Back to Pistaclub

Privacy Policy

How Pistaclub collects, uses, and protects your personal data — and the rights you have over it.

Last updated: 2026-07-16

This Privacy Policy explains how Pistaclub ("we", "us", "our") processes personal data in connection with the Pistaclub website, mobile apps, and related services (together, the "Service"). It applies to riders, event organizers, marketplace users, guests, and anyone who contacts us.

Pistaclub is a neutral intermediary information society service. We host content posted by users and organizers and we facilitate bookings — we do not organize events, sell goods, or act as a party to any rider ↔ organizer or buyer ↔ seller contract. This document explains how that division shapes who is responsible for which data.

1. Who we are

The controller responsible for personal data under this Policy is:

Pistaclub s.r.o. (pending incorporation) Prague, Czech Republic (registered address pending) Czech Republic IČO: (pending)

Privacy contact: privacy@pistaclub.appData Protection Officer: dpo@pistaclub.app

2. Controller vs processor — who is responsible for what

Different pieces of your data have different legal owners. This table is the single reference the Organizer Data Processing Agreement points at.

Data categoryPistaclub roleOrganizer roleLegal basis
Account & profile (email, name, nickname, avatar, language, currency)ControllerContract (Terms of Service)
Garage, laptimes, favorites, forum posts, marketplace listingsControllerContract + legitimate interest
Rider PII you share at event booking (name, phone, address, DOB, licence, insurance, medical info)ProcessorControllerRider's contract with the organizer
Marketplace listing data + contact reveal between buyer & sellerProcessor (facilitator)Buyer's / seller's request
Event photos uploaded by the organizerProcessorControllerOrganizer's legitimate interest + rider consent (see §7)
Payment data (Stripe Connect destination charges)Processor (technical facilitator only)Merchant of recordRider's payment contract with organizer
Bank-transfer bookingsNot involved in fundsSole recipient of fundsRider ↔ organizer direct transfer
Moderation logs, audit trails, DSA noticesControllerLegal obligation (DSA, GDPR Art. 30)

What this means in practice: if you want an organizer to stop using data you shared with them for their event, contact the organizer directly — they control it. If you want us to stop using data we control (your account, laptimes, marketplace history), contact us. Either party is bound by GDPR obligations for the data they control.

3. What personal data we collect

Pistaclub uses a tiered data model so you can see exactly which fields are shared with whom.

  • Tier 1 — public profile: email (only shown to you), first/last name or chosen nickname, avatar, home country/city, preferred language and currency.
  • Tier 2 — shared on request: phone number, structured address, motorcycles in your garage, laptimes, event booking history.
  • Tier 3 — special-category data (GDPR Art. 9): blood type, allergies, medical conditions, medications, and emergency contact. Shared per-booking with a specific organizer, only when you explicitly tick the box during that booking.
  • Tier 4 — sensitive identifiers: date of birth, driver's licence number, national ID / passport number, insurance policy details. Never shared with organizers directly by us — the organizer collects them themselves through their registration form.
  • Technical & operational: IP address, device info, user-agent, session tokens, referrer, moderation logs, audit trails.

4. How we use your data

  • Operate the Service (accounts, sign-in, notifications).
  • Facilitate event bookings and marketplace transactions between users.
  • Comply with legal obligations (DSA notice-and-action, GDPR responses).
  • Protect the platform (fraud, abuse, moderation).
  • Keep an admin-only, field-level change history of core records (organizer profiles, events, listings, tracks, reviews, public rider profiles) for fraud prevention and dispute resolution — legitimate interest; change values are retained for 36 months, then stripped.
  • Improve the Service (aggregate analytics — cookie-gated).
  • Communicate with you (transactional emails; marketing only when you opt in).

5. Who we share your data with

  • Event organizers — only the data you explicitly submit when you register for their event, and (for Art. 9 data) only when you tick the per-booking sharing box. Organizers become independent controllers of that data — see §2.
  • Other users — only your public-tier data (name / nickname, avatar, laptimes, public posts, listings).
  • Service providers (sub-processors) — hosting (Base44), payment processing (Stripe), transactional email, storage, error monitoring. Each is bound by a written contract with GDPR-compliant safeguards. The full always-current list — with purpose, jurisdiction, data categories, and safeguards for each — is on our Sub-processors page.
  • Legal authorities — when required by law, court order, or a valid DSA / GDPR request.

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising (California CCPA / CPRA meaning).

6. International transfers

Some sub-processors process data outside the European Economic Area. Where that happens, we rely on European Commission Standard Contractual Clauses or an adequacy decision to ensure equivalent protection.

Organizers can upload photos taken at their events. Photos of you are personal data — the organizer is the controller of those photos. We help distribute them and can auto-suggest tags, but the decision to publish, remove, or share a photo lies with the organizer.

