Privacy Policy
Digital Motorsports Club (DMC) & Digital Endurance App
Version 1.2 · Last updated: August 19, 2026
1. Introduction
Welcome to the Digital Motorsports Club (hereinafter: "DMC", "we", "us", or "our"). DMC operates the Digital Endurance App, the Digital Endurance Championship, and related white-label SaaS platforms (hereinafter collectively: the "Platform").
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, process, and protect your personal data in compliance with the European General Data Protection Regulation (GDPR).
Controller Details: Digital Motorsports Club (DMC) Located in: Groningen, The Netherlands Email: [email protected]
2. What Personal Data We Collect
To provide you with a professional sim racing environment, we collect the following types of personal data:
-
Identity Data: Your real first and last name.
-
Contact Data: Your email address.
-
Authentication & Gaming Data: Your connected Steam account ID (Steam64 ID) and Discord account ID.
-
Telemetry & Performance Data: In-game data extracted via our telemetry agent or server logs, including lap times, throttle/brake inputs, steering angles, track position, and incident history.
-
Financial Data: Payment statuses and transaction IDs processed via our payment provider (Stripe). Please note: We do not collect or store your credit card details; these are handled securely by Stripe.
-
User-Generated Content: Media you upload, such as team logos or video evidence for steward reviews.
-
Registration Screening Data: Where a competition organiser on the Platform maintains a registration watchlist, this consists of the name of an individual or team recorded as previously excluded from that organiser's competitions, together with a factual statement of the conduct concerned. See Section 3 and Section 5.
3. Purpose and Legal Basis for Processing
Under the GDPR, we only process your data when we have a valid legal basis:
-
To provide our services (Performance of a Contract): We use your Identity Data, Steam64 ID, and Discord ID to create your account, manage your team roster, grant you access to the Le Mans Ultimate game servers, and automate Discord role assignments.
-
To ensure sporting integrity (Legitimate Interest & Contract): Telemetry data, incident logs, and Review Requests are processed to calculate the Endurance Index, detect cheating, and allow Race Stewards to make objective, data-driven decisions during and after races.
-
To process payments (Performance of a Contract & Legal Obligation): We process transaction data to verify entry fee payments and comply with tax and accounting laws.
-
To communicate with you (Legitimate Interest): We use your email and Discord ID to send essential platform notifications (e.g., steward decisions, server passwords, team invitations).
-
To screen registrations (Legitimate Interest): Where a competition organiser maintains a registration watchlist, names submitted at registration are compared against it so that a human reviewer may consider whether an applicant was previously excluded from that organiser's competitions. No exclusion is automated. Every match is reviewed by a person, and the reviewer must confirm that the applicant is the same individual or team before any adverse outcome is possible. A documented balancing assessment is maintained for this processing and is available on request. Watchlist data is never shared between competition organisers on the Platform.
4. How We Share Your Data
We never sell your personal data. We only share data with trusted third-party processors necessary to operate the Platform:
-
Cloud Hosting Providers: Our databases and object storage are hosted on secure, GDPR-compliant cloud infrastructure (Google Cloud) located strictly within European Union data centres.
-
Network and Security Provider: Cloudflare provides DNS resolution, traffic proxying, and protection against denial-of-service attacks. Traffic between you and the Platform passes through Cloudflare's network.
-
Email Delivery: Google Workspace delivers our transactional and notification email.
-
Payment Processors: Stripe handles all financial transactions.
-
Gaming Infrastructure: Steam (OpenID authentication), Discord (OAuth2 and automated webhooks), and RaceControl.gg / Studio 397 (to provision game servers and validate driver connections).
Notices sent on an organiser's behalf. Some notifications are sent by the Platform on behalf of a competition organiser. Where a notice invites you to reply, your reply is delivered to that organiser's own email address and leaves the Platform. Correspondence conducted by email in this way is handled by the organiser and is not recorded against your Platform account.
Malware scanning. Files you upload are scanned for malicious software before being made available. This scanning is performed by software running within our own cloud infrastructure. Your files are not sent to any third-party scanning service.
5. Data Retention and the "Right to be Forgotten"
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected.
-
Account Deletion: If you request deletion of your account, we will delete or anonymise your Identity Data, Contact Data, Steam64 ID, and Discord ID (Right to be Forgotten).
-
Deletion is scheduled, not immediate. An erasure request takes effect after a period of thirty (30) days, during which your participation in competitions is suspended and you may cancel the request. This exists so that a request made in error can be reversed. After that period the erasure is carried out and cannot be undone.
-
What deletion means in practice. Because your account is the anchor for records that must be retained (see below), erasure is performed by permanently overwriting your personal data rather than removing the underlying record. Your name is replaced with a non-identifying placeholder, and your email address and linked account identifiers are replaced with values that identify no person and cannot be used to contact you. Some technical identifiers are retained in a placeholder form solely because the record cannot exist without them.
-
Residual references. We remove your name from free-text records wherever we can do so without destroying information about other people. In rare cases a reference may persist where removing it would corrupt a record concerning another participant, or a published result. We do not retain such references deliberately, and we will remove any brought to our attention where removal is possible.
