Privacy Notice

Last updated: 2026-08-24

This notice describes what Runsheet sends, what it does not, and what you can do about it. It is written to be read in full — it is short on purpose.

1. Controller

The data controller is Luca Villa.

For privacy questions or to exercise your rights: [email protected]

2. Scope

This notice covers the Runsheet desktop application for Windows, account creation and sign-in, licence migration and renewal, usage reporting, optional feedback, and the optional feature that shares tyre pressures with a phone through a QR code. It does not cover other MotorsportSoftware products, which have notices of their own.

Runsheet works offline. Everything you create in it — vehicles, events, sessions, setups, runsheets, laps, tyre data, jobs, reports, notes, images and track files — is stored in a database on your own computer.

3. What the app reports

While you are signed in, a usage report is sent periodically. It is aggregated by calendar week and contains counters, not content. If you are offline the counters wait on your computer and are sent later.

The report is attached to your account, and therefore to your account identifier and email address. On versions that use a licence key it is attached to the licence, and therefore to the customer name registered to it. It is not anonymous, and this notice does not pretend otherwise.

A report contains:

  • the app version, the operating system and its version, the processor architecture, the interface language and your time-zone offset
  • how many times the app was started, how long it stayed open, and which days of the week it was used
  • how many vehicles, events, setups, runsheets, runs and laps exist on your computer — how many, never which
  • which internal operations ran and how often, each identified by a fixed name such as sheet.update
  • which operations failed, identified by the same fixed name and the error code
  • which areas of the app were used, and which screens and sub-screens were opened
  • printing and file exports, recorded by file extension only
  • failures of the app engine to start, failed updates, and errors raised by the interface, each by technical reason
  • the dates of a few firsts: first sign-in, first vehicle, first event, first setup, first runsheet, first lap
  • the hour of the day, in your own local time, at which actions were performed, and the days you worked offline

4. What is never sent

Usage reports carry none of the following, in any form:

  • the names of the tracks you run at, of your events, vehicles, drivers, engineers or mechanics — only how many there are
  • setup values, tyre pressures, temperatures, lap times, fuel figures
  • notes, comments, debriefs and job descriptions
  • file names, folder paths, images, track layouts or GPS files
  • the contents of your database, in any form

The work that makes you competitive stays on your computer. That is a design decision, not a promise: the component that keeps the counters is compiled without any networking library at all — it could not reach the internet if it were asked to. What leaves is a fixed list of counters, assembled and sent by a separate part of the application.

5. The names you choose

Runsheet lets you name drivers, engineers, mechanics, team members, vehicles and tracks. Those names are free text, typed by you, and they are often the names of real people.

They never travel with the usage reports. The signal names listed in section 3 are fixed identifiers written into the source code; they cannot contain anything you typed. Even an exported file is reported by its extension alone — xlsx, never Monza_Race2_Rossi.xlsx.

Those names can leave your computer only through a deliberate action: the QR share described below, a feedback message or screenshot you choose to send, or a backup or export file that you create and then choose to send to someone. In each case you decide what leaves and to whom.

6. Sharing tyre pressures with your phone

The QR button in Tyre Pressure is a separate, deliberate action, and it works differently from usage reporting. When you press it, the rows of that table — cold and hot pressures, temperatures, number of laps, bleed values, and the track, event, session, driver and tyre-set fields as you filled them in — are uploaded so that the page opening on your phone can display them.

The link is unguessable but not secret: anyone holding it can open that share. The stored rows cannot be listed or searched — they can only be retrieved by knowing the exact six-character code — and each share is deleted automatically 30 days after it is created. Nothing is uploaded unless you press that button.

If you would rather a person's real name were not readable by anyone holding the link, put initials or a code in the Driver field instead.

7. Accounts, licence migration and service messages

Creating an account requires an email address and password; an account name is optional. The email address is verified with a one-time code. Signing in creates a session record holding a session identifier, a general device description, and the times of claim, refresh and expiry. Only one desktop session per user is active at a time, so a confirmed sign-in elsewhere ends the previous one. Passwords are handled by the authentication provider and stored only in hashed form; recovery codes are hashed as well.

When a verified account is created, an operational notice is sent to the internal MotorsportSoftware sales address with the account name, email, access type and expiry, plus the current marketing-consent status. Similar internal notices are generated when an effective licence reaches 30 days and 7 days before expiry, and when it is renewed. These notices help us administer the trial or licence and prepare support or renewal work. A declined or missing marketing consent is shown as do not contact for marketing; the operational notice is not itself a marketing subscription.

