Privacy Policy
This Privacy Policy explains what personal data we collect when you use the Lapvio service, why we collect it, how we use and share it, and the rights you have over it.
It applies to the Lapvio service in all its forms: the driver app at lapvio.com, the Lapvio mobile app for Android and iOS, organizer admin portals at [organizer].lapvio.com/admin, and the driver event portals at [organizer].lapvio.com/d/[token]. It also applies to our marketing site, our emails to you, and any other interaction you have with Lapvio. If you installed the Lapvio app from Google Play or the App Store, this is the privacy policy for that app.
If you only have time for the short version: we collect the minimum we need to run the service, we never sell your data, we use a small number of well-known suppliers to host and process it, you can see and delete your data at any time, and we'll tell you clearly before anything material changes.
1. Who is responsible for your data
Lapvio is operated by Amahi s.r.o., a Czech limited liability company with registered office at Kurzova 2222/16, Stodůlky, 155 00 Praha 5, Czech Republic, ID No. (IČO) 29494621, VAT No. (DIČ) CZ29494621, registered with the Municipal Court in Prague, file C 447404. In this policy, "Amahi," "we," "us," and "our" refer to Amahi s.r.o.; "Lapvio" refers to the service.
For privacy questions, exercising your rights, or any other data-protection matter, contact us at privacy@lapvio.com. For everything else: info@lapvio.com. Postal address: Kurzova 2222/16, Stodůlky, 155 00 Praha 5, Czech Republic.
We are not legally required to appoint a Data Protection Officer, and we have not appointed one. Privacy questions go to privacy@lapvio.com and are handled by Amahi s.r.o. directly.
When we are the controller, and when we are not
Lapvio has two distinct sides. Which one applies determines who is responsible for your data under the GDPR.
The driver app (lapvio.com and the Lapvio mobile app). When you create a Lapvio account, log a trackday, follow another driver, publish a post, or upload a car photo, Amahi s.r.o. is the controller of that data. We decide what we collect and why, and this Privacy Policy describes it.
Organizer event portals ([organizer].lapvio.com/d/[token]). When you register for a specific trackday (submit your details, sign a waiver, complete a briefing), the organizer running that event is the controller of the data you provide for that event. They decide why they collect it (to run their event, to comply with their insurance, to communicate with you about the day). We act as their processor under a Data Processing Agreement with each organizer. We process that data on their instructions, using our infrastructure, but we do not decide what to do with it.
In practice this means: when you ask "why does this organizer have my phone number?", that's a question for the organizer. When you ask "why does Lapvio show my trackday history on my profile?", that's a question for us, and the answer is in this policy.
Coaches you book. There is a third case. When you book a coaching session from a coach on Lapvio, we pass your booking details (your name, email, phone, and any note you add) to that coach so they can deliver the session. For that data, the coach is an independent controller; they decide how to use it to run their session, under their own responsibility, and we are neither their processor nor a joint controller. We describe this sharing in Section 4.3. Our own processing of your booking (taking the payment, recording the order on your account) is covered by this policy, with us as controller.
The two sides connect through your Lapvio profile. If you claim a profile, your verified event history from organizers becomes visible on your Lapvio profile (subject to your privacy settings). At that point we are the controller of the display of that history, while the underlying event registration data remains under the relevant organizer's control.
2. What data we collect
2.1 When you create a Lapvio account
To create an account, at lapvio.com or in the mobile app, you give us your email address. During the OTP sign-in flow we send a 6-digit code to that address; verifying the code creates your account. You then choose a display name, a username (which becomes part of your public profile URL lapvio.com/[username]), and optionally an avatar, a short bio, and a home circuit.
