The California Motorsports Company

Trackside

Privacy Policy

Last updated September 4, 2026

This Privacy Policy describes how Trackside handles information when you use the iOS app or visit this website. In this policy, "we," "us," and "our" refer to the developer of Trackside. Trackside connects to compatible Porsche vehicles, displays telemetry, records track sessions, and can control supported action cameras.

Trackside is designed to be local-first. It does not include advertising and does not track you across other companies' apps or websites. Detailed telemetry, GPS routes, photos, and videos generally remain on your devices or in storage you control, except when you explicitly request a feature requiring server processing. If you choose to use Friends, Trackside sends account information, friend connections, and limited lap and session summaries to our service so you and accepted friends can compare track days. When you explicitly share a lap or session with selected friends, Trackside also uploads the detailed telemetry and GPS data needed for them to replay and compare it. The app sends limited product-usage events to PostHog so we can understand which features are useful and improve reliability. Optional Porsche sign-in and iCloud sync use services provided by Porsche and Apple as described below.

1. Information We Handle

Vehicle connection and Porsche sign-in

Trackside uses your local network to connect directly to the telemetry gateway on a compatible vehicle's PCM Wi-Fi. When you save a car, the app may store its name, icon, vehicle profile and calibration settings, PCM Wi-Fi network name and password, gateway address and port, certificate information, connection type, and last-used date. The app also creates a device identifier used for the vehicle connection. This connection information is stored in the iOS Keychain on your device.

If you choose to sign in with your Porsche account, the sign-in page is provided by Porsche. Trackside does not receive or store the password you enter on that page. After sign-in, Porsche provides authorization and refresh tokens that Trackside uses to request the application gateway tokens needed to authorize a compatible PCM connection. These tokens are stored in the iOS Keychain and are exchanged directly with Porsche services and your vehicle. Porsche handles account and sign-in information under its own privacy practices.

Telemetry, sessions, and location

While connected, Trackside processes telemetry made available by your vehicle, which may include speed, engine and transmission data, braking, steering, acceleration, vehicle location, lap timing, and other driving or vehicle signals. If you record a session, the app saves the available telemetry, timestamps, vehicle and app metadata, track details, and calculated lap or driving metrics in files on your device.

With your permission, Trackside uses precise location to identify the current PCM Wi-Fi network and to record your phone's GPS route during a telemetry session, including while the app continues an active recording in the background. Recorded location information may include latitude, longitude, altitude, speed, course, accuracy, timestamps, and a session start location. Location and telemetry files can be exported by you in formats such as JSONL, CSV, and GPX.

AI coaching

AI coaching is optional and runs only when you request it. Trackside sends our service a bounded subset of the selected session, which may include track and lap information, precise latitude and longitude, altitude, heading, GPS accuracy, speed, engine RPM, gear, throttle, braking, steering, acceleration, and related vehicle signals. Our service forwards this information to OpenAI to generate the requested coaching report. Submitted telemetry and generated reports are not intentionally stored in Trackside's account database, although we retain limited generation metadata for service operation and allowance enforcement.

OpenAI requests are made with application-state storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days and does not train its models on API data by default unless the customer opts in. See OpenAI's API data controls.

Camera, Bluetooth, and videos

With your permission, Trackside uses the iPhone or iPad camera to scan a vehicle connection QR code. The QR code may contain the PCM Wi-Fi network name, password, certificate information, and related connection details. Scanning is processed on your device; the app does not save or upload the camera image.

Trackside uses Bluetooth to discover, connect to, and control supported GoPro and DJI cameras. The app processes information such as camera name, model, brand, Bluetooth identifier assigned by iOS, advertised services, signal strength, connection state, recording state, capabilities, and command responses. If you remember a camera, related connection details are stored locally on your device.

If you choose a video from Photos or Files, Trackside accesses that selected video to link it to a recorded session, inspect its timing and technical metadata, play it with telemetry, and create exports you request. The app stores a local Photos identifier or file bookmark and related video metadata. It does not upload selected videos to us. The original video remains in Photos or at the file location you selected, and exported videos are shared or saved only at your direction.

If you provide a supported video URL, our service temporarily retrieves and processes that remote file to deliver it to your device. This does not upload videos selected from Photos or Files, and temporary server files are deleted after the request.

iCloud sync

If iCloud sync is enabled, Trackside syncs saved vehicle connection details through iCloud Keychain and copies recorded session data and related metadata files to the app's private iCloud Drive container. This allows saved cars and sessions to be restored on your devices. Porsche authorization tokens are not included in this sync, so Porsche may require you to sign in separately on a new device. Linked or exported video files are not included. Apple operates iCloud and processes this information under your Apple Account and Apple's privacy practices. We do not operate or access your iCloud Keychain or private iCloud Drive container.

