Legal

Privacy policy

What TrackSpace collects, why it collects it, and what you can do about it.

Last updated 21 September 2026

TrackSpace is a tool for tracking what you run, what wears out on it, and how you drove. This policy explains what we hold, who we hand it to, and how you get it back or get rid of it. It covers the TrackSpace web application and its API.

What we collect

Your identity

Signing in goes through Auth0, using Google as the identity provider. We never see or store your password or passkey — Auth0 handles authentication and tells us only that it succeeded. What we keep in our own database is an account identifier and the display name you choose. Auth0 holds your email address and Google account details under Okta's privacy policy.

What you put into the app

The records you create: cars, tracks, events and trips, consumables and service intervals, sessions and lap times, goals, coaching and setup notes, and your preferences. If you set a home location, we store the text you typed and the coordinates derived from it.

Files you upload

Photos of your cars, tracks and parts, and telemetry or lap-timer files you import. Telemetry files contain GPS traces of your laps, which is location data about where and when you drove.

Payment details

Subscriptions are processed by Stripe. Card numbers never reach TrackSpace — they go directly to Stripe, which is PCI-DSS certified. We store only the Stripe customer and subscription identifiers needed to know which plan you are on. Stripe's handling of your payment data is governed by the Stripe privacy policy.

A record of changes

The app keeps an activity log of changes made to your data, so you can see what changed and when. You can read it on your Activity page.

Technical data

Ordinary web-server and application logs — IP address, browser type, timestamps, errors — kept to run the service and diagnose faults.

How you found us

When you first arrive at the public site we note how you got here: the campaign tags on the link you clicked, if it had any, and the page you landed on. The referring site is recorded only when you arrive by clicking a link from outside TrackSpace — an advert, an invitation, a shared day. Moving around inside the app records nothing. This is held in a cookie for 30 days and, if you go on to create an account, written against that account once, at sign-up; it is never updated afterwards. We use it for one thing: counting which of our adverts and invitations lead to accounts.

Why we collect it

  • To provide the service — your records are the service.
  • To sign you in and keep your session secure.
  • To take payment for a subscription and apply the right plan limits.
  • To keep it working — diagnosing errors, preventing abuse, keeping backups.
  • To measure our advertising — whether an advert or invitation led to an account.

Where the GDPR applies, our lawful bases are performance of a contract (running the account you signed up for), legitimate interests (security and service reliability), and legal obligation (financial records). We do not sell your personal information. What you put into the app is never used for advertising or behavioural profiling; the only advertising-related processing is the measurement described under Cookies and local storage.

Who else touches your data

These are service providers acting on our instructions, not audiences for your data. They are separate from the sharing you choose, which is covered below:

  • Auth0 (Okta) — authentication and identity.
  • Stripe — subscription payments.
  • Microsoft Azure — hosting, database and backups.
  • OpenStreetMap (Nominatim) — if you set a home location, that text is sent to a geocoding service to turn it into coordinates.
  • Open-Meteo — track coordinates and dates are sent to a weather service to retrieve conditions for a session.
  • Meta Platforms — advertising measurement on the public pages only (see Cookies and local storage).

We may also disclose information where the law requires it, or to protect the rights and safety of our users. If TrackSpace is ever sold or merged, your data would transfer with it, and you would be told before that happened.

When you share, you are instructing us to disclose

This is the one part of the policy where you decide that your data leaves your account. Sharing a day, or creating a private link, is an instruction to TrackSpace to disclose that data to the people you name or to whoever holds the link, and your permission for us to do so. We act on that instruction until you withdraw it. Nothing is shared unless you share it.

What that instruction covers, so there are no surprises:

  • You choose what goes in. A share is one day — never your whole account — and you pick what it carries: sessions and lap times, telemetry files, setup, goals and debriefs, video links.
  • A private link needs no account. Anyone holding the link can read the day, without signing in and without us knowing who they are. Treat the link itself as the key: forwarding it grants access as surely as sending the data.
  • Named recipients are different. Where you share with someone who has a TrackSpace account, we know who they are and you can cut off that one person without disturbing the rest.
  • It is a standing grant, not a snapshot. A shared day resolves live, so sessions you add later become visible to whoever already holds the share — that is the point of handing a coach the morning while the afternoon is still to run.
  • Your name travels with it. A shared day identifies you as the driver, along with the track and the date.

Withdrawing the instruction. Every share carries an expiry date, and you can revoke one at any time. Both stop future access. Neither can undo what has already been read, and where a share included telemetry files, it cannot recall a file that has already been downloaded. Share accordingly.

Being findable. Holding a TrackSpace account makes your display name and handle discoverable by other signed-in users searching for someone to connect with. No records of yours are exposed by a connection on its own — connecting is what makes someone available to share with, not a share in itself.

Where your data is held

On Microsoft Azure in the South Central US region, with authentication in Auth0's US region. If you are in the UK, the EEA or Switzerland, your data is therefore transferred to and processed in the United States. Our providers rely on the European Commission's Standard Contractual Clauses for those transfers.

How long we keep it

For as long as your account exists. Delete your account and we delete your records, your uploaded files, your activity log and your subscription record from our database. Backups roll off on their own schedule, and we keep whatever financial records the law obliges us to keep.

Your rights

Two of these are built into the app rather than being a request you have to make:

  • Get a copy — export your data from your Profile page, at any time, without asking us.
  • Delete it — delete your data or your whole account from the same page. It is immediate and it is not reversible.
  • Correct it — edit any record in the app directly.
  • Object, restrict, or complain — write to us at the address below. If you are in the UK or EEA you may also complain to your local data-protection authority.

If you are a California resident, the CCPA gives you the rights to know, delete, correct and opt out of sale. We do not sell personal information, and we will not treat you differently for exercising any of these rights.

Cookies and local storage

We use cookies that are necessary for the service — keeping you signed in and your session secure — and the browser's local storage to remember interface preferences such as your theme. One further first-party cookie remembers how you first arrived at the public site, for 30 days, so that a sign-up can be counted against the advert or invitation that led to it (see How you found us).

Advertising measurement. On the public pages only — never inside your account — we load the Meta Pixel to measure whether our advertising on Instagram and Facebook leads to sign-ups. It sets Meta's own cookies and tells Meta that a browser viewed a public page, opened the sign-up page, or completed sign-up. It does not see anything you put into the app. You can limit it with a content blocker, your browser's third-party-cookie setting, or Meta's ad-preferences controls.

Children

TrackSpace is not intended for anyone under 18 — the Terms of Service set 18 as the minimum age for an account — and we do not knowingly collect their data. If you believe a minor has given us information, write to us and we will remove it.

Changes to this policy

If we change it materially, we will update the date at the top of this page and tell you in the app before the change takes effect.

Contact us

For any privacy question or request, including access, deletion or objection, write to trackspace.support@outlook.com.

An unhandled error has occurred. Reload

Rejoining the server…

Rejoin failed… trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.