We also collect:
- IP address and rough device information (browser, operating system), captured automatically by our hosting provider
- Authentication metadata, when you logged in, from what session
- Your theme preference (dark / light) and language preference
- Your marketing-email opt-in choice
2.2 When you use Lapvio
As you use the service we collect data about what you do with it:
- Trackdays you log manually: date, circuit, car, slot type, optional notes, optional best lap time, optional onboard video link, your visibility choices for each
- Cars you add to your garage: make, model, year, optional licence plate, optional notes, optional photo, tags
- Followers and following: the social graph of who you follow and who follows you
- Achievements you earn: the list of badges and when each was awarded
- Linked email addresses: additional emails you verify so we can merge history from different organizers into one account
- Coaching sessions you book: which coach, which session, the date, and the booking details (name, email, phone, any note) that we pass to the coach to deliver it
- Posts and social content: posts you publish, comments and replies, mentions, reactions, and the photos and videos you attach to any of them, each visible according to the audience you chose for it
- Chats and direct messages: the messages you send and receive on Lapvio, and who you exchanged them with
- Content reports and blocks: reports you submit about someone else's content, reports others submit about yours, and the list of users you have blocked
- Lap-timing files you import: files you choose to import from your lap timer (for example a RaceBox CSV export), including lap and sector times and the precise GPS trace your lap timer recorded on track, from which we derive things like your racing line and the start/finish coordinates of the circuit
- Push notification data: your device's push token, basic device information (platform and model), and your notification preferences, collected only if you turn notifications on
- In-app announcements you've seen: when the app shows you a Lapvio announcement (a short tap-through story), we record that you've seen it and whether you finished it, so we don't replay it
- Enquiries and feedback: enquiries you send to a Coach, feedback you send us from the app, and demo requests from our marketing site. These submissions also record your IP address and browser type, which we use only for abuse prevention
- Your privacy and notification preferences
2.3 When you attend an organizer's trackday
When an organizer registers you for an event (directly, or via WooCommerce sync from their shop), they create a registration record on our infrastructure. The data in that record is collected by the organizer, not by us, but it travels through Lapvio. Typically it includes your name, email, phone number, language preference, slot type, car details, and licence plate. The organizer decides exactly what to ask.
When you complete the registration flow on their event portal, the organizer also collects:
- Confirmation that you completed the safety briefing and when
- A signed waiver, handled by DocuSeal on the organizer's behalf, returned as a PDF and an audit trail
- Any notes the organizer adds about you (their CRM)
- Day-of check-in status, group/pit/transponder assignments, and any flags they record (payment due, incident, no-show, etc.)
Your Lapvio account is not required to attend an organizer's trackday; magic-link access works without it. If you do not have a Lapvio account, none of the data above touches your Lapvio profile, because there is no Lapvio profile.
2.4 If an organizer registers you for an event before you've signed up to Lapvio
When an organizer registers you for an event, we may hold your name and email so that signing up to Lapvio later is seamless and your event history is already there when you arrive. This placeholder is not visible to anyone and does not give anyone access to an account. If you never sign up, we anonymise it after five years of inactivity.
2.5 What we do not collect
We don't ask for and don't collect:
- Date of birth, ID numbers, government-issued documents, or photographs of your driving licence (organizers may request these; we store what they collect on their behalf, but Lapvio itself does not)
- Bank account or payment card numbers: Stripe handles all payment data, we never see it
- Health information
- Live device location: neither the website nor the mobile app tracks where your device is, and the app does not run any GPS tracking of its own. One honest caveat: lap-timing files you choose to import (Section 2.2) contain precise GPS positions recorded on track by your lap timer, and we store and process those as part of your trackday history, but only because you imported them
- Information from third-party social networks beyond what you give us at signup
2.6 Cookies and similar technologies
We use cookies for sign-in, language and theme preferences, consent storage, and (only with your consent) for Google Analytics and the Meta Pixel. Full detail is in the Cookie Policy.
The mobile app does not use advertising cookies. Its usage analytics (PostHog) and crash diagnostics (Sentry) are described in Sections 3 and 4.1, and you can turn analytics off at any time in the app settings.
