Skip to content

Trust & Security

Registered, accountable, and built carefully.

Laces takes money from runners and settles it to organizers, so the least we owe you is a straight account of how that is protected. Below is what is actually in place today, who we are as a legal entity, and, in its own section, what we do not yet have.

  • Registered Ugandan company
  • TLS + HSTS everywhere
  • AES-256 encryption at rest
  • Licensed payment partners
  • Append-only audit log
  • We never see your PIN

Who you are dealing with

Laces is a product of Apta Innovations Limited, a private company limited by shares incorporated in Uganda. These are the same details that appear in our Terms and in every merchant agreement we sign.

Lacesthe trading name of Apta Innovations Limited
Registered company
Apta Innovations Limited
Company registration
80045435006790
Incorporated
10 July 2026, Republic of Uganda
Governing statute
Companies Act 2012
Registered office
Kyanja, Kisaasi Central A, Nakawa Division, Kampala, Central, Uganda
Registered postal
P.O. Box 209717, Kampala GPO, Uganda
Trading as
Laces (laces.run)
Data protection registration
Personal Data Protection Office: application in progress

Laces is software. The money is moved by licensed partners.

Apta Innovations Limited is not a bank, not a deposit-taker, and not a licensed payment service provider. We do not hold client funds as a financial institution. Collection and payout are performed by licensed aggregators, Flutterwave and Eversend, under their own authorisations and their own terms. We say this in Recital B of our Merchant Service Agreement rather than leaving it to be assumed.

The licensed aggregators we use

Because Laces is not licensed to move money itself, every payment runs through a licensed aggregator that is. They are regulated in their own right, they hold the authorisations, and they publish their own licence registers, so you can verify them without taking our word for it. The current list is Schedule 2 of the Merchant Service Agreement.

Payments made through a partner are also subject to that partner's own terms. We may add, replace or remove a partner under clause 3.5 of the Merchant Service Agreement; when we do, this list and the sub-processor table in our Privacy Policy change with it.

What is actually in place

Every item below exists today. We have deliberately not listed measures we intend to build, because a security claim you rely on and we have not implemented is worse than no claim at all.

  • Encrypted in transit and at rest

    Every connection uses TLS, enforced by HTTP Strict Transport Security so a browser will not fall back to an unencrypted one. Stored data is encrypted with Google Cloud Firestore's server-side AES-256.

  • Your Mobile Money PIN never reaches us

    You enter it in your telco's own prompt, on your own handset. It does not pass through Laces, and there is no screen anywhere on the platform that asks for it.

  • No card numbers, because there are no cards

    Laces collects by mobile money. We do not store full card numbers, and we never ask for one.

  • Payment secrets never reach the browser

    API credentials live in Google Secret Manager. The keys visible in the page (Firebase web, Turnstile, reCAPTCHA) are public, domain-scoped keys designed to be seen, and grant no access on their own.

  • Withdrawals need a fresh one-time code

    Emailed to the requesting user and bound to that specific amount and that specific destination, so an intercepted code cannot authorise a different payout. Only a hash is stored, and it is checked inside a single atomic transaction.

  • Access is scoped by role

    A volunteer reaches one event, often a single collection station, and cannot see revenue. The permission check on financial data is a hard gate, not a hidden menu item.

  • An append-only audit log

    Every issuance, refund, manual payment mark, role change, device pairing and export records who did it and when. The system has no code path that edits or deletes an audit entry.

  • Automated abuse controls

    Cloudflare Turnstile at checkout, Firebase App Check on the apps, rate limiting on the API, and a strict Content Security Policy governing what the site may load and where it may send data.

Where your data is held

Your data is stored and processed outside Uganda. Section 19 of the Data Protection Act requires us to say so plainly rather than let it be inferred.

  • Database

    Registrations, orders, ledger

    Google Cloud Firestore: European Union multi-region (Belgium, Netherlands)

  • Application servers

    The API

    Google Cloud Functions: United States (Iowa, us-central1)

  • Website

    laces.run

    Netlify's global content network

  • Email

    Receipts and tickets

    Resend

  • Payments

    Collection and payouts

    Eversend

Our sub-processors

Every third party that processes personal data on our behalf. The full table, with each provider's own privacy policy, is in the Privacy Policy. We do not sell your data, and entering one race does not put you on another organizer's list.

  • Eversend

    Payment collection and organizer payouts

  • Flutterwave

    Refunds and payments taken before the Eversend move

  • Google Cloud / Firebase

    Database, authentication, storage, compute

  • Netlify

    Hosting and serving laces.run

  • Resend

    Receipts, tickets and transactional email

  • Cloudflare

    Turnstile bot protection, checkout only

  • Google Analytics 4

    Public pages only, never checkout or order lookup

Stated plainly

A trust page that lists only strengths is a sales page. These are the things a reasonable person would want to know before trusting us, and they are disclosed in our Privacy Policy and Merchant Service Agreement too.

  • Multi-factor authentication is not enforced on sign-in.

    Organizer sign-in is email and password through Firebase Authentication. The one-time code described above is step-up verification on withdrawals specifically, it protects the action that moves money, not the account. We consider account-level MFA a priority and this page will change when it ships.

  • We are not a licensed financial institution.

    Laces is not a bank and holds no deposit-taking or payment licence. Regulated money movement is performed by licensed payment partners. Balances shown on Laces are a record of what an organizer is owed, not insured deposits.

  • Our data protection registration has not been issued yet.

    Registration with the Personal Data Protection Office as a data collector, controller and processor is in progress. We will publish the number here once it is issued rather than showing one we do not hold. No separate Data Protection Officer has been formally designated; requests reach a named individual responsible for data protection within Apta Innovations Limited.

  • No system is perfectly secure.

    If a breach occurs that is likely to result in risk to you, we will notify you and the Personal Data Protection Office as the Data Protection Act requires.

What Laces will never ask you for

If anyone asks for any of these (by call, SMS, WhatsApp or email, however convincing) it is not us.

  • Your Mobile Money PIN, for any reason, on any channel
  • Your password, or a one-time code sent to you
  • Payment to a personal phone number or account to 'confirm' an entry
  • Remote access to your phone or computer

Pay for an entry only on laces.run, and check the organizer's name on the race page before you pay. If something looks wrong, tell us at hello@laces.run.

Reporting a vulnerability

If you have found a security problem in Laces, we want to hear about it before anyone else does.

Email security@laces.run with enough detail to reproduce the issue. We will acknowledge you.

We will not pursue anyone who reports a genuine issue in good faith, provided you do not access, alter or retain other people's data while investigating, and you give us a reasonable chance to fix it before publishing.

For privacy requests instead, write to privacy@laces.run, or read the Privacy Policy.

Questions

No, and we do not present ourselves as one. Laces is software. Collection and payout of money are performed by licensed aggregators (Eversend, and Flutterwave for refunds and historical activity) under their own authorisations. This is stated in Recital B of our Merchant Service Agreement, and the partners are listed in its Schedule 2.

The documents behind this page: Privacy Policy, Terms of Service, and the Merchant Service Agreement. Where this page and a legal document disagree, the document governs.