How Pistaclub collects, uses, and protects your personal data — and the rights you have over it.
Last updated: 2026-07-16
This Privacy Policy explains how Pistaclub ("we", "us", "our") processes personal data in connection with the Pistaclub website, mobile apps, and related services (together, the "Service"). It applies to riders, event organizers, marketplace users, guests, and anyone who contacts us.
Pistaclub is a neutral intermediary information society service. We host content posted by users and organizers and we facilitate bookings — we do not organize events, sell goods, or act as a party to any rider ↔ organizer or buyer ↔ seller contract. This document explains how that division shapes who is responsible for which data.
The controller responsible for personal data under this Policy is:
Pistaclub s.r.o. (pending incorporation) Prague, Czech Republic (registered address pending) Czech Republic IČO: (pending)
Privacy contact: privacy@pistaclub.app — Data Protection Officer: dpo@pistaclub.app
Different pieces of your data have different legal owners. This table is the single reference the Organizer Data Processing Agreement points at.
| Data category | Pistaclub role | Organizer role | Legal basis |
|---|---|---|---|
| Account & profile (email, name, nickname, avatar, language, currency) | Controller | — | Contract (Terms of Service) |
| Garage, laptimes, favorites, forum posts, marketplace listings | Controller | — | Contract + legitimate interest |
| Rider PII you share at event booking (name, phone, address, DOB, licence, insurance, medical info) | Processor | Controller | Rider's contract with the organizer |
| Marketplace listing data + contact reveal between buyer & seller | Processor (facilitator) | — | Buyer's / seller's request |
| Event photos uploaded by the organizer | Processor | Controller | Organizer's legitimate interest + rider consent (see §7) |
| Payment data (Stripe Connect destination charges) | Processor (technical facilitator only) | Merchant of record | Rider's payment contract with organizer |
| Bank-transfer bookings | Not involved in funds | Sole recipient of funds | Rider ↔ organizer direct transfer |
| Moderation logs, audit trails, DSA notices | Controller | — | Legal obligation (DSA, GDPR Art. 30) |
What this means in practice: if you want an organizer to stop using data you shared with them for their event, contact the organizer directly — they control it. If you want us to stop using data we control (your account, laptimes, marketplace history), contact us. Either party is bound by GDPR obligations for the data they control.
Pistaclub uses a tiered data model so you can see exactly which fields are shared with whom.
We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising (California CCPA / CPRA meaning).
Some sub-processors process data outside the European Economic Area. Where that happens, we rely on European Commission Standard Contractual Clauses or an adequacy decision to ensure equivalent protection.
Organizers can upload photos taken at their events. Photos of you are personal data — the organizer is the controller of those photos. We help distribute them and can auto-suggest tags, but the decision to publish, remove, or share a photo lies with the organizer.
You can request removal of a photo of yourself at any time using the "wrong tag / remove me" button on the photo, or by contacting the organizer directly. Formal takedown requests come with a 48-hour organizer response SLA — see the dedicated Photo Consent & Auto-Tagging Policy (version 2026-09-01) for the full mechanism, your control toggles in Profile → Settings, and the legal basis for each processing step.
If you buy photographs. We process your purchase record — what you bought, when, the amount, and the licences granted — to deliver the files, to support the sale, and to keep the financial records the law requires. The organizer, as seller, receives the information they need to fulfil and account for the sale. The lawful basis is performance of your purchase contract with the organizer and our legal obligation to keep accounting records; retention follows the statutory recordkeeping period in §9. Buyers' terms are in the Photo Licence.
Automated tagging (limited trial). For a small number of organizers, event photographs are analysed by automated systems, including third-party AI models, to suggest which rider appears in each photograph. The lawful basis is the organizer's legitimate interest in organising their event gallery, subject to your right to object and to have a tag of you removed; the organizer reviews suggestions and decides what is published. No facial-recognition or biometric templates are stored — matching uses visible race numbers and colours together with the participant list of that specific event. Sub-processors used are listed on our Sub-processors page.
We use essential cookies to keep you signed in and to keep the Service secure. Analytics cookies are optional and only run after you consent via the cookie banner. A dedicated Cookie Policy lists every cookie by name, purpose, duration, and party — see the footer link.
The table below summarises retention periods for each category of data. Detailed enforcement is documented in our internal Records of Processing Activities (available on request from privacy@pistaclub.app).
| Data category | Retention |
|---|---|
| Active account | For the life of the account |
| Deleted account (identifiers) | Pseudonymized immediately on deletion request |
| Payment transactions | 24 months from event/organizer purge; 10 years for accounting (CZ tax law) |
| Legal-acceptance ledger | Indefinite while account exists; pseudonymized on delete |
| Cookie consent events | Indefinite |
| Marketplace listings | 3 months + up to 5 extensions; archived at expiry; hard-deleted 12 months post-archive |
| Marketplace search log | 90 days |
| Registration evidence | 24 months from event/organizer purge (pseudonymized) |
| Event signatures (waivers) | 24 months from event purge (pseudonymized) |
| Policy versions | 24 months from organizer purge (content redacted) |
| Content reports (resolved with action) | 5 years |
| Content reports (dismissed) | 1 year, then anonymized |
| Moderation actions | 5 years, then anonymized (aggregates survive) |
| Phone verifications (OTP) | 30 days |
| Event chat mutes (inactive) | 1 year post-unmute |
| Track moderators (deactivated) | 5 years |
| Transparency snapshots (published) | Indefinite |
| Transparency snapshots (draft) | 30 days |
| Field-level change history (audit ledger) | 36 months full values, then value-stripped (field names + timestamps kept); pseudonymized on account deletion / record purge |
| Direct messages | Retained while both parties active; deleted with either account |
| Event photos | Follow event lifecycle; 48h takedown SLA on rider request |
You have the right to:
Exercise most rights from Settings → Your rights, or by emailing privacy@pistaclub.app. We respond within 30 days (GDPR Art. 12(3)).
The Service is not intended for users under 16 years old. This threshold is the highest of the applicable national floors under GDPR Article 8 across the countries we serve, and applies uniformly. We do not knowingly collect data from anyone under 16; accounts identified as belonging to users under this age are suspended and their data deleted.
You confirm your age at signup. Where a paid transaction is involved (event booking, marketplace purchase, Premium subscription), we additionally collect your date of birth to enforce this threshold.
If you believe we are not processing your data lawfully, you have the right to lodge a complaint with a supervisory authority. Ours is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů — uoou.cz). EU/EEA residents may lodge a complaint with their national DPA. UK residents may contact the ICO. Californian residents have equivalent rights under the CCPA / CPRA (see §10). Brazilian residents may contact the ANPD under the LGPD.
We use TLS in transit, field-level access controls for sensitive data, immutable audit logging, role-based access, and hash-chained tamper-evidence for legal records (registration evidence, signed waivers, policy versions, payment transactions). See the ROPA and Security Audit Framework (available on request from privacy@pistaclub.app).
For DSA-related notices and single-point-of-contact requests, use dsa@pistaclub.app.
We may update this Policy. Material changes will be notified in-app and by email where we have one on file. The "Last updated" date above tells you when the current version took effect. If you disagree with a material change, you have 30 days of read-only access to export your data and cancel any active subscription before the change applies to you.
Privacy questions: privacy@pistaclub.app. General contact: hello@pistaclub.app.