Privacy Policy

Effective 26 August 2026

The short version

  • No ads, no third-party analytics, no tracking pixels, and we never sell your data.
  • Your recorded activities live in an encrypted database on your device. If you use LaceLock without an account, your recorded activities and saved routes stay on your device. If you create an account and sign in, your routes and activities can sync between your devices.
  • You can delete your account and synced data at any time, in the app or at lacelock.uk/account-deletion.
  • LaceLock works the same wherever you are. Depending on where you live, you may have specific rights over your data under local privacy law.

Who we are

LaceLock is an outdoor navigation app for hikers, walkers, trail runners, cyclists and mountain bikers, available for iOS and Android and on the web at lacelock.uk.

LaceLock is operated by Roberto Katalinic, trading as Big Dog Software Development, who is the data controller for the personal data described in this policy.

For anything privacy-related, you can contact us at:

We are in the process of appointing an EEA representative under Article 27 of the EU GDPR; their details will be listed here once appointed. Until then, EEA users can contact us directly at support@lacelock.uk.

Data we collect

Account data

You can use LaceLock without an account. Browsing the map and recording activities work locally on your device.

If you create an account, we store:

  • Your email address.
  • A secure password hash. We never store your password itself.
  • An internal account ID.
  • Whether your email address has been confirmed.

That is the complete list. There is no profile beyond this: we do not collect a display name, photo, phone number, date of birth or any other profile information.

If you sign in with Google or Apple, we store the email address provided by that sign-in provider. For Apple, this may be a private relay address if you choose to use one. We never see your Google or Apple password.

Location and activity data

LaceLock's core feature is recording and following outdoor routes.

When you record an activity, LaceLock collects your precise GPS location on your device, including while the screen is off during an active recording. On Android, recording runs as a visible foreground service with an ongoing notification; LaceLock does not request Android's separate "background location" permission.

A recorded activity may include:

  • Activity name.
  • Activity type.
  • Start and end time.
  • Duration.
  • Distance.
  • Pace or speed.
  • Elevation data.
  • GPS trail, including latitude, longitude, elevation and timestamp for each recorded point.

Precise route and location data can sometimes reveal sensitive information. That is why we keep sharing off by default and let you control what you choose to share.

This information is stored in an encrypted database on your device.

If you are signed in, your recorded tracks, planned routes and saved routes sync to our servers so they can follow you across your devices. Synced data is private to your account unless you choose to share it.

If you are not signed in, your recorded activities and saved routes do not sync to our servers.

Map use and server logs

When you use the map, search for a place, load map tiles, plan a route, or sync data, our servers receive standard technical information. This may include your IP address, the request made, the map area or tile requested, search terms, device/browser/app information, and the date and time of the request.

Map, search and routing services all run on our own servers. Place search is answered from our own place database; no third-party search or geocoding provider receives your queries.

We use this information to provide the service, keep it secure, troubleshoot problems, prevent abuse and maintain reliability. We do not use it to build advertising profiles.

Technical logs are kept for 30 days, unless needed longer to investigate security, abuse or technical issues.

Weather forecasts

When you view weather for a point on the map, your app asks our server, and our server fetches the forecast from the Norwegian Meteorological Institute (MET Norway, api.met.no). To do this, the location you asked about is sent to MET Norway, rounded to roughly 1 km. No account information, device identifier or IP address of yours is included — the request comes from our server, not your device. Forecasts are cached on our server for 30 minutes.

Map style fallback

In rare cases where the app cannot load its bundled map style or fonts, it may fall back to fetching a basic map style or font files from demotiles.maplibre.org, a public server run by the MapLibre open-source project. In that case your device contacts that server directly and it receives your IP address, like any web request. No account or location data is sent.

Website cookies and local storage

The LaceLock website sets no cookies at all — no advertising cookies, no analytics cookies, no tracking pixels.

If you sign in on the website, your browser keeps your sign-in session in its local storage so you stay signed in. Signing out removes it. That is the only thing the website stores in your browser.

If LaceLock ever introduces non-essential analytics, tracking or marketing cookies, we will ask for consent before using them.

What stays on your device

The following stays on your device unless you create an account and sign in, or choose to export or share it:

  • Activities recorded while not signed in.
  • Saved routes created while not signed in.
  • Downloaded offline map regions.
  • Cached map tiles.
  • The local encrypted activity database.

The key that encrypts the local database is generated on your device and stored in your device's secure storage (iOS Keychain / Android Keystore). It is marked as usable on that device only and is not included in cloud backups of your device.

Uninstalling the app removes the local database and cached maps, subject to your device operating system and backup settings.

Why we use your data

For users in the UK and the EEA, data protection law requires us to have a lawful basis for using your personal data. The table below shows the basis we rely on for each purpose under the UK GDPR and the EU GDPR.

