Privacy Policy
Last updated: 17 August 2026
This policy describes what happens to information when you use GripCalc. It is written against the code that ships, so every statement in it can be checked against the app's own files. Where something genuinely cannot be established from the code, this policy says so rather than guessing.
1. Who is responsible for your information
GripCalc is built and run by Sam Hayes, an individual operating on his own account. Sam Hayes is the data controller for the purposes of the UK GDPR. There is no company behind GripCalc, so there is no company registration number to quote.
The address for anything in this policy is gripcalc@gmail.com. It is a real mailbox and it is read. If you need a postal address in order to make a formal request, ask at that address and it will be given to you.
2. The short version
- There are no accounts. GripCalc never asks who you are.
- Your setups, sessions and settings are written to your own browser's storage on your own device. They are not uploaded to us.
- No cookies are set, by GripCalc or by Google Analytics, because analytics consent is set to denied before the analytics tag loads.
- Denying that consent stops the cookie. It does not stop the transmission: usage events are still sent to Google. Section 5 lists exactly what they carry, including the one event that can carry text you typed.
- One feature, the ambient temperature auto-fill, sends your location coordinates to a weather service, and only if you grant location permission.
3. What GripCalc stores on your device
These entries are written by your browser into its own storage for this site. The entries themselves stay on the device: none of them is uploaded to us or to anyone else. Some analytics events do carry a single enumerated value that is also held here, or a category worked out from one: the circuit you selected, the class the database puts your car in, the number of sessions in an export. Section 5.1 lists every one of them.
| Entry | What it holds | Why | Kept until |
|---|---|---|---|
| gripCalcInputs | The car, tyre, circuit, temperatures, corner deltas, road pressures and unit choices currently in the form | So the app opens where you left it | You clear it |
| gripCalcSessions | Your saved sessions: what was calculated, any pyrometer readings, lap times and tread depths you entered, and any notes | The session history and the comparison between sessions. Without an active membership the store keeps your most recent 50 sessions. With a membership active nothing is trimmed. The history drawer shows everything the store holds; a free-tier display limit of 10 applies only once memberships can be bought | You clear it, or, without a membership, the session drops out of the most recent 50 |
| gripCalcCarProfiles | Setup records you enter against a car name: front weight distribution, kerb weight, camber, suspension make and type | Weight distribution refines an estimated pressure split; the rest rides out in the CSV export | You clear it |
| gripCalcPro | The membership code you redeemed and the date you redeemed it | So the device stays entitled between visits | You clear it |
| gripCalcTheme | The word dark or light | Your appearance choice | You clear it |
| gripCalcFeedbackNudge | A count of sessions since the last feedback prompt, the time of that prompt, and a flag once you have sent feedback | So the app asks for feedback at most occasionally, and never again once you have given it | You clear it |
| gripCalcAnnounce:… | A marker that you dismissed one particular announcement line. The text of the announcement forms part of the entry name | So a dismissed notice does not come back | You clear it |
| disclaimerAccepted disclaimerVersion disclaimerAcceptedAt disclaimerAcceptedDate |
That you accepted the gate, which version of it you accepted, and when. The last two hold the same timestamp | This is the record of your agreement to the Terms, and it is what decides whether you are asked again after the terms change | You clear it |
| gripCalcAnalyticsOff | The single character 1, and nothing else. It exists only if you opened a page with ?ga=off in the address, which is how we keep our own testing out of our own analytics. You are welcome to set it: while it is there, no analytics event and no page view leaves this device | To switch analytics off for this device | You clear it, or open a page with ?ga=on |
| tempAutoFilled | A flag that the ambient temperature has already been filled in automatically once | So the app does not ask for your location twice in one sitting. This one is session storage, not local storage | You close the tab |
To remove any of it: Clear All in the History drawer deletes your saved sessions, and only those. Clearing this site's data in your browser settings removes everything in the table above, including the record that you accepted the Terms, which means the gate will ask you again.
4. Cookies and similar technologies
GripCalc sets no cookies of its own. Google Analytics is loaded with consent mode set to denied for analytics storage, advertising storage, advertising user data and advertising personalisation, and that instruction runs before the analytics tag is requested. The result is that the tag does not write the usual analytics cookies and does not place a device identifier on your machine.
