Legal
Privacy Policy
What personal data Laces collects from participants and organizers, why, how long it is kept, and how to get a copy or have it deleted. Written against Uganda's Data Protection and Privacy Act 2019.
Last updated 17 August 2026 · Laces · 11 min read
Keep a copy of this document
A formatted PDF with a cover page, page numbers and the date you retrieved it.
Laces holds personal data about people who run races. Names, phone numbers, emergency contacts, dates of birth, sometimes a medical note. This document says exactly what we hold, why, who sees it, how long we keep it, and how to get it back or have it removed.
This policy is written against Uganda’s Data Protection and Privacy Act 2019 (“the DPA”) and the Data Protection and Privacy Regulations 2021.
- “Personal data” means information about an identified or identifiable person, as the DPA defines it.
- “Data subject” is you: the person the data is about.
- “Data collector, controller and processor” are the DPA’s terms for the roles below. Section 3 explains who is which.
1. Who is responsible for your data
Laces is a product of Apta Innovations Limited, a private company limited by shares, incorporated in the Republic of Uganda on 10 July 2026 under the Companies Act 2012. Apta Innovations Limited is the data controller described in this policy.
| Registered company | Apta Innovations Limited |
| Company registration | 80045435006790 |
| Registered office | Kyanja, Kisaasi Central A, Nakawa Division, Kampala, Central, Uganda |
| Registered postal | P.O. Box 209717, Kampala GPO, Uganda |
| Trading as | Laces (laces.run) |
Registration with the Personal Data Protection Office (PDPO). Registration as a data collector, controller and processor under the DPA and the 2021 Regulations is in progress. This entry will carry the registration number once it is issued; we would rather show you an honest status than a number we do not yet hold.
Data protection contact: privacy@laces.run, or write to the postal address above.
Requests reach a named individual responsible for data protection within Apta Innovations Limited. No separate Data Protection Officer has been formally designated, and we will name one here if and when the appointment is made rather than implying a role that does not exist.
2. The short version
- We collect what is needed to sell you an entry, get you a ticket, and let a volunteer hand you the right kit at the right tent.
- We do not sell personal data. Not to anyone, for any price.
- The organizer of the event you entered sees your registration data, because they need it to run the event you entered.
- You can ask for a copy of your data, or ask us to delete it, at privacy@laces.run.
3. Who is the controller: Laces, or the organizer?
This matters, and it is not the same answer for every field.
The organizer is the controller for the registration data of the participants in their event: the answers to their sign-up questions, the waiver acceptance, the emergency contact, the shirt size. They decided to collect it and they decide what it is used for within their event. Laces processes it on their behalf.
Laces is the controller for the account data of organizers, for payment and order records, for the platform’s own logs and security data, and for the records we are required to keep independently of any one event.
In practice this means: a request about your registration in a specific race may need to involve that race’s organizer, and we will tell you when it does. A request about your Laces account or your payment record is ours to answer.
4. What we collect
4.1 From participants
| Data | Why we hold it |
|---|---|
| Full name | Identifies your entry; printed on the manifest and often the bib |
| Phone number | The ticket, collection reminders, and finding your order at the tent |
| Email address | Receipt, ticket PDF, and event notices |
| Emergency contact name and phone | Given to event medical staff if you are hurt during the event |
| Date of birth or age | Age-category entry rules, and results categories |
| Gender | Results categories, and shirt sizing where the organizer uses it |
| Shirt or kit size | Packing your kit and forecasting stock |
| District or nationality | Where the organizer collects it, usually for reporting to a sponsor or authority |
| Club or affiliation | Team standings and affiliation leaderboards |
| Waiver acceptance | The version accepted, the timestamp, and the IP address it came from |
| Order and payment records | The order code, amount, status, and the mobile-money reference |
| Collection records | Which items you were issued, at which station, by which volunteer, and when |
Medical information. Some organizers ask about allergies, conditions or medication. Under the DPA this is special personal data and gets stricter handling: it is collected only where the organizer has asked for it, it is visible only to the organizer and their designated medical staff, it is never used for anything but participant safety, and it is deleted on the schedule in section 8 rather than kept indefinitely.
