Privacy Policy
Last updated 2026-08-02
In short: we run no analytics trackers and no advertising cookies. We never see your F1 Fantasy password, and we never see your card details. Here is the complete and accurate list of what we do store.
1. Who processes your data
The data controller is Vitalii Ivashchenko (Ukraine). For any question about data processing, write to support@gridiq.world.
2. What we store
Account:
- email address and user identifier;
- sign-in method and registration date;
- your chosen interface language.
F1 Fantasy link (if you enable it):
- a session token and a player identifier — both encrypted, with the encryption key held separately from the database;
- snapshots of your lineup and its history;
- your saved plans, tracked rivals, and comparison settings.
We do not request, accept, or store your F1 Fantasy password.
Telegram (if you connect notifications):
- your Telegram user ID, chat ID, and username;
- your notification settings and a record of messages sent.
Payments:
- your Paddle customer ID and subscription ID;
- current plan, status, and the end date of the paid period;
- your Race Pack credit balance and Paddle event IDs used for deduplication.
We never receive or store your card number, expiry date, CVV, or billing address in any form: the payment form belongs entirely to Paddle, and all we receive is a notification that payment succeeded.
Feedback (if you send any):
- the text of your report — exactly what you wrote in the form or to the bot;
- technical details needed to reproduce it: screen address, app version, language, window size and browser type;
- your user identifier, so that we can reply.
3. Data about other players
The service displays public F1 Fantasy standings: the leaderboard of top managers and the tables of private leagues you have connected. To compute statistics and show trends over time, we store snapshots of those tables.
Those snapshots contain team names, the display names of their owners, positions, points, and lineups — that is, information the game itself publishes in open standings. These people are not our users.
The legal basis is legitimate interest: without historical snapshots there is no league analytics and no comparison against other players, which is what the service exists to provide. We minimise what we keep: persistent player identifiers are stored as an irreversible cryptographic hash, and the original values are never saved.
Some of these snapshots are not collected by our servers directly but by the GridIQ browser extension running on our users’ machines — see section 4.
If you play F1 Fantasy and do not want your data in our snapshots, email support@gridiq.world — we will delete it and add you to an exclusion list.
4. The GridIQ browser extension
The extension is an optional part of the service. It runs inside your own browser, where you are already signed in to F1 Fantasy, and never asks for or receives your F1 account password.
What it does:
- reads your squad, your past rounds and your player identifier on the F1 Fantasy site, and passes them to your GridIQ account;
- syncs the standings of the private leagues you belong to;
- when our server asks it to, fetches lineups of managers from the top-500 standings and passes them to us — that data feeds the snapshots described in section 3.
More on that last point: those requests come from your browser and carry your F1 session, because the game only serves other players’ lineups to a signed-in user. Only what the game itself shows its players about each other is collected — team lineups from the standings; none of your personal data is part of that transfer. It happens in the background during a normal sync: the extension takes no action in the game on your behalf and changes nothing in your own team.
The extension cannot change your lineup, make transfers, or take any other action on your behalf in F1 Fantasy — access is read-only.
On your device the extension stores only its own settings (for example the league size limit used when syncing). Data goes to our domains only; the extension sends nothing to any third party.
You can opt out at any time: remove the extension in your browser and unlink your team in GridIQ settings. The rest of the service keeps working. Data collected before that is deleted on request — see section 9.
5. Why we process it
- to provide the service and show you your own data and projections — basis: performance of a contract;
- to process payment and confirm your paid access — basis: performance of a contract and statutory accounting obligations;
- to send deadline notifications if you enabled them — basis: your consent, which you can withdraw at any time;
- to keep the service secure and prevent abuse — basis: legitimate interest;
- to build analytical models on standings data — basis: legitimate interest.
We do not sell personal data, do not share it with advertising networks, and make no automated decisions producing legal effects for you.
6. Cookies, trackers, and local storage
The site carries no advertising pixels and no third-party trackers, and we do not sell your data. The one thing we measure is product analytics through PostHog, and it runs only with your consent.
Until you press “Allow” in the banner, the analytics code is not loaded at all — not a single request reaches PostHog. Declining and not answering mean the same thing to us: nothing is sent.
With consent given, we record very little: which screens you opened, that you signed up or signed in, that you linked a squad, and that you paid. You appear in those events as an internal account identifier — not your email, not your name.
The first screen of a visit carries one extra label: where you arrived from — an AI assistant (ChatGPT, Perplexity, Claude, Gemini, Copilot) or "other". It is a label from a short list and nothing more: we do not store the address of the page you came from, let alone anything you typed into a search box.
What the analytics does not do: it records no sessions — we cannot replay what you did on screen; it does not collect clicks or typed text; it builds no advertising profiles.
The data is stored on PostHog’s European servers. You can change your mind at any time in settings, under “Privacy”: collection stops immediately, and on your next page load the analytics code is once again not loaded.
Payments are recorded by our server rather than by the browser, so your consent answer travels with the order: if you declined, no payment event is sent to analytics.
Your browser’s local storage holds only strictly necessary values, which never leave your device:
- your session token (so you are not signed out on every visit);
- your chosen theme and language;
- your answer to the analytics question — so we do not ask again;
- optimizer budget settings and temporary data for comparison screens.
The service worker caches only static interface files — fonts, icons, and scripts. It never stores your personal data.
7. Who we share data with
We use the following providers, each in a narrow role:
- Supabase — authentication and account storage;
- Vercel — web application hosting;
- Railway — backend and database hosting;
- Paddle — payment processing as Merchant of Record;
- PostHog — product analytics on European servers, only with your consent;
- Telegram — delivering notifications, if you connected them;
- F1 Fantasy — requests made on your behalf while linking is enabled.
Some providers are located outside your country of residence, so data may be transferred internationally under the standard contractual safeguards those providers offer.
We may also disclose data where required by law or where necessary to protect the rights and safety of our users.
8. How long we keep it
- account data — for as long as the account exists;
- the F1 Fantasy link token — until you revoke the link or the token expires;
- lineup and standings snapshots — for the current and previous seasons, since the historical analytics are built on them;
- payment records — for the period required by tax and accounting law.
9. Your rights
You may request access to your data, correction, deletion, restriction, or portability; object to processing based on legitimate interest; and withdraw consent you previously gave.
There is not yet a self-service delete button in the interface — deletion requests are handled manually. Email support@gridiq.world from your account address and we will delete your account and associated data within 30 days. Payment records are retained to the extent the law requires.
You can turn off notifications and unlink Telegram yourself under Settings at any time.
If you believe we process your data unlawfully, you may lodge a complaint with the data-protection supervisory authority where you live.
10. Security
Connections to the site are protected by TLS. F1 Fantasy access tokens are stored encrypted; one-time Telegram linking links are stored only as a hash and expire after 15 minutes; persistent identifiers of players in standings are hashed. Account passwords are held by Supabase, and we have no access to them.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the supervisory authority within the timeframes the law sets.
11. Changes to this policy
We will notify you by email or an in-app notice of material changes. Last updated: 2026-08-02.
Questions about this document: support@gridiq.world