Privacy Policy
Effective July 19, 2026
This Privacy Policy describes how Linden LLC ("we", "us") collects, uses, and shares information when you use the Laps mobile application, the getlaps.io website, and related services ("Laps").
1. Information we collect
- Account information — your name, email address, and sign-in identifiers when you register with email, Apple, or Google.
- Telemetry you record — GPS location, speed, lap times, g-forces, and related session data captured while you actively record a session at a track. Recording only happens when you start it.
- Heart rate — read from Apple Health or Health Connect, only if you grant permission, to show vitals for your recorded sessions. See Section 4.
- Profile and settings — vehicles, units, privacy preferences, and social connections you configure in the app.
- Purchase information — subscription status from the Apple App Store, Google Play, or Stripe via our billing provider RevenueCat. We never see or store your full payment card details.
2. How we use information
- To provide the Service: syncing sessions, computing lap analytics, leaderboards.
- To authenticate you and secure your account (including one-time email codes).
- To process subscriptions and unlock paid features.
- To communicate service updates and respond to support requests.
We do not sell your personal information or use it for third-party advertising.
3. Location data
Precise location is collected only while you record a session and is used to compute lap timing, track position, and session maps. Your recorded sessions are private by default; you choose what to share to leaderboards or with other users.
4. Health data
If you choose to connect it, Laps reads heart rate from Apple Health on iOS and Health Connect on Android so your track sessions can show heart-rate vitals alongside lap and telemetry data. Heart rate is the only health data we request.
We read it only after you grant permission in the system health prompt, and we never write any data back to Apple Health or Health Connect. When a session syncs, we store a summary — your average heart rate, your maximum heart rate, and time spent in each heart-rate zone — rather than the underlying beat-by-beat samples.
Health data is used solely to show your session vitals. It is never used for advertising, never shared with data brokers, and is not included in the product-usage events described in Section 5. You can revoke access at any time in iOS Settings → Privacy & Security → Health, or in the Health Connect app on Android. Revoking stops any further reads; vitals already saved to a session remain until you delete that session or your account (Section 7).
5. Website and mobile app analytics
On the getlaps.io website we use Google Analytics to understand how visitors find and use the site (for example, which pages are viewed and where visitors come from). Analytics only runs if you accept it in the cookie banner shown on your first visit — no analytics cookies are set and no data is sent to Google until you accept. You can change your choice at any time using the "Cookie preferences" link in the website footer. We use analytics in aggregate and do not use it for advertising. The Laps mobile app does not include Google Analytics.
In the Laps mobile app, we use PostHog on PostHog's US cloud to process product-usage events when an account is created, a session is recorded or viewed, or the upgrade screen is viewed. We also process subscription-lifecycle events through PostHog. These events are linked to your internal account ID, not your name or email, and are not used for cross-app tracking or advertising. They do not include precise location, lap telemetry, or session content, and IP-derived location is disabled.
You can stop in-app usage events from your device by turning off "Share Usage Analytics" in Settings. Account-creation and subscription-billing events are processed server-side for service operation and are not affected by this toggle. Analytics data is deleted when you request account deletion through the flow described in Section 7.
6. Service providers
We share data only with processors needed to run Laps:
- Supabase (database hosting)
- Fly.io (application hosting)
- ElectricSQL (data synchronization)
- RevenueCat (subscription management)
- Apple and Google (sign-in and billing, if you use them)
- Stripe (billing, if you purchase on the web)
- Resend (transactional email, e.g. verification codes)
- Mapbox (map rendering; map tiles are requested by the app)
- Google Analytics (website usage analytics, only with your consent)
- PostHog (mobile app product and subscription analytics, hosted in the US)
7. Data retention and deletion
Your data is retained while your account is active. You can delete your account at any time from Account settings in the app; this permanently deletes your synced sessions, profile, vehicles, settings, and social data from our servers. Recordings kept only on your device are under your control.
8. Security
Data is encrypted in transit. Access to production systems is restricted and credentialed. No system is perfectly secure; please use a strong, unique password.
9. Children
Laps is not directed to children under 13, and we do not knowingly collect their data.
10. Your rights
Depending on your region, you may have rights to access, correct, export, or delete your personal data. Most of these are available directly in the app; for anything else, contact us and we will respond within a reasonable timeframe.
11. Changes
We may update this policy from time to time. Material changes will be communicated in the app or by email.
12. Contact
Privacy questions: support@getlaps.io