4.2 From organizers
Account name, email, and phone; organisation name, handle, and contact details; the payout account and the KYC documentation required to verify it; and the audit trail of actions taken in the Admin App.
We do not store your password. Sign-in is handled by Firebase Authentication (Google), which holds the credential. Laces never receives or stores a password or a password hash.
4.3 Automatically
Device and browser information, IP address, and pages visited. Used for security, rate limiting, fraud prevention and understanding whether the checkout is working.
Analytics. The public site uses Google Analytics 4 via the Firebase
Analytics SDK. It records a single explicit event, page_view, carrying the
page path, page location and page title, alongside the session and device
information Google Analytics collects by default. IP addresses are handled
according to Google’s own processing
terms; Laces does not receive or
store a visitor IP through analytics, and we do not send any personal data (no
name, phone, email, order code or amount) to Google Analytics.
Analytics is deliberately absent from the pages that handle money. The checkout and the order-lookup pages mount no analytics at all, so those pages open no connection to Google. That is a design decision recorded in the code, not a configuration that might drift.
4.4 What we deliberately do not collect
- We never see or store your Mobile Money PIN. You enter it on your own handset, in your telco’s own prompt. It does not pass through Laces.
- We do not store full card numbers. Card payments are not supported.
- We do not track you across other websites, and we do not run advertising pixels on the race pages.
5. Why we are allowed to hold it
The DPA requires a lawful basis for each purpose:
| Purpose | Lawful basis |
|---|---|
| Selling you an entry and issuing your ticket | Performance of a contract with you |
| Handing you your kit and preventing double-issue | Performance of a contract; the organizer’s legitimate interest in running the event |
| Emergency contact and medical data | Your explicit consent, given at registration, plus the vital interests of the data subject where an emergency actually occurs |
| Sending transactional messages (receipt, collection reminder, refund notice) | Performance of a contract |
| Sending marketing about other races | Your consent, separately given, and withdrawable at any time |
| Fraud prevention, security and rate limiting | Our legitimate interest in a platform that is not abused |
| Keeping financial records | Legal obligation |
Consent is a real choice. Where we rely on consent, refusing it does not stop you entering a race. Marketing consent is a separate, unticked option, not a condition of registering.
6. Who sees your data
- The organizer of the event you entered, and the volunteers they have authorised, scoped to that event and, for station volunteers, often to a single collection station. Volunteers do not see revenue.
- Authorities, where we are legally required to disclose.
Our sub-processors
These are every third party that processes personal data on our behalf. The list is kept current; if we add one, it appears here.
| Provider | Role | What it receives | Their policy |
|---|---|---|---|
| Eversend | Payment collection and organizer payouts | Payer phone number, amount, order reference; payout account details | Privacy |
| Google Cloud / Firebase | Database, authentication, file storage, compute | All platform data at rest and in processing | Firebase · Google |
| Google Analytics 4 | Web analytics on public pages only | Page views, device and session data. No name, phone, email or order data | Analytics |
| Netlify | Hosting and serving laces.run |
Request logs, including IP address | Privacy |
| Resend | Sending receipts, tickets and transactional email | Recipient email address and message content | Privacy |
| Cloudflare | Turnstile bot protection, checkout page only | Browser and network signals used to tell a human from a script | Turnstile |
We do not send SMS, and no SMS provider processes your data. Tickets, receipts and notices go by email and are available on the order-lookup page.
We do not sell your data, and we do not share it with other organizers. Entering one race does not put you on another organizer’s list.
7. Where your data is held
Your data is stored and processed outside Uganda. Section 19 of the DPA requires us to say so plainly rather than leave it to be inferred:
| Layer | Where it runs |
|---|---|
| Database (registrations, orders, ledger) | Google Cloud Firestore, European Union multi-region (Belgium and the Netherlands) |
| Application servers (the API) | Google Cloud Functions, United States (Iowa, us-central1) |
| Website hosting | Netlify’s global content network |
| Email delivery | Resend |
| Payments | Eversend |
The safeguard we rely on is that each of these providers is contractually bound, under its own data-processing terms, to process personal data only on our instructions and to apply security measures at least equivalent to those required under the DPA. Google Cloud and Netlify both operate under standard contractual clauses for international transfers.
