Privacy Policy
The short version: we collect only what we need to run your team profile. We do not sell your data. We do not use tracking or advertising cookies. You can request deletion of your data at any time by emailing [email protected].
Contents
1. Who We Are
Race Team Wiki (raceteam.wiki) is the world's first comprehensive racing team index, cataloging over 2,705 teams across 125 racing series and 49 countries. The service is operated by StaaS Fund, a venture fund based in Georgia, USA. When this policy refers to "we," "us," or "our," it means Race Team Wiki and StaaS Fund.
This Privacy Policy explains how we collect, use, and protect personal information when you use raceteam.wiki, claim a team profile, subscribe to a premium plan, or communicate with us.
2. Data We Collect
2.1 Account Information
When you create an account, we collect:
- Email address — used to authenticate your account and send transactional emails about your team
- Password — stored as a salted cryptographic hash via Supabase Auth; we never store plaintext passwords
- Display name — optional, used on your profile
2.2 Team Profile Data
When you claim or edit a team profile, we collect and store:
- Team name, description, founding year, country, and series affiliations
- Driver names and roles
- Car make, model, class, and number
- Social media links (Instagram, Twitter/X, YouTube, TikTok, Facebook, website)
- Stripe payment link URL (your own Stripe link — we do not process this payment)
- Sponsor names and URLs
- Race results and championship standings
2.3 Photos and Media
Photos and logos you upload are stored in Supabase Storage. Free accounts may upload 1 team photo. Premium subscribers may upload up to 10 photos (10 MB each) and a team logo. You retain ownership of all media you upload.
2.4 Payment Information
Premium subscriptions are processed entirely by Stripe. When you subscribe, Stripe collects your credit card number, billing name, and billing address. We never see or store your full card number — Stripe provides us only with a non-sensitive subscription status token. We store your Stripe Customer ID and subscription status in our database to manage your account tier.
2.5 Usage Data
Cloudflare, our hosting and CDN provider, collects standard web server logs including IP addresses, browser type, referring URL, and pages visited. This data is processed by Cloudflare and used for security, performance, and analytics. We do not use Google Analytics or any third-party behavioral tracking scripts.
2.6 Communications
If you contact us by email, we retain that correspondence to respond to your inquiry and improve our service.
3. How We Use Your Data
We use the information we collect to:
- Create and manage your account and team profile
- Display your team profile publicly on raceteam.wiki
- Authenticate you when you log in
- Send transactional emails: claim confirmations, approval notifications, profile completion tips, and subscription receipts
- Process and manage your premium subscription via Stripe
- Rank and display teams on our Discover page based on profile completeness
- Investigate abuse, enforce our Terms of Service, and comply with legal obligations
- Improve the platform based on aggregate, anonymized usage patterns
We do not use your data for advertising targeting, behavioral profiling, or sale to third parties. Ever.
4. Third-Party Processors
We use the following third-party services to operate Race Team Wiki. Each acts as a data processor under our instructions:
Supabase (Database, Auth, and File Storage)
Supabase hosts our PostgreSQL database, authentication system, and file storage. All team profile data, user accounts, and uploaded media are stored in Supabase. Supabase infrastructure is hosted on AWS. Supabase Privacy Policy.
Stripe (Payment Processing)
Stripe processes all premium subscription payments. Stripe is PCI-DSS Level 1 certified. Your full payment card details are transmitted directly to Stripe and never pass through our servers. We receive only subscription status information. Stripe Privacy Policy.
Cloudflare (Hosting and CDN)
Cloudflare Pages hosts and serves the raceteam.wiki website globally. Cloudflare also provides DDoS protection, HTTPS termination, and web application firewall (WAF) services. Cloudflare processes request logs including IP addresses. Cloudflare Privacy Policy.
Resend (Transactional Email)
Resend delivers transactional emails on our behalf — including claim confirmations, onboarding sequences, and subscription notifications. Resend processes your email address solely to deliver these messages. Resend Privacy Policy.
We do not use advertising networks, social media tracking pixels, or behavioral analytics platforms.
5. Cookies & Tracking
Race Team Wiki uses only essential cookies necessary for the site to function. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
Essential Auth Session Cookie
When you log in, Supabase Auth sets a session cookie in your browser to keep you authenticated across page loads. This cookie:
- Contains only a session token — no personal data is stored in the cookie itself
- Is set as
HttpOnlyandSecure - Expires when you log out or your session ends
- Is strictly necessary to use authenticated features (claiming a team, accessing your dashboard)
Because we use only essential cookies, we do not display a cookie consent banner. You may clear your cookies at any time through your browser settings, which will log you out of your account.
