Lacet Privacy Policy

Last updated: 20 July 2026

Lacet turns the mountain passes ("cols") you climb into a collection. This policy explains what personal data Lacet collects, why, how long it is kept, who it is shared with, and the rights you have over it. It is written to be readable, but it is also meant to be accurate — where the app behaves in a way that matters to your privacy, we say exactly what happens.

Lacet is available on iPhone only. It has no advertising, runs no third-party tracking or analytics SDKs, and never sells your data.

1. Who is responsible for your data

The controller responsible for your personal data is:

If you have any question about this policy or your data, email the address above.

2. What data we collect and where it comes from

Account and identity

When you sign in, Lacet uses Sign in with Apple only. From Apple we receive:

You also choose a display name (up to 50 characters), which you provide directly.

Ride and fitness data (from Wahoo and Strava)

Lacet does not track your location or record rides on your device. Instead, when you connect a Wahoo or Strava account, your rides are imported automatically from that provider. For each imported ride we receive and store:

This is precise location data and fitness data. It is imported from the provider you connected, not collected by the app itself.

Data we derive

From your imported rides, Lacet computes and stores your collection and records: which cols (and which sides of each col) you have "bagged", your climb times, your VAM (vertical metres per hour), personal bests, and experience points (XP).

Social data

If you use Lacet's social features, we store:

Challenges

We store the challenges you create or join, including any titles you write.

Notifications

If you turn on push notifications, we store an Apple Push Notification device token so we can send you "reveal" alerts.

Connection tokens

To keep your ride sources connected and to be able to disconnect them, we store:

Error diagnostics

Lacet may use Sentry to report software errors so we can fix crashes and bugs. Sending of personal data to Sentry is disabled — error reports are technical diagnostics, not your personal data.

3. Why we use your data and the legal basis

Under the EU GDPR and the Swiss Federal Act on Data Protection (FADP), we rely on the following legal bases.

What we do Why Legal basis
Create and run your account; import rides; build your collection, records and leaderboards; show your activity to your accepted friends To provide the app you asked for Performance of a contract (our Terms of Service)
Store encrypted connection tokens so your ride sources stay connected and can be revoked To provide the app you asked for Performance of a contract
Send push notifications about new col reveals Because you asked us to Your consent (you opt in; you can turn it off any time in iOS Settings)
Secure the service (TLS, certificate pinning, encryption at rest) and prevent abuse (blocks, reports, moderation) To keep the service and its users safe Legitimate interests
Report software errors via Sentry (no personal data) To keep the app working Legitimate interests

We do not carry out any automated decision-making that produces legal or similarly significant effects about you.

4. Who your data is shared with

Lacet does not sell your data and does not share it for advertising. Your data is shared only in these ways:

Other users (friends only)

Your display name and your climbing activity (bagged cols, times, reactions) are visible only to friends you have accepted. Friending happens through invite links — there is no public profile or public directory, and leaderboards are limited to your friends.

Service providers (sub-processors)

We rely on a small number of providers to run the service:

These providers act on our instructions or, where they are independent controllers of their own service (Apple, Wahoo, Strava), under their own privacy policies for the data you hold with them directly.

Legal reasons

We may disclose data if required by law or to protect our rights, users or the public, to the extent Swiss law permits.

5. International transfers

Your data is stored with our hosting provider. The hosting provider and region are Hetzner Online GmbH, Germany, European Union. Where data is transferred outside Switzerland or the European Economic Area, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses or an adequacy decision) as required by the GDPR and the FADP. Apple, Wahoo and Strava process data under their own transfer arrangements.

6. How long we keep your data

We keep your data for as long as your account exists, and then delete it as described here.

When you delete your account

Account deletion in the app is immediate and permanent. It revokes your Sign in with Apple grant and your Wahoo and Strava grants (if a provider cannot be reached at that moment, deletion still proceeds — you can also revoke access in that provider’s own account settings), then erases all of your data — including your GPS tracks, records and social data. This cannot be undone.

When you disconnect a ride source

Disconnecting a provider is deliberately different for each provider, and we want to be clear about it:

Diagnostics

Error diagnostics in Sentry are retained only for as long as needed to investigate and fix issues, per Sentry's retention settings.

7. Your rights

Under the GDPR and the Swiss FADP you have the right to:

Two of these are built directly into the app:

For any right that isn't a button in the app, or if you have a question, email open@hubermanuel.ch and we will respond as required by law.

Complaints

If you believe we have mishandled your data, you can complain to a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). In the EU/EEA you may contact the data protection authority in your country of residence.

8. Children

Lacet is not intended for children under the minimum age set out in our Terms of Service. We do not knowingly collect data from anyone below that age.

9. Security

We protect your data with TLS and certificate pinning for data in transit, and we encrypt sensitive tokens at rest (your Wahoo/Strava OAuth tokens and your Apple refresh token, using AES-256-GCM). No system is perfectly secure, but we take reasonable and appropriate measures to protect your information.

10. Attribution

The col catalogue in the app (routes, surface data, history, elevation profiles) is built from open data sources including OpenStreetMap, Wikipedia and national elevation services. Attribution for these sources is provided in the app's Licenses & Attribution screen. This catalogue data is about places, not about you.

11. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you in the app. The "Last updated" date at the top shows the current version.

← Back to lacet.bike