Privacy

Privacy Policy

Information notice pursuant to Regulation (EU) 2016/679 GDPR

Last update: 18 July 2026

1. Introduction and organisation information

Next Sim Racing is committed to serving its customers and contacts to the best of its ability. Part of this commitment involves the responsible management of personal data collected through the website nextsim.racing and any related interactions.

1.1. Data controller

F85 di Luca Bortolami, registered in Italy, VAT Number 04720250275, e-mail: support@nextsim.racing.

Our primary objectives in processing such data include:

  • Improving users' experience on our platform by understanding customer needs and preferences.

  • Providing timely assistance and responding to questions or support requests.

  • Improving our products and services to meet the evolving needs of our users.

  • Carrying out necessary business operations, such as billing and account management.

It is our policy to treat personal data with the utmost respect for privacy and security. We adhere to all relevant regulations and guidelines to ensure that the data we process is protected against unauthorised access, disclosure, alteration, and destruction. Our practices are designed to safeguard the confidentiality and integrity of your personal data, while enabling us to provide you with the services you entrust to us.

2. Scope of application

Our privacy policy is designed to protect the personal data of all our stakeholders, including website visitors, registered users, and customers. Whether you are simply browsing our website, using our services as a registered user, or interacting with us as a customer, we ensure that your personal data is handled according to the highest standards of privacy and security. This policy outlines our practices and your rights regarding personal data.

3. Data collection and processing

Our commitment to transparency and data protection extends to the way we collect and use your personal data. We collect personal data through various interactions, including, but not limited to, when you use our services or products via the web portal, or when you provide us with information directly. The following list details the types of personal data we may process:

  • Billing details, including billing name, address, country, e-mail address, company name and tax or VAT

  • Device ID

  • IP address

  • Operating system and version

  • Approximate location based on IP

  • Interaction logs (e.g., clicks, time spent on pages)

  • Transaction and subscription information, including amounts, currency, payment status, purchase history, subscription status and renewal or cancellation information

  • Stripe identifiers, including customer, subscription, invoice, payment, charge and payment method identifiers

  • Authentication and session data, including the session identifier, internal user identifier, authentication status, and session creation, last activity and expiration timestamps, one-time-password data, email address, machine identifiers associated with plugin authentication

The primary ways we use the collected personal data include:

  • Authentication and security

  • Personalisation and customisation of the user experience

  • Communication activities

  • Performance analysis and monitoring

  • Transaction processing

  • Compliance with legal obligations

  • Customer support

  • Fraud prevention and risk management

3.1. Payment Processing

Payments are processed through Stripe Checkout. Payment credentials are entered directly into a payment interface hosted and operated by Stripe and are transmitted directly to Stripe. Next Sim Racing does not receive or store complete card numbers, card verification codes (CVC/CVV), complete bank account credentials or online banking authentica-tion credentials. Stripe processes the complete payment information necessary to complete the transaction. Next Sim Racing receives or may access only limited transaction and billing information, such as payment status, amount, currency, Stripe identifiers, bill-ing details, payment method type, card brand and the last four digits of the payment card where made available by Stripe. Stripe processes identification and billing information, payment credentials, billing address, IP address, transaction information and information required for fraud prevention and regulatory compliance. The information received or accessible by Next Sim Racing is limited to billing and transaction details, payment and subscription status, amounts and currency, Stripe customer, subscription, invoice, payment and charge identifiers, and limited pay-ment method information such as the method type, card brand and last four digits where available. Next Sim Racing does not receive or store complete payment card numbers or card verification codes.

4. Legal bases for processing

In compliance with Article 6 of the GDPR, the processing of personal data is based on the following legal bases, depending on the specific purpose for which the data is collected and used:

1. Performance of a contract (Art. 6, para. 1, point (b), GDPR): Processing is strictly necessary to provide the requested services, manage accounts, and fulfil the Terms of Service.

  • Authentication and security: to allow access to the portal and use of software dashboards.

  • Transaction processing: to complete purchases, process payments, and provide subscription products or services.

  • Customer support: to respond promptly to queries, provide technical support, and handle requests from registered users.

2. Compliance with a legal obligation (Art. 6, para. 1, point (c), GDPR): Processing is necessary to comply with obligations under applicable laws and regulations:

  • Compliance with legal obligations: retention of tax data, invoice processing, and accounting reporting required by applicable Italian and international tax law.