Why the data is not held in Uganda. No major cloud provider currently operates a data-centre region inside Uganda. Storing in the EU means the data sits under one of the stricter privacy regimes in the world; the alternative available to us was self-hosting, which would mean weaker physical security, weaker redundancy and a worse outcome for the people in the database.
By registering for an event or creating an account, you consent to this transfer. If you object to it, we cannot provide the service, because there is no version of the platform that runs without it.
8. How long we keep it
| Data | Retention |
|---|---|
| Registration data for a completed event | 24 months after the event, so a returning participant’s details can be pre-filled the next year. Deleted sooner on request |
| Special personal data (medical, allergies) | 90 days after the event ends. It exists for race-day safety and has no purpose after that |
| Order and payment records | 7 years, the period books and records must be kept under Uganda’s Income Tax Act and the Companies Act 2012 |
| Waiver acceptance records | 7 years after the event, covering the limitation period for a contract claim under the Limitation Act |
| Collection and audit records | 7 years. Append-only: they are the evidence that makes a disputed issuance or a stock discrepancy traceable, so they are never edited or selectively deleted |
| Ledger entries | 7 years. Append-only, for the same reason and the same statutory period |
| Organizer account and KYC data | For the life of the account, plus 7 years after closure |
| Web analytics records | 180 days, then permanently deleted by a scheduled job |
| Server and security logs | 90 days |
| A closed user account | 30 days after you request deletion, then the sign-in, user record and memberships are permanently deleted |
Be aware of what the financial-records row means in practice. An order, its amount, and the ledger entries behind it are kept for seven years even if you ask for deletion, because we are required to keep them and because they are also your proof of purchase. Section 9 explains what we can reduce them to.
Honest note on how retention is enforced. Analytics deletion (180 days) and account deletion (30 days) run automatically as scheduled jobs. The other periods in this table are policy, applied on request and on review, rather than an automatic timer on every record today. We would rather state that than imply a deletion pipeline we have not built.
When a retention period ends, data is deleted or irreversibly anonymised. Anonymised, aggregate figures, such as how many people ran a 10KM in Kampala in 2026, are not personal data and may be kept.
9. Your rights under the DPA
You have the right to:
- Be told what we hold about you and what we do with it. This document.
- Access your data and get a copy of it.
- Correct anything inaccurate.
- Delete your data, where we do not have an overriding legal obligation to keep it.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, where consent was the basis. Withdrawing marketing consent does not affect an entry you have already bought.
- Complain to the Personal Data Protection Office.
How to exercise them
Email privacy@laces.run from the address on your order, or write to us at P.O. Box 209717, Kampala GPO, Uganda.
We respond within 30 days. We aim to answer most requests in a few working days; 30 days is the outer limit and is the period the DPA allows. If a request is complex enough to need longer, we will tell you before the 30 days are up, and why.
Export. We will provide your data in a machine-readable format (your registrations, orders, and the answers you gave) within that same period.
Deletion. We will delete what we are not required to keep, and tell you plainly what is being retained and why. Financial records of a completed purchase generally cannot be deleted on request, because we are required to keep them; the registration data attached to them can be reduced to the minimum needed to keep the financial record intelligible.
There is no charge for either. We may ask you to verify your identity first, usually by confirming the phone number the order was placed with, because handing someone else’s registration data to whoever asks for it would be a worse failure than an inconvenient verification step.
Complaints
If you are not satisfied with how we have handled a request, you can complain to the Personal Data Protection Office (PDPO), the supervisory authority established under the DPA, at pdpo.go.ug. You do not have to come to us first, but we would rather you did, because we can usually fix it faster.
10. Security
What is actually in place. This section describes controls that exist today. We have deliberately not listed measures we intend to build, because a security claim a reader relies on and we have not implemented is worse than no claim at all.
- Data in transit is encrypted with TLS, enforced by HTTP Strict Transport Security so a browser will not fall back to an unencrypted connection.
- Data at rest is encrypted by Google Cloud Firestore’s server-side AES-256 encryption, applied to all stored data.
- A strict Content Security Policy governs what the site is permitted to load and where it may send data.
- Access is scoped by role. Volunteers reach one event, often a single collection station, and cannot see revenue figures: the permission check for financial data is a hard gate, not a hidden menu item.