If the app detects a licence that was already activated on the computer, migration uses the licence key and technical installation identifier to prove that the licence belongs to that installation and to preserve its real expiry date. If the email is missing or different, a separate one-time verification code is required before the licence can be claimed.

At successful email verification or licence migration, Cloudflare supplies the two-letter country code inferred from the network request. We retain that country code with the account to measure product adoption by country. We do not place the IP address, city, region, postal code, coordinates or machine identifier in this adoption-statistics record. The internal dashboard shows country totals; groups with fewer than three accounts are combined as Other.

Product-news email is optional and controlled by the checkbox shown during account creation and in the account profile. Missing, declined or withdrawn consent is treated as no consent. You can change that choice at any time.

7.1 Feedback you choose to send

The feedback command prepares a message to MotorsportSoftware support. It contains the category and text you type, the app version, operating system, current screen, account and user identifiers, and your account email so that support can reply. A screenshot of the app window is attached only if you choose to include it. Feedback is not sent automatically.

8. Why, and on what legal basis

Purpose Data Legal basis
Delivering the application you bought, and letting you sign in Account and licence data, session records Performance of a contract
Keeping one active session per user, and preventing licence sharing Session records, installation identifier Performance of a contract; legitimate interest in protecting the service
Administering new accounts, trials, expiry and renewal Account name and email, access type and expiry, marketing-consent status Performance of a contract; legitimate interest in administering the service
Measuring adoption by country Two-letter country code linked to the account; aggregate country totals Legitimate interest in product planning, using data minimisation
Finding and fixing faults — above all installations where the app fails to start Failure reasons, error counters, app version, operating system Legitimate interest in a working product
Understanding which features are used, to decide what to build and what to drop Feature and screen counters, entity counts, activity days and hours Legitimate interest in improving the product
Showing tyre pressures on your phone The rows of the table you chose to share A service you explicitly requested
Answering feedback you choose to send Your message, technical context and optional screenshot A service you explicitly requested; legitimate interest in support and fault correction
Sending optional product news Email address and consent record Consent, which you can withdraw at any time
Delivering updates The request your app makes to download a release Legitimate interest in distributing fixes

9. Who else is involved

  • Supabase — provides authentication and hosts the database holding accounts, licences, consent records, country codes, usage reports and shared sessions.
  • Cloudflare — serves this website and the account API, performs bot protection, resolves the request country at the edge, sends transactional and internal service email, hosts the internal tools used to read aggregate reports, and distributes Windows updates from the Runsheet update feed.
  • GitHub — distributes the public Runsheet v4 bridge installers used by older app versions and by the website download page.

Usage data is not sold, and is not shared with anyone beyond the providers above, who process it on instructions and for the sole purpose of running the service. Some of them operate across multiple regions, so processing may involve transfers outside the European Economic Area; the database holding accounts and usage reports is hosted in the European Union.

10. How long it is kept

Weekly usage reports are kept for as long as they are useful to understand how the product is used, and are deleted on request; the copy on your own computer keeps only the most recent weeks and discards the rest by itself. Account data, consent history and the acquisition country code are kept for the life of the account. Online session records expire within seven days of the last refresh; the desktop can use its locally protected, last-validated access state offline for up to 30 days. Licence data is kept for the life of the licence and for the period accounting rules require afterwards. Sessions shared by QR code are deleted automatically 30 days after they are created.

Operational sales-notification records contain account and event identifiers and expiry facts, not a second copy of the email address or account name; those contact details are resolved only when a message is sent. Feedback and email-delivery records are kept only as long as needed for support, security and service administration, subject to the providers' operational retention.

Everything stored on your own computer, including the backups you create, stays there until you delete it, and is not ours to keep or remove.

11. Your rights

You can ask what is held about you, ask for a copy, ask for corrections, ask for deletion, and object to processing based on legitimate interest — including the usage reporting described in section 3. There is no switch inside the application to turn that reporting off; write and it will be handled.

Write to [email protected] from the address the account or the licence is registered to, and you will get an answer.

If you are in the European Union and believe the processing is unlawful, you also have the right to lodge a complaint with your national supervisory authority.

12. Changes

When what the app reports changes, this page is updated and the date at the top changes with it. The Help tab inside the app carries a short summary and a link back to this page.