Grid|Strategy
  • How it works
  • Features
  • Dashboard
  • Coming Soon

Privacy Policy

Effective Date: February 25, 2026
This Privacy Policy explains how GridStrategy collects, uses, stores, shares, and protects your personal information when you use the Service. It applies globally and includes specific provisions for users in the European Economic Area (EEA), United Kingdom, California, and other jurisdictions with enhanced privacy rights.

1. Who We Are and How to Contact Us

GridStrategy ("we," "us," or "our") operates the GridStrategy platform at gridstrategy.io, an independent Formula 1 race strategy analytics service. We are the data controller for personal information collected through the Service.

For any privacy-related questions, requests, or concerns, you may contact us at:

Privacy Inquiries: privacy@gridstrategy.io
Data Protection Officer: dpo@gridstrategy.io
Website: gridstrategy.io/privacy

We aim to respond to all legitimate privacy requests within thirty (30) days, and within the legally required timeframes for jurisdictions with specific response deadlines.

2. Information We Collect

We collect the following categories of information, depending on how you interact with the Service:

2.1 Information You Provide Directly

  • Account registration data: name, email address, username, and password (stored as a cryptographic hash)
  • Communication data: any information you submit when contacting us for support, feedback, or other inquiries
  • Preferences and settings: your saved dashboard configurations, notification preferences, and display settings

2.2 Information Collected Automatically

  • Log data: IP address, browser type and version, operating system, referring URLs, pages visited, and timestamps
  • Device information: device identifiers, screen resolution, and hardware characteristics
  • Usage data: features accessed, session duration, interaction patterns, and navigation paths within the Service
  • Cookies and similar tracking technologies: session cookies, persistent cookies, and local storage identifiers (see Section 7)
  • Approximate geolocation: derived from IP address (country and region level only)

2.3 Information from Third Parties

  • Authentication providers: if you choose to register or log in via a third-party authentication service (e.g., Google OAuth), we receive your name and email address from that provider, subject to the permissions you grant
  • Analytics services: aggregated, anonymized data from analytics tools we use to understand Service usage

2.4 Information We Do Not Collect

We do not intentionally collect:

  • Payment card information (if payments are processed, they are handled by a PCI-DSS compliant third-party processor and we do not store card data)
  • Precise GPS or real-time location data
  • Sensitive personal data including racial or ethnic origin, political opinions, religious beliefs, health data, or biometric identifiers
  • Personal information from individuals we know to be under the age of 16

3. How We Use Your Information

We use the information we collect for the following purposes, each tied to a lawful basis:

3.1 Providing and Operating the Service

Lawful basis: Performance of contract. We use your account information and usage data to authenticate you, deliver the features you request, maintain your preferences, and operate the platform.

3.2 Service Improvement and Analytics

Lawful basis: Legitimate interests. We analyze aggregated usage patterns to understand how the Service is used, identify areas for improvement, diagnose technical problems, and develop new features. This analysis does not involve decisions that significantly affect you individually.

3.3 Communications

Lawful basis: Consent (for marketing); legitimate interests (for service communications). We may send you service-related communications (account notices, security alerts, policy updates) and, where you have opted in, product updates and newsletters. You may withdraw marketing consent at any time.

3.4 Security and Fraud Prevention

Lawful basis: Legitimate interests; legal obligation. We process certain data to detect, investigate, and prevent fraudulent, abusive, or unauthorized activity, and to protect the security and integrity of the Service and our users.

3.5 Legal Compliance

Lawful basis: Legal obligation. We may process your data to comply with applicable laws, regulations, court orders, or binding requests from competent authorities.

3.6 What We Do Not Do

  • We do not sell your personal information to third parties
  • We do not use your data for automated profiling that produces legal or similarly significant effects
  • We do not use your data to serve targeted advertising from third-party ad networks
  • We do not share your data with Formula 1 teams, FIA, or race organizers

4. How We Share Your Information

We share your personal information only in the limited circumstances described below. We do not sell, rent, or trade personal information.

