Effective date
Effective August 4, 2026.
Information collected
SporxTime offers a low-trust email and password account. We collect the email address you submit, a salted and versioned scrypt password hash, password update time, account status, and an authentication version. We do not verify that the email belongs to you and do not offer email password recovery.
For account security, we store hashed verification answers, hashed browser and network bindings, hashed rate-limit keys, server-side Session Token hashes, timestamps, and temporary failed-authentication records. Standard server and security logs may process an IP address, device or browser information, requested URL, referring page, and timestamp.
If you contact us, we receive the information you choose to provide, such as your name, email address, message, and any correction details.
How information is used
We use account and technical information to register and authenticate low-trust accounts, maintain server-side sessions, process password changes, prevent automated abuse, deliver pages, diagnose failures, and respond to requests or correction reports.
SporxTime does not sell personal information or use site-submitted information to build sensitive personal profiles.
Cookies and local storage
Public content does not require an account. st_session maintains sign-in for up to 30 days, st_challenge_browser binds a registration or sign-in image code for up to 10 minutes, and st_cookie_consent remembers a cookie-notice acknowledgement for up to 180 days. SporxTime currently uses no advertising, analytics, or cross-site tracking cookies. See the Cookie Policy for details.
Service providers and retention
Hosting and database providers may process limited account and technical data on our behalf. Sessions expire after 30 days unless revoked earlier. Verification challenges and failed-attempt records are retained only as needed for abuse prevention and routine cleanup; logs and correspondence are retained only as reasonably needed for security, reliability, legal obligations, and the request that prompted collection.
Passwords, password hashes, verification answers, Session Tokens, authentication secrets, and full email addresses must not be written to application logs. Changing a password revokes every old session and creates a new session for the browser completing the change.
External links
Official land-manager, weather, race, and registration links lead to third-party services with their own privacy policies. SporxTime does not control those services.
Your choices and contact
You may choose not to send optional contact information. Depending on where you live, you may also have rights to request access, correction, or deletion of personal information that we hold, subject to applicable exceptions.
Privacy questions or requests can be sent through the Contact page. We may need enough information to verify and fulfill a request.
Policy changes
We may revise this policy when site features or data practices change. The effective date above identifies the current version.