Vibetronics LLC / Vibe Stints
Privacy Policy
Effective October 2, 2026 · Version 1.2
How team records, telemetry, shared access and the Windows Companion handle information.
1. Who handles your data
Vibe Stints is provided by Vibetronics LLC, a Georgia limited liability company and subsidiary of Vibewright Labs LLC. Contact our shared support team at hello@vibewrightlabs.com, identifying Vibe Stints, or write to Vibetronics LLC, 1870 The Exchange SE, Ste 220 #580353, Atlanta, GA 30339, USA.
This notice covers the website, team API and Windows Companion. Vibetronics determines how information is processed to provide the service. Team members also decide which driver information to upload and whether to share it; we do not assume that holding a team link gives a person every driver's permission. Vibewright Labs staff may handle support and operations for us.
2. Information and purposes
We process team names and access tokens; roster names and last-seen timestamps; driver names, car, track, session dates, lap order/type/times, pace summaries, fuel and conditions where available; team notes; and upload filenames, sizes and timestamps. Drivers may provide these themselves or teammates may supply them. The original telemetry file can contain information beyond the fields we extract, including setup details. We use this information to maintain team logs, comparisons, uploads, notes and the optional pool.
Files selected in the browser are parsed on your device before you choose Save. Saving transmits parsed records and attempts to attach the original file. The Companion uploads automatically after configuration. Support correspondence includes your contact information and what you send; we use it to answer requests, investigate issues and document their resolution.
Servers and delivery providers process connection information such as IP address, request URL, user agent and time for delivery, security and troubleshooting. The API uses temporary in-memory IP counts for rate limits. Because team credentials appear in URLs, treat links and diagnostic logs as confidential. We do not require an email account or payment details for the beta.
4. Companion and browser storage
The Companion watches the telemetry folder you select, detects newly finished .ibt files, parses them locally and uploads their records and original files to the configured team. Existing files are marked as seen on its first scan. It reads iRacing shared memory locally for live timing, fetches your team's benchmark records and sends your saved quick notes with a stint. The live overlay itself is not a continuous telemetry upload.
The app saves its team link, driver override, folder path, pause/overlay preferences and upload history locally in %APPDATA%\VibeStints by default. The history records filenames, sizes and upload status/IDs. Local diagnostic output can include paths, driver/session information and errors. The app checks for updates at startup and about every four hours and downloads available updates; update requests expose ordinary connection information to our delivery infrastructure.
Pause uploads prevents new scans but an in-progress upload may finish. Hiding the overlay leaves uploads running. Quit the Companion to stop its processing and update checks. Uninstalling does not remove server records or guarantee removal of its local configuration/history. After quitting/uninstalling, you can remove the app's local data folder yourself; keep your original telemetry folder unless you independently choose to remove it. Clearing upload history can change which files are recognized as already seen.
The website stores theme, units, preferred driver name and team filter choices in your browser's local storage. Clear this site's browser storage to reset them. The Companion's Team window shows your team page from vibestints.com and keeps that page's theme, units, roster-name and filter choices, with ordinary browser data such as cached site files, in %APPDATA%\VibeStints\team-window. These features do not use advertising cookies or session replay. The Companion does not contain an advertising analytics or remote crash-reporting SDK.
5. Retention, providers and backups
Raw files: new downloads are refused seven days after upload completion, even if the disk file has not yet been removed. A download started before expiry may finish. Automatic disk cleanup runs at startup and every six hours; normally physical removal follows within that interval, but outages or storage failures can delay it. Expired files are not made downloadable because cleanup is delayed. Abandoned multipart uploads are eligible for cleanup after 24 hours.
Saved records: teams, stints, laps, notes and roster entries have no automatic age-based expiry in the beta. They remain while the team uses the service unless removed or retention is otherwise necessary for a request, dispute, security or legal obligation. Deleting a stint removes its active laps, note and attached raw file; its roster name is separate. We do not promise perpetual hosting. Keep independent copies of records you need.
Infrastructure: DigitalOcean hosts the origin, managed PostgreSQL database and provider backups; bunny.net delivers the website and downloads globally. Database backup operations use Backblaze B2 and restricted operational copies. Google Fonts receives connection data when existing site pages request its fonts. Shared support uses our business email infrastructure, including Proton; correspondence and request records are accessible to staff handling support. Providers process information to deliver these functions. Legal disclosures or a business transfer may also require disclosure, with applicable protections.