Friends and Sign in with Apple

Friends is optional. If you enable it, Trackside uses Sign in with Apple to create an account with an Apple-provided account identifier and, when Apple supplies it, your name. We assign an internal profile identifier and handle, issue a limited-duration Trackside session token, and store your friend connections and private reusable invite code. We do not request your Apple email address.

While you are signed in to Friends, Trackside sends qualifying recorded and imported session summaries to our service. These summaries can include a local session identifier used to prevent duplicates, canonical track and layout, recording date and track-local day, an optional vehicle display name, completed lap count, lap indexes, and lap durations. Your profile and these summaries are available to you and your accepted friends, not through a public people directory or global leaderboard.

Full lap and session sharing is optional and occurs only when you choose specific friends and save that choice. For each lap you share, Trackside uploads a replay archive to our service. A shared session consists of separate archives for its analyzed laps. An archive may include detailed and full-resolution vehicle telemetry, phone and vehicle GPS traces, precise latitude and longitude, altitude, speed, course or heading, GPS accuracy, timestamps, engine and transmission data, gear, throttle, braking, steering, acceleration, chassis and driving- technique events, track and lap information, an optional vehicle display name, and calculated statistics and analysis. Our service stores the archive and its sharing metadata so only the friends you select can download, replay, and compare it in Trackside. Shared archives do not include photos, videos, or evidence files.

Our service validates the Apple identity token and short-lived authorization code, stores Apple's refresh token in encrypted form, and stores only a cryptographic hash of the Trackside session token used by the app. We use the Apple refresh token to verify the account's authorization and revoke it when the Trackside account is deleted.

Settings, diagnostics, and support

Trackside stores app settings and operational state on your device, such as unit choices, recording preferences, remembered cameras, sync settings, and recent connection status. The app may produce system and operational logs on your device for debugging, but it does not include a service that sends those logs to us automatically. If you contact us, we receive your email address, message, and any logs, files, or technical details you choose to provide.

Product analytics

Trackside sends limited product-interaction events to PostHog, our analytics provider. These events indicate actions such as opening the app, enabling Demo Mode or iCloud sync, setting up or attempting to connect a car, starting or saving a recording, opening a replay, linking a video, or completing a video-overlay export. Event properties are limited to general categories and outcomes, such as connection method, success or failure, demo or vehicle source, whether a track was recognized, whether a video was linked, and export resolution.

Before you sign into Friends, analytics events use a randomly generated installation identifier. While you are signed in, Trackside may associate analytics events with your internal Trackside profile identifier, and PostHog may create a person profile so account activity can be analyzed together. We do not send PostHog your name, email address, Porsche account details, telemetry, GPS routes, track names, photos, videos, or vehicle identifiers.

Website technical information

We do not set advertising or analytics cookies on this privacy page. The hosting and DNS providers for this website may process standard technical information, such as IP address, browser user agent, requested URL, and request time, to deliver and secure the site.

2. How We Use Information

We use information to:

  • sign you in with Porsche when you request it and authorize compatible vehicle connections;
  • save and reconnect to vehicles over their PCM Wi-Fi networks;
  • display, record, analyze, replay, sync, and export telemetry and track sessions;
  • discover, remember, connect to, and control supported action cameras;
  • link selected videos to sessions and create telemetry video exports you request;
  • create and secure your optional Friends account;
  • connect you with people whose private invite links you accept;
  • sync limited lap and session summaries and show them to you and your accepted friends;
  • store and deliver detailed lap and session telemetry you explicitly share with selected friends;
  • remember your settings and keep active recordings operating as expected;
  • measure feature use and general success or failure outcomes to improve the app;
  • respond to support requests and troubleshoot issues you report;
  • maintain and secure the app and website; and
  • comply with legal obligations.

3. Service Providers and Sharing

We do not sell your personal information. We do not use your information for targeted advertising or cross-app tracking. Information is processed or shared only as needed to provide features you request, follow your direction, comply with law, or protect rights, safety, and security.