3. Why we process your data, and the legal basis for each purpose
Under GDPR Article 6, every processing activity needs a lawful basis. Here is each thing we do with your data and why we are entitled to do it.
| What we do | Lawful basis | Plain explanation |
|---|---|---|
| Create and maintain your Lapvio account | Contract, Article 6(1)(b) | We need to process your email and credentials to give you the account you signed up for |
| Display your public profile, history, and garage | Consent, Article 6(1)(a) | At signup you choose the privacy setting for each section. Default is public; you can change any of it |
| Send transactional emails (OTP codes, claim invitation, post-event recap, achievement notifications) | Contract / legitimate interest, Article 6(1)(b) and (f) | These emails are necessary to operate the service |
| Send marketing emails about new features, new circuits, organizers joining the platform | Legitimate interest with opt-out, Article 6(1)(f) and Czech Act 480/2004 §7(3) | You can opt out at any time using the link in every marketing email or in your settings. We rely on the customer-relationship exception in Czech law |
| Provide your data to organizers as their processor | Article 6(1)(b) for the organizer; Article 28 for our role | When you register for an organizer's event, we hold their data on their behalf. Their privacy notice covers the controller side |
| Pass your booking details to a coach you booked | Contract, Article 6(1)(b) | When you book a coaching session, we share your name and contact details with the coach so they can deliver it. The coach is then an independent controller (Section 4.3) |
| Operate the social feed, chats, and public content | Contract, Article 6(1)(b) | Posting, commenting, reacting, and messaging are part of the service you signed up for. Who can see what follows the visibility settings you choose |
| Moderate content and act on reports and blocks | Legitimate interest and legal obligation, Article 6(1)(f) and (c) | We review reported content, honour blocks, and remove content that breaks our rules or the law, to keep the platform safe for everyone |
| Send push notifications to your device | Contract and consent, Article 6(1)(b) and (a) | Only if you turn notifications on, via the operating system permission and your in-app preferences. You can turn them off at any time in the app settings or in your device's settings |
| Run analytics with Google Analytics 4 | Consent, Article 6(1)(a) | Only after you accept analytics cookies in the banner |
| Run advertising measurement with Meta Pixel | Consent, Article 6(1)(a) | Only after you accept marketing cookies in the banner |
| Measure how the mobile app is used, with PostHog (EU-hosted) | Legitimate interest, Article 6(1)(f) | Usage analytics that show us which features work and which don't. You can opt out at any time with the analytics toggle in the app settings |
| Diagnose crashes and errors in the mobile app, with Sentry (EU-hosted) | Legitimate interest, Article 6(1)(f) | When the app crashes or misbehaves, a diagnostic report tells us what went wrong so we can fix it |
| Detect, prevent, and respond to fraud, abuse, and security incidents | Legitimate interest, Article 6(1)(f) | We need to keep the platform safe |
| Comply with legal obligations (tax records, lawful requests from authorities) | Legal obligation, Article 6(1)(c) | When the law requires us to keep or share data |
| Defend legal claims | Legitimate interest, Article 6(1)(f) | We may keep relevant data while a dispute is unresolved |
A note on consent
Where consent is the basis (your public profile defaults, analytics cookies, marketing cookies), you can withdraw it at any time. Withdrawal does not affect anything we did before withdrawal, but we stop the processing from then on. For analytics and marketing cookies, the link to revisit your choices is in the footer of every page. In the mobile app, the analytics opt-out toggle is in the app settings, and push notifications can be turned off there or in your device's settings.
A note on promoted content
The feed and the app may show clearly marked promoted content, from organizers or from Lapvio itself. For promoted content we measure only aggregate view and click counts. We do not build a per-user advertising profile, and we do not share any of your personal data with the party whose content is promoted.
4. Who we share your data with
We share data in four ways: with sub-processors who run parts of our infrastructure, with organizers when you register for their events, with coaches when you book a session from them, and with the public through your profile (if you've made it public). We never sell your data to anyone.
4.1 Sub-processors
These are companies we use to run Lapvio. Each one only sees the data they need for their specific role, and each is bound by a Data Processing Agreement that meets GDPR Article 28 requirements.
