Privacy Policy
AS SMART ENTERPRISES LLP runs BOXBOXBOX in Guindy, Chennai. This is the plain-English account of what we collect, why we collect it, who else ever sees it and what you can make us do about it. The short version: we ask for as little as we can, we store it in India, and we do not sell it.
01Who we are
AS SMART ENTERPRISES LLP ("we", "us") runs the sim racing lounge trading as BOXBOXBOX at 25/32 Readymade Garment Complex, SIDCO Industrial Estate, Guindy, Chennai - 32, Tamil Nadu, India. We are the Data Fiduciary for the personal data described here, which means we decide why and how it is used and we are answerable for it.
For anything on this page — a question, a correction, withdrawing consent or a complaint — write to [email protected] or message +91 63859 42471 on WhatsApp. That is our Grievance Officer channel under the Digital Personal Data Protection Act 2023, and we answer it.
02What we collect, and why
We ask for as little as we can and we tell you why at the point we ask. In full:
Your name, when you check in — so your waiver is attached to a real person. Your email address, if you sign in with Google — so you can see your own lap history.
Your phone number, if you choose to give one — so staff can call you when a rig is free. It is optional: check-in works without it, and you can ask us to delete a number you gave us earlier.
Your driver tag and lap times — so the leaderboard and your profile work. Lap times are read directly from the game by the rig, never typed in by hand. If your lap tops a board, how it was driven (throttle, brake, braking points) is shown to other drivers as the lap to beat, under your tag or three letters of your name — never your name.
Your waiver: the exact declaration you ticked, the signature mark generated in your name, the date and time you accepted it, which version of the terms was on screen, and the IP address and browser the acceptance came from — this is the evidence that you agreed, and it is the reason we can let you on a rig at all. We keep the IP address and browser for the waiver record only; the visit analytics below never store either.
Health and age declarations you make at check-in, and a parent or guardian's details if the driver is under 18 — so we do not put someone on a rig it is unsafe for.
Basic website analytics: which pages were visited, roughly where from, and which link brought you. We use this to work out whether our posts bring anyone in.
On the booking page, the choices you make as you go — how many drivers, which rig, how long, which day and time — how far you get, and whether you end up booking. Never what you type: your name, number and email are only kept if you book, as the booking itself. We use it to see where the booking page loses people, so we can make it simpler. It is anonymous in the same way as the analytics above, and carries your account only if you are signed in.
Taps on our own short links and QR codes — which code was tapped, when, and whether it was a phone or a computer. Nothing else: a tap happens before we know anything at all about who made it, so there is no id, no name and no IP address on that record, and there is no way to join it to anything else. We count them to tell a poster that works from one nobody scans.
What you do while you are signed in: when you sign in, and which pages of your own garage you open — your dashboard, your session reports. Those records carry your account, because you are logged into it; a visit from a browser that is not signed in stays anonymous. We look at this to see whether the garage is worth keeping and what to build next, and to tell an occasional driver from a regular. It does not follow you anywhere but this site, it never records your IP address, and it is never sold, shared or used to advertise at you.
Your name and email for marketing — offers, event nights and news about the lounge — if you signed the waiver yourself on our site. The declaration you tick there says so in as many words, and ticking it is the consent. It is a couple of emails a month at most, every one of them carries a one-tap unsubscribe link, and an unsubscribe is final: use it once and no campaign reaches you again, whatever else is true of your account. Nobody is added by checking in at the desk.
03Consent, and taking it back
We process your data on your consent. Where consent is the basis, you can withdraw it at any time and it must be as easy to withdraw as it was to give.
Marketing email: every message we send carries a one-click unsubscribe link, and it works immediately. You can also just tell us.
Everything else: write to us and we will stop, and delete what we no longer need. Understand that withdrawing consent for the waiver record means we cannot let you drive, because the waiver is the basis on which we do.
04We do not sell your data
We have never sold personal data and we do not intend to. We do not rent it, trade it, or hand it to data brokers, advertising networks or list builders. There is no arrangement under which anyone pays us for access to our customers.
The only third parties who see any of it are the service providers we need to run the place, listed below, and each of them sees only the slice their job requires.
05Who else touches it
Google — sign-in only. If you sign in with Google we receive your name and email address from them; we never receive your password. Resend — delivers the emails you have opted in to. It receives your name and email address, and nothing else. MySiteGPT — powers the chat bubble on our website. Anything you type into that chat goes to them; do not put personal details in it. Google Maps — the map on our location page is embedded from Google, so loading that page tells Google your IP address.
We will also disclose data where the law actually requires it — a court order, a lawful demand from an authority. We will tell you if that happens unless we are forbidden from doing so.
06Where it is stored
Our database — your account, your waiver, your sessions and your lap times — is hosted on servers located in India.
Be aware of the honest exception: the service providers named above operate their own infrastructure, and email delivery and the website chat widget may process data outside India. That is limited to what those specific functions need. Everything we hold ourselves stays in India.
07How long we keep it
A signed waiver is kept for 12 months from signing, which is how long it is valid, and then for as long as a claim arising from that session could still be brought against us.
Session and lap records are kept while your account exists, because they are your history and the leaderboard.
Marketing contacts are removed as soon as you unsubscribe.
Website analytics from browsers that are not signed in are anonymous and not tied to your name. The page records that do carry your account are kept while the account exists: ask us to delete the account and the name comes off them, leaving only an anonymous visit.
When we no longer need something for the purpose we collected it for, and no law requires us to keep it, we delete it.
08Your rights
Under the DPDP Act 2023 you can ask us for: a summary of the personal data we hold about you and what we do with it; a list of who we have shared it with; correction of anything wrong, incomplete or out of date; erasure of data we no longer need; and you can nominate someone to exercise these rights if you die or become incapacitated.
Ask at [email protected]. We will respond within a reasonable period, and we will not charge you for it.
If we have not sorted it out to your satisfaction, you can complain to the Data Protection Board of India.
09Children
Anyone under 18 is a child under the DPDP Act, and we do not process a child's data without a parent or guardian's consent.
In practice: an under-18 driver checks in with a parent or guardian present, and it is the parent or guardian who reads the waiver and signs it. We record their name, their relationship to the driver and their contact number.
We do not do behavioural advertising or tracking aimed at children, and we do not send marketing email to an account we know belongs to one.
10Keeping it safe
Access to customer records is limited to the owner and floor staff who need it to run a shift, and every account is behind a login. Traffic to this site is encrypted. Rig telemetry reaches us over authenticated connections from the rigs themselves.
No system is perfectly safe. If a breach affects your personal data we will notify you and the Data Protection Board, as the Act requires, and tell you plainly what happened and what to do about it.
11Cookies
We use a cookie to keep you signed in, and a record of page visits to understand which of our posts bring people in and which parts of the site get used. A visit from a browser that is not signed in is anonymous: the record stores an id we generated for that browser, not your name. A visit made while you are signed in carries your account instead — it is the same record, with your name on it, because you are logged into that account. Neither one stores your IP address. We do not run third-party advertising cookies and we do not sell anything about you to anyone.
We may also run Microsoft Clarity, which builds heatmaps and records sessions — a replay of clicks, scrolling and mouse movement on the page — so we can see where the site is confusing. Clarity is Microsoft's, sets its own cookies, and the recordings are processed on their systems under their terms. We ask before it runs: it stays off unless you press ALLOW on the banner, saying no keeps the site working exactly the same, and clearing your browser storage for this site asks you again.
12Changes
This notice was last updated on 26 September 2026. If we change how we use your data in a way that matters, we will say so here and, where the change needs your consent, ask for it before we act on it.