Privacy Policy

Last updated: March 30, 2026

1. Who We Are

RegattaReport is operated by SailSync ("we", "us", "our"). We are the data controller responsible for your personal data. For questions about how we handle your data, contact us at privacy@regattareport.ai.

2. What Data We Collect

We collect the following personal data:

  • Email address — provided when downloading reports, making purchases, creating an account, or watching events
  • Name — optionally provided during account creation
  • Payment information — processed by Stripe; we do not store card numbers
  • Files you upload — race data files submitted for custom report requests
  • Usage data — pages visited, reports downloaded, events watched

3. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Contract performance — to deliver reports you purchase or request, and to manage your account
  • Legitimate interest — to send transactional emails (purchase confirmations, report delivery), to improve our service, and to prevent fraud
  • Consent — to send notification emails when you watch an event (you can unsubscribe at any time)

4. How We Use Your Data

  • To deliver free and purchased reports to your email
  • To process payments via Stripe
  • To notify you about events you are watching
  • To produce custom reports you request
  • To manage your account and provide customer support
  • To improve our service and understand usage patterns

5. Third-Party Services

We share your data with the following third-party services, each of which has their own privacy policy:

  • SailSync.ai (Sail Sync, LLC) — AI-powered report generation and race data analysis (race data, event information)
  • Stripe — payment processing (email, payment details)
  • SendGrid — email delivery (email address, email content)
  • Amazon Web Services (AWS) — infrastructure, file storage, hosting (all data)
  • Vercel — website hosting (usage data, IP addresses)

Some of these services are based in the United States. Where data is transferred outside the European Economic Area (EEA), we rely on Standard Contractual Clauses and adequacy decisions as appropriate.

6. Cookies and Local Storage

We use the following technologies to store data in your browser:

  • Authentication token (localStorage) — keeps you signed in
  • Email address (localStorage) — pre-fills forms for convenience
  • Theme preference (localStorage) — remembers light/dark mode choice
  • Cookie consent (localStorage) — remembers your consent decision

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. All stored data is essential for the Service to function.

7. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — request that we limit how we use your data
  • Portability — request your data in a machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — withdraw consent for notification emails at any time via the unsubscribe link

To exercise any of these rights, contact us at privacy@regattareport.ai. We will respond within 30 days.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Purchase records are retained for accounting and tax purposes. You may request deletion of your account and associated data at any time.

9. Data Security

We protect your data using encryption in transit (TLS/SSL), encrypted credentials storage, and access controls. Payment data is processed by Stripe and never stored on our servers. File uploads are stored in encrypted AWS S3 buckets with time-limited access URLs.

10. AI Processing

Our reports are generated using SailSync.ai (Sail Sync, LLC), which uses artificial intelligence technology to analyze race data. Race data that you provide or that is publicly available may be processed by SailSync.ai's AI systems to produce analysis. This processing is carried out under the legal basis of contract performance (to deliver the report you requested). Reports may contain inaccuracies due to the nature of AI processing and imperfect data sources.

11. Children

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "last updated" date at the top indicates the most recent revision.

13. Contact & Complaints

For privacy inquiries: privacy@regattareport.ai

If you are in the EU and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local Data Protection Authority.