| Provider | What they do | What they receive | Where |
|---|---|---|---|
| Supabase | Database, file storage, authentication | Everything in the service, but encrypted at rest and accessed only by Lapvio code | EU (eu-central-1, Frankfurt) |
| Vercel | Application hosting, server logs | Page requests, IP addresses, application logs | Regional, including EU and US edge locations |
| Postmark | Transactional email delivery | Recipient email, subject line, email content, delivery status | United States (DPF certified) |
| DocuSeal | Waiver signing on behalf of organizers | Driver name, email, waiver content, signed PDF, audit trail | EU (DocuSeal EU servers) |
| Stripe | Payment processing for trackday bookings, coaching sessions, and coaching content where an organizer, coach, or instructor uses Stripe Connect | Payment amount, currency, your name and email (for the receipt), card data (handled directly by Stripe, we never see it) | Ireland and United States |
| Google (OAuth) | Sign-in for organizer admins only | Email and name from your Google account | United States (DPF certified) |
| QuickChart | QR code image generation for check-in | Driver name, event ID, encoded in the QR | United States |
| Google Analytics 4 (loaded via Google Tag Manager) | Aggregate usage analytics, only with consent | Truncated IP, device fingerprint, page interactions | United States (DPF certified) |
| Meta Pixel | Advertising measurement, only with consent | IP, device ID, browser type, page interactions, referral source | United States (DPF certified) |
| Expo | Push notification delivery for the mobile app | Device push token, notification content | United States (DPF where applicable) |
| Google Firebase Cloud Messaging | Transport of push notifications to Android devices | Device push token, notification content | United States and EU (DPF certified) |
| Mapbox | Map tiles for the circuits map | Your device's IP address when map tiles load | United States |
| PostHog | Mobile app usage analytics | Usage events, device model, app version | EU (hosted in Germany) |
| Sentry | Crash and error diagnostics for the mobile app | Crash reports: device model, OS version, app state at the time of the error | EU (EU data residency) |
We keep this list current. When we add or remove a sub-processor, we update this page and post a notice. If you sign up for our notification list (via your account settings), we'll email you about changes.
4.2 Organizers
When you register for an organizer's event, that organizer sees the registration data you provide, plus any data they ask for and any data they generate about you (notes, flags, check-in status). We share this with them because they are the controller of it; it is their event, their data, their relationship with you.
If you have a claimed Lapvio profile, an organizer running an event you attend may also see basic profile information: your display name and language preference, so they can recognise you in their CRM and address you correctly.
Organizers do not see data from other organizers' events. They do not see your manual trackday entries, your followers, or your activity on the rest of the platform.
4.3 Coaches you book from
When you book a coaching session from a coach on Lapvio, we share with that coach the details they need to deliver it: your name, email, phone number, and any note you added to the booking. We share this because the coach is the seller of the session and needs it to provide the service you bought.
Once we have shared it, the coach is an independent controller of that data, not our processor. They must use it only to deliver and administer your session and for purposes you would reasonably expect, give you their own privacy information where the law requires it, and meet their own GDPR obligations toward it. If you want to know how a particular coach handles your data, or to exercise your rights against the coach, contact the coach directly. If you can't reach them, email privacy@lapvio.com and we'll help where we can.
Coaches also use Lapvio tools to run their coaching business. They receive enquiries you send them through their Lapvio profile, and they may keep notes about the people they coach in their Lapvio coach workspace. For those enquiries and notes, too, the coach is the controller and we act as their processor: we store that data on the coach's behalf and on their instructions, and questions about it belong to the coach. When you submit an enquiry to a Coach, we also record your IP address and browser type on our own behalf, purely for abuse prevention (legitimate interest, Article 6(1)(f)).
Coaches do not receive your manual trackday entries, your followers, your activity elsewhere on the platform, or any booking other than the one you made with them.
4.4 Other Lapvio drivers and the public
Your public profile (at lapvio.com/[username]) is visible to anyone, signed in or not, depending on your privacy settings. By default the following sections are public:
- Display name, username, avatar, bio, home circuit
- Event history (verified events from organizers and any manual entries you've marked public)
- Cars in your garage
- Circuits map
- Achievements
- Following list
By default the following are private:
- Lap times
- Email address (always private)
- Manual entries you've marked private
- Marketing and notification preferences
You can change any of these defaults in your privacy settings.
Posts, comments, and reactions you publish in the feed are visible according to the audience you chose when posting. Comments and reactions are visible to whoever can see the content they are attached to.
If you follow another driver, your username is visible in their followers list (subject to their privacy settings).
