Privacy Policy
Last updated: August 18, 2026
1. Who We Are
PitLane Systems LLC (“PitLane,” “we,” “us,” or “our”) is a Texas limited liability company based in Austin, TX. We operate the website pitlanesystems.com and the desktop application PitLane Director AC (collectively, the “Service”).
For questions about this policy, contact us at gray@pitlanesystems.com or by mail:
PitLane Systems LLC
5900 Balcones Drive STE 100
Austin, TX 78731
United States
2. Data We Collect
Information you provide
- Account information: name, email address, and password (stored as a cryptographic hash — we never store your password in plain text)
- Payment information: processed entirely by Stripe. We do not store credit card numbers, expiration dates, or CVV codes. We receive and store your Stripe customer ID and subscription status.
- Waitlist email: if you join our waitlist, we store your email address
Information collected automatically
- Device identifiers: when you activate PitLane Director AC, we store a randomly generated device ID and device name to enforce per-plan device limits
- Session data: IP address, user agent, and session tokens for authentication and security
- Analytics data:we use Vercel Analytics, which collects anonymous, aggregated usage data without cookies or personal identifiers. With your consent, we also use PostHog for product analytics and session replay; if you decline, PostHog instead operates in a cookieless mode that counts visits anonymously without storing anything on your device (see “Cookies and Product Analytics” below).
- Crash and error reports: the desktop application may send crash reports and error diagnostics to help us identify and fix issues. This includes stack traces, error messages, application version, and operating system information. Reports of native crashes may include a memory snapshot of the application at the moment of failure, and our error-monitoring provider derives an approximate (city-level) location from your network connection. During the closed beta, crash reports include your account email address so we can follow up with you directly; from general-release builds (v1.0 and later) they are linked to a pseudonymous identifier instead.
- Usage telemetry: the desktop application may send usage data, linked to your account, such as feature usage (which overlays are activated), session duration, application health metrics (startup success, sidecar connection status, update check outcomes), and Assetto Corsa / CSP version information. This data does not include race content such as driver names, lap times, or race results.
- Pre-activation diagnostics: before the desktop application is licensed, it may send a small number of setup and activation events (for example, that activation was attempted and why it did not succeed, such as a device limit being reached) so we can find out where installation fails. They carry an installation identifier, the application version, and the outcome, and contain no name, email address, file path, or race content.
These events are not linked to an account when they are sent, because at that point there is no account to link them to. However, the installation identifier is the same one the application uses once it is licensed, so if that installation later activates successfully, we can associate the earlier events with the resulting account. We treat them as your data accordingly: deleting your account deletes them along with the rest of your usage history.
In general-release builds (v1.0 and later), you may opt out of crash reporting and usage telemetry at any time via Settings in the desktop application. Opting out does not affect core functionality such as license validation, subscription management, or update checks.
Closed beta exception: during the closed beta, crash reporting and usage telemetry are always enabled as a condition of beta participation — this diagnostic data is how issues get found and fixed before general release. The data collected is unchanged and remains subject to the limits described in this section.
3. How We Use Your Data
- To provide, maintain, and improve the Service
- To process payments and manage your subscription
- To verify your email address via one-time verification codes
- To enforce license terms and device activation limits
- To communicate with you about your account, subscription, or changes to our terms
- To send optional product news and release announcements — only if you opt in, and you can stop them at any time from your account page or via the unsubscribe link included in every such email
- To detect, prevent, and address fraud, abuse, and security issues
- To understand usage patterns through website analytics and desktop application telemetry
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), we process your personal data under the following legal bases:
- Contractual necessity: account data, payment processing, and subscription management are required to provide the Service you have purchased
- Legitimate interest: device tracking for license enforcement, session data for security, and analytics for service improvement
- Consent: optional product-news emails, which you opt in to and can withdraw at any time from your account page or via the unsubscribe link in every such email
5. Third-Party Processors
We share data only with the following service providers, solely for the purposes described above. We do not sell, rent, or trade your personal information to any third party.