PurposeData usedLawful basis
To create and manage your accountEmail address, password hash, account ID, email confirmation statusContract
To let you record activities and save routesGPS trail, activity data, route dataContract
To sync your routes and activities across devicesAccount ID, synced routes, recorded tracks, activity dataContract
To provide map, search, route-planning and weather featuresIP address, map requests, search terms, route-planning requests, weather lookupsContract
To send account emailsEmail addressContract
To keep the service secure and prevent abuseServer logs, IP address, device/app information, security signalsLegitimate interests
To troubleshoot, maintain and improve reliabilityError logs, diagnostic information, technical request dataLegitimate interests
To comply with legal obligationsAccount data, logs or other relevant information where requiredLegal obligation
To send optional updates you have asked forEmail addressConsent

Your device location settings control whether LaceLock can access precise location data. You can withdraw location permission at any time in your device settings. If you withdraw location permission, some core features may not work.

Providing your email address is necessary to create an account; without it, you can still use LaceLock's core map and offline recording features, but you will not be able to create an account or sync data across devices. Providing precise location is necessary to record or follow a route; without it, those specific features will not work.

Where we rely on legitimate interests, we do so to keep LaceLock secure, reliable and protected from misuse. You have the right to object to processing based on legitimate interests. See "Your rights and complaints" below.

Sharing

We do not sell, rent or share your personal data with anyone for marketing.

Data may leave our systems only in the following circumstances.

Track sharing you choose

If you choose to share a track, anyone with the link can view that track.

A shared track page shows:

  • Track name.
  • Activity type.
  • Start time.
  • Duration.
  • The full GPS trail (latitude, longitude, elevation and timestamps).

It never shows your email address, account ID or any other account information.

Sharing is off by default and controlled per track. Share links use long random identifiers, are not listed anywhere, and cannot be guessed.

Share links expire automatically 24 hours after they are created, and stop working immediately if you delete the track or your account. However, anyone who has viewed or downloaded the shared information may be able to copy it before the link expires.

GPX export you choose

You can export an activity as a GPX file. The file contains the track name, activity type, and the GPS trail (latitude, longitude, elevation and timestamps) — nothing else, and no account information. The file is handed to the app or service you choose to share it with. From that point, the other app or service is responsible for how it uses the file.

Sign-in providers

If you use Sign in with Google or Sign in with Apple, those providers process the sign-in under their own privacy policies.

Email delivery

Transactional emails — email address confirmation, password reset, and email-change confirmation — are delivered through Microsoft's email service (Microsoft 365 / Microsoft Graph), which processes your email address for that purpose under Microsoft's data protection terms.

Legal and security reasons

We may disclose information if required by law, court order or a competent authority, or where necessary to protect LaceLock, our users or the security of the service.

Third-party services and processors

We use a small number of third-party services to operate LaceLock.

ServicePurposeData involvedLocation / transfer information
Our own servers (UK)Core app, map, search, routing, sync and account hostingAccount data, synced routes, activity data, server logsUnited Kingdom
Microsoft (Microsoft 365 / Graph)Transactional emailEmail address, email content/metadataMay be processed outside the UK under Microsoft's data protection terms, which include approved transfer safeguards
Apple (Sign in with Apple)Optional account sign-inEmail address / Apple account identifierPer Apple's privacy policy
Google (Google Sign-In)Optional account sign-inEmail address / Google account identifierPer Google's privacy policy
MET Norway (api.met.no)Weather forecastsApproximate location of the forecast point (rounded to ~1 km), sent from our serverNorway (EEA)
MapLibre demo server (demotiles.maplibre.org)Emergency map style/font fallback onlyIP address of the requesting devicePublic open-source infrastructure

We use no analytics service, no crash-reporting service, no advertising network and no payment processor. LaceLock currently has no paid features.

Map data is © OpenStreetMap contributors. Map tiles are served from our own servers.

International data transfers

Our map, search, routing, sync and account servers are hosted in the United Kingdom.

Some third-party services may process personal data outside the UK and the EEA — principally Microsoft (email delivery), and Google or Apple if you use their sign-in. Weather requests go to MET Norway in the EEA, which UK adequacy regulations cover.

For users in the UK, where we transfer personal data outside the UK, we do so only where an appropriate safeguard or lawful transfer mechanism is in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

For users in the EEA, where we or our processors transfer personal data outside the EEA, we rely on an appropriate safeguard under the EU GDPR, such as an EU adequacy decision or the EU Standard Contractual Clauses.

How long we keep data

We keep personal data only for as long as needed for the purposes described in this policy.

Data typeRetention
Account dataKept until you delete your account
Synced tracks and routesKept until you delete them or delete your account
Shared track linksExpire after 24 hours, or immediately if you delete the track or your account
Local device dataKept on your device until you delete it or uninstall the app, subject to device backup settings
Server logsKept for 30 days, unless needed longer for security, abuse-prevention or troubleshooting
BackupsRotated after 14 days
Emails you send to supportKept for up to 12 months after your query is resolved

Deleting your account

You can delete your account in two ways:

If you cannot sign in, email support@lacelock.uk from your account email address and we will delete it for you after verifying the request.