What GripCalc does use is your browser's local storage and session storage, listed in section 3. Storing or reading information on your device is regulated in the UK by the Privacy and Electronic Communications Regulations, which require your consent unless the storage is strictly necessary for a service you have asked for. Our position is that every entry in section 3 is there only to deliver something you asked the app to do: remember your setup, keep your sessions, hold your appearance choice, record that you accepted the Terms, and stop pestering you for feedback. None of it is used for analytics, advertising, profiling or tracking, and none of it is read by anyone but the app on your own device.
If you would rather it were not there, clear the site's data or block storage for this site in your browser. The calculator still calculates. It just forgets everything between visits, and asks you to accept the Terms each time.
5. What leaves your device
5.1 Google Analytics
Every page of GripCalc loads Google Analytics 4. Consent mode is set to denied first, as described in section 4, so nothing is stored on your device and no analytics identifier is placed or stored on it.
Consent mode governs storage, not transmission. Each event listed below is still sent over the network to Google, and Google, like the recipient of any web request, sees the IP address the request came from and the browser user-agent string that accompanies it. Google derives an approximate location from that address, typically a country or a city, and a browser and device description from the user-agent, as part of its standard reporting. That is the extent of the "device information" and "location" you will see attributed to analytics anywhere in this policy: we neither send nor ask for more. It would be easy to write that we receive counts only, because counts are all we ever look at, but that would describe our reporting rather than the transmission, so this section describes the transmission.
These are the events, in full, and what each one carries:
| Event | What it carries |
|---|---|
| page_view | Sent automatically by the analytics tag for each page. If you arrived from a link on our home page, the value landing is added, and nothing else is |
| tire_pressure_calculation | Whether the figures came from published data or an estimate, the vehicle's class, whether the safety guard rail clamped the result, and whether a circuit was selected. Not the car, not the tyre, not the numbers |
| session_outcome | The circuit's database identifier, how many corners landed in the tyre's temperature window, how many corners were measured, and whether a lap time and tread depths were entered |
| open_help | Which help topic you opened, and its title |
| open_shop, shop_click | That the kit drawer was opened, and the identifier of the item clicked |
| share_card_sent | That the share card was sent, and which method was used: the operating system's share sheet, or a download to your device |
| history_exported | How many sessions were in the export |
| car_profile_saved | That a car profile was saved. No profile contents |
| pro_redeemed, pro_redeem_failed, pro_subscribe_click | That a membership code was accepted or rejected, or the membership panel's button was pressed. Never the code itself |
| disclaimer_accepted, disclaimer_declined | That the gate was accepted or declined, and which version |
| open_feedback_drawer, feedback_nudge_shown | That the feedback panel was opened, or that the occasional feedback card was shown |
| submit_user_feedback | Your star rating, the category you chose, the length of your message, the page path, a timestamp, and the first 500 characters of the message you wrote |
| error_thrown | The browser's error message, cut to 150 characters, the file name it came from and the line number |
| pwa_installed, pwa_install_prompt, launched_standalone | That the app was installed, what you answered to the install prompt, and that it was opened as an installed app rather than in a browser tab |
The feedback box is the one place where text you have typed leaves the device. Whatever you write in it, up to the first 500 characters, is sent to Google along with the rest of that event. Please do not put your name, your email address, a registration number or anything else you would not want handed to a third party into that box. It is disclosed here precisely because it is the exception to everything else on this page.
The error report is the other place where a string we did not choose is sent. It is produced by your browser, not by you, but a browser error message can occasionally contain part of a web address.
To stop analytics entirely, block requests to googletagmanager.com with a browser extension or your browser's own privacy settings. That does not stop the app's own code from calling gtag: a small local copy of that function is defined on the page before the analytics tag ever loads, so every call above still runs and never throws. What that local function does is push each event onto an in-page queue; it is the analytics tag, once loaded, that reads the queue and sends it to Google. Block the tag and the queue is simply never read, so nothing above is transmitted. Nothing in the app breaks either way: the calculator, the history, the analysis and the offline mode all work exactly the same.