  • Management of the right of withdrawal: to collect and process withdrawal requests sent via the dedicated electronic function on the site, and to send mandatory receipt confirmation communications, as required by European consumer protection legislation.

3. Legitimate interest (Art. 6, para. 1, point (f), GDPR): Processing is based on the Data Controller's legitimate interest, provided that the user's fundamental rights and freedoms do not override it:

  • Fraud prevention and risk management: to monitor and protect the platform against unauthorised access, payment fraud, and service abuse.

  • Performance analysis and monitoring: to measure web traffic and collect anonymised statistics aimed at optimising the infrastructure, resolving technical system issues, and improving the service offered.


4. Explicit consent (Art. 6, para. 1, point (a), GDPR): Processing is based on prior, free, and revocable consent provided by the user:

  • Communication activities: for sending newsletters, promotional updates, and commercial communications not strictly related to the technical operation of the service.

  • Personalisation and customisation of the user experience: for the use of non-essential cookies and advanced tracking technologies, aimed at adapting the platform to user preferences.

The user has the right to withdraw their consent at any time through their account settings or by contacting us directly at support@nextsim.racing, without affecting the lawfulness of processing based on consent before its withdrawal.

5. Minimum age and children's privacy

Our website, nextsim.racing, and related services do not contain restricted, harmful, or adult content; the platform provides software dashboards designed exclusively for car racing simulations. However, in accordance with applicable data protection laws (including the GDPR), users must be at least 16 years old to autonomously consent to the processing of their personal data. If you are under 16, you may browse our website, but you are required to obtain the explicit involvement and consent of a parent or legal guardian before creating an account or subscribing to our services.

6. Data retention and protection

6.1. Data Storage and Processing Locations

Personal data is primarily stored on secure servers located in the Netherlands (NL) through our backend hosting infrastructure provider, Railway. Due to the integrated use of external platforms essential for the provision of our services, including Railway, Upstash, Stripe, Cloudflare, Framer, Brevo, Zoho, Discord and Steam, some processing activities may also take place in other locations, including other countries within the European Union and the United States.

Data hosting partners: We collaborate with reliable data hosting service providers committed to adopting state-of-the-art security measures. These partners are selected based on their compliance with strict data protection standards.

6.2. Data retention periods

We retain personal data only for as long as necessary for the purposes for which it was collected, taking into account the nature of the data, the purposes of the processing, applicable legal requirements and the need to establish, exercise or defend legal claims. The following retention periods normally apply:

  • Account and profile data: retained for as long as the user account remains active.

  • Authentication sessions: Website session records are retained for up to 7 days and are deleted earlier when the user signs out, the session is revoked, or the related account is deleted. Plugin session records expire after 8 days of inactivity and are subject to an absolute maximum duration of 30 days. Expired or revoked records are automatically removed from session database. Temporary login data, such as OTP index, challenges and login results are retained for up to 15 minutes.

  • Customer support and contact requests: retained for up to 24 months after the request has been closed, unless a longer period is necessary to manage an ongoing dispute or comply with a legal obligation.

  • Withdrawal requests: retained for the time necessary to process and document the request and, where necessary, until the expiry of the applicable limitation periods for the establishment, exercise or defence of legal claims.

  • Billing, transaction, accounting and tax data: retained for 10 years from the relevant accounting record, or for any longer period required by applicable tax, accounting or legal obligations.

  • Application, technical and security logs: normally retained for no longer than 180 days. Relevant records may be retained for a longer period where necessary to investigate a security incident, prevent fraud, address misuse of the service or comply with a binding legal request.

When an account is deleted, access to the service is revoked immediately. Account, profile and authentication data that are no longer necessary are deleted or irreversibly anonymised without undue delay. Data required for accounting, taxation, payment records, withdrawal management, fraud prevention, dispute resolution or compliance with legal obligations may be retained for the applicable periods described above.

Where personal data is contained in system backups, residual copies are deleted according to the applicable backup rotation schedule and are not restored except where necessary for disaster recovery, security or legal compliance purposes.

At the end of the applicable retention period, personal data is deleted, irreversibly anonymised or otherwise rendered inaccessible, unless further retention is required by law.