4.1 Service Providers

We engage trusted third-party vendors to help operate the Service, including cloud hosting providers, authentication services, error monitoring tools, and email delivery providers. These vendors process data on our behalf under contractual obligations that require them to protect your information and prohibit use for their own purposes.

4.2 Business Transfers

If GridStrategy is involved in a merger, acquisition, asset sale, or other business combination, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

4.3 Legal Disclosure

We may disclose your information if required by law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of GridStrategy, our users, or the public. Where legally permitted, we will notify you of such requests.

4.4 With Your Consent

We may share your information with third parties when you have explicitly consented to such sharing.

4.5 Aggregated or Anonymized Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, analytics, or other purposes.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, as required by applicable law, or as needed to resolve disputes and enforce our agreements.

  • Account data: retained for the duration of your account, plus 90 days following deletion to allow for recovery, and thereafter for up to 3 years where required for legal compliance
  • Usage and log data: retained for 12 months in identifiable form, then aggregated or deleted
  • Communications: retained for 3 years from last contact
  • Legal hold: where data is subject to a legal hold or ongoing investigation, retention may be extended as required

When data is no longer required, we securely delete or anonymize it. You may request earlier deletion subject to the limitations described in Section 6.

6. Your Privacy Rights

Depending on where you are located, you may have certain rights regarding your personal information. We honor these rights globally, not only where legally mandated.

6.1 Rights Available to All Users

  • Access: request a copy of the personal information we hold about you
  • Correction: request that we correct inaccurate or incomplete information
  • Deletion: request deletion of your personal information, subject to legal retention requirements
  • Objection: object to our processing of your data based on legitimate interests
  • Withdrawal of consent: withdraw consent for processing based on consent at any time, without affecting the lawfulness of prior processing
  • Complaint: lodge a complaint with your applicable data protection authority

6.2 Additional Rights for EEA and UK Users (GDPR / UK GDPR)

If you are located in the European Economic Area or United Kingdom, you also have the right to:

  • Data portability: receive your personal data in a structured, commonly used, machine-readable format
  • Restriction of processing: request that we restrict processing of your data in certain circumstances
  • Not be subject to solely automated decisions: where decisions have legal or significant effects, request human review

Our legal bases for processing under GDPR are: contract performance (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), legal obligation (Article 6(1)(c)), and consent (Article 6(1)(a)) where applicable. You may contact our Data Protection Officer at dpo@gridstrategy.io or lodge a complaint with your local supervisory authority.

6.3 Rights for California Residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete it, the right to opt out of sale (we do not sell personal information), the right to correct inaccurate information, the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising these rights.

To submit a verifiable consumer request, contact us at privacy@gridstrategy.io. We will respond within 45 days, with a possible 45-day extension when reasonably necessary. We do not discriminate against users who exercise their CCPA rights.

6.4 Rights for Other Jurisdictions

Users in Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), Japan (APPI), South Korea (PIPA), and other jurisdictions with applicable privacy laws may also have rights under their respective laws. We will honor valid rights requests in accordance with the applicable law of your jurisdiction. Contact us at privacy@gridstrategy.io to make a request.

6.5 How to Exercise Your Rights

To exercise any of the rights described above, submit a request to privacy@gridstrategy.io. We may require verification of your identity before fulfilling requests to protect against unauthorized access. We will not charge a fee for reasonable requests, but may do so for repetitive or manifestly unfounded requests as permitted by applicable law.

7. Cookies and Tracking Technologies

7.1 What We Use

We use the following categories of cookies and similar technologies:

  • Strictly necessary cookies: required for the Service to function. These cannot be disabled.
  • Session authentication tokens
  • CSRF protection tokens
  • Load balancing cookies
  • Functional cookies: enable features and remember your preferences.
  • Dashboard layout and settings preferences
  • Language and display preferences
  • Analytics cookies: help us understand how the Service is used.
  • Page view and session analytics (aggregated, no cross-site tracking)
  • We do not use advertising or tracking cookies from third-party ad networks.

