Privacy Policy
Last updated: 22 September 2026
This Policy explains how we collect and use personal data across every part of iPitCommand: this website (ipitcommand.com), our documentation (docs.ipitcommand.com), the web portal (app.ipitcommand.com), and the iPitCommand Windows desktop client.
1. Who We Are
The data controller responsible for your personal data is Konstantinos Athanasopoulos, an individual trading as "iPitCommand", established in Greece, address for service Emmanouil Pappa 10, Patras 26332. You can contact us by email using the Contact link.
2. What Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account & profile data | Email address, display name, iRacing driver ID, iRating, license class | Provided by you at signup / retrieved from iRacing when you link your account |
| Team & roster data | Team name, roster membership, roles, invitations | Provided by you or a teammate |
| Telemetry & usage data | Lap times, fuel consumption, tire temperatures and wear, car/track identifiers, session data | Sent automatically by the Desktop Client while iRacing is running, tied to your account |
| Technical & diagnostic data | IP address, device/OS/browser information, app version, crash reports, error logs, stack traces, and related diagnostic information | Collected automatically through our error-monitoring and diagnostic systems, including Sentry (see Section 4) |
| Support communications | Content of emails or messages you send us | Provided by you |
We do not collect or store your payment card details. Payment information is collected and processed directly by Paddle.com, our payment provider and Merchant of Record, acting as an independent controller of that data. See Paddle's own Privacy Policy.
3. Why We Process Your Data & Legal Basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and administering your account; providing the Service you've subscribed to | Performance of a contract |
| Linking your iRacing identity and building your personal/team fuel & tire knowledge base | Performance of a contract |
| Managing your subscription, access entitlement, and billing-related records; payment processing is handled by Paddle as an independent controller | Performance of a contract |
| Detecting and diagnosing crashes and errors, investigating bugs, and maintaining the security, stability, and reliability of the Service | Legitimate interests — operating, maintaining, securing, and improving a reliable product |
| Understanding overall product usage and improving the Service (Google Analytics) | Consent where required by applicable ePrivacy rules; otherwise our legitimate interests in understanding and improving the Service, where permitted by applicable law |
| Determining whether the consent banner should be displayed based on the visitor's approximate country | Legitimate interests — applying the site's privacy and consent requirements, where permitted by applicable law |
| Complying with tax, accounting, and other legal obligations | Legal obligation |
| Responding to support requests, questions, and other communications you send us | Performance of a contract and/or legitimate interests in providing customer support |
4. Third-Party Providers & Services
| Provider | Purpose | Where used |
|---|---|---|
| Paddle.com (Merchant of Record) | Payments, subscription billing, tax/VAT handling, order support | Checkout / Billing page (Web Portal) |
| Google LLC — Firebase Authentication | Account sign-in and identity verification | Web Portal, Desktop Client |
| Google LLC — Google Analytics (GA4) | Website and product usage analytics | ipitcommand.com, docs.ipitcommand.com, Web Portal |
| Microsoft — Azure Application Insights | Usage analytics and diagnostics | Desktop Client |
| Cloudflare, Inc. | CDN, caching, security, and IP-based country detection for consent management | All web properties |
| Functional Software, Inc. (Sentry) | Error monitoring, crash reporting, diagnostics, and bug investigation | Windows Desktop Client, Web Portal (SaaS) |
| Oracle Cloud Infrastructure (OCI) — Germany Central (Frankfurt) | Application hosting, storage, and backups | All products |
5. International Data Transfers
Some of the providers above may process personal data outside the EEA or the United Kingdom, including in the United States. Where such transfers are subject to the GDPR or UK GDPR, we rely on an applicable adequacy decision where available, including the EU-U.S. Data Privacy Framework or UK Extension where the relevant recipient is covered, or otherwise on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where required for UK restricted transfers, the UK International Data Transfer Agreement or UK Addendum.
6. Cookies & Similar Technologies
Our website, documentation, and web portal use certain cookies and similar technologies that are necessary for the operation and security of the Service. We also use Google Analytics (GA4) for non-essential usage analytics, such as pages visited, approximate location, device and browser information, and referral source.
