Trust & Security
Registered, accountable, and built carefully.
Laces takes money from runners and settles it to organizers, so the least we owe you is a straight account of how that is protected. Below is what is actually in place today, who we are as a legal entity, and, in its own section, what we do not yet have.
- Registered Ugandan company
- TLS + HSTS everywhere
- AES-256 encryption at rest
- Licensed payment partners
- Append-only audit log
- We never see your PIN
Who you are dealing with
Laces is a product of Apta Innovations Limited, a private company limited by shares incorporated in Uganda. These are the same details that appear in our Terms and in every merchant agreement we sign.
- Registered company
- Apta Innovations Limited
- Company registration
- 80045435006790
- Incorporated
- 10 July 2026, Republic of Uganda
- Governing statute
- Companies Act 2012
- Registered office
- Kyanja, Kisaasi Central A, Nakawa Division, Kampala, Central, Uganda
- Registered postal
- P.O. Box 209717, Kampala GPO, Uganda
- Trading as
- Laces (laces.run)
- Data protection registration
- Personal Data Protection Office: application in progress
Laces is software. The money is moved by licensed partners.
Apta Innovations Limited is not a bank, not a deposit-taker, and not a licensed payment service provider. We do not hold client funds as a financial institution. Collection and payout are performed by licensed aggregators, Flutterwave and Eversend, under their own authorisations and their own terms. We say this in Recital B of our Merchant Service Agreement rather than leaving it to be assumed.
The licensed aggregators we use
Because Laces is not licensed to move money itself, every payment runs through a licensed aggregator that is. They are regulated in their own right, they hold the authorisations, and they publish their own licence registers, so you can verify them without taking our word for it. The current list is Schedule 2 of the Merchant Service Agreement.
Eversend
PrimaryMobile money collection at checkout, and instant transfers when an organizer withdraws.
Flutterwave
Refunds and historical activityProcesses refunds, and remains the rail for payments taken before the move to Eversend.
Payments made through a partner are also subject to that partner's own terms. We may add, replace or remove a partner under clause 3.5 of the Merchant Service Agreement; when we do, this list and the sub-processor table in our Privacy Policy change with it.
What is actually in place
Every item below exists today. We have deliberately not listed measures we intend to build, because a security claim you rely on and we have not implemented is worse than no claim at all.
Encrypted in transit and at rest
Every connection uses TLS, enforced by HTTP Strict Transport Security so a browser will not fall back to an unencrypted one. Stored data is encrypted with Google Cloud Firestore's server-side AES-256.
Your Mobile Money PIN never reaches us
You enter it in your telco's own prompt, on your own handset. It does not pass through Laces, and there is no screen anywhere on the platform that asks for it.
No card numbers, because there are no cards
Laces collects by mobile money. We do not store full card numbers, and we never ask for one.
Payment secrets never reach the browser
API credentials live in Google Secret Manager. The keys visible in the page (Firebase web, Turnstile, reCAPTCHA) are public, domain-scoped keys designed to be seen, and grant no access on their own.
Withdrawals need a fresh one-time code
Emailed to the requesting user and bound to that specific amount and that specific destination, so an intercepted code cannot authorise a different payout. Only a hash is stored, and it is checked inside a single atomic transaction.
Access is scoped by role
A volunteer reaches one event, often a single collection station, and cannot see revenue. The permission check on financial data is a hard gate, not a hidden menu item.
An append-only audit log
Every issuance, refund, manual payment mark, role change, device pairing and export records who did it and when. The system has no code path that edits or deletes an audit entry.
Automated abuse controls
Cloudflare Turnstile at checkout, Firebase App Check on the apps, rate limiting on the API, and a strict Content Security Policy governing what the site may load and where it may send data.
Where your data is held
Your data is stored and processed outside Uganda. Section 19 of the Data Protection Act requires us to say so plainly rather than let it be inferred.
