Legal
Privacy policy
Draft pending review. The details marked in yellow will be completed before sales open. The Spanish version is binding.
Last updated: Pending: publication date
1. Controller
- Controller: Isaac Albalá Pending: full name, NIF Pending: tax ID (NIF), address Pending: address VERIFY: Spanish law (LSSI) requires a domicile or physical establishment; a PO box may not be enough, Spain.
- Privacy contact: vantareappsoporte@gmail.com (subject "Privacy").
- No data protection officer (not required for this activity).
2. Summary in five lines
- Your racing telemetry is processed on your computer and is not uploaded.
- Paid plans need an account (sign-in via Clerk) and a license (Supabase).
- You pay Polar, which is the seller and processes payment data as its own controller.
- Crash reports go to PostHog (EU) without identifying you, and only if you accept: the app asks you on first launch, and you can turn them off. Usage data is sent only if you turn it on.
- We do not sell your data or use it for advertising.
3. What we process, why, and on what legal basis
| Data | When | Purpose | Legal basis (GDPR art. 6) |
|---|---|---|---|
| Account: Clerk user ID, sign-in provider (Google, Discord or email) and the data that provider shares with Clerk (usually email and name) | If you sign in | Create and keep your account, link your plan | Contract (6.1.b) |
| License: internal account ID, plan and validity dates, device ID (non-reversible SHA-256 hash of the Windows machine ID), signed license credential | When activating or checking the license | Grant plan access, limit active devices, prevent fraud | Contract (6.1.b) and legitimate interest in preventing misuse (6.1.f) |
| Purchase: purchase email, Polar customer and order IDs, product, amount, status (paid, refunded, cancelled), dates. Polar notices may include name and country VERIFY which fields arrive | On purchase, renewal, cancellation or refund | Grant or remove the license, refunds, bookkeeping | Contract (6.1.b) and legal accounting/tax duty (6.1.c) |
| Crash reports (off until you accept; the app asks on first launch, and you can turn them off): app version, OS family, crash code and numeric stack addresses. No messages, paths, user name or personal ID | If the app crashes and you have accepted | Find and fix bugs | Consent (6.1.a), revocable in Settings → Privacy |
| Usage data (off by default): random installation ID, version and channel, simulator when a live session starts, visible widget types | Only if you enable "Send usage data" | Learn which simulators and widgets are used to prioritise development | Consent (6.1.a), revocable in Settings → Privacy |
| Bug reports you send (testers/nightly builds only): text you write, module, up to 3 screenshots you choose, app and Windows version, random installation ID, your account | Only if you submit a report in the app | Reproduce and fix the bug you report | Consent (6.1.a) / legitimate interest in handling your request |
| Support: email, messages and anything you send by email or Discord | If you contact us | Reply and solve issues | Contract or legitimate interest (6.1.b/f) |
| Waitlist: email, simulator and current overlay, language and consent version | If you sign up on vantare.app | Notify you of the launch and news | Consent (6.1.a) |
| vantare.app website: IP address and technical request data in server logs | When you visit | Serve and protect the website | Legitimate interest (6.1.f) |
| Calendar and updates: IP address when fetching the public calendar or downloading an update | When you use those features | Show the calendar and update the app | Contract / legitimate interest (6.1.b/f) |
What we do NOT collect: simulator telemetry (laps, times, positions, driver names), your layouts and settings, and telemetry recordings stay on your computer. The app takes no automatic screenshots, logs no clicks or screens, and records no sessions. Crash and usage events are sent without a person profile and without the IP address as an event property; the connection IP still reaches PostHog with the request VERIFY: enable "Discard client IP data" in PostHog.
Engineer voice (if included in your build): voices are generated or cached on your computer; no voice or audio is sent to any server VERIFY whether the module ships.
We make no automated decisions with legal effects on you and do no profiling.
