Privacy Policy
Last updated: March 9, 2026
1. Overview
F1 Pitwall ("we", "us", "our") respects your privacy. This policy explains what data we collect, why we collect it, and how we protect it.
The short version: We collect only what's needed to run the service. We don't sell your data. We don't track you across other sites.
2. Data We Collect
Account Information (via Google Sign-In)
- Name
- Email address
- Profile picture URL
- Google account ID
We request only the openid email profile scopes. We do not access your contacts, calendar, drive, or any other Google services.
Subscription and Billing Data (via Stripe)
- Stripe customer ID
- Subscription plan and status
- Billing period dates
We do not store your credit card number, CVV, or full payment details. All payment processing is handled by Stripe, which is PCI-DSS Level 1 certified.
Usage Data
- Saved fantasy teams (drivers, constructors, chips, scores)
- Session cookies for authentication
Analytics
We use Google Analytics to understand how the site is used (page views, traffic sources). Google Analytics uses cookies. You can opt out using a browser extension or by disabling cookies.
3. How We Use Your Data
- Authentication: To log you in and maintain your session.
- Service delivery: To save your teams, track your season, and gate features by subscription tier.
- Billing: To process payments and manage your subscription through Stripe.
- Communication: To send transactional emails (payment receipts, subscription changes). We do not send marketing emails.
- Improvement: Aggregate, anonymized analytics to understand usage patterns.
4. Data Storage and Security
- Account and team data is stored in Cloudflare D1 (SQLite), hosted on Cloudflare's global network.
- Authentication uses HttpOnly, Secure, SameSite cookies.
- All traffic is served over HTTPS.
- Billing data is managed by Stripe with industry-standard encryption.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties, except:
- Stripe: For payment processing (governed by Stripe's Privacy Policy).
- Google: For authentication (governed by Google's Privacy Policy).
- Google Analytics: For anonymized usage analytics.
- Legal requirements: If required by law, subpoena, or court order.
6. Data Retention
- Account data is retained while your account is active.
- Team and season data is retained to provide historical tracking across seasons.
- If you delete your account, we will delete your personal data within 30 days. Anonymized aggregate data may be retained.
7. Your Rights
You have the right to:
- Access your personal data.
- Correct inaccurate data (update via Google account or contact us).
- Delete your account and associated data.
- Export your team and season data.
- Withdraw consent by logging out and ceasing use of the Service.
To exercise any of these rights, contact admin@f1pitwall.dev.
8. Cookies
| Cookie | Purpose | Duration |
|---|---|---|
f1pw_session | Authentication session | 30 days |
_ga, _gid | Google Analytics | Up to 2 years |
9. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email. The "Last updated" date at the top reflects the most recent revision.
11. Contact
Questions about your privacy? Contact us at admin@f1pitwall.dev.