Privacy Notice

Last updated: 2026-07-15

1. Controller

The data controller is RUBINO LORENZO, an Italian sole proprietorship trading publicly as MotorsportSoftware.com, with registered office at Via Domenico Zampieri 23, 40033 Casalecchio di Reno (BO), Italy; VAT number 04085421206; REA BO-585008.

For privacy requests, rights requests, or questions: [email protected]

2. Scope of this notice

This notice describes the personal data processing carried out through TimeTool, an app for schedule and event-time management, including:

  • Sign-in with Apple or Google
  • Human verification during sign-in to reduce automated abuse
  • Subscription to shared streams
  • Creation and sync of private events
  • Optional PDF import with AI-assisted extraction
  • Push notifications and Live Activities
  • Website memberships and one-time PDF extraction purchases processed through Stripe

3. Categories of personal data processed

Account and authentication data

  • Username stored in the display name field
  • Email address, when provided by the sign-in provider
  • Phone number, when present in the provider identity
  • Technical account and provider identifiers
  • Role, tier, and account status

Core app data

  • Subscribed streams
  • Shared schedule events
  • Private events
  • Groups, memberships, and operational metadata required for sync

PDF upload and extraction data

  • Uploaded PDF content
  • File metadata and extraction-run metadata
  • Candidate events derived from model output
  • Review and publish/save decisions
  • AI usage metadata, including model, token counts, and cost for some admin flows

Device and runtime data

  • APNs device token
  • Live Activity token
  • Human-verification token and browser/network signals processed by Cloudflare Turnstile during sign-in
  • Local cache, sync state, and local preferences stored on the device

Billing and transaction data

  • Selected product, price, currency, tax, transaction status, renewal period, refunds, and billing history
  • Stripe customer, Checkout Session, subscription, payment, charge, invoice, and event identifiers
  • Billing name, email, address, country, and tax identifier when supplied at checkout
  • Checkout consent, product entitlement, and account-linking metadata

Payment-card details are collected directly by Stripe. TimeTool does not receive or store the full card number or card security code.

4. Purposes and legal bases

Purpose Examples of data Legal basis
Account creation, sign-in, and profile management Username, email, phone if available, account/provider identifiers Performance of a contract or pre-contractual measures
Delivery of the app's main features Streams, shared events, private events, sync flows Performance of a contract
Push notifications and Live Activity updates APNs token, Live Activity token, stream/event identifiers Performance of a contract and technical/operational legitimate interest
Security, access control, abuse prevention, and service reliability Internal identifiers, account state, human-verification tokens, strictly necessary technical logs Legitimate interest
Optional PDF extraction requested by the user PDF content, model output, run metadata Performance of a user-requested service
Paid checkout, subscriptions, entitlements, cancellation, and refunds Stripe and TimeTool account identifiers, selected product, billing and transaction data Performance of a contract or pre-contractual measures
Tax, accounting, fraud prevention, and payment dispute handling Billing address and tax data, transaction records, refund and dispute information Legal obligation and legitimate interest in preventing fraud and defending legal claims

5. How AI PDF extraction works

The PDF import feature is optional. If a user chooses to use it:

  • The PDF is uploaded from the device
  • The file is stored temporarily in service infrastructure to allow processing
  • The content is sent to third-party AI providers to extract events and schedule data
  • The results are reviewed by the user or an admin before saving or publishing

TimeTool does not technically block every non-schedule PDF. If a user uploads documents containing unnecessary personal data, that data may be transmitted to AI providers. Manual event entry remains available as an alternative.

Users should upload timetable or schedule PDFs only and avoid documents containing contact lists, travel details, rooming lists, logistics packs, or other unnecessary personal data.

6. Whether providing data is mandatory

Providing the data needed for account creation, sign-in, event sync, and stream management is necessary to use the related service features.

Using PDF extraction with AI is optional. If a user does not want to use that feature, events can be entered manually.

7. Recipients of personal data

Personal data may be processed by providers that support the technical operation of the service. The main recipients or providers involved are:

  • Cloudflare — APIs, queues, workflows, Turnstile human verification, and temporary PDF storage
  • Supabase — authentication and the application database
  • OpenAI — primary AI inference provider for PDF extraction
  • Anthropic — alternate AI inference provider
  • Stripe — website Checkout, payment processing, subscriptions, tax calculation, fraud prevention, receipts, refunds, and the customer billing portal
  • Apple — Sign in with Apple, push notifications, Live Activities, and App Store billing where used
  • Google — Google sign-in

Stripe acts as a service provider for payment processing and may also process some data as an independent controller for its regulatory, security, and fraud-prevention obligations. See Stripe's Privacy Policy.

8. International transfers

Some processing may involve transfers of personal data outside the European Economic Area. In particular, cloud and payment infrastructure and their subprocessors may operate across multiple regions, and the AI providers used for PDF extraction may involve processing or storage outside the EEA. Providers use the transfer safeguards described in their applicable data-processing and privacy terms.

9. Retention periods

Category Retention rule
Account and profile data For the lifetime of the account; deleted on account deletion except for minimal technical or legal needs
Published shared events Deleted about 24 hours after the event ends
Private cloud events Kept until the user deletes them or deletes the account
Local cache and preferences Kept until local removal, app uninstall, or data clearing
PDFs stored temporarily Deleted after success, failure, or cancellation
APNs tokens Until logout or later invalidation
Live Activity tokens Until the activity ends or is replaced
Billing, invoice, tax, refund, and payment-dispute records Normally 10 years from the relevant accounting record, and longer only where necessary for an unresolved legal claim, tax assessment, or other binding obligation

10. Processing methods

Processing is carried out using electronic systems and organizational measures consistent with the purposes described above, with reasonable technical and organizational safeguards intended to reduce the risk of unauthorized access, loss, or misuse.

11. Data subject rights

Subject to the limits set by the GDPR, data subjects may request:

  • Access to personal data
  • Rectification of inaccurate data
  • Erasure
  • Restriction of processing
  • Objection where applicable
  • Portability where applicable

Requests may be sent to [email protected].

If you believe the processing violates applicable law, you may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

12. Account deletion

TimeTool includes an in-app account deletion flow. Account deletion removes application account data according to the logic currently implemented, subject to what remains necessary to prevent fraudulent technical recreation of a deleted identity, comply with legal obligations, preserve billing and tax records, and retain strictly necessary data until the corresponding technical retention work is complete. Stripe may retain payment data under its own legal obligations and retention rules.

13. Changes to this notice

This notice may be updated if the service, vendors, retention rules, or legal requirements change. The version published on this website is the official version that applies at the time of consultation.