5.2 GripCalc's own server
Three things are sent to gripcalc.com's own server, introduced in August 2026. First, feedback: when you submit the in-app feedback form, your star rating, category and message go to our server so the people who run GripCalc can actually read them, as well as to Google Analytics as described above. No account, identifier, or email address accompanies them, which is also why we cannot reply individually. Second, an event mirror: the same analytics events listed in section 5.1 are also counted on our own server. The server stores the event name, its listed fields and a timestamp, and deliberately nothing else: no IP address, no user-agent, no cookie, no identifier of any kind is written down, so two events from the same person are indistinguishable from two events from two people. Third, membership codes: redeeming a Pro code sends the code itself to our server to check it has not been revoked, and the server records that the code was used one more time. The code identifies a purchase, not a person, and nothing else travels with it.
As with any web request, our server necessarily sees the IP address a request came from while handling it; unlike the analytics service, it does not record it against any of the above. The owner-exclusion switch that silences analytics (end of section 5.1) silences the event mirror too. These requests only ever happen online; offline, the app works exactly the same and simply sends nothing.
5.3 The weather lookup
If you grant your browser's location permission, the app reads your position and sends the latitude and longitude to the Open-Meteo weather service to fetch the current air temperature, which it then puts in the ambient temperature field. The coordinates are sent at the precision your browser reports them, which on a phone can be accurate to a few metres. Nothing else goes with the request: no identifier, no session data, no reference to what you were calculating. The reply is used only to fill in that one number.
Refuse the location permission and the request never happens: the ambient temperature is then simply the value you type, and the app says on screen that the figure was entered rather than measured. If you do allow location but the weather service cannot be reached, the app falls back to a seasonal average for your latitude, worked out on your device, and labels the figure an estimate.
5.4 The app's own files
On opening, the app fetches its configuration file from gripcalc.com. Every font, stylesheet, script, icon and photograph is served from gripcalc.com as well: there is no content delivery network, no third-party font service, no advertising script, no social media pixel and no tag manager beyond the analytics tag named above. The only requests GripCalc itself makes to anyone other than gripcalc.com are the two described in 5.1 and 5.2. Pages you open yourself by tapping a share button or a retailer link are covered in 5.4.
5.5 Links, shares and downloads
"Share this setup" and "Share this session" both draw a pit-board image of your session on your device. Where your browser can share files, that image is handed to your operating system's share sheet, so you pick which app receives it and what happens from there is between you and that app, governed by its own policy, not ours. Where your browser cannot share files, the image is downloaded straight to your device instead, for you to send on yourself. Either way the image is drawn on your device and is never uploaded to us. Kit links go to retailers' own websites, where their policies apply.
5.6 Web server logs
GripCalc is served as static files from an ordinary web server. Web servers commonly keep short-lived request logs holding an IP address, a timestamp, the page requested and the browser user-agent, for security and fault-finding. We do not use such logs to build any picture of an individual, and the app itself writes nothing to them beyond the ordinary act of fetching a page. We cannot state a precise retention period for them in this document; if you need that figure, ask at gripcalc@gmail.com.
6. Our lawful basis
For the analytics in section 5.1 we rely on legitimate interests under Article 6(1)(f) of the UK GDPR. The interest is measuring aggregate use of a free tool: which features are used, how often a recommendation rests on published data rather than an estimate, and whether the numbers land in the tyre's temperature window. Without that there is no honest way to decide what to build or which data to add next.
Our assessment, in plain terms and stated as the operator's own view rather than as settled law: the processing is limited to the events listed above; it creates no account, no profile and no advertising identifier; consent mode is denied so nothing is stored on your device; and the app functions identically for anyone who blocks it. Against that we weigh the fact that these events are still transmitted to a very large advertising company, and that your IP address reaches it in the course of the request. That is the reason section 5.1 is written the way it is instead of claiming nothing happens.
We do not claim consent as the basis for analytics, because we do not ask you for it. Naming a basis we have not obtained would be worse than the processing itself.
For the feedback, event mirror and code validation in section 5.2 we rely on legitimate interests for the first two (hearing from our users and understanding use of the product, collected without identifiers) and performance of a contract for code validation (checking the membership you redeemed is genuine and current).
