything on this page does not make sense to you, email support@myracingpath.com and we will explain it in plain English, properly, not with a brush-off.
- For users under 18 we apply additional protections by default: high privacy settings, geolocation off, profiling for marketing disabled, no public profile feature at all, no nudge techniques, and automated safety checks on what you type into our AI features and on what they write back.
- MyRacingPath has a minimum age of 13, sign-up refuses anyone younger, and there is no under-13 account type or consent route around that minimum age. Our Parental Consent Policy explains what that means.
- If you join a team, the team manager can see your racing record: exactly what is listed in the disclosure shown to you before you accept, and nothing more. A team manager never sees your AI conversations, your private notes, your date of birth, your consent status or any safety flags. Teammates on the same team see topline numbers only: display name, session and race counts, podiums and overall Skill Score. If you are under 18, the join completes only after a parent or guardian approves it by emailed link, and they are shown what would be shared before they decide.
- The launch notification list asks anyone under 16 to check with a parent or guardian before joining. It collects an email address and nothing else, it does not create an account, and a parent can ask us to remove an address at any time by emailing us. We do not use it to profile anyone or to target advertising.
11. Security
- We use industry-standard security measures including encryption in transit and at rest, role-based access controls, and regular security reviews.
- No system is 100% secure. We will notify affected users and the ICO of any personal data breach that poses a risk to your rights within 72 hours where required under Article 33.
- You are responsible for keeping your password secure.
12. Cookies and tracking
We use cookies and similar technologies. See our Cookie Policy for full details. Behavioural advertising cookies are not used on accounts for users under 18.
13. Changes to this policy
- We review and update this Privacy Policy regularly. The “Last updated” date reflects the most recent version.
- For material changes, we will notify you by email at least 30 days before the change takes effect.
14. How to complain
Contact us first at support@myracingpath.com. Our Complaints page sets out the route: we acknowledge every complaint within 30 days and respond without undue delay, complaining is free, and it does not affect your account. You can also complain directly to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or 0303 123 1113, whether or not you complain to us first, or to your local supervisory authority if you are in the EU or EEA.