1. Introduction
We are committed to protecting your privacy and handling your personal information with care, collecting only what is necessary.
2. Information We Collect
2.1 Account Registration
When you create an account, we collect:
- Display name
- Email address
- Password (stored as a one-way hash — we cannot read it)
We do not require your legal name, date of birth, address, or payment information for basic membership.
2.2 Profile Information (Optional)
Members may choose to add:
- Profile bio / description
- Profile photo
- Vehicle details (make, model, engine size)
- Racing categories / regions
This information is only collected if you choose to provide it.
2.3 Race Data
Members may upload or have imported:
- Lap times and race results
- Race dates, tracks, and positions
- Vehicle information associated with a race
Race data from public racing events (e.g., emails from Picton Karting Track) may be imported and associated with your account if your name matches. You will always be asked to confirm before this data is published under your account.
2.4 Contact Forms & Enquiries
When you use our contact, expression of interest, or sponsorship enquiry forms, we collect:
- Name
- Email address
- Phone number (optional)
- Your message
2.5 Technical Data
We automatically collect limited technical data for site operation:
- IP address (for rate limiting and security; not retained beyond 30 days)
- Session identifiers (stored in your browser, expire on logout or 30 days)
- Basic access logs (retained for 90 days; no PII beyond IP)
We do not use tracking cookies, third-party analytics services, or advertising networks.
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide member account services | Contract performance |
| Import and display your race results | Contract performance |
| Send account-related emails (verification, password reset) | Contract performance |
| Respond to enquiries | Legitimate interests |
| Maintain site security (rate limiting, abuse prevention) | Legitimate interests |
| Comply with legal obligations | Legal obligation |
4. Information Sharing
We do not sell your personal information.
We share information only where:
- You have consented (e.g., making your profile public to other members)
- Required by law (e.g., responding to a valid legal request)
- Service providers who process data on our behalf under strict data processing agreements
Third-Party Services
- hCaptcha — used on forms to prevent bot submissions. Subject to hCaptcha's privacy policy.
- Email delivery provider — used to send transactional emails. Email addresses are transmitted but not retained beyond delivery.
- LLM API (OpenAI-compatible) — used to parse non-standard race result emails. We do not send personal information to LLM APIs; only race result content is processed, and data is not used for model training.
5. Data Storage & Security
- Data is stored on servers located in Australia (AWS Sydney region)
- Passwords are stored using Argon2id hashing — we cannot recover your password
- All connections are encrypted using TLS 1.2 or higher
- Access to personal data is restricted to authorised personnel and admins
- Admin actions are logged in an audit trail
- We conduct regular security reviews
6. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your account and associated personal data
- Withdraw consent where consent is the basis for processing
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy
To exercise these rights, contact us. We will respond within 30 days.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Race results | Until you delete them, or account deletion |
| Contact/enquiry messages | 2 years |
| Security logs (IP addresses) | 30 days |
| Access logs | 90 days |
| Email verification tokens | 24 hours |
| Password reset tokens | 1 hour |
8. Children's Privacy
The Website is not directed at children under 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent.
For members under 18, we encourage parental awareness. If you believe a child's data has been submitted without appropriate consent, contact us immediately.
9. Cookies
We use only essential cookies necessary for the operation of the Website:
- Session cookie — keeps you logged in
- CSRF token cookie — protects forms from cross-site request forgery
No advertising, tracking, or analytics cookies are used.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date above and, where changes are significant, notify registered members by email.
11. Contact Us
For privacy-related enquiries or to exercise your rights:
Website: killerwattracing.com/contact
For complaints, you may also contact the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992