Legal · Privacy

Privacy Policy

Last updated: 25 July 2026

1. Data controller

The data controller for personal data processed through this website and the ACLOG platform is:

PitlineLab
Country: Italy (EU)
Email: privacy@pitlinelab.com
Website: pitlinelab.com

For any privacy-related request, please use the email address above or the Privacy Request Form on the homepage.

2. What personal data we collect

We collect personal data in the following contexts:

ContextData collected
Newsletter (homepage)Email (required), name (optional), language preference, subscription status, subscription/revocation dates, confirmation and unsubscribe token hashes, IP address hash. For registered users: additional marketing consent proof with timestamp and security metadata.
Account registrationName, email address, password (stored via secure hash with password_hash, using Argon2id where available — never in plain text)
Google Sign-InName, email address and Google account identifier (subject ID) provided by Google. We do not receive your Google password.
User profile (optional)Team name, country, city, timezone, biography, profile photo, preferred language, marketing opt-in preference
Technical session dataSession token (stored as a SHA-256 hash), IP address, browser user-agent string, last activity timestamp
Privacy request formFull name, email address, request type and message content
Analytics (Google Analytics 4)Anonymized page views, session duration, referral source, approximate geographic region. No cross-site tracking.

We do not collect payment card data directly. Payment processing, when introduced, will be handled entirely by external payment providers. PitlineLab will not receive or store card numbers.

3. How we use your data

  • Newsletter and marketing — to send updates about ACLOG, sim racing guides and product news, only with your consent: via newsletter subscription with email confirmation (double opt-in) or via marketing consent in your account.
  • Service communications — for necessary administrative emails about account, security, licenses or important platform changes.
  • Security and fraud prevention — to detect and block brute-force attacks, track failed login attempts and maintain an audit log of administrator actions.
  • Analytics — to understand how pages are used and improve the site.
  • Legal obligations — to comply with applicable laws, respond to lawful requests from authorities, or enforce our terms.

We do not sell personal data to third parties. We do not use personal data for automated profiling that produces legal or similarly significant effects.

5. Google Sign-In

ACLOG offers "Sign in with Google" as an alternative to email/password registration. When you use this option:

  • You are redirected to Google's authentication servers. PitlineLab does not receive your Google password at any point.
  • Google sends us an ID token containing your name, email address and a unique Google account identifier (subject ID).
  • We store the subject ID in our database to link your Google account to your PitlineLab account. This ID does not give us access to any other Google service or data.
  • If your email address from Google matches an existing PitlineLab account, the accounts are linked automatically.
  • You can disconnect Google Sign-In from your account at any time via the Security section of your dashboard.

Google's use of your data during the authentication process is governed by Google's Privacy Policy.

6. Cookies and analytics

We use the following cookies and tracking technologies:

Name / typePurposeDuration
Session cookie (PHP)Maintains your login session. HttpOnly, SameSite=Strict.Session
Remember-me cookieKeeps you logged in for up to 30 days. HttpOnly, Secure.30 days
Google Analytics 4 (_ga, _ga_*)Anonymous page view tracking. IP anonymization enabled. Processed by Google Ireland Ltd.Up to 2 years

We do not use advertising cookies, cross-site tracking, fingerprinting or any third-party social media pixels.

You can disable Google Analytics by installing the Google Analytics Opt-out Browser Add-on, or by blocking the googletagmanager.com domain in your browser.

7. Data retention

  • Newsletter and marketing consent records — retained while you remain subscribed. After consent withdrawal, retained as long as necessary to demonstrate compliance with privacy and anti-spam obligations (typically up to 3 years).
  • Account data — retained while your account is active. Deleted within 30 days of a confirmed deletion request.
  • Session tokens — expire after 20 minutes of inactivity (standard) or 30 days (remember-me). Deleted automatically.
  • Security logs — admin audit logs and login attempt records retained for 12 months.
  • Analytics data — retained for 14 months per Google's default settings.
  • Privacy request records — retained for 3 years to demonstrate compliance.

8. Data sharing and third parties

We do not sell, rent or trade personal data. We share data only in the following circumstances:

  • Hosting provider (Aruba S.p.A.) — our website and database are hosted on Aruba shared hosting servers in the EU. Aruba acts as a data processor under a standard data processing agreement.
  • Google Analytics — anonymized analytics data processed by Google Ireland Ltd. under Google's standard data processing terms.
  • Google Sign-In — the authentication exchange is processed by Google's identity servers. See Section 5.
  • Payment processor (future) — when payment processing is introduced, a third-party gateway will handle card data. PitlineLab will not receive or store card numbers.
  • Legal obligation — we may disclose data if required by applicable law, court order or government authority.

Transfers outside the EU/EEA. If you accept Analytics or use Google Sign-In, some data may be processed by Google outside the EU/EEA. These transfers are governed by Google's Standard Contractual Clauses (SCC) approved by the European Commission under GDPR Art. 46(2)(c), which provide appropriate safeguards for your personal data. You can review Google's data transfer mechanisms at business.safety.google/gdpr.

9. Your rights

Under GDPR and applicable privacy laws, you have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data. We will confirm deletion within 30 days.
  • Portability — request your data in a structured, machine-readable format.
  • Restriction — ask us to stop processing your data in certain circumstances.
  • Objection — object to processing based on legitimate interest, including marketing.
  • Withdraw consent — if processing is based on consent (e.g. marketing emails), you can withdraw it at any time.

To exercise any of these rights, use our Privacy Request Form or email privacy@pitlinelab.com. We will respond within 30 days.

10. Security measures

  • Passwords are hashed securely with password_hash, using Argon2id where available — they cannot be reversed.
  • In production, connections to the site use HTTPS/TLS.
  • Session tokens are stored as SHA-256 hashes — the raw token never touches the database.
  • The admin area requires two-factor authentication for all logins.
  • Rate limiting and brute-force protection are applied to all authentication endpoints.
  • Security events are logged to an audit log.
  • Database credentials and cryptographic keys are stored in server-only configuration files, not in source code.

No transmission over the internet is 100% secure. If you discover a security vulnerability, please report it to privacy@pitlinelab.com.

11. Contact and updates

For any privacy-related question or request, contact us at:

PitlineLab — Privacy
privacy@pitlinelab.com

This policy may be updated from time to time. The "Last updated" date at the top of this page will change when we make a material update. We will notify registered users by email for significant changes.

Previous versions of this policy are available on request.