Google Analytics is a non-essential analytics service. In jurisdictions where prior consent is required for its use, Google Analytics is not loaded, and its analytics cookies or similar identifiers are not set or used, unless you have first given your consent through our cookie-consent banner.
In jurisdictions where applicable law permits us to use Analytics without prior consent, Analytics may be activated automatically. You can nevertheless reject or withdraw Analytics through our Cookie Settings.
You can change or withdraw your consent at any time through our cookie settings. Essential cookies that are strictly necessary for the operation of the website or a service you have expressly requested may still be used without consent where permitted by law.
We also use Sentry for essential error and crash monitoring. Sentry is used to detect, diagnose, and investigate technical errors and bugs affecting the Service. It is not used for advertising or behavioral analytics, and it is not controlled by the optional Analytics setting in our Cookie Settings. Sentry error monitoring remains active while the relevant Service components are in use. This does not affect any rights you may have under applicable data-protection law, including the right to object where that right applies.
Cookies used by iPitCommand
| Cookie | Purpose | Provider | Category | Duration |
|---|---|---|---|---|
__Host-ipc_consent_v1 |
Stores your Analytics consent preference for the current iPitCommand web property. | iPitCommand | Necessary | 180 days (approximately 6 months) |
_ga |
Used by Google Analytics to distinguish users. | Analytics | 2 years by default | |
_ga_* |
Used by Google Analytics to persist session state. | Analytics | 2 years by default |
Google Analytics cookie duration and Google Analytics data retention are separate settings.
The _ga and _ga_* cookies may remain in the browser for their
configured cookie lifetime, while the user-level and event-level Analytics data described
in Section 7 is retained for 14 months.
Your cookie and Analytics preference is stored separately for each iPitCommand web property. A choice made on one web property does not automatically apply to the others.
7. Data Retention
- Accounting, tax, and subscription transaction records are retained for as long as necessary to comply with applicable legal and tax obligations, including applicable Greek record-retention requirements, which may require retention for at least five years. Other account and support data is retained only for as long as reasonably necessary for the purposes described in this Policy.
- Google Analytics user-level and event-level data is retained for 14 months in accordance with our configured Google Analytics retention settings; aggregated reporting data may be retained for longer.
- Telemetry data that powers your personal or team Knowledge Base is kept for as long as your Account is active. If you request account deletion, the data is deleted from our active systems; residual copies may remain temporarily in encrypted backups until those backups expire under our normal backup-retention cycle.
- Sentry crash reports, error logs, and related diagnostic information are retained for a limited period in accordance with our configured Sentry retention settings and are automatically deleted thereafter.
8. Your Rights
Under applicable data-protection law, including the GDPR and UK GDPR where applicable, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Request erasure of your data ("right to be forgotten");
- Restrict or object to certain processing, including processing based on our legitimate interests;
- Receive a copy of certain personal data in a portable format, where the conditions for data portability under applicable law are met;
- Withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you — the Service's predictions are informational only.
To exercise any of these rights, contact us using the details in Section 1. You also have the right to lodge a complaint with your national data protection authority. In Greece, this is:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifisias Avenue 1–3, PC 115 23, Athens, Greece
Tel: +30 210 6475 600 · Email: [email protected] ·
www.dpa.gr
9. Children
The Service is not directed at, and must not be used by, anyone under 13. Users aged 13 to 17 may use the Service only with authorization from a parent or legal guardian and, where required by applicable law, with any required parental or legal-representative consent for processing based on consent. We do not knowingly collect personal data from children under 13.
For users in Greece, where processing is based on consent, the applicable age for a minor to provide that consent independently is 15; below that age, consent must be given by the minor's legal representative.
See Section 3 (Eligibility & Accounts) of our Terms of Service for the corresponding account and access requirements.
10. Security
We use reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS/TLS) and credential management handled by Firebase Authentication. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be highlighted here with an updated "Last updated" date, and, where required by law, we will notify you directly.
12. Contact Us
For any privacy question or to exercise your rights, please contact us by email using the Contact link.