  • Porsche, for optional account authentication, authorization tokens, and services used to enable a compatible PCM connection;
  • Apple, for iOS, Keychain, location, Maps, Photos, Files, iCloud Drive, App Store or TestFlight distribution, and related system services;
  • your vehicle and cameras, through direct local-network or Bluetooth connections needed to provide telemetry and camera controls;
  • PostHog, for limited installation-based and account-linked analytics;
  • Cloudflare, for hosting and securing the backend, Friends, AI-coaching gateway, stored shared-lap and shared-session archives, and temporary reference-video URL processing;
  • OpenAI, for generating AI coaching from the telemetry context you submit;
  • your accepted Trackside friends, who can see your profile, shared track days, optional vehicle display name, and lap statistics, and who can access the detailed telemetry and GPS data for laps and sessions you specifically share with them;
  • website, DNS, and email providers, for delivering this website and messages you choose to send us; and
  • recipients you choose, when you export or share session data, location files, videos, or other content.

We may also disclose information if required by law or reasonably necessary to protect rights, safety, or security, or as part of a merger, financing, acquisition, or sale of assets subject to appropriate safeguards.

4. Retention and Deletion

Recorded sessions, linked-video references, remembered cameras, settings, and related files remain on your device until you remove them, clear the relevant app data, or delete the app. You can delete individual sessions and saved cars in Trackside and can sign out of Porsche to remove saved authorization tokens. Keychain items and system-managed data may follow Apple's retention behavior and may not always be removed by uninstalling the app alone.

When iCloud session sync is enabled, deleting a session in Trackside records that deletion for sync and removes the app's active iCloud copy when synchronization completes. Limited copies may remain temporarily in iCloud backups or other system-managed storage. Videos linked from Photos or Files remain at their original locations, and exports remain wherever you save or share them, unless you delete them separately.

Friends account information, friendships, invite information, and published lap and session summaries remain in our service while your account exists. Deleting a local session removes its published summary during a later Friends synchronization.

Detailed lap and session archives remain in our service while you continue sharing them and your account is eligible for the sharing feature. You can stop sharing a lap or session with one or more friends using Trackside's sharing controls. A recipient can remove a shared lap or session from their account. Removing a friendship removes each person's access to the other's shared statistics and archives. When an archive has no remaining recipients, when the owner's Friends account is deleted, or when the owner's sharing eligibility ends, the stored archive is deleted. Deleting the original session from your device does not by itself delete an archive you previously shared; use the sharing controls before or after deleting the local session to stop sharing it.

You can delete your Friends account in Trackside; this removes its profile, friendships, invite information, published summaries, lap results, active Trackside sessions, and shared lap and session archives from our service and asks Apple to revoke the associated Sign in with Apple authorization. Limited backup, security, and operational records may remain temporarily as permitted by law and our service providers' standard retention practices.

Support emails and related technical details are kept for as long as reasonably needed to respond, maintain support records, improve the app, and meet legal obligations.

Analytics associated with an installation or Trackside profile are retained only as long as reasonably needed to understand product usage, improve Trackside, and maintain business records, subject to our PostHog retention settings. Aggregated or de-identified information may be retained longer.

5. Security

We use reasonable technical and organizational measures to protect information we handle. Trackside stores Porsche authorization tokens, saved vehicle connection details, and its Friends session token in the iOS Keychain, and most app information remains on your device or in your private iCloud container. The Friends service requires authenticated HTTPS requests, limits profiles and shared statistics to the account owner and accepted friends, limits detailed lap and session archives to the friends specifically selected as recipients, stores only hashed Trackside session tokens, and encrypts Apple's refresh token before database storage. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.

6. Children's Privacy

Trackside is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate action.

7. Your Choices and Rights

You can choose whether to sign in with Porsche or Apple, use Friends, share a lap or session with selected friends, save a vehicle, enable iCloud sync, remember a camera, record a session, link a video, export information, or contact us. Within Trackside, you can stop sharing laps or sessions, remove shared laps or sessions you received, remove friends, sign out of Friends, or delete your Friends account. You can manage camera, Bluetooth, local- network, location, Photos, and iCloud access through Trackside and iOS Settings. Turning off a permission may limit the features that depend on it.

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection related to personal information we hold about you. Most detailed app data is controlled directly by you on your device, in your Apple Account, or through Porsche. We operate the Friends account, lap-summary, and shared lap and session archive services described above. To make a request concerning information we hold, including Friends data or analytics associated with an installation or Trackside profile, contact us using the address below. Deleting Trackside stops future analytics events from that installation but does not itself delete a Friends account or previously shared archives; use the in-app sharing and account deletion controls before removing the app.

Some browsers offer "Do Not Track" signals. Because there is no common standard for those signals, this website does not respond to them. We do not set tracking cookies.

8. Changes to This Policy

We may update this Privacy Policy as Trackside, its service providers, or legal requirements change. We will update the date above and provide any additional notice required by law.

9. Contact

For privacy questions or requests, email trackside@californiamotorsports.co.