Short version: we collect what we need to run your account and nothing else. No advertising trackers, no analytics scripts, and you appear under a username rather than your real name.
Last updated: 30 July 2026
The operator of grabalap.co.uk is the data controller for the information described here. For anything about your data, email info@grabalap.co.uk.
When you create an account: your name, email address, a securely hashed version of your password (never the password itself), your role (rider or tuner), and the optional profile details you choose to add — race number, bike, home country and the tracks you ride. We also record the date you joined and the IP address the sign-up came from, to catch abuse.
When you upload a lap: the AiM data file itself and the details attached to it — track, bike, session, conditions and lap time.
When you use the contact or track-request form: your name, email, and whatever you write in the message.
When you buy something: your order details. Card numbers go straight to Stripe — they never touch our server and we never see them.
Automatically: a session cookie so you stay signed in, and standard web-server logs kept by our host.
We use one cookie that matters: the sign-in session cookie. It's set only after you sign in, it can't be read by JavaScript, and it disappears when you sign out. Your browser also stores your display name locally so the site can paint the menu instantly — that stays on your device.
There are no advertising cookies, no analytics cookies and no third-party trackers on this site, which is why you'll never see a cookie consent banner here.
Riders are shown publicly by username, not by full name. Your email address, IP address and account details are never shown to other users. If you'd rather your real name appeared on your profile, that's a choice you make yourself — and you can reverse it.
We don't sell your data and we never will. We share it only with the services needed to run the platform:
Your data is stored on servers in the UK/EU. We keep your account data for as long as your account is open. Close your account and we delete your personal details, keeping only what we're legally required to keep for accounting — typically transaction records for six years. Contact-form messages are cleared once they've been dealt with.
Passwords are hashed with bcrypt, so nobody — including us — can read them. The whole site runs over HTTPS. Account files sit outside the public web root, admin access is rate-limited and logged, and sign-in attempts are throttled. If a breach ever affected your rights, we'd tell you and the ICO within 72 hours.
Under UK GDPR you can ask us to: show you what we hold about you, correct anything wrong, delete it, restrict what we do with it, hand it over in a portable format, or object to a particular use. Email info@grabalap.co.uk and we'll respond within one month, free of charge.
If you're unhappy with how we've handled it, you can complain to the Information Commissioner's Office at ico.org.uk — but please give us the chance to fix it first.
GrabALap is for adults. We don't knowingly collect data from anyone under 18. If you believe a child has created an account, tell us and we'll remove it.
If we change how we handle your data we'll update this page and change the date at the top. Material changes are emailed to account holders before they take effect.
Anything at all about your data: info@grabalap.co.uk. See also our Terms & Conditions.