What we collect
If you join the briefing or save a Race Trip Monitor, we may collect your email address and submission time. For abuse prevention, we keep short-lived rate-limit counters keyed by a one-way token derived from the reverse proxy's client identifier; that token is not stored in the monitor or trip-request record.
For a Race Trip Monitor, we also store the selected race, target budget, number of travelers and nights, trip style, planning estimate, and current booking signal. We use these fields to operate the requested monitoring baseline and improve the trip monitor.
For a tailored trip request, we additionally store your name, departure city or airport, trip type, main travel priority, planning timeline, explicit partner-consent choice, consent wording locale and version, the exact wording shown and its integrity hash, the consent timestamp, and a one-way idempotency-key hash used to make an uncertain retry safe. Each submission is stored separately from a basic race monitor and remains unverified until we confirm ownership of the supplied email address. The current collection-only pilot does not automatically send a verification email, contact you, or transfer the request to a partner.
While a tailored request is being sent, the browser may keep a random retry token and a one-way fingerprint in sessionStorage. The fingerprint is derived from the submitted form but the form fields themselves are not written there. This tab-scoped retry state is removed after the site confirms receipt.
We also keep minimal first-party product analytics: an event name, page path, selected guide or race, optional editorial story identifier and placement, optional package style, optional outbound-link category, a predefined provider identifier and affiliate placement for explicit commercial links, optional predefined campaign identifier from the landing URL, and timestamp. To keep a predefined campaign attached while you move from the homepage to a race guide, that identifier may be carried in internal links. Arbitrary provider, placement, or campaign text and full URL query strings are discarded. These records do not include email addresses, raw IP addresses, persistent visitor identifiers, or advertising profiles. We do not use cookies or browser storage for first-party campaign attribution. A one-way technical identifier may be retained separately for rate limiting and is never stored with analytics events.
How we use data
- To send the race travel briefing, operate requested Race Trip Monitor updates, review a tailored trip request, or respond to a request.
- We do not share an unverified request. After email ownership is confirmed, we may share a tailored trip request with a suitable licensed travel partner only if you explicitly selected the separate partner-sharing consent. A basic race monitor is never shared for this purpose.
- To prevent spam, abuse, and duplicate submissions.
- To understand which race planning topics visitors care about.
- To improve guides, comparison pages, and planning tools.
What we do not do
- We do not sell personal data or travel packages, and we do not take payment for a tailored trip request.
- We do not claim official Formula 1, FIA, promoter, team, or ticket-provider affiliation.
- We do not ask for payment details or passport/visa documents in the current MVP.
Third-party services
The site uses hosting, infrastructure, analytics, email delivery, form handling, and affiliate partners. When you choose an explicit outbound link, outbound providers receive standard technical request data such as your IP address, browser information, referring page, and the destination URL parameters needed to serve and attribute that click.
Current explicit affiliate links may send you to Gootickets for race tickets; to TicketOne through Awin for the official Monza sales channel; to Expedia for stays; to Aviasales for flight comparison; and through Travelpayouts tracking redirects to GetRentacar for car rental.
Grand Prix Weekender does not load an automatic link-monetization script or allow a third party to scan and rewrite page links. If we add a major service that materially changes data handling, this policy will be updated.
Retention and deletion
Newsletter, price-alert, and inquiry records are kept only as long as useful for the product or required for security and operations. Trip-request records are immutable during normal application processing, but an authorized privacy-deletion procedure can remove an approved record without enabling ordinary edits. You can request deletion by emailing partners@gpweekender.com.
Contact
Questions or deletion requests: partners@gpweekender.com.