Database
Registrations, orders, ledger
Google Cloud Firestore: European Union multi-region (Belgium, Netherlands)
Application servers
The API
Google Cloud Functions: United States (Iowa, us-central1)
Website
laces.run
Netlify's global content network
Email
Receipts and tickets
Resend
Payments
Collection and payouts
Eversend
Our sub-processors
Every third party that processes personal data on our behalf. The full table, with each provider's own privacy policy, is in the Privacy Policy. We do not sell your data, and entering one race does not put you on another organizer's list.
Eversend
Payment collection and organizer payouts
Flutterwave
Refunds and payments taken before the Eversend move
Google Cloud / Firebase
Database, authentication, storage, compute
Netlify
Hosting and serving laces.run
Resend
Receipts, tickets and transactional email
Cloudflare
Turnstile bot protection, checkout only
Google Analytics 4
Public pages only, never checkout or order lookup
Stated plainly
A trust page that lists only strengths is a sales page. These are the things a reasonable person would want to know before trusting us, and they are disclosed in our Privacy Policy and Merchant Service Agreement too.
Multi-factor authentication is not enforced on sign-in.
Organizer sign-in is email and password through Firebase Authentication. The one-time code described above is step-up verification on withdrawals specifically, it protects the action that moves money, not the account. We consider account-level MFA a priority and this page will change when it ships.
We are not a licensed financial institution.
Laces is not a bank and holds no deposit-taking or payment licence. Regulated money movement is performed by licensed payment partners. Balances shown on Laces are a record of what an organizer is owed, not insured deposits.
Our data protection registration has not been issued yet.
Registration with the Personal Data Protection Office as a data collector, controller and processor is in progress. We will publish the number here once it is issued rather than showing one we do not hold. No separate Data Protection Officer has been formally designated; requests reach a named individual responsible for data protection within Apta Innovations Limited.
No system is perfectly secure.
If a breach occurs that is likely to result in risk to you, we will notify you and the Personal Data Protection Office as the Data Protection Act requires.
What Laces will never ask you for
If anyone asks for any of these (by call, SMS, WhatsApp or email, however convincing) it is not us.
- Your Mobile Money PIN, for any reason, on any channel
- Your password, or a one-time code sent to you
- Payment to a personal phone number or account to 'confirm' an entry
- Remote access to your phone or computer
Pay for an entry only on laces.run, and check the organizer's name on the race page before you pay. If something looks wrong, tell us at hello@laces.run.
Reporting a vulnerability
If you have found a security problem in Laces, we want to hear about it before anyone else does.
Email security@laces.run with enough detail to reproduce the issue. We will acknowledge you.
We will not pursue anyone who reports a genuine issue in good faith, provided you do not access, alter or retain other people's data while investigating, and you give us a reasonable chance to fix it before publishing.
For privacy requests instead, write to privacy@laces.run, or read the Privacy Policy.
Questions
No, and we do not present ourselves as one. Laces is software. Collection and payout of money are performed by licensed aggregators (Eversend, and Flutterwave for refunds and historical activity) under their own authorisations. This is stated in Recital B of our Merchant Service Agreement, and the partners are listed in its Schedule 2.
To the licensed aggregator handling that payment (Eversend, or Flutterwave on older activity) which settles it to the organizer's balance on Laces in real time. The organizer then withdraws it to their own bank or mobile money account, any day of the week. Laces holds no client funds as a deposit-taker and is not a bank.
No. You enter it in your telco's own prompt on your own handset. It does not pass through Laces, and no Laces screen, email or staff member will ever ask for it.
Outside Uganda. The database runs in Google Cloud Firestore's European Union multi-region (Belgium and the Netherlands), and the API runs in Google Cloud Functions in the United States. No major cloud provider currently operates a region inside Uganda; storing in the EU places the data under one of the stricter privacy regimes in the world.
Not at sign-in, and we would rather say so than imply otherwise. Withdrawals, the action that moves money, do require a fresh one-time code bound to the amount and destination. Account-level MFA is a priority and this page will change when it ships, not before.
Email security@laces.run with enough detail to reproduce it. We will acknowledge you, and we will not pursue anyone who reports a genuine issue in good faith and does not access, alter or retain other people's data while investigating.
The documents behind this page: Privacy Policy, Terms of Service, and the Merchant Service Agreement. Where this page and a legal document disagree, the document governs.