6.3. Data protection measures
  • Security audits and monitoring: Security audits are conducted regularly to identify and resolve potential vulnerabilities. We also monitor our systems for unusual activity to prevent unauthorised access.

  • Access control: Access to personal information is strictly limited to authorised personnel who have a legitimate business need to access the data. We enforce strict access controls and review permissions regularly.

  • Encryption: To protect data both during transfer and at rest, we use advanced encryption technologies.

7. Data sharing and disclosure

We are committed to safeguarding your personal data and ensuring it is treated with the utmost respect. This commitment extends to how we handle the sharing and disclosure of your data.

7.1. Sharing of personal data

Third-party service providers: We may share user data with third-party service providers who perform services on our behalf. Such trusted entities may have access to personally identifiable information only on a need-to-know basis and will be contractually obliged to keep user data confidential. These partners are prohibited from using user personal data for any purpose other than providing the services we request, and they are required to maintain the confidentiality of user data.

7.2. Data processing agreements

When we share your data with third-party service providers, we do so under the protection of Data Processing Agreements (DPAs) that ensure your information is handled in accordance with the GDPR and other relevant data protection laws. These agreements require third parties to implement appropriate technical and organisational measures to ensure the security of your data.

7.3. Transparency and control

We believe in transparency and the importance of ensuring you have control over your personal data. You will always be informed of any significant changes to our data sharing practices, and where applicable, you will have the opportunity to consent to these changes. Your trust is important to us, and we are committed to ensuring that your personal data is disclosed only in accordance with this policy and only when there is a justified reason to do so. For any questions or concerns about how we share and disclose personal data, please contact us at support@nextsim.racing.

8. Integrated providers and purposes

Provider

Provider

Purpose

Purpose

Data collected

Data collected

Processing location

Processing location

Privacy

Privacy

Brevo

Brevo

Customer support, performance analysis and monitoring.

Customer support, performance analysis and monitoring.

Full name, e-mail address and/or phone number, IP address, interaction logs (e.g., clicks, time spent on pages), subscription data (invoice or order number).

Full name, e-mail address and/or phone number, IP address, interaction logs (e.g., clicks, time spent on pages), subscription data (invoice or order number).

United States, France

United States, France

Cloudflare

Cloudflare

Authentication, security, personalisation and customisation of user experience, fraud prevention, risk management, performance analysis and monitoring.

Authentication, security, personalisation and customisation of user experience, fraud prevention, risk management, performance analysis and monitoring.

Visitor IP address, device ID, web traffic data.

Visitor IP address, device ID, web traffic data.

European Union, United States

European Union, United States

Discord

Discord

Authentication and security.

Authentication and security.

IP address (during login), Discord user ID, email, username, profile image.

IP address (during login), Discord user ID, email, username, profile image.

United States

United States

Framer

Framer

Content distribution, performance analysis and monitoring, authentication and security.

Content distribution, performance analysis and monitoring, authentication and security.

IP address, browser and operating system information (technical browsing data).

IP address, browser and operating system information (technical browsing data).

United States

United States

Railway

Railway

Authentication, security, performance analysis and monitoring, compliance with legal obligations, fraud prevention, risk management, transaction processing.

Authentication, security, performance analysis and monitoring, compliance with legal obligations, fraud prevention, risk management, transaction processing.

Full name, company name, tax ID/Vat number, billing address, e-mail address, third-party authentication data (Discord/Steam ID), subscription data (ID, expiry, type, billing details).

Full name, company name, tax ID/Vat number, billing address, e-mail address, third-party authentication data (Discord/Steam ID), subscription data (ID, expiry, type, billing details).

Netherlands

Netherlands

Steam

Steam

Authentication and security. 

Authentication and security. 

IP address (during login), Steam user ID, username, profile image.

IP address (during login), Steam user ID, username, profile image.

United States

United States

Stripe

Stripe

Transaction and payment processing, fraud prevention, risk management, authentication, security, compliance with legal obligations.

Transaction and payment processing, fraud prevention, risk management, authentication, security, compliance with legal obligations.