6. Email Communications
By creating an account and claiming a team, you consent to receive transactional emails related to your account. These include:
- Claim submission confirmation
- Claim approval or rejection notification
- Onboarding tips to complete your team profile (a short email sequence via Resend)
- Premium subscription receipts and renewal reminders
- Important service announcements (outages, policy changes)
Transactional emails are necessary to operate the service and cannot be opted out of while your account is active. If you receive onboarding or marketing-style emails beyond the core transactional set, you may unsubscribe via the link at the bottom of any such email. To stop all emails, you may request account deletion.
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the service:
- Account data (email, hashed password) — retained while your account is active; deleted within 30 days of an account deletion request
- Team profile data — retained while the team profile exists; can be deleted by the team owner at any time or upon account deletion request
- Uploaded photos and media — deleted from Supabase Storage within 30 days of account or profile deletion
- Stripe billing records — retained as required by financial regulations (typically 7 years); contact Stripe directly regarding their retention of payment data
- Web server logs (Cloudflare) — retained per Cloudflare's standard log retention schedule
- Email correspondence — retained for up to 2 years to support ongoing customer service
8. Security
We take reasonable technical and organizational measures to protect your personal data:
- HTTPS everywhere — all traffic to raceteam.wiki is encrypted in transit via TLS, enforced by Cloudflare
- No plaintext passwords — passwords are hashed and salted by Supabase Auth using industry-standard algorithms
- Encrypted storage — Supabase database and file storage are encrypted at rest
- Payment security — card data goes directly to Stripe (PCI-DSS Level 1) and never touches our servers
- Row-level security — Supabase database policies ensure users can only read and write their own data
- Web application firewall — Cloudflare WAF protects against common web attacks
No system is 100% secure. If you believe you have found a security vulnerability, please contact us at [email protected] before disclosing publicly.
9. Children's Privacy
Race Team Wiki is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided personal information to us, please contact us at [email protected] and we will delete that information promptly.
Note: many youth racing teams (karting, junior formula, etc.) are represented in our index. In these cases, team profiles are typically managed by a parent, guardian, or adult team manager — not the minor driver directly. If you are setting up a profile for a junior team, the account must be created and managed by an adult (18+).
10. Your Rights Under GDPR (EU and UK Residents)
If you are located in the European Union or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Right of Access — You may request a copy of the personal data we hold about you.
- Right to Rectification — You may request correction of inaccurate or incomplete personal data. You can update most profile data directly in your dashboard.
- Right to Erasure ("Right to be Forgotten") — You may request deletion of your personal data. We will comply within 30 days, subject to any legal retention obligations.
- Right to Data Portability — You may request your data in a structured, machine-readable format.
- Right to Object — You may object to processing of your personal data for certain purposes.
- Right to Restrict Processing — You may request that we limit how we use your data while a dispute is resolved.
- Right to Withdraw Consent — Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
Our legal basis for processing your data is performance of a contract (operating your team profile and subscription) and legitimate interests (security, fraud prevention, service improvement).
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
11. Your Rights Under CCPA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:
- Right to Know — You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete — You may request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out of Sale — We do not sell personal information. There is nothing to opt out of.
- Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA rights.
To submit a CCPA request, email [email protected] with the subject line "CCPA Request." We will respond within 45 days.
12. How to Request Data Deletion
You may request complete deletion of your account and associated personal data at any time:
- Email [email protected] with the subject line "Delete My Account"
- Include the email address associated with your account
- We will confirm receipt within 2 business days and complete deletion within 30 days
Deletion includes: your account credentials, team profile data (if you are the sole owner), and uploaded media. Your Stripe billing history is subject to Stripe's own retention obligations. Anonymized, aggregate data (e.g., total team counts used in site statistics) may be retained as it is not linked to you personally.
If you claimed a team that should remain in the public index after your account is deleted, let us know in your deletion request — we can unlink the team from your account and return it to unclaimed status rather than removing it entirely.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time as our service evolves or as legal requirements change. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice on the site for significant changes
- Where required by law, notify you by email
Continued use of Race Team Wiki after changes take effect constitutes acceptance of the updated policy. We encourage you to review this page periodically.
14. Contact Us
Questions, requests, or concerns about this Privacy Policy?
Race Team Wiki · Operated by StaaS Fund · Georgia, USA