- Every issuance, refund, manual payment mark, role change, device pairing and export writes to an append-only audit log, recording who did it and when. The system has no code path that edits or deletes an audit entry.
- Payment credentials and API secrets are held in Google Secret Manager and never reach the browser. The keys present in the page (the Firebase web key, the Turnstile site key, the reCAPTCHA site key) are public, domain-scoped keys designed to be visible, and grant no access on their own.
- A withdrawal requires a fresh one-time code, emailed to the requesting user and bound to that specific amount and destination. Only a hash of the code is stored, and it is checked inside a single atomic transaction.
- Automated abuse controls: Cloudflare Turnstile at checkout, Firebase App Check on the apps, and rate limiting on the API.
- We never see your Mobile Money PIN. You enter it in your telco’s own prompt, on your own handset.
What we do not yet have, stated plainly. Sign-in to an organizer account is by email and password through Firebase Authentication; multi-factor authentication is not currently enforced on sign-in. The one-time code described above protects withdrawals specifically: it is step-up verification on the action that moves money, not two-factor authentication on the account. We consider account-level MFA a priority, and this policy will be updated when it ships rather than in advance of it.
No system is perfectly secure. If a breach occurs that is likely to result in risk to you, we will notify you and the PDPO as the DPA requires.
11. Children
Children do run races. An entry for a participant under 18 must be completed by a parent or legal guardian, who provides their own contact details and accepts the waiver on the child’s behalf.
We collect the minimum needed to let a child take part safely. We do not market to children.
How guardian consent works. Where an organizer allows under-18s into a distance, the sign-up form for that event automatically requires a parent or guardian name and phone number, and the guardian accepts the waiver on the child’s behalf. The organizer sets the age limit; the guardian questions follow from it, so the two cannot fall out of step.
Someone other than a guardian may complete the purchase: a school, a club, or an employer buying a block of entries. Where that happens, the buyer is responsible for having the guardian’s permission, and the guardian’s details must still be given for the entry.
Be aware of the limit of this control. Laces does not independently verify a participant’s age or a guardian’s identity. The rule above is a condition of using the platform that organizers and buyers must meet, enforced through the registration form and the organizer’s own checks at kit collection, not a technical guarantee we can make on our own. If you believe a child has been registered without their guardian’s knowledge, contact privacy@laces.run and we will act on it.
12. Cookies
Laces uses the minimum set of cookies and local storage needed to run the site. This is the complete inventory.
Set by Laces
| Name | Purpose | Expires |
|---|---|---|
laces_registrant_name, laces_registrant_phone, laces_registrant_email, laces_registrant_kin_name, laces_registrant_kin_phone |
Pre-fills your details the next time you enter a race, so you do not retype them | 30 days |
These are written only after you successfully submit a registration, never
as you type, and they are SameSite=Lax and Secure. Clearing your browser
cookies removes them, and the site works normally without them.
laces_trace in local storage is a developer diagnostic switch. It holds no
personal data.
Set by our providers
| Set by | Purpose | Where |
|---|---|---|
| Google Analytics / Firebase | Distinguishes one visit and one device from another for page-view measurement | Public pages only |
| Firebase Authentication | Keeps you signed in (browser storage, not a cookie) | Signed-in areas |
| Cloudflare Turnstile | Confirms the checkout is being used by a person, not a script | /pay only |
| Google reCAPTCHA | Supports Firebase App Check’s abuse protection | App surfaces |
Neither the checkout nor the order-lookup page loads analytics, so no measurement cookie is set on the pages where you enter payment details or view an order.
We run no advertising cookies, no advertising pixels, and no cross-site tracking. You can block or clear any of the above in your browser; only the sign-in storage is required for a signed-in account to work.
13. Changes
We will update this policy as the platform changes. Material changes will be notified by email to the address on your account. The date at the top is the last update.
14. Contact
Apta Innovations Limited (trading as Laces) Company registration 80045435006790
- Data protection: privacy@laces.run
- Legal: legal@laces.run
- Registered office: Kyanja, Kisaasi Central A, Nakawa Division, Kampala, Uganda
- Postal: P.O. Box 209717, Kampala GPO, Uganda
- Supervisory authority: Personal Data Protection Office, Uganda, pdpo.go.ug