Stripe processes identification and billing information, payment credentials, billing address, IP address, transaction information and information required for fraud prevention and regulatory compliance. The information received or accessible by Next Sim Racing is limited to billing and transaction details, payment and subscription status, amounts and currency, Stripe customer, subscription, invoice, payment and charge identifiers, and limited payment method information such as the method type, card brand and last four digits where available. Next Sim Racing does not receive or store complete payment card numbers or card verification codes.

Stripe processes identification and billing information, payment credentials, billing address, IP address, transaction information and information required for fraud prevention and regulatory compliance. The information received or accessible by Next Sim Racing is limited to billing and transaction details, payment and subscription status, amounts and currency, Stripe customer, subscription, invoice, payment and charge identifiers, and limited payment method information such as the method type, card brand and last four digits where available. Next Sim Racing does not receive or store complete payment card numbers or card verification codes.

United States

United States

Upstash

Upstash

Storage and management of website and plugin authentication sessions; temporary OAuth, social-login and email OTP data; plugin device authentication; Authentication security.

Storage and management of website and plugin authentication sessions; temporary OAuth, social-login and email OTP data; plugin device authentication; Authentication security.

Internal user and session identifiers, authentication provider and provider identifier, username, avatar, profile URL, email address, machine identifier, client-generated public cryptographic key and key identifier, authentication timestamps, redirect and login-state information, OTP hashes and attempt data, transactional email identifiers, temporary security nonces and checkout idempotency identifiers.

Internal user and session identifiers, authentication provider and provider identifier, username, avatar, profile URL, email address, machine identifier, client-generated public cryptographic key and key identifier, authentication timestamps, redirect and login-state information, OTP hashes and attempt data, transactional email identifiers, temporary security nonces and checkout idempotency identifiers.

Germany

Germany

Zoho

Zoho

Compliance with legal obligations, customer support.

Compliance with legal obligations, customer support.

User e-mail address and any personal data inserted by the user in the email text.

User e-mail address and any personal data inserted by the user in the email text.

European Union, United States

European Union, United States

9. Rights and choices

We recognise and respect your rights regarding your personal data, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. We are committed to ensuring that you can exercise your rights effectively. 

9.1. Your rights
  • Right of access (Art. 15 GDPR): You have the right to request access to the personal data we hold about you and to obtain information on how we process it.

  • Right to rectification (Art. 16 GDPR): If you believe that the personal data we hold about you is incorrect or incomplete, you have the right to request its rectification or completion. 

  • Right to erasure ('right to be forgotten') (Art. 17 GDPR): You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, among other circumstances. 

  • Right to restriction of processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your personal data under certain conditions. 

  • Right to data portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit such data to another data controller. 

  • Right to object (Art. 21 GDPR): You have the right to object to the processing of your personal data, under certain conditions, including processing for direct marketing purposes. 

  • Right to withdraw consent (Art. 7, para. 3, GDPR): Where the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. 

  • Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates applicable data protection laws. 

9.2. Exercising your rights

To exercise any of these rights, please contact us at support@nextsim.racing. We will respond to your request in accordance with applicable data protection laws and within the timeframes prescribed by those laws. Please note that, in some cases, we may need to verify your identity as part of the procedure to ensure the security of your personal data.

10. Cookies and tracking technologies

We are committed to ensuring maximum transparency regarding the use of cookies and other tracking technologies on our website, nextsim.racing.

10.1. What are cookies and tracking technologies

Cookies are small data files stored on your device that allow us to remember your preferences and collect information about your use of the website. Tracking technologies, such as web beacons and pixel tags, help us understand how you interact with our site and which pages you visit.

10.2. How we use these technologies
  • Essential cookies: Necessary for the functioning of the website, for example, for authentication and security. They do not require consent.

  • Performance and analysis cookies: Collect information on how visitors use our website, which pages are visited most frequently, and whether error messages are received from web pages. These cookies help us improve our website.

  • Functional cookies: Allow the website to provide advanced features and personalisation, such as remembering your preferences.

  • Advertising and targeting cookies: Used to provide advertisements more relevant to the user and their interests. They are also used to limit the number of times you see an advertisement and to help measure the effectiveness of the advertising campaign.

10.3. Your choices and consent

Upon your first visit, our website will show you a cookie consent banner, where you can:

  • Accept all cookies: Consent to the use of all cookies and tracking technologies.

