docs/privacy/data-map.md). It has not been reviewed by a lawyer and should be before it is relied on for a real launch, particularly the sections on legal basis, international transfer, and the audit-trail retention rationale, which the engineering team has explicitly flagged as pending legal sign-off. Fields marked like this need a real value filled in before publishing.
ApexTrack ("we", "us") provides [LEGAL ENTITY NAME], an offline-first component lifecycle and traceability platform for motorsport teams. This policy explains what personal data we collect through the product and this website, why, how long we keep it, and what control you have over it.
1. What we collect
ApexTrack is used by a team (a race team, workshop, or similar organization). Almost everything the product stores is scoped to that team, not to an individual outside it. The table below is drawn directly from our internal data map and lists every field that constitutes personal data.
| Data | Why we have it | How long we keep it |
|---|---|---|
| Email address | Login identity; invitations are sent to it | While your account is active; deleted when your account is deleted |
| Full name, avatar photo | Displayed to your teammates in the app | While your account is active; deleted when your account is deleted |
| Email notification preferences | Whether you've opted into the weekly fleet digest or the weekly security report | While your account is active |
| Your name/email as it appears in the audit trail (status changes, session logs, exports) | Non-repudiation for safety-critical actions — proving who changed what, and when, on a part with a physical failure limit | Indefinite, by design. This is an append-only safety record — see §4 |
| Your name as it appears on an NDT clearance (signed inspection sign-off) | Non-repudiation of the engineer who cleared a quarantined part for service | Indefinite — same rationale as above |
| Free-text notes you write on a component or clearance | Operational context you chose to record — these can incidentally name people (e.g. "inspected by Jane") | Indefinite — see §4 |
| Push notification subscription (device endpoint) | Delivering fleet health alerts to your device, if you opt in | Until you disable push or your account is deleted |
| Browser/device error reports | Diagnosing crashes — stored in our own database, not sent to a third-party crash-reporting vendor | [RETENTION PERIOD — not yet defined] |
We do not run any third-party advertising or analytics trackers on this site or in the app — there is no Google Analytics, Meta Pixel, or similar script anywhere in our code, and there is nothing to opt out of on that front.
2. Your team's operational data
Component records, session logs, chassis, calibration values, and photos are your team's operational data, not something we consider "personal data about you" specifically — but they can incidentally contain it (a note field, a photo with someone in frame). This data belongs to your team; we act as the processor that stores and syncs it.
3. Why we process it (legal basis)
- Performing the service you signed up for — account data, team data, and sync exist because the product doesn't work without them.
- Legitimate interest in safety and accountability — the audit trail and clearance records exist because this is safety-critical software tracking physical parts with failure limits; being able to prove who did what is the point of the feature, not incidental to it.
- Consent — the weekly fleet digest, the weekly security report, and push notifications are all opt-in per user, controlled from your Profile page.
[If you operate in the EU/UK, confirm this section correctly maps to GDPR Article 6 with counsel before publishing.]
4. Retention, and the tension we're upfront about
Most account data is deleted when your account is deleted. The exception is the audit trail and clearance history, which is designed to be append-only and to outlive the individual user — a quarantine decision or an NDT clearance from three years ago has to remain provable even if the person who made it has since left the team. That is in direct tension with a right to erasure, and we say so plainly rather than pretending it isn't: it is documented as an open item requiring legal sign-off, not a settled position.
What we do today when an account is deleted:
- Your email address is replaced with a fixed, non-reversible placeholder everywhere it appears in the audit trail and clearance records — the record of that an action happened survives; the identifying text pointing back to you does not.
- Your avatar photo is deleted from storage.
- Your account and profile are deleted outright.
- The structural, non-identifying parts of the audit trail (what changed, on which component, when) are kept indefinitely, because they are themselves the safety record.
- Free-text notes are not automatically scanned or redacted — a note is reviewed manually on request, because automatically stripping text risks destroying safety context along with a name.
5. Who else sees it
We use a small number of infrastructure providers to run the service. None of them are permitted to use your data for their own purposes.
| Provider | Role |
|---|---|
| Supabase | Database, authentication, file storage, and the serverless functions that power sync, invitations, and the API. This is where essentially all product data lives. |
| [Email provider — SMTP, operator-configured] | Delivers transactional email: invitations, the weekly fleet digest, the weekly security report. |
| Azure Static Web Apps | Hosts the app and this website. |
We do not sell personal data, and we do not share it with anyone for their own marketing purposes.
6. International transfer
[Depends on which Supabase project region you provision and where your users are. Fill in once infrastructure region is finalized — do not leave this section templated at launch.]
7. Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact [email protected]. For the audit-trail exception described in §4, we'll redact identifying text rather than delete the underlying safety record, and we'll tell you plainly if that's what we're doing.
8. Security
Team data is isolated at the database level — every query is scoped to your team by row-level security policies enforced server-side, not by a client-side filter. Data in transit is encrypted (HTTPS). We run a weekly automated scan for dependency vulnerabilities and leaked secrets; the current status is public at our security reports. No system is perfectly secure, and this policy is not a guarantee against every possible incident.
9. Children
ApexTrack is a business tool for motorsport teams and is not directed at, or knowingly used to collect data from, children.
10. Changes to this policy
If we make a material change to how we handle personal data, we'll update the date at the top of this page and, where required, notify team admins directly.
11. Contact
[LEGAL ENTITY NAME]
[ADDRESS]
[email protected]