-
Immutable Sporting Records (Exception): Please be aware that to preserve the historical integrity and statistics of the championships, your public race results, penalty logs, track records, and Endurance Index scores are considered part of the permanent sporting record. Upon account deletion, these records will be anonymised (replacing your name with "Former Driver") rather than completely erased, based on our legitimate interest in maintaining the integrity of past competition results.
-
Financial Records (Exception): Payment statuses, transaction identifiers, and invoice records are retained for the period required by Dutch tax and accounting law, with the person to whom they relate anonymised. This retention is a legal obligation and is not affected by an erasure request.
-
Sanction Records (Exception): Where a competition organiser has permanently excluded you from their competitions, that organiser may retain your Steam and Discord account identifiers for the purpose of recognising and preventing a further registration. This retention is scoped to that organiser only, is subject to an expiry period, and survives deletion of your account. No name is retained with it.
-
Registration Watchlist Data: A watchlist entry is retained without a fixed expiry period, because the conduct it records does not cease to be relevant after a set time. Every entry is subject to a mandatory review at least once every twelve months, at which the organiser must either confirm that it remains necessary or deactivate it. Deactivated entries are retained as a record of the decision but are no longer used for screening.
6. Data Security
We implement strict security measures to prevent your personal data from being accidentally lost, accessed, altered, or disclosed in an unauthorised way. All data in transit is encrypted using TLS 1.3, and all data at rest is encrypted using industry-standard AES-256 encryption. Access to the administrative backend (Race Control Room) is strictly limited to verified DMC Staff and Stewards via Role-Based Access Control (RBAC).
Uploaded files are scanned for malicious software before they are made available on the Platform. A file that fails this check is deleted and is never served. You will be notified if a file you uploaded is rejected, and you may upload a replacement.
7. Cookies and Similar Technologies
We use a small number of cookies that are strictly necessary for the platform to work. We do not use cookies for analytics, advertising, or tracking you across other websites, and we do not share cookie data with third parties for those purposes.
Because every cookie we set is strictly necessary to provide the service you have asked for, we rely on the exemption in Article 5(3) of the ePrivacy Directive and do not ask for your consent to set them. We do tell you about them, which is what this section and our Cookies page are for.
What we use cookies for
-
Keeping you signed in. When you sign in, we store a session cookie so you do not have to sign in again on every page.
-
Security. We store a token used to protect the sign-in process against cross-site request forgery, and a short-lived token used while linking your Steam account. These protect your account from being taken over.
-
Completing sign-in. We temporarily store the page you were on before signing in, and a short-lived value used to secure the exchange with Discord, so we can return you to the right place safely.
-
Remembering your cookie choice. We store the fact that you have seen and acknowledged our cookie notice, so we do not show it on every page.
Some of these are set before you sign in — the security token in particular is set the first time you load the site, because it protects the sign-in form itself.
How long they last
The cookies above last between ten minutes and six months, depending on their purpose. The full list, with the exact name, purpose and lifetime of every cookie, is published at digitalendurance.app/cookies and is generated directly from the application, so it is always current.
Controlling cookies
You can clear or block cookies in your browser settings. Because the cookies we use are strictly necessary, blocking them for this site will prevent you from signing in and using your account.
Changes to our use of cookies
If we ever introduce cookies that are not strictly necessary — for example analytics — we will ask for your consent before setting them, and you will be able to refuse without losing access to the service.
8. Your Privacy Rights
Under the GDPR, you have the following rights regarding your personal data:
-
Right of Access: You can request a copy of the personal data we hold about you.
-
Right to Rectification: You can ask us to correct inaccurate or incomplete data. Corrections to your name are reviewed before they are applied, because our Terms of Service require the use of a real name.
-
Right to Erasure: You can request the deletion of your personal data (subject to the exceptions in Section 5).
-
Right to Restriction of Processing: You can ask us to suspend the processing of your data. Where we grant a restriction, we suspend processing that relies on legitimate interest — including registration screening, statistical rating, and analytics — while continuing processing necessary to perform our contract with you or to comply with a legal obligation. We will tell you what a restriction does and does not cover before it takes effect.
-
Right to Data Portability: You can request the transfer of your data to you or a third party in a structured, machine-readable format.
-
Right to Object: You can object to the processing of your data where we rely on a legitimate interest.
To exercise any of these rights, use the Privacy section of your account in the Participant Dashboard, or contact us at [email protected]. Requests for access, portability, and erasure are handled by the Platform directly. Requests for restriction or objection are assessed by a person, and we will respond within one month.
Where a record is held about you for registration screening, you may request a copy of it and ask us to correct it if it is inaccurate.
9. Supervisory Authority
If you believe that we are processing your personal data in violation of the GDPR, you have the right to lodge a complaint with the relevant supervisory authority. Because DMC operates from The Netherlands, our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect technological or legal changes. Each version carries a version number, and we will notify you of any significant changes via the Platform or via Discord/email before they take effect.