Privacy Policy
Our legal commitments regarding personal data collection, processing transparency, AI safety pre-screening, and statutory retention schedules under the Digital Personal Data Protection Act (DPDPA 2023) and Information Technology Act (2000).
Scope & Legal Identity
This Privacy Policy governs the collection, processing, storage, and protection of information by Race to One (owned, operated, and managed by RaceToOne Digital, a sole proprietorship represented by its proprietor M Meenakshi, operating online via racetoone.com and associated mirrors, collectively referred to as “Race to One”, “the Platform”, “we”, “us”, or “our”).
Race to One is a digital promotional billboard and creator discovery showcase that helps indie developers, creators, startups, and web projects reach wider audiences through competitive promotional placement. We operate in strict conformity with India’s Digital Personal Data Protection Act, 2023 (“DPDPA”), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
Information We Collect & Radical Data Minimization
We practice radical data minimization. We only collect the minimal technical and promotional data strictly necessary to fulfill your advertising request, secure the platform, and maintain statutory audit trails:
A. Public Promotional Data
Information explicitly submitted by you for public display across the billboard, top standings bar, and live stream:
- Brand or Display Name (max 40 chars)
- Promotional Tagline (max 100 chars)
- Target Destination URL (HTTPS mandatory)
- Selected Content Category Badge
- Optional public social handles (e.g., X, YouTube)
B. Technical & Audit Telemetry
Information generated automatically when interacting with our servers for cybersecurity, DDoS mitigation, and rate limiting:
- Internet Protocol (IP) address
- Browser type, user-agent, and screen resolution
- Timestamp of submission or request
- Referral URL and click-redirect metrics
Zero Sensitive Financial Data Stored by Race to One
We never view, handle, or store full credit or debit card numbers, CVV codes, net banking passwords, or UPI PINs on our servers. All transactions are securely routed directly through RBI-licensed, PCI-DSS Level 1 compliant payment gateways. We only retain anonymized order reference tokens, transaction IDs, gross amounts, and currency identifiers for tax accounting.
Lawful Grounds for Data Processing
In accordance with Section 4 and Section 6 of the Digital Personal Data Protection Act, 2023, we process personal and operational data only under recognized lawful bases:
- •Contractual Fulfillment: To display, render, rank, and maintain your brand showcase and outbound backlink in real time upon successful payment.
- •Statutory Legal Obligations: To generate digital receipts, comply with goods and services tax (GST) mandates, audit standards, and directives issued by law enforcement or regulatory authorities.
- •Legitimate Use & Cybersecurity: To prevent fraud, mitigate automated bot abuse, enforce rate limits, and preserve platform integrity under CERT-In guidelines.
- •Specific Informed Consent: Manifested when you submit your public brand information, confirm our Terms of Service, and initiate promotional participation.
Automated Safety Pre-Screening & AI Moderation
To protect visitors and maintain advertising ecosystem integrity, all candidate URLs undergo automated pre-screening via Google Gemini Flash AI and safety threat intelligence feeds prior to billboard activation.
The automated scanner parses destination domain metadata to immediately detect and reject prohibited content categories, including real-money gambling, adult pornography, deceptive financial/Ponzi schemes, malicious phishing portals, and hate speech. No personally identifiable creator metadata is used to train third-party machine learning models.
Outbound Redirect Sanitization Telemetry (/go?url=...)
All external website links placed on Race to One are routed through our internal sanitization and telemetry gateway: /go?url=[destination].
This gateway performs real-time URL validation to block destination tampering, phishing redirects, and malicious payloads. We log non-personally identifiable click aggregates (counter tallies, anonymous referrer categories) to verify billboard reach for participating brands.
External Destination Notice: Once you leave Race to One via an outbound link, third-party sites are governed entirely by their own privacy policies and terms. We encourage visitors to review their respective privacy practices.
