What we collect, what it's for, who we share it with and how to control it.
This policy explains what data assettocorsaevo.es collects, what it's used for, who it's shared with and how to exercise your rights. Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 apply.
The owner of assettocorsaevo.es. For anything to do with your data, including exercising your rights, write to contacto@assettocorsaevo.es.
| When | What | Why | Legal basis |
|---|---|---|---|
| Creating an account | Email, username, hashed password | To identify you and give you access | Performance of a contract |
| Subscribing or buying | Name, email, country, billing details, payment history | To charge, invoice and meet tax obligations | Contract and legal obligation |
| Posting a listing | Listing content, image and links you upload | To publish it in the directory | Performance of a contract |
| Entering an event | Your username on the public entry list | To organise the grid | Performance of a contract |
| Browsing | IP address, browser, pages viewed | Security and aggregate statistics | Legitimate interest |
| Advertising | Third-party cookie identifiers | To display ads | Your consent |
We never collect card details. You enter them directly into Stripe's payment page and this site never sees or stores them.
Only the providers needed to run the service, all bound by data processing agreements:
We don't sell or hand over your data to third parties for commercial purposes. Some of these providers may process data outside the European Economic Area, relying on the standard contractual clauses approved by the European Commission.
You can exercise your rights of access, rectification, erasure, objection, restriction and portability at any time, and withdraw any consent you've given. Just write to contacto@assettocorsaevo.es from the email address on your account. We reply within 30 days at the latest.
If you believe your data hasn't been handled properly, you can complain to the Spanish Data Protection Agency (aepd.es).
You must be 14 or over to create an account. If we find an account belonging to someone younger without consent from a parent or guardian, we delete it.
Passwords are stored hashed, never in plain text. Database access is restricted by row-level policies, so each user can only read and change their own data. All traffic to the site is encrypted over HTTPS.
If this policy changes materially, we announce it on the site and, where it affects data already collected, by email.
Last updated: 9 August 2026