Privacy policy
Draft of 29 September 2026. Not yet in force.
This notice covers the AfterLap website and mobile apps. The beta is for adults aged 18 or older. We do not sell personal information or use it for targeted advertising.
1. Who is responsible
To be completed: provider name
To be completed: street and number
To be completed: postcode and city, Germany
Email: support@afterlap.io
2. What we use and why
Account and support
Google sign-in or an email link supplies your email address and account identifier. We store your display name, any chosen handle and preferences, including units and public identity. We process messages you send us to provide support. These uses provide the service you request (Art. 6(1)(b) GDPR); handling statutory privacy requests fulfils legal obligations (Art. 6(1)(c)). Providing data is voluntary, but account details and recording data are needed to use the corresponding features. Photos, personal vehicle labels and public identity are optional.
Location, recordings and weather
When you record, the app collects precise GPS position, altitude, speed and heading, accelerometer and gyroscope data, timestamps, and device information such as phone model, operating-system version, battery level and thermal status. Recording can continue in the background. This can reveal where and when you drive, including your starting location. The recording file stays on your phone until you choose to upload it. Uploaded recordings become times, speed and G-force traces, comparisons and replays. The app can ask your phone's platform provider to turn coordinates into a place name.
During recording, an online weather lookup sends coordinates and, when available, altitude to AfterLap even before you upload the recording. A weather provider receives an approximate location, without your account identifier or your device's IP address. Weather is saved with the session. These features provide the requested service (Art. 6(1)(b) GDPR). You control location access in your phone's settings; without it, GPS recording cannot work.
Vehicles
We store the specifications and optional photos, nicknames, modifications, tyres and paint you add. Vehicle identification sends your vehicle-description text and year to an AI service to suggest specifications, and a list of the model's factory colours is requested with only its make, model and year. When you add a car with a photo, a reduced copy of it is sent to the same AI service to suggest its make and model, and after you upload it, to suggest the car's paint colour; you can change both. We do not attach your account details or recordings to these requests; do not put personal information in the description, and prefer a photo without people or readable number plates. This supports the requested garage feature (Art. 6(1)(b) GDPR).
Public results and optional public identity
Uploading lets eligible results appear on public leaderboards, in public replays and as opponents in other users' races. Providing those shared comparisons is part of the service (Art. 6(1)(b) GDPR). By default, your displayed name is Anonymous: we withhold your name, handle, profile, photos, personal vehicle details and recording date. Results and the car's make and model remain visible. Lap and segment replays reveal the named course and driven line; acceleration and braking replays use a neutral strip without the original location.
Turning on public identity additionally publishes your display name, handle, profile, car photos, nickname, modifications, tyres and recording date. This is optional consent (Art. 6(1)(a) GDPR). Turn it off in Settings to withdraw consent for future display. This does not affect the lawfulness of earlier use or remove the underlying ranked results. We cannot recall copies others have already made of public information.
Technical data and cookies
Our infrastructure processes IP addresses, request times and URLs, browser or app information, and diagnostic logs to deliver, secure and troubleshoot the service. Our legitimate interests are preventing abuse and keeping AfterLap working (Art. 6(1)(f) GDPR). IP-derived country can set the map's initial view; we do not save it in your profile. Automated checks calculate and validate results; we do not use solely automated decisions with legal or similarly significant effects on you.
Necessary sign-in cookies, a units-preference cookie and local app storage support requested functions (§ 25(2) TDDDG). Web sign-in and units cookies are session cookies by default; your browser controls when its session ends, including any session-restore feature. If you choose “Keep me signed in”, we use persistent sign-in cookies and a preference cookie on that browser for up to 30 days with your consent (§ 25(1) TDDDG). Sign out to withdraw that choice and clear the sign-in cookies. Removing cookies can sign you out or reset preferences. The mobile app stores its sign-in session securely on your device until you sign out or the session is invalidated. We do not add advertising or analytics trackers or track you across unrelated websites. Do Not Track and Global Privacy Control signals do not change this behaviour: there is no data sale or cross-context advertising to opt out of.
3. Who receives data
We share data with the following categories of recipients as needed for the purposes above:
- Hosting, authentication and storage providers: account and vehicle data, recordings, photos, results and technical data.
- Recording-analysis and AI providers: sensor and location data for analysis; vehicle-description text and year for identification, and a reduced copy of vehicle photos to suggest the make, model and paint colour.
- Weather, map and place-name providers: locations needed for those features and, for direct requests from your device, your IP address and requested map areas.
- Sign-in and app-distribution providers: data needed when you use Google sign-in or obtain the app through an app store.
- Other users and visitors: public results and, if enabled, your public identity.
The providers we currently use are Apple, CARTO, Cloudflare, Esri, Google, MET Norway, Modal, OpenAI, Supabase and Vercel.
Google, Apple and map providers process direct interactions under their own privacy notices and may associate them with other information they hold about you. AfterLap does not request cross-site tracking. We may disclose information where legally required or necessary to establish or defend legal claims (Art. 6(1)(c) or (f) GDPR).
International processing
Providers may process data in the US and other countries outside the European Economic Area. These transfers rely on an adequacy decision, including the EU–US Data Privacy Framework for certified providers, or on the EU Standard Contractual Clauses in the providers' data-processing terms. Contact us for a copy of the safeguards relevant to your data.
4. Storage and deletion
We keep account and garage details while your account is active. You can delete recordings, vehicles or your account in the app or website. Deleting a vehicle also removes its recordings from your account. Account deletion removes your sign-in, profile, garage and composed races. Removed recordings and their results no longer appear in leaderboards, profiles, replays or other users' races, or contribute to rankings and comparisons. Associated photos and race files are removed through scheduled storage cleanup.
After deletion, recording data (including location and timestamps), calculated results and vehicle specifications are retained internally for statistics and service development (Art. 6(1)(f) GDPR), without the account association or personal labels. These data are not available to other users and currently have no automatic expiry. You can request erasure as described below.
Support messages are kept for the request and any related unresolved dispute or legal retention requirement. Technical logs expire under the providers' retention schedules; copies in backups remain until those backups rotate out. Information needed for an ongoing security incident or legal obligation may be kept until that need ends.
5. Your privacy rights
You can edit your profile and preferences in Settings. For privacy questions or requests, contact support@afterlap.io.
Where the GDPR applies, you have rights to access, correction, erasure, restriction of processing and data portability, subject to its conditions. You may object to processing based on legitimate interests for reasons relating to your situation. You can withdraw consent at any time, including by turning off public identity in Settings; this does not affect earlier lawful processing. You can also complain to a data protection authority, particularly where you live or work in the EEA or where an alleged infringement occurred.
US residents can use the same contact to exercise rights under applicable state law. We may request information needed to verify your identity before handling a request.
6. Changes
The date above identifies this version. We post updates here and notify account holders of material changes by email or a prominent notice in the service before they take effect. Where a new use requires consent, we ask separately.