4. Providers (processors) and recipients
| Provider | Purpose | Role | Location and transfer safeguards |
|---|---|---|---|
| Polar Software, Inc. (USA) | Checkout, payment, taxes, receipts, refunds, customer portal | Independent controller as seller (Merchant of Record); see its privacy policy | USA; EU Standard Contractual Clauses, per its policy |
| Clerk, Inc. (USA) | Sign-in and account management, in the app and on the website sign-in page (clerk.vantare.app) | Processor | USA; VERIFY: EU-US Data Privacy Framework and/or SCCs in its DPA |
| Supabase, Inc. | Account and license database, server functions, calendar, bug reports | Processor | VERIFY project region; DPA with SCCs |
PostHog (EU instance, eu.i.posthog.com) | Crash reports and usage data | Processor | Data hosted in the EU; VERIFY signed DPA |
| Cloudflare, Inc. | Hosting and security for vantare.app (request logs) and the waitlist database (Cloudflare D1, EU jurisdiction) | Processor | Global network; DPF and SCCs VERIFY |
| GitHub, Inc. (Microsoft) | Installer and update downloads from GitHub Releases | Independent controller of its logs | USA; DPF |
| Google LLC | Support email (Gmail) | Processor | USA; DPF |
| Discord Inc. | Community and support if you contact us on Discord | Independent controller | USA; its policy |
| Microsoft (Microsoft Store) | If you install from the Store: distribution and installation | Independent controller of Store data | Its privacy policy; payment is still through Polar VERIFY at Store launch |
We do not share data with third parties except where required by law (e.g. tax authorities).
5. Retention
- Account and license: while you have an account. If you ask for deletion, they are deleted within 30 days VERIFY procedure: currently manual, except what we must keep by law.
- Purchase data: as long as tax and commercial law requires (generally up to 6 years). Full Polar notices received by the server are purged after 30 days (180 days if held for error review).
- Crash reports and usage data: 12 months VERIFY that the PostHog retention setting matches. Locally, at most 32 pending items of each type are kept and deleted once sent or if you withdraw permission.
- Bug reports you send: until the bug is resolved and at most 24 months.
- Support: 2 years from last contact.
- Waitlist: until you unsubscribe or up to 6 months after sales open.
- Website logs: per Cloudflare configuration VERIFY, typically days.
6. Your rights
You can request access, rectification, erasure, objection, restriction and portability, and withdraw consent at any time (without affecting prior processing). Write to vantareappsoporte@gmail.com from your account email; we reply within one month.
- Crash reports and usage data: change them in Settings → Privacy. Turning them off deletes unsent pending items.
- For payment data you can also contact Polar.
If you think we have mishandled your data, you can complain to the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or the authority in your EU country.
7. Children
Vantare is not aimed at children under 14. We do not knowingly create accounts for under-14s (art. 7 Spanish LOPDGDD). Buying requires being an adult or parental/guardian permission.
8. Security
We use encrypted connections, signed license credentials, stripping of paths, emails and tokens from reports before storing and sending them, and restricted database access. If a security breach affects you, we will notify the AEPD and, where the law requires, you.
9. Cookies and website
vantare.app uses no analytics or advertising cookies. It may only use technical elements strictly needed to work, which need no consent. Fonts are served by the website itself and no page loads resources from Google. Only the tester sign-in page (vantare.app/acceso and vantare.app/en/access) loads a service from another company: Clerk sign-in at clerk.vantare.app and, when Clerk needs it, the Cloudflare Turnstile bot check. There Clerk receives your IP and what you type to sign in, and uses strictly necessary technical cookies to keep your session, which need no consent. The rest of the website loads nothing from third parties. To limit abuse of the waitlist, we keep a salted hash of your IP with the hour, never the IP itself; it is only used to count attempts per hour and is deleted automatically with the next sign-up after 24 hours. If we add analytics or non-essential cookies in the future, we will ask first with a banner and update this policy.
The desktop app uses no cookies. It stores settings, layouts, your sign-in session and a random installation ID on your computer.
10. Changes
If we materially change this policy, we will tell you in the app or by email before it applies.