← Back to home Deutsche Fassung

Privacy Policy

Last updated: 6 September 2026

The short version. PaceMate processes your driving and telemetry data entirely on your own machine. Your laps, your recordings and your settings never leave your PC and are never stored on our servers. What we do store is only what is needed for your licence, your account and running the website — all of it listed individually below.

This is a courtesy translation. In case of any discrepancy, the German version is the legally binding one.

1. Controller

Dominik Schmitt
Amelungenstraße 62
96129 Strullendorf
Germany
Email: [email protected]

A data protection officer is not legally required and has not been appointed.

2. Where the site runs

The website and all related services run on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Germany. Backups are stored, encrypted, with the same provider (Falkenstein, Germany). A data processing agreement under Art. 28 GDPR is in place.

Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in secure, reliable operation.

3. Server log files

Every request is automatically logged with the data your browser transmits:

This data is technically necessary to deliver the site and serves to detect and fend off attacks. It is not combined with other data sources and is deleted automatically after 14 days at the latest. Legal basis: Art. 6 (1) (f) GDPR.

4. Content delivery network: Cloudflare

Access to pace-mate.com is routed through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare acts as an intermediary, distributes delivery and mitigates attacks. In doing so, Cloudflare processes your IP address. Transfer to the USA may occur; Cloudflare is certified under the EU-US Data Privacy Framework and standard contractual clauses are additionally in place.

Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in availability and attack mitigation. See the Cloudflare privacy policy.

5. Cookies

We use no advertising, tracking or analytics cookies. There is no cookie banner because there is nothing to consent to. Only the following strictly necessary or convenience cookies are used:

NamePurposeLifetime
cf_ipcountry Country code, so we can offer you the site in a matching language (notice banner). Contains the country only, not a precise location. 1 hour
lang_banner_dismissed Remembers that you closed the language notice. 30 days
pm_at, pm_rt Keep you signed in after login. Only set if you have an account and sign in. Not readable by JavaScript. 15 minutes / 30 days

Legal basis: § 25 (2) no. 2 TDDDG in conjunction with Art. 6 (1) (b) or (f) GDPR — these cookies are strictly necessary for the function you requested.

6. Fonts

All fonts are served from our own server. No connection is made to Google Fonts or any other external provider, and no IP address is transmitted to third parties for this purpose.

7. Creating an account and the beta key

An account is created with the sign-up form on the home page or on the sign-up page. We process your email address in order to confirm it, to write to you about your account, and to send you your access key.

While the closed beta is running, the key is issued automatically once you have confirmed your email address. The separate beta form that used to sit on the home page no longer exists — there is only one way to a key, and that is the account.

Legal basis: Art. 6 (1) (b) GDPR (contract and pre-contractual measures at your request).

8. User account

If you create an account, we process:

DataFormPurpose
Email addressplaintextSign-in, account correspondence, delivery of the licence key
PasswordArgon2id hash onlySign-in. The password itself is never stored and cannot be viewed by us.
Licence keySHA-256 hash onlyLinking the key to the account
Session tokenshash onlyStaying signed in, detecting stolen sessions
TimestampsplaintextRegistration, last sign-in, last password change
Failed attemptscounterProtection against automated password guessing
IP address in the security loghash onlyDetecting abuse patterns. The address itself is not stored there.
Stripe customer numberplaintextLinking your account to your subscription. Only exists once you have subscribed.
Subscription status and period endplaintextKnowing how long your access runs and when it renews

Legal basis: Art. 6 (1) (b) GDPR (performance of contract) and, for the security measures, Art. 6 (1) (f) GDPR.

Retention: Account data is stored for as long as the account exists. If you delete your account, the account, its licence link and all sign-in data are deleted immediately. Security log entries no longer contain personal data afterwards and are removed after 12 months at the latest.

9. Checking passwords against known breaches

When you choose a password, we check whether it has appeared in known data breaches, using Have I Been Pwned with k-anonymity: only the first five characters of a digest of your password are transmitted. Neither the password, nor your email address, nor any other personal data leaves our server, and the provider cannot determine which password the query refers to.

Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in protecting user accounts.

10. Email delivery

For confirmation, licence and security emails we use the mail service of Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The recipient address and the message content are processed through Google's systems. Transfer to the USA may occur; Google is certified under the EU-US Data Privacy Framework.

Legal basis: Art. 6 (1) (b) GDPR.

11. Payments: Stripe

Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When you take out a subscription we transmit your email address and your account identifier to Stripe; you enter your payment details and your billing address on Stripe's own page. You can pay there by card or by PayPal.

We never see your full card details. They do not pass through our server and are not stored there. What we receive back from Stripe is the customer number, the status of your subscription, its period end, and — for the free trial only — a one-way digest of the card fingerprint (see below).

Paying by PayPal. At checkout you can choose PayPal instead of a card. The payment is then handled by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. Your email address and the amount are transmitted; signing in and approving the payment happen on a PayPal page, and PayPal's own privacy notice applies in addition. Legal basis: Art. 6 (1) (b) GDPR.

Transfer to the USA (Stripe, Inc.) may occur; the basis for it is the EU standard contractual clauses, and a data processing agreement under Art. 28 GDPR is in place. Stripe's own privacy policy applies to what Stripe does with the data as a controller: stripe.com/privacy.

Free trial, and why we keep a card digest. A trial can only be started once per person. To make that hold even after an account is deleted, we store a keyed one-way digest (HMAC-SHA-256) of the card fingerprint Stripe gives us — never the card number, and nothing that could be turned back into one. That digest is the only piece of data about you that deliberately outlives your account; without it, deleting an account and signing up again would reset the trial. It is deleted after 24 months.

Legal basis: Art. 6 (1) (b) GDPR (performance of contract) for the payment itself, and Art. 6 (1) (f) GDPR (legitimate interest in preventing repeated misuse of the free trial) for the card digest.

12. Cancellations

If you cancel through the cancellation form, we store your declaration together with the date and time it reached us: your email address, and any name, contract reference and reason you enter. § 312k (4) of the German Civil Code requires us to confirm exactly this to you, and to keep it available as evidence. The entry is deleted after three years (§ 195 German Civil Code).

Legal basis: Art. 6 (1) (c) GDPR (legal obligation) and Art. 6 (1) (b) GDPR.

13. Licence check in the software

On start-up, PaceMate verifies your licence key through the service KeyAuth. Transmitted are: the licence key, your IP address, and an identifier derived from your machine's hardware characteristics (HWID). The sole purpose is to detect use of one key on multiple machines.

If the licence server is unreachable, PaceMate continues to run offline for a limited period; no data is transmitted during that time.

Your email address is not transmitted to KeyAuth.

Legal basis: Art. 6 (1) (b) GDPR (performance of the licence agreement) and Art. 6 (1) (f) GDPR (protection against unauthorised use).

14. What the software does NOT transmit

All of this data resides solely on your machine under %AppData% and is never transmitted to us.

15. Backups

The database is backed up nightly. Backups are end-to-end encrypted and cannot be read on the server itself. They are stored with Hetzner in Germany and deleted after 90 days. If you delete your account, your data disappears from the live systems immediately; it drops out of the backups when that period expires.

16. Your rights

You have the right at any time to:

An email to [email protected] is enough. You can also delete your account yourself at any time.

17. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de

18. Changes to this policy

We update this policy when our processing changes. The current version is always on this page; the date at the top shows when it was last revised.