Backup copies: deletion from the active service does not instantly edit historical database/provider backups, disaster-recovery copies or legacy migration copies. These are restricted to recovery, security and legal needs and are handled separately from live access. There is no single guaranteed final-erasure date covering every backup destination. For a removal request we will explain the applicable backup limitations, record the change for recovery handling, and address remaining copies through the provider's retention process or a verified administrative process. Raw-file download expiry does not establish backup retention.
Support records are kept while needed to resolve the matter and establish what action was taken, or for a legal/security reason. Operational log retention depends on the hosting/delivery provider and relevant investigation needs; request information about a specific record using the contact below.
Optional public website analytics
Optional PostHog analytics is off until you choose Allow analytics. If allowed, we count public page visits and declared signup or enquiry actions, including successful form responses. We send a public page path, a broad traffic-source category, event time, and random identifiers that last only for the current page. We do not send form contents, email addresses, private links, raw campaign tags, recordings or advertising identifiers. We use PostHog's US service with IP storage and location enrichment disabled; ordinary network requests still reach its infrastructure.
The Analytics choices button lets you withdraw permission at any time. We save only your allow/off choice in this site's local storage until you clear or change it. Global Privacy Control and Do Not Track keep this optional analytics off. Withdrawal stops future measurement and clears the in-memory identifiers; it cannot retract events already received. These choices do not stop essential hosting, security or a submission you request. Analytics events are retained according to our PostHog project retention setting and reviewed for continued usefulness; the identifiers are not reused across page loads or connected to your account.
PostHog processes these optional measurements for us; see PostHog's privacy notice. Permission to analytics is separate from requesting email updates or a service.
This measurement is limited to public pages, team-creation success and Companion download clicks. It is not installed in the private team dashboard or the Companion, and receives no team credential, driver or telemetry data.
6. Your choices and requests
Email hello@vibewrightlabs.com with “Vibe Stints privacy request,” the driver/team name, relevant stint IDs or dates, and the change you want: access/copy, correction, deletion, roster removal, sharing objection or a team/link issue. Do not send the full invite link, raw telemetry, identity documents or another person's data in your initial message. We will request only information reasonably needed to locate the records and verify your identity or authority through an appropriate channel.
There is no self-service whole-team deletion, roster deletion or link rotation in the current app. A team link alone does not prove exclusive ownership of a team. We review requests affecting others before changing or disclosing their records, and can discuss individual-driver removal separately. Existing stint deletion and turning off the team's sharing setting remain available to link holders. Pause Companion uploads before removing records to avoid new uploads.
We respond without undue delay and within applicable legal time limits. We will explain any verification needed, limitations, denial or additional time, and how to challenge a decision. Depending on applicable law, you may have rights of access, correction, deletion, portability, restriction or objection, withdrawal of consent where used, and complaint to a supervisory authority. You can use this request route regardless of location; we will not penalize you for exercising an applicable right.
7. Legal bases, location and safety
Our core hosting is in the United States and delivery operates globally. Where data-protection law requires a legal basis, processing requested team/software functions is based on providing the service or our legitimate interests in enabling authorized team collaboration; security, maintenance and support rely on those operational interests or legal obligations. Optional sharing must have an appropriate basis for each affected person; team permission does not override an individual's rights. Where consent is required, it must be obtained and can be withdrawn. Contact us for the safeguards applicable to a particular international transfer; we do not treat use of the site as a waiver of transfer protections.
The service is not directed to children under 13. Do not submit their personal information. Contact us if such information was provided so we can investigate and address it. We use HTTPS, access restrictions and protected infrastructure; no service can guarantee perfect security. Report an exposed link privately through support.
The beta does not use browser Do Not Track or Global Privacy Control to change essential team features or saved display preferences. We do not use cross-site advertising tracking. A browser signal does not change a whole team's sharing setting; turn off the team's sharing setting or contact us about your records.
8. Notice changes
We post changes with a new date and highlight material changes on the site or Companion as appropriate. Before using information for a materially new purpose, we will provide the required notice and request consent where needed. This notice describes our service; it does not limit rights under applicable law.