Public Billboard Records & Hall of Fame Permanence
Race to One is inherently a public promotional chronicle. By submitting a brand entry, you acknowledge and agree that:
- •Your brand name, tagline, category, achieved standing, and tenure duration become part of the publicly visible Season Stream.
- •Participants finishing in the Top 3 upon completion of a 100-day season cycle are permanently etched into the Hall of Fame as an immutable historical record of that season’s challenge.
- •Even after a brand is overtaken from the #1 spot, its public backlink value and campaign listing remain active in the scrollable Season Stream.
Statutory Data Retention Schedules
We retain data only as long as necessary to accomplish the operational and legal purposes specified herein:
| Data Classification | Retention Window | Statutory Justification / Authority |
|---|---|---|
| Payment & Invoicing Records | 7 Years | Section 44AA of Income Tax Act, 1961 & CGST Act, 2017 |
| Server & Cybersecurity Logs | 180 Days | CERT-In Directives No. 20(3)/2022-CERT-In |
| Customer Support & Queries | 24 Months | Dispute resolution and consumer service audit trail |
| Public Season Stream & Hall of Fame | Permanent Archive | Public sports/promotional challenge historical record |
Third-Party Sub-Processors & Data Sharing
We do not sell, rent, monetize, or broker personal data to advertisers, brokers, or marketing syndicates. We share necessary data only with trusted infrastructure sub-processors bound by strict confidentiality and data protection agreements:
- •Payment Gateways (e.g. Razorpay / Stripe): Secure transaction settlement, UPI intent, and compliance verification.
- •Cloud & Database Hosting (Google Cloud / Firebase): Encrypted multi-region hosting, real-time leaderboard data sync, and database persistence.
- •AI Safety Inference (Google Gemini API): Automated scanning of candidate landing pages against prohibited advertising taxonomies.
- •Legal & Statutory Authorities: Only when strictly mandated by a valid court order, warrant, or formal government regulatory subpoena.
Cookies & Client Storage
Race to One does not deploy invasive cross-site advertising cookies, behavioral tracking pixels, or fingerprinting scripts. We utilize only strictly necessary browser session/local storage to preserve essential functional state (e.g., active season filters, client-side UI preferences, and local submission modal draft states).
Your Rights Under DPDPA 2023
As a Data Principal under India’s Digital Personal Data Protection Act, you are entitled to exercise the following statutory rights:
1. Right to Access & Summary
Request a structured summary of personal data processed about you and the identities of processors shared with.
2. Right to Correction & Update
Request correction of inaccurate display tags, broken destination URLs, or outdated brand handles with proof of transaction.
3. Right to Grievance Redressal
Access an expedited grievance resolution process directly managed by our designated Grievance Officer.
4. Right to Nominate
Nominate an individual to exercise data principal rights in the event of incapacity or demise under Section 14.
Age Restriction (18+ Solely)
Race to One is a commercial advertising platform and is not directed at minors under the age of 18. Only persons competent to contract under the Indian Contract Act, 1872, may submit promotional billboard entries and execute payment transactions. If we determine that a minor has submitted unauthorized data, we will promptly delist the entry upon verified notice.
Grievance Redressal & Statutory Officer
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the provisions of DPDPA 2023, you may address all inquiries, data access requests, or privacy grievances to our designated officer:
Grievance Officer: M Meenakshi
RaceToOne Digital • Data Protection & Statutory Compliance Desk
Direct Escalation Email: contact@racetoone.com
Statutory Acknowledgement Timeline: Within 48 Hours
Statutory Grievance Resolution Timeline: Within 15 to 30 Business Days
When contacting the Grievance Desk regarding an active campaign, please provide your brand name, destination URL, approximate transaction timestamp, and payment receipt identifier for expedited verification.
Modifications & Historical Revisions
We reserve the right to revise this Privacy Policy periodically to reflect enhancements in data protection jurisprudence, statutory regulatory advisories, or platform functionality. Any modifications will be published directly on this page with an updated “Last Revised” timestamp. Continued participation on the Platform after an update constitutes your acknowledgment of the amended policy.