4.5 Sharing to other apps, and public post links
You can share your content and your Lapvio cards (a lap time, an achievement, a post) to third-party apps such as Instagram Stories or WhatsApp. Sharing is always something you start yourself, and once the content arrives in the other app, that platform's own terms and privacy policy apply to it. When you share to Instagram Stories, the app identifies itself to Meta with a Lapvio app identifier so Instagram accepts the share; beyond the image you chose to share, we do not send Meta any of your personal data in that flow.
Posts also have public permalink pages at lapvio.com/p/.... Anyone with the link can view such a page, and search engines may index it, in each case according to the visibility settings of the post.
4.6 Authorities, lawyers, advisors
We may share data with public authorities (police, tax authorities, courts) if a binding legal request requires it. We push back on overly broad requests where the law lets us. We may also share data with our professional advisors (accountants, lawyers, auditors) under their own duty of confidentiality.
4.7 In a corporate transaction
If Amahi s.r.o. is sold, merges with another company, or has its assets acquired, your data may transfer to the buyer. We will tell you in advance and you'll have the right to delete your account before any transfer takes effect.
5. International transfers
Some of our sub-processors are based in the United States. Whenever we send personal data to the US, we rely on:
- The EU-US Data Privacy Framework for providers that are certified under it (Google, Meta, Postmark, Stripe US entity, and Expo where applicable)
- Standard Contractual Clauses (the European Commission's 2021 SCCs) as a backup, signed with each provider
- Supplementary measures where required: at minimum, encryption in transit and at rest
Supabase data and DocuSeal data stay in the EU. PostHog and Sentry are configured for EU hosting, so mobile app analytics and crash data stay in the EU too. Vercel hosts at edge locations including EU data centres; the application data itself remains in Supabase. Mapbox receives your device's IP address in the United States when map tiles load; that transfer relies on the safeguards above.
If the EU-US Data Privacy Framework is invalidated by the courts, we will switch to SCCs alone and notify you of any material change in protection.
6. How long we keep data
The general principle: we keep data only as long as we have a reason to. Specifically:
| Type of data | Retention |
|---|---|
| Active Lapvio account data | Until you delete your account |
| Deleted Lapvio account data | Anonymised within 30 days of deletion request: display name replaced with "Deleted driver", avatar/bio/garage/manual entries/followers cleared. Event registration data held on behalf of organizers stays under the organizer's retention policy |
| Unclaimed shell profiles | 5 years from the last event activity associated with that email, then anonymised |
| Social content (posts, comments, reactions, attached media) | Until you delete the content, or until you delete your account |
| Imported lap-timing files and the data derived from them | Until you delete the import, or until you delete your account |
| Push notification tokens | Deleted when you log out, when you delete your account, or when the token stops working |
| Server logs (IP, request data) at Vercel | 30 days |
| Application logs at Supabase | 90 days |
| Email delivery logs at Postmark | 45 days |
| Marketing email opt-out records | Indefinitely (we have to remember not to email you) |
| Tax-relevant data (invoices, payment records) | 10 years from end of tax year (Czech Act 235/2004 on VAT) |
| Disputes and legal claims | For the duration of the dispute plus the limitation period |
When data is no longer needed for any of these purposes, we either anonymise it (so it is no longer personal data) or delete it.
7. Your rights
Under the GDPR you have specific rights over your data. We honour all of them, free of charge, and respond to any request within 30 days (extendable by 60 days for complex requests, with notice).
| Right | What it means | How to use it |
|---|---|---|
| Access, Article 15 | A copy of the data we hold about you | Email privacy@lapvio.com or use the data export tool in your account settings (when available) |
| Rectification, Article 16 | Correct inaccurate or incomplete data | Most data is editable directly in your settings. For anything you can't edit, email us |
| Erasure / "right to be forgotten", Article 17 | Delete your data | Use the delete-account button in settings, or email us; see Account and Data Deletion for the full process. We anonymise per the retention table above |
| Restriction, Article 18 | Limit how we use your data while a dispute is being resolved | Email us with the specific reason |
| Portability, Article 20 | Receive your data in a portable format you can move elsewhere | Email us; we'll send a JSON or CSV export |
| Objection, Article 21 | Object to processing based on legitimate interest, including direct marketing | Click the unsubscribe link in any marketing email, change your settings, or email us. Marketing objections are honoured immediately and unconditionally |
| Withdraw consent | Take back consent for any consent-based processing | Change your settings or revisit the cookie banner via the footer link |
| Complaint to a regulator | Lodge a complaint about how we handle your data | Czech: Úřad pro ochranu osobních údajů (uoou.cz). You can also complain to the data protection authority of your country of residence |
To exercise any right, email privacy@lapvio.com from the email address linked to your account, or use the controls in your settings. We may ask one or two security questions to verify it's really you before acting.
