Return to International Motorsport Series

Data and privacy

Privacy Policy

How IMS applications and online services process information, and how you can request access, correction, or deletion.

Effective and last updated 21 September 2026

Scope and operator

This policy applies to all Discord applications, bots, websites, and online services operated for International Motorsport Series. These currently include R2–D2, Darth Webbah, IMS Setups (the Setup Bot), and the website at ims-league.com, together with future IMS applications that link to this policy (collectively, the Services).

International Motorsport Series (IMS, we, us, or our) operates the Services and is the data controller for personal data where IMS decides why and how it is processed. Individual Services process different subsets of data according to their functions; using one IMS bot does not mean every IMS bot receives every category described below.

Information we process

Discord identity and interactions

Depending on the Service used, we may process a Discord user ID, username, display name, avatar, server and channel IDs, roles, permissions, command inputs, form entries, button or menu selections, interaction responses, votes, and related message or interaction IDs. These identifiers let a bot respond to the correct person, apply IMS permissions, and link an account to the correct driver alias.

League, racing, setup, and session data

Relevant Services may process driver aliases, registrations, team and division assignments, contracts, check-ins, stewarding or league actions, race results, grid positions, lap times, standings, statistics, awards, votes, and historical records. Setup-related Services may process setup data and files, their game, car, circuit, session, author, and upload metadata, and telemetry or session data supplied to or generated for the requested feature. A bot processes only the categories needed for its available functions.

Message content and files

IMS bots primarily process slash commands, forms, buttons, menus, and files or text deliberately submitted to them. They do not use every normal conversation in the IMS Discord server as a general-purpose data source or create a blanket archive of unrelated chat.

Some Services, including R2–D2, can read normal message content where a feature requires it. This is limited to configured channels or threads, explicit bot mentions and replies, messages a user or administrator specifically references, and defined workflows such as quotes, check-ins, Wordle statistics, showcase feeds, private newsroom or history work, and operational recovery. In those cases the bot may process the message text, author, timestamp, reactions, attachments, and message or channel identifiers needed to provide that feature. Content intentionally submitted to a persistent archive or editorial workflow may be retained as part of that workflow.

Website sign-in

Website sign-in requests Discord's basic identifypermission and, where required to verify IMS membership, the permission needed to confirm membership of the IMS server. Discord provides your user ID, username, global display name, avatar information, and the membership response. We use your Discord ID to match your account to an IMS driver record. The site stores and uses a protected hashed account key for authorised features and signed-in usage records.

Website sign-in does not request your email address, friends list, or Discord message history. The short-lived Discord access token used to complete sign-in is not retained after identity and membership checks finish.

Website, cookies, and technical information

Guests can browse without a Discord account. Hosting and security services may process IP address, browser and device information, timestamps, requested pages, security signals, and diagnostic logs. Signed-in first-party usage records include access times, session and page-view counts, approximate active time, actions, and the website section last used. They do not include form contents, Discord messages, IP-based profiles, or device fingerprints.

The site measures LCP, INP, and CLS using only a fixed performance bucket, normalized route template, mobile or desktop class, and date. Daily aggregates contain no account, cookie, IP address, user agent, exact page slug, or device identifier. We do not use advertising cookies or third-party behavioural analytics.

Discord sign-in uses a protected state cookie for up to ten minutes. A signed, HTTP-only session cookie stores Discord identity fields and an expiry for up to seven days and is deleted on sign-out. Guest mode and an unlocked-view marker use session storage and normally end with that browser session. A separate HTTP-only IMS News cookie keeps a random identifier for up to one year; only its hash is stored with a current rating or article-view count.

IMS News lets readers mark a story as a good read or as needing work. The site hashes the random browser identifier before storage and keeps at most one current response for that browser and story. Ratings are not joined to Discord accounts. Readers never see the tally; authorised site administrators see aggregate upvote and downvote totals only.

How we use information

We process information to:

  • respond to commands and provide requested IMS tools;
  • authenticate users, verify permissions, and match driver identities;
  • administer registrations, rosters, teams, setups, race weekends, stewarding, votes, and other league workflows;
  • calculate, maintain, publish, and explain results, lap times, standings, records, statistics, and historical comparisons;
  • operate, secure, troubleshoot, and improve the Services; and
  • comply with legal obligations and applicable platform rules.

Depending on the data and context, the legal basis may be performance of the Service you request, your consent, IMS's legitimate interests in operating and preserving the league, or compliance with a legal obligation. You may withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.

Public and member-visible information

Driver aliases, avatars, results, lap times, standings, teams, awards, setup authorship or shared setup files, published articles, statistics, and selected current league records may be visible to IMS members or public website visitors. Restricted account, ballot, administration, security, and operational data is not intentionally published.