Deleting your account immediately and permanently removes your account, your synced tracks and routes, and any active share links from our live systems. Residual copies in nightly backups are kept for disaster recovery and are overwritten within 14 days.

Security

All traffic between your device and our servers is encrypted using HTTPS.

The local activity database on your device is encrypted at rest; the encryption key is generated on your device and held in your device's secure storage (iOS Keychain / Android Keystore), usable on that device only.

Our servers are hosted in the United Kingdom.

We use technical and organisational measures designed to protect personal data, including:

  • Encrypted connections.
  • Local database encryption.
  • Restricted production access.
  • Account-level data separation enforced at database level, so each account can only ever read its own data.
  • Industry-standard password hashing.
  • Server monitoring and abuse prevention.
  • Encrypted, rotated backups.

If we identify a personal data breach, we will take appropriate steps to investigate, contain and respond to it. Where legally required, we will notify the relevant regulator and/or affected users. No system is completely secure. If you think your account or data has been compromised, contact us at support@lacelock.uk.

Your rights and complaints

If you are in the UK or EEA, you have rights over your personal data. Depending on your circumstances, these may include the right to access, correct, delete, restrict or export your data, object to certain processing, and withdraw consent where we rely on it.

We do not make solely automated decisions that have a legal or similarly significant effect on you.

You can manage much of your data directly in LaceLock: your activity and route data is visible in the app, tracks can be exported as GPX files, tracks and routes can be deleted, and account deletion is self-service.

For anything else, email support@lacelock.uk. If you make a formal request, such as a request to access your data, we will respond within one month; if your request is complex or you have made several, we may extend this by up to two further months and will tell you if we do. We may need to confirm your identity before responding.

If you are unhappy with how we handle your personal data, please contact us first so we can try to put it right. You can also complain to a data protection regulator:

  • In the UK: the Information Commissioner's Office at ico.org.uk
  • In the EEA: your local data protection authority

Additional information for international users

Depending on where you live, you may have additional rights under local privacy law. Where local law gives you stronger protection than this policy, we will comply with that law.

EEA users

If you are in the European Economic Area, you can contact us directly at support@lacelock.uk. We are in the process of appointing an EEA representative under Article 27 of the EU GDPR; their details will be listed here once appointed.

New Zealand users

If you are in New Zealand, the Privacy Act 2020 may apply to how we handle your personal information.

The approach set out in this policy is intended to be consistent with the Information Privacy Principles under that Act: we collect and use your information fairly and for the purposes described here, take reasonable steps to keep it secure, and do not keep it for longer than necessary.

You have the right to request access to, and correction of, your personal information. In practice, your activity and route data is visible directly in the app, and you can export or delete it, or delete your account, at any time. For anything else, email support@lacelock.uk.

If you are unhappy with how we have handled a privacy request, you can complain to New Zealand's Office of the Privacy Commissioner.

If we send you marketing emails, these will include an unsubscribe option.

Other jurisdictions

We have not included separate country-specific sections where the rights and protections are already covered by this policy, or where LaceLock does not currently meet the relevant applicability thresholds for that law.

We will review this as LaceLock grows and update this policy if additional country-specific disclosures become necessary.

Children

You must be at least 16 to create a LaceLock account. Creating an account requires you to confirm that you are 16 or older — via a confirmation at email sign-up, or by continuing with Google or Apple sign-in, which is stated to confirm the same. LaceLock is not directed at children under 16, and we do not knowingly collect personal data from children under 16.

If you are 16 or 17, you should still use LaceLock only with the involvement of a parent or guardian.

If you have reason to believe a child has created an account without appropriate consent, contact us at support@lacelock.uk and we will delete that personal data.

If you are a US resident and believe a child under 13 has provided us with personal data, contact us and we will delete it.

Because LaceLock may be used by 16- and 17-year-olds, and location data can be particularly sensitive for children, we keep sharing off by default and take care not to collect more than we need.

App permissions

LaceLock asks for these device permissions:

  • Location (precise), to record and follow routes. On iOS this includes the "Always" option so recording continues with the screen off; on Android, recording runs as a visible foreground service instead, and the separate background-location permission is not requested.
  • Notifications (Android), used only to show the ongoing recording notification. We do not send push notifications.

Saving a GPX file uses your device's standard file picker and needs no storage permission.

You can change app permissions at any time in your device settings. Some features may stop working if you remove permissions.

Marketing

If you join our waitlist or otherwise ask to receive updates about LaceLock, we use your email address to send you news, such as launch updates and new features. You can unsubscribe at any time. We do not sell your data or share it with third parties for their own marketing.

Aside from updates you have asked for, we only send transactional emails needed to operate your account: email confirmation, password reset, and email-change confirmation.

Changes to this policy

If this policy changes, the new version will be posted here with an updated effective date. We will flag material changes in the app or by another appropriate method.