RaceDIRECT Suite
Privacy Policy
Effective 14 August 2026 · applies to race.direct and every *.race.direct product
Who we are
The RaceDIRECT suite (race.direct and its products — RacePARTS, RaceVAULT, RaceRP, RaceSMART) is operated by KJNgineering Pty Ltd (Australia) — "we", "us". We provide motorsport operations tools to teams. This policy explains what personal information we collect, why, and the choices you have. We handle personal information in accordance with the Australian Privacy Act 1988 (including the Australian Privacy Principles) and, where it applies to you, the EU/UK GDPR.
Privacy contact: info@race.direct.
What we collect
Account information. Email address, name, optional profile details (photo, country, timezone), your team memberships and roles, and your notification preferences.
Sign-in information. If you use a password, it is stored only as a salted hash by our authentication provider. If you sign in with Google or Microsoft, we receive your name, email address, and profile photo from that provider — nothing else — and we never see your password for those services.
Content your team stores. The data teams put into the products (parts and inventory records, documents and invoices, telemetry, session media, email sent to team addresses). Your team controls this content; we process it to provide the service.
Operational data. Server logs, error diagnostics, and service-health telemetry needed to run and secure the suite. We do not run advertising trackers or sell data — the only cookies we set are strictly necessary (your session and your selected team).
How we use it
To operate the suite: authenticate you, apply your team's access rules, deliver notifications and emails you've opted into, provide support, keep the service secure (rate-limiting, abuse prevention, audit of administrative actions), and improve reliability. We do not use your information for advertising, and we do not sell or rent personal information to anyone.
Google user data. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google sign-in data only to authenticate you and display your name and photo in the suite.
Who processes it for us
We use a small set of infrastructure providers as processors, under their standard data-protection terms:
- Fly.io — application hosting (primary region: Sydney)
- Supabase — authentication and the platform database
- Neon — product databases
- Cloudflare — DNS, network security, file and media storage
- Resend — email delivery (notifications, invitations, team email)
- Sentry — error diagnostics (scrubbed of credentials)
- Google / Microsoft — only if you choose them for sign-in
Some providers store data outside Australia (including the United States and the EU). Where the GDPR applies, transfers rely on standard contractual clauses or equivalent safeguards.
Security & retention
All traffic is encrypted in transit (TLS). Stored credentials are encrypted at rest, administrative access requires multi-factor sign-in, and provider credentials are tracked and rotated. We keep your account information while your account exists; notification items expire automatically (30 days by default); raw service telemetry is kept for 35 days before aggregation; logs are retained for a limited period. Team content is retained until your team deletes it or offboards.
Your rights
You can view and correct your profile at any time from your account page. You may request access to, correction of, or deletion of your personal information — email info@race.direct and we will respond within 30 days. Deleting your account removes your profile and sign-in identities; content owned by a team remains under that team's control. If you are in the EU/UK you additionally have the rights to restriction, portability, and objection, and the right to complain to your supervisory authority; in Australia you may complain to the OAIC.
Other things you should know
The suite is a professional tool and is not directed at children under 16. We may update this policy as the suite evolves — material changes will be announced in-product, and the effective date above always reflects the current version. This page is the single policy for every *.race.direct product; product pages link here.
RaceDIRECT · Motorsport Tools · race.direct