Retention

Retention depends on the Service and record. We keep personal data only for the period stated below or, where no fixed period is practical, for as long as it remains necessary for the stated function, security, dispute handling, or the legitimate IMS sporting archive. We periodically remove, replace, aggregate, or de-identify records that are no longer needed.

  • Website authentication: OAuth state lasts up to ten minutes; sign-in sessions last up to seven days.
  • Website analytics: identified usage summaries and member profiles are retained on a rolling 90-day basis; detailed recent activity is retained for up to 30 days; anonymous Web Vitals aggregates are retained for 90 days.
  • News feedback: a current story rating and hashed browser view aggregate remain until changed or the diagnostics dataset is retired. Named viewer details disappear with the 90-day member profile retention; unsigned visits remain anonymous aggregates. Article-view totals and signed-in viewer names are visible only to site administrators.
  • Bot status: each new heartbeat replaces the bot's previous readiness, uptime, and receipt-time record.
  • Operational bot data: transient command payloads and working files are discarded when the response or transfer completes unless needed for recovery, audit, abuse prevention, or a continuing feature. R2–D2's local command-performance telemetry is pruned after 24 hours. Discord messages and attachments remain subject to the retention of the Discord channel in which they were posted.
  • Darth Webbah operations: active registration, role, roster, contract, check-in, and race-operation records are kept while current and may be retained afterward where needed to prove or preserve the corresponding league decision or sporting history.
  • IMS Setups: setup files, setup metadata, and supplied telemetry or session data remain while needed for the active setup library, provenance, moderation, or the sharing function for which they were submitted. They are removed or de-identified when the library entry is removed and no overriding legal, security, or dispute need remains.
  • Sporting and editorial archive: driver aliases, race results, lap times, standings, finalized votes or awards, published material, and related provenance may be retained for the life of the IMS historical archive. Where reasonably possible, a direct Discord account link will be removed while the sporting record remains under a driver alias.

Provider logs and backups may persist for their normal rotation period after live data is deleted. We do not use backups to restore data that was validly deleted unless required for disaster recovery, and any restored copy remains subject to the deletion request.

Third-party services

We use or integrate with the following service categories:

  • Discord provides the application platform, OAuth, interactions, messages, files, roles, and Discord-hosted media.
  • Cloudflare provides DNS, content delivery, security, website hosting and compute, plus D1 database and R2 object storage for the website.
  • Google and YouTube provide OAuth and video upload, metadata, thumbnails, feeds, and privacy-enhanced embedded playback for IMS video features.
  • Twitch provides stream schedules, VOD and clip metadata, media transfer, and user-initiated embedded playback.
  • External media providers and CDNs, including Discord media, Formula1.com, YouTube image servers, and FlagCDN, may receive an ordinary browser request when their media is displayed.
  • IMS-controlled hosting and databases include the computers and local SQLite storage used to operate the Discord bots and preserve authorised league records.

These organisations may act as service providers or as independent controllers for their own platform activity. Their handling is also governed by their own terms and privacy policies. We do not sell personal information or Discord API data.

Security

We use role and user access controls, restricted command permissions, signed sessions, protected cookies, hashed account matching, scoped service secrets, and other reasonable safeguards. No system is perfectly secure, so we cannot guarantee absolute security.

Your choices and requests

Subject to applicable law, you may request access to and a copy of the personal data IMS associates with you, correction of inaccurate or incomplete data, deletion, restriction, or an objection to certain processing. You may also withdraw consent where processing relies on it.

Email privacy@ims-league.comor contact an IMS administrator through the official IMS Discord server. State which IMS Service and account or driver alias the request concerns. We may ask for reasonable verification, such as confirming control of the relevant Discord account. We will respond within the period required by applicable law and explain any information that cannot be changed or deleted because of a legal obligation, security need, dispute, another person's rights, or the integrity of an IMS sporting record.

You may also complain to the data-protection authority that applies in your country. Using the website as a guest, declining Discord authorisation, leaving a non-required field blank, or signing out may reduce the data processed by the relevant Service.

Children and international use

The Services are not directed to children under 13. You must also meet Discord's minimum age requirement for your country. IMS members and our service providers may be located in different countries, so information may be processed outside your own country subject to safeguards required by applicable law.

Changes and contact

We may update this policy when an IMS Service, provider, or legal requirement changes. The effective and last-updated date above will be revised when we publish a change.

IMS is the operator and privacy contact for these Services. Email privacy@ims-league.com or contact an IMS administrator through the official IMS Discord server.