You can request removal of a photo of yourself at any time using the "wrong tag / remove me" button on the photo, or by contacting the organizer directly. Formal takedown requests come with a 48-hour organizer response SLA — see the dedicated Photo Consent & Auto-Tagging Policy (version 2026-09-01) for the full mechanism, your control toggles in Profile → Settings, and the legal basis for each processing step.

If you buy photographs. We process your purchase record — what you bought, when, the amount, and the licences granted — to deliver the files, to support the sale, and to keep the financial records the law requires. The organizer, as seller, receives the information they need to fulfil and account for the sale. The lawful basis is performance of your purchase contract with the organizer and our legal obligation to keep accounting records; retention follows the statutory recordkeeping period in §9. Buyers' terms are in the Photo Licence.

Automated tagging (limited trial). For a small number of organizers, event photographs are analysed by automated systems, including third-party AI models, to suggest which rider appears in each photograph. The lawful basis is the organizer's legitimate interest in organising their event gallery, subject to your right to object and to have a tag of you removed; the organizer reviews suggestions and decides what is published. No facial-recognition or biometric templates are stored — matching uses visible race numbers and colours together with the participant list of that specific event. Sub-processors used are listed on our Sub-processors page.

8. Cookies and similar technologies

We use essential cookies to keep you signed in and to keep the Service secure. Analytics cookies are optional and only run after you consent via the cookie banner. A dedicated Cookie Policy lists every cookie by name, purpose, duration, and party — see the footer link.

9. How long we keep your data

The table below summarises retention periods for each category of data. Detailed enforcement is documented in our internal Records of Processing Activities (available on request from privacy@pistaclub.app).

Data categoryRetention
Active accountFor the life of the account
Deleted account (identifiers)Pseudonymized immediately on deletion request
Payment transactions24 months from event/organizer purge; 10 years for accounting (CZ tax law)
Legal-acceptance ledgerIndefinite while account exists; pseudonymized on delete
Cookie consent eventsIndefinite
Marketplace listings3 months + up to 5 extensions; archived at expiry; hard-deleted 12 months post-archive
Marketplace search log90 days
Registration evidence24 months from event/organizer purge (pseudonymized)
Event signatures (waivers)24 months from event purge (pseudonymized)
Policy versions24 months from organizer purge (content redacted)
Content reports (resolved with action)5 years
Content reports (dismissed)1 year, then anonymized
Moderation actions5 years, then anonymized (aggregates survive)
Phone verifications (OTP)30 days
Event chat mutes (inactive)1 year post-unmute
Track moderators (deactivated)5 years
Transparency snapshots (published)Indefinite
Transparency snapshots (draft)30 days
Field-level change history (audit ledger)36 months full values, then value-stripped (field names + timestamps kept); pseudonymized on account deletion / record purge
Direct messagesRetained while both parties active; deleted with either account
Event photosFollow event lifecycle; 48h takedown SLA on rider request

10. Your rights (GDPR / LGPD / UK GDPR / CCPA)

You have the right to:

  • Access — request a copy of the data we hold about you.
  • Rectify — correct inaccurate data.
  • Erase — request deletion of your account and data.
  • Restrict — limit how we process your data.
  • Object — object to processing based on legitimate interest.
  • Portability — export your data in machine-readable form (JSON).
  • Withdraw consent — where processing is based on consent, without affecting past processing.
  • Complain to a supervisory authority — see §12.

Exercise most rights from Settings → Your rights, or by emailing privacy@pistaclub.app. We respond within 30 days (GDPR Art. 12(3)).

11. Children and minimum age

The Service is not intended for users under 16 years old. This threshold is the highest of the applicable national floors under GDPR Article 8 across the countries we serve, and applies uniformly. We do not knowingly collect data from anyone under 16; accounts identified as belonging to users under this age are suspended and their data deleted.

You confirm your age at signup. Where a paid transaction is involved (event booking, marketplace purchase, Premium subscription), we additionally collect your date of birth to enforce this threshold.

12. Complaints and supervisory authority

If you believe we are not processing your data lawfully, you have the right to lodge a complaint with a supervisory authority. Ours is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů — uoou.cz). EU/EEA residents may lodge a complaint with their national DPA. UK residents may contact the ICO. Californian residents have equivalent rights under the CCPA / CPRA (see §10). Brazilian residents may contact the ANPD under the LGPD.

13. How we protect your data

We use TLS in transit, field-level access controls for sensitive data, immutable audit logging, role-based access, and hash-chained tamper-evidence for legal records (registration evidence, signed waivers, policy versions, payment transactions). See the ROPA and Security Audit Framework (available on request from privacy@pistaclub.app).

14. Digital Services Act contact

For DSA-related notices and single-point-of-contact requests, use dsa@pistaclub.app.

15. Changes to this Policy

We may update this Policy. Material changes will be notified in-app and by email where we have one on file. The "Last updated" date above tells you when the current version took effect. If you disagree with a material change, you have 30 days of read-only access to export your data and cancel any active subscription before the change applies to you.

16. Contact

Privacy questions: privacy@pistaclub.app. General contact: hello@pistaclub.app.