7.2 Your Cookie Choices

You can control cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, and be notified when cookies are set. Note that disabling cookies may affect Service functionality. Our cookie consent banner (where required) allows you to manage non-essential cookies at the time of first access.

7.3 Do Not Track

We respect browser-level Do Not Track (DNT) signals. When we detect a DNT signal, we limit data collection to what is strictly necessary to provide the Service.

8. International Data Transfers

GridStrategy operates globally. Your personal information may be transferred to and processed in countries other than your country of residence, including the United States, which may have different data protection laws than those in your jurisdiction.

Where we transfer personal data from the EEA, UK, or Switzerland to countries not recognized as providing an adequate level of protection, we implement appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreements (IDTAs) where applicable
  • Binding Corporate Rules where established

You may request a copy of the relevant transfer mechanism by contacting us at privacy@gridstrategy.io.

9. Security of Your Information

We implement technical, administrative, and physical safeguards designed to protect your personal information from unauthorized access, use, alteration, and disclosure. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of sensitive data at rest using industry-standard algorithms
  • Hashing of passwords using a modern, salted algorithm (passwords are never stored in plaintext)
  • Access controls limiting employee access to personal data on a need-to-know basis
  • Regular security assessments and monitoring

No security system is impenetrable. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law, typically within 72 hours of becoming aware of the breach.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@gridstrategy.io and we will promptly delete that information.

If we learn that we have collected personal information from a child under 16 without verified parental consent, we will take immediate steps to delete that information.

11. Third-Party Links and Services

The Service may contain links to third-party websites or integrate with third-party data providers such as OpenF1 and FastF1. These third parties have their own privacy policies. We are not responsible for the privacy practices of third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated policy on the Service with a revised effective date
  • Displaying a prominent notice on the Service for a reasonable period
  • Sending an email notification to registered users where the change materially affects your rights

Your continued use of the Service after the revised policy becomes effective constitutes acceptance of the changes. If you do not agree, you should stop using the Service and may request deletion of your account and data.

13. Jurisdiction-Specific Disclosures

13.1 European Economic Area and United Kingdom

GridStrategy acts as data controller for personal information processed through the Service. Our Data Protection Officer can be reached at dpo@gridstrategy.io. You have the right to lodge a complaint with your national supervisory authority.

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on users.

13.2 California

GridStrategy does not sell personal information as defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We do not share personal information for cross-context behavioral advertising. California residents may submit privacy rights requests at privacy@gridstrategy.io.

Categories of personal information collected in the preceding 12 months: identifiers (name, email, IP address); internet or network activity; geolocation data (country/region level only); inferences drawn from usage data. Business or commercial purposes: service operation, security, analytics, legal compliance.

13.3 Brazil (LGPD)

For users in Brazil, we process personal data on the following legal bases under the Lei Geral de Protecao de Dados: consent (Article 7, I), contract performance (Article 7, V), legitimate interests (Article 7, IX), and legal obligation (Article 7, II). Brazilian users may exercise their rights under Articles 17-22 of the LGPD by contacting privacy@gridstrategy.io.

13.4 Canada (PIPEDA / provincial laws)

We collect, use, and disclose personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial privacy legislation. Our privacy practices are overseen by our designated Privacy Officer reachable at privacy@gridstrategy.io. Canadian users may file complaints with the Office of the Privacy Commissioner of Canada.

14. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or our data practices:

GridStrategy Privacy Team
Email: privacy@gridstrategy.io
DPO: dpo@gridstrategy.io
Website: gridstrategy.io/privacy

We take all privacy inquiries seriously and will respond within the timeframes required by applicable law, and in no case later than thirty (30) days from receipt of a valid request.

Effective Date: February 25, 2026. This policy supersedes all previous versions of the GridStrategy Privacy Policy.
Grid|Strategy· gridstrategy.io
Terms of Use Privacy Policy
GridStrategy is an unofficial fan project and is not associated with Formula 1, FIA, or any F1 team. F1, Formula One, and Grand Prix are trademarks of Formula One Licensing B.V.