- Stripe (San Francisco, CA) — payment processing and subscription management
- Resend (San Francisco, CA) — email delivery (verification codes, security notices, and the optional product-news digest), including delivery-failure and complaint notifications that include the affected email address and are used to maintain an internal do-not-email suppression list
- Amazon Web Services (Seattle, WA) — email delivery and delivery-feedback infrastructure (Amazon SES and SNS); email may be delivered through AWS instead of Resend, under the same purposes and suppression handling
- Vercel (San Francisco, CA) — website hosting and anonymous analytics
- PostHog (San Francisco, CA) — product analytics and session replay (only when you accept analytics cookies; see Section 10)
- Neon — database hosting (PostgreSQL)
- Sentry (San Francisco, CA) — crash reporting and error monitoring for the desktop application
- Cloudflare (San Francisco, CA) — content delivery and object storage (R2) for application updates and installer downloads
Each processor maintains industry-standard security practices and, where applicable, Standard Contractual Clauses for international data transfers.
6. International Data Transfers
Your data is stored and processed in the United States. If you are located outside the US, your data will be transferred to the US for processing. Our third-party processors maintain appropriate safeguards, including Standard Contractual Clauses, for transfers of personal data from the EEA.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. You can delete your account yourself at any time from your account page: deletion cancels any active subscription immediately and permanently erases your account, device, and usage data from our systems. Records we are required to keep for legal obligations (e.g., tax and billing records held by our payment processor) are retained for the legally mandated period.
One narrow exception: if an email address has permanently bounced or its owner has reported our mail as spam, the address stays on an internal do-not-email suppression list even after account deletion. Retaining it is how we honor that objection and our anti-spam obligations, and it is used for no other purpose.
Waitlist email addresses are retained until we launch the product or you request removal, whichever comes first.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: request that we correct inaccurate data
- Deletion:request that we delete your personal data (“right to be forgotten”)
- Portability: request your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interest
- Restriction: request that we restrict processing of your data
You can exercise the deletion right directly: deleting your account from your account page erases your data as described in Section 7, no request needed. For any other right, contact us at gray@pitlanesystems.com. We will respond within 30 days.
EEA residents have the right to lodge a complaint with their local data protection supervisory authority.
9. Sale of Personal Information
We do not sell, rent, or trade your personal information. We have never sold personal information and have no plans to do so.
10. Cookies and Product Analytics
We use functional session cookies that are strictly necessary to authenticate your account and maintain your login state. These cookies are always on — you cannot opt out without breaking core functionality.
With your consent, we also use PostHog for product analytics. When you accept analytics cookies via the banner shown on your first visit, PostHog collects:
- Pages you visit and the order you visit them in
- Clicks, form interactions, and scroll depth (input field contents are masked and never sent)
- Browser type, operating system, screen size, and approximate geographic region (derived from IP, IP itself is truncated)
- Session replays — recordings of your browsing session with all input fields masked. Used to debug usability issues.
- If you sign up or sign in, your user ID and email so we can associate behavior with your account
We do not use this data for advertising and we do not sell or share it with third parties beyond PostHog. The data is stored in the United States and retained for up to 12 months.
You can decline analytics cookies on the consent banner shown on your first visit, or change your choice later by clearing your browser's site data for pitlanesystems.com and reloading. We honor the “Do Not Track” and Global Privacy Control browser signals as an automatic decline.
If you decline(or before you make a choice), PostHog operates in a cookieless mode: nothing is stored on your device, and page visits are counted using a privacy-preserving identifier computed on PostHog's servers that rotates daily, so your visits cannot be linked across days or to your account. In this mode we receive aggregate visit counts only — no session replays, no click tracking tied to a persistent profile, and no association with any account you may have.
11. Age Requirement
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from users under 18. If we learn that we have collected personal data from a user under 18, we will delete it promptly.
12. Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS/HTTPS)
- Cryptographic password hashing (passwords are never stored in plain text)
- RSA-2048 signed tokens for desktop application authentication
- Secure, access-controlled database hosting
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website at least 30 days before the changes take effect. Non-material updates — such as substituting a service provider that performs the same function under equivalent safeguards — take effect when posted here, with the date above updated accordingly. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.