  • Reject non-essential cookies: Only cookies essential to provide you with the necessary functions of the website will be used.

  • Customise your preferences: Choose which categories of cookies you wish to authorise.

10.4. Changes to our use of cookies

We may update our use of cookies and tracking technologies to improve our services or to comply with legal requirements. We will inform you of any significant changes and will ask for your consent where necessary. For more detailed information on the cookies we use, their purposes, and how you can manage your preferences, please consult our Cookie Policy. If you have any questions or concerns about our use of cookies and tracking technologies, please do not hesitate to contact us at support@nextsim.racing.

11. International data transfers

We may transfer your personal data to locations outside your country of residence, including countries that may have different data protection laws than those in your jurisdiction. We assure you that such transfers are carried out with the utmost care and in compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR).

Since many of our integrated third-party service providers operate globally and have their headquarters or main infrastructure in the United States, your personal data may be transferred to and processed in the United States. To ensure that your data remains accurately protected, all data transfers outside the EU are carried out in compliance with strict regulatory safeguards, in accordance with Chapter V of the GDPR. This includes the application of Standard Contractual Clauses (SCCs) approved by the European Commission and alignment with legal adequacy mechanisms (such as the EU-US Data Privacy Framework), where applicable.

12. Data breach notification procedures

We understand the importance of protecting your personal data and taking proactive measures to safeguard it. In the event of a data breach that may pose a risk to your privacy rights and freedoms, we have established clear procedures to identify, assess, and promptly mitigate the impact of the breach.

12.1. Detection and assessment
  • Internal monitoring: We adopt robust security measures and monitoring systems to detect and respond promptly to potential data breaches.

  • Breach impact assessment: Upon detection of a data breach, we will perform a thorough assessment to determine the nature and scope of the breach, including the types of personal data involved and the potential impact on affected individuals.

12.2. Notification obligations
  • Supervisory authority: If required by law, we will notify the breach to the competent data protection authorities within 72 hours, following the procedures specified by applicable regulations.

  • Data subjects: If a data breach poses a significant risk to your privacy rights and freedoms, we will inform you within 72 hours, providing clear and concise information about the breach, the types of personal data concerned, and the measures you can take to protect yourself.

12.3. Communication channels
  • E-mail notification: We may inform data subjects via e-mail, using the contact information provided to us, if feasible and appropriate. 

12.4 Support and assistance
  • In the event of a data breach, we are committed to providing affected individuals with the support and assistance they need, including guidance on measures they can take to mitigate potential risks associated with the breach. Point of contact: If you have questions or concerns regarding a data breach or if you believe you have been involved, please contact us immediately at support@nextsim.racing.

13. Updates and changes to the policy

We are committed to keeping you informed about how we process your personal data and about any changes to our privacy practices. We may update this privacy policy from time to time to reflect changes in legal requirements, industry standards, or our business operations.

13.1. Notification of changes
  • Notification procedure: In the event of significant changes to our privacy policy that may affect your rights or the way we process your personal data, we will inform you via visible means, such as e-mail, website notifications, or other approved channels. We will also indicate the effective date of the updated policy at the top of the document.

  • Review of changes: We encourage you to review our privacy policy periodically to stay informed about how we collect, use, and protect your personal data. Continued use of our services after any changes to the policy implies acceptance of the updated terms. 

14. Contact Us

If you have any questions or concerns about our privacy policy or any of its updates, please do not hesitate to contact us at support@nextsim.racing. We are at your disposal to answer any requests and to ensure that you have the necessary information to feel secure regarding the processing of your personal data.

Next Sim Racing è un marchio di F85 di Luca Bortolami • Sede Legale: Via Fossolovara 35, 30039 Stra (VE), Italia • P. IVA e numero di iscrizione nel Registro della Camera di Commercio di []: 04720250275 • R.E.A.: AA – 0000000

© 2026 Next Sim Racing All rights reserved

Next Sim Racing è un marchio di F85 di Luca Bortolami • Sede Legale: Via Fossolovara 35, 30039 Stra (VE), Italia • P. IVA e numero di iscrizione nel Registro della Camera di Commercio di []: 04720250275 • R.E.A.: AA – 0000000

© 2026 Next Sim Racing All rights reserved

Create a free website with Framer, the website builder loved by startups, designers and agencies.