This document is a starting point that has not been reviewed by an attorney licensed in your jurisdiction. It is intended to be replaced with finalized terms before public launch. Until then, Holeshot is operating in a private pilot under direct agreement between Shift Labs LLC and individual track owners. If you have questions, please contact legal@holeshot.app.
Version: 2026-04-25-draft · Last updated: April 25, 2026
Data Processing Addendum
This Data Processing Addendum (the “DPA”) is entered into between Shift Labs LLC (“Holeshot”, “Processor”) and the motocross facility identified in the Track account (the “Track”, “Controller”), and forms part of the Holeshot Terms of Service.
It applies whenever Holeshot processes personal information about riders, guardians, spectators, or other end-users on behalf of the Track in connection with the Track's use of the Holeshot platform.
1. Definitions
- “Personal Information” means information that identifies, relates to, or could reasonably be linked to an individual, processed by Holeshot on the Track's behalf.
- “Applicable Privacy Law” means the U.S. state privacy laws applicable to the Track's processing of Personal Information of its end-users (including, where applicable, the California Consumer Privacy Act / California Privacy Rights Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, and similar laws).
2. Roles
For Personal Information collected by Holeshot specifically to operate the Track's events (rider registrations, waivers, race-class entries, emergency contacts, guardian information, ticket purchases): the Track is the “business” / controller and Holeshot is the “service provider” / processor.
For Personal Information that Holeshot collects from account holders directly to operate the Holeshot platform itself (such as Track-owner accounts and cross-track operational data), Holeshot is the controller / business.
3. Holeshot's obligations
Holeshot will:
- Process Personal Information only on documented instructions from the Track, which are constituted by the Track's use of the Platform's features and configuration;
- Not sell Personal Information, share it for cross-context behavioral advertising, or retain, use, or disclose it outside the direct business relationship with the Track or as required by law;
- Not combine Personal Information received from the Track with Personal Information from other sources for purposes other than operating the Platform on the Track's behalf;
- Implement reasonable security safeguards (see Section 6);
- Notify the Track without undue delay after becoming aware of a confirmed personal-information breach affecting the Track's end-users;
- Provide reasonable assistance with end-user data-subject requests (access, correction, deletion, portability, opt-outs) where the request is routed to Holeshot rather than the Track.
4. Track's obligations
The Track represents and warrants that it will:
- Use the Platform in compliance with Applicable Privacy Law;
- Provide its own privacy notices to its riders, guardians, spectators, and other end-users as required;
- Have a lawful basis for collecting and providing the Personal Information it submits to the Platform;
- Not provide special-category information through the Platform other than what is contemplated by the Platform's features (e.g., date of birth on registration; emergency-contact information);
- Promptly forward any data-subject request that the Track receives directly and that Holeshot is required to act on as a service provider.
5. Sub-processors
The Track authorizes Holeshot to engage the following sub-processors to deliver the Platform:
- Stripe, Inc. — payments, payouts, dispute handling
- Clerk, Inc. — account-holder authentication
- Google LLC — cloud database and storage
- Resend, Inc. — transactional email delivery
Holeshot will impose written terms on each sub-processor at least as protective as this DPA. Holeshot will provide reasonable advance notice before engaging a new sub-processor that materially expands the categories of Personal Information processed; the Track may object to a new sub-processor on reasonable grounds.
6. Security
Holeshot maintains administrative, technical, and physical safeguards designed to protect Personal Information, including encryption in transit, access controls (role-based, least-privilege), audit logging, secret-management practices, and routine review of dependencies.
[ATTORNEY: confirm whether a security exhibit (HIPAA-style) listing specific technical measures is required for the contractual minimum, or whether a high-level reference is sufficient for SaaS at this scale.]
7. International transfers
Holeshot operates in the United States. Personal Information will be processed on infrastructure located in the United States. The Platform is not currently offered to data subjects in the EU or UK; if the Track expects to register data subjects from those jurisdictions, the Track must contact Holeshot in advance.
8. Audit and verification
Holeshot will reasonably cooperate with the Track's requests for information necessary to demonstrate compliance with this DPA. Onsite audits are not provided.
[ATTORNEY: confirm whether to add SOC 2 / ISO references once available, frequency of audit-information requests, and a cap on free auditor support.]
9. Return or deletion
Upon termination of the Track's use of the Platform, Holeshot will, on the Track's written request, return or delete the Track's Personal Information, except for information Holeshot is required to retain by law (including waivers and payment records subject to the retention periods in the Holeshot Privacy Policy).
10. Liability
Each party's liability under this DPA is governed by, and forms part of, the limitations and exclusions of liability set forth in the Holeshot Terms of Service.
11. Order of precedence
In the event of any conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of Personal Information of the Track's end-users.
12. Contact
Shift Labs LLC
privacy@holeshot.app