For the weather lookup in section 5.3, the request happens only after you grant your browser's location permission, which is a separate and specific choice you make, and we treat it as your consent for that one request. Withdraw it in your browser settings and the request stops.
The on-device storage in section 3 is not something we process at all: it never reaches us. It is governed by the storage rules described in section 4.
This assessment was written by the operator and not by a solicitor. Independent legal review is intended and has not yet happened. If a review changes the position, this policy will be changed with it and the date at the top will say when.
7. How long anything is kept
On your device: until you clear it, subject to the limits described in section 3. Analytics events held by Google are kept for the retention period configured in the Google Analytics property and are governed by Google's own terms. We cannot verify that setting from the app's code; ask at gripcalc@gmail.com if you need the current figure. On GripCalc's own server (section 5.2): feedback is kept until reviewed and then as long as it is useful, event counts indefinitely (they contain no identifier to expire), and code redemption records for the life of the membership.
8. Who anything is shared with
- Google, for the analytics events in section 5.1 (Google's privacy policy).
- Open-Meteo, coordinates only, and only when you allow location access (Open-Meteo's terms).
That is the entire list. We do not sell, rent or trade information about you. There is no advertising network, no data broker and no mailing list. We would disclose information if the law required us to, and there is very little to disclose: no accounts, no server-side record of your sessions, and no identifier that would let us pick you out of the analytics.
9. Transfers outside the UK
Google is a United States company and its analytics infrastructure processes data outside the UK. That transfer is made under Google's own arrangements as the processor of those events, set out in Google's terms. We do not rely on your consent as the transfer mechanism: consent buried in a policy you did not separately agree to is not a proper basis for a routine, repeated transfer.
Requests to Open-Meteo go to that service's own servers, which may be outside the UK. Only the coordinates travel, and only when you allow it.
10. Your rights
Under the UK GDPR you have the right to ask for access to personal data we hold about you, to have it corrected or erased, to have its use restricted, to object to processing carried out on the basis of legitimate interests, and to receive it in a portable form. GripCalc makes no automated decisions that produce legal effects about anyone.
Two practical points, stated honestly. First, because there is no account and no identifier, we usually cannot find "your" events inside the analytics in order to act on a request; if you tell us roughly when you sent feedback we will do what we can, which for analytics events means asking Google to delete them. Second, almost everything a request of this kind would be aimed at is already on your device and under your control:
- Read it: everything in section 3 is visible in your browser's developer tools: under Local Storage for this site, except tempAutoFilled, which is Session Storage and is gone once you close the tab.
- Export it: with a membership active, Export CSV in the History drawer writes every session, outcome, lap time and tread reading to a CSV file on your device. Without a membership the data is still yours and still readable as above; the CSV button is part of the paid tier.
- Delete it: Clear All in the History drawer deletes your saved sessions. Clearing the site's data in your browser deletes everything in section 3.
To object to the analytics processing without waiting for us, block the analytics as described at the end of section 5.1. Nothing else changes.
If you think your information has been handled wrongly you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first at gripcalc@gmail.com so it can be put right, but you are not obliged to.
11. Children
GripCalc is a tool for people who take cars on circuits and is not directed at children. It asks nobody for personal information, so it collects none from children either. If you believe a child has typed something identifying into the feedback box, tell us at gripcalc@gmail.com and we will do what we can to have it removed.
12. Security
The site is served over HTTPS. There are no accounts, so there is no password of yours to lose, and there is no server-side database of your sessions, so there is nothing of yours on our side to breach. The other side of that is that your data is protected by your own device: anyone holding your unlocked phone can read your session history.
13. Changes to this policy
This policy is updated when the code it describes changes, and the date at the top says when that last happened. If what leaves your device changes materially, the acceptance gate's version is raised at the same time, so you are asked to look again rather than being moved quietly onto new terms.
14. Contact
Sam Hayes, operator and data controller, GripCalc
Email: gripcalc@gmail.com
The in-app feedback form reaches us too (sections 5.1 and 5.2), but read the warning in section 5.1 before you put anything personal in it. Email is the better route for anything to do with your data or your rights.
See also the Terms of Service.