privacy.txt

Useful stats without an analytics identity.

GitRacer does not set analytics cookies, does not use session replay, and does not build person profiles. We use cookieless PostHog only after its privacy-safe server hash mode is enabled.

Your theme choice is stored locally in your browser. It is a functional preference, not an advertising or analytics identifier.

Public GitHub data

When someone opens a race URL, we store the public GitHub handle, display name, profile URL, avatar source, contribution years, and public daily contribution totals. Race URLs and their handles are public by design. Avatars are cached in our own object storage.

Traffic analytics

PostHog records page views, page exits, web-vital performance, race creation, period changes, refreshes, shares, and sponsor impressions or clicks. Autocapture, recordings, heatmaps, form capture, cross-site advertising, and identified person profiles are disabled.

Requests go through gitracer.io/ph to PostHog’s EU region. Cookieless mode uses a rotating server-side hash to estimate anonymous visitors without writing an identifier to cookies, local storage, or session storage. This is strong for aggregate daily visitors and time-on-page, but intentionally weaker for cross-day retention and long user journeys.

Abuse protection

To protect the GitHub quota, the connecting IP is combined with a secret and hourly bucket, then hashed. Only that short-lived hash and a counter are stored; the raw IP is not stored in GitRacer’s database. Expired buckets are deleted opportunistically.

Your browser signals

If your browser sends Do Not Track or Global Privacy Control, the analytics script does not initialize. Core race functionality remains available.

Legal note

This page describes the implemented technical behavior, not legal advice. Before selling sponsorships, the operator should add business identity and contact details and review the final policy for the countries being served.