If we deny a request (for example, if you ask us to delete data we are legally required to keep), we will explain why and tell you what your options are.
8. Children
Lapvio is not intended for anyone under 18. Trackday participation generally requires a driving licence, and we don't accept account signups from minors. If you believe a minor has created an account, email privacy@lapvio.com and we will close it.
9. How we keep your data secure
We apply the security measures appropriate for a service of our size and risk profile:
- All data is encrypted in transit (TLS 1.2+) and at rest (Supabase database encryption, storage bucket encryption)
- Authentication is OTP-only: no passwords to lose or reuse
- Magic-link tokens are stored as SHA-256 hashes; the raw token is never stored or logged on our servers
- Access to production systems is limited to a small number of authorised people, all with multi-factor authentication
- We follow least-privilege principles: sub-processors only see what they strictly need
- We log all admin access for audit
- We rely on our sub-processors' security certifications (Supabase: SOC 2 Type II; Vercel: SOC 2; Stripe: PCI DSS Level 1)
No system is perfectly secure. If a breach occurs that is likely to result in a risk to you, we will notify you and the Czech ÚOOÚ within 72 hours of becoming aware, in accordance with GDPR Articles 33 and 34.
10. Changes to this policy
We may update this policy as the service changes, the law changes, or we change sub-processors. The "last updated" date at the top tells you when the most recent version went live, and a version number identifies which one applies.
For minor changes (fixing typos, clarifying wording), we update the page in place.
For material changes (for example, adding a new processing purpose, adding a new sub-processor, changing retention periods materially, or changing how rights work), we will:
- Email all account holders at least 14 days before the change takes effect
- Show an in-app notice the next time you sign in
- Require re-acceptance if the change requires it under the GDPR
You always have the right to delete your account if you don't agree with a change.
11. Contact and Imprint
Contact
Privacy and data protection questions: privacy@lapvio.com
General contact: info@lapvio.com
Postal address: Amahi s.r.o., Kurzova 2222/16, Stodůlky, 155 00 Praha 5, Czech Republic
Identification of the operator (Imprint / Provozovatel / Anbieterkennzeichnung)
In accordance with §435 of Czech Act No. 89/2012 (Civil Code), the Czech Act No. 634/1992 on consumer protection, and §5 of the German Digital Services Act (DDG, formerly TMG), the operator of the Lapvio service is:
Amahi s.r.o.
Kurzova 2222/16, Stodůlky
155 00 Praha 5
Czech Republic
ID No. (IČO): 29494621
VAT No. (DIČ): CZ29494621
Registered with the Municipal Court in Prague, file C 447404
Email: info@lapvio.com
The company is represented by its statutory body in accordance with the entry in the Czech Commercial Register. Current details on the registered representative are available at or.justice.cz.
Out-of-court dispute resolution for consumers
Under §14 of Czech Act No. 634/1992 on consumer protection, consumers have the right to out-of-court resolution of disputes arising from this service. The competent body is:
Česká obchodní inspekce (Czech Trade Inspection Authority)
Štěpánská 567/15, 120 00 Praha 2
coi.cz · adr.coi.cz
Consumers in the European Union may also use the EU Online Dispute Resolution platform at ec.europa.eu/consumers/odr to start an ADR procedure online.
We will respond to any out-of-court dispute resolution proposal sent to us by ČOI or via the ODR platform.
Supervisory authority for personal data
Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7
Czech Republic
uoou.cz · posta@uoou.cz · +420 234 665 111
You can complain to ÚOOÚ (or to the data protection authority of your country of residence) if you believe we have mishandled your personal data.