This Privacy Policy explains how Lapas ("Platform", "we", "our", "us") collects, uses, and stores personal data when you use:
- public business pages (business cards)
- booking pages
- business dashboard
The Platform is available at lapas.tech and its subdomains (including dashboard.lapas.tech, booking.lapas.tech, card.lapas.tech).
We operate from Lithuania (European Union) and process data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Data Controller
Maksim Možeiko (individual activity) Individual activity certificate No. 1457771 Address: Zarasai, Lithuania Email: privacy@lapas.tech
2. What data we collect
2.1 Business accounts (dashboard)
- email address
- password (stored securely as a hashed value)
2.2 Business profile data
- business name and description
- address and map link
- contact details (phone, email, social links)
- language, timezone, currency
- images (such as logo or service photos)
- public page URL (slug)
2.3 Booking data (customers)
- name
- email address
- phone number (optional)
- booking notes or answers
- appointment details (time, selected service, status)
2.4 Feedback and communication
- message content
- account or business reference (if applicable)
2.5 Technical and security data
We process limited technical data (such as IP address) to:
- prevent abuse
- apply rate limiting
- protect the Platform
This data is not used for tracking or analytics.
2.6 Subscription and billing data
This section applies only to business users who subscribe to our paid Pro plan.
Stored by us:
- your subscription plan and status
- Stripe customer, subscription, and price identifiers
- the end date of your current billing period
- whether a discount applies to your account
We also send your internal business identifier to Stripe so that payments can be matched to the correct account.
Collected and stored by Stripe, not by us:
- billing name, address, and country
- Tax ID / VAT number, if you provide one
- payment card details
- invoice and transaction history
We never receive or store full payment card numbers. Card details are entered on a checkout page hosted by Stripe and never pass through our systems.
3. Why we use your data
We use personal data to:
- provide booking and business profile functionality
- authenticate users and manage accounts
- process and manage bookings
- send booking-related communications
- process subscription payments and issue invoices
- maintain accounting and tax records
- provide support
- ensure Platform security and prevent abuse and payment fraud
Legal basis for processing:
- performance of a contract (providing the Platform and managing your subscription)
- legitimate interests (security, fraud prevention, and platform operation)
- legal obligations (in particular accounting and tax record-keeping)
- consent (where explicitly provided, if applicable)
4. Where your data is stored
Your data may be stored using trusted service providers:
- Database (PostgreSQL via Neon) — accounts, bookings, business data
- Cloudflare R2 — images (logos, service images)
- Resend — email delivery (booking notifications)
- Stripe — subscription payments, billing, and invoices
Stripe
Payments for the Pro plan are processed by Stripe Payments Europe, Limited and Stripe Technology Europe, Limited (Ireland). Stripe processes personal data on our behalf under Stripe's Data Processing Agreement, which forms part of our Stripe Services Agreement.
To provide its services, Stripe transfers personal data to Stripe, LLC in the United States. Stripe is certified under the EU–U.S. Data Privacy Framework; where an additional transfer mechanism is required, Stripe's Data Transfers Addendum (incorporating the EU Standard Contractual Clauses) applies.
Stripe's own privacy policy is available at stripe.com/privacy.
Other providers
Some providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards (e.g. standard contractual clauses).
5. Cookies and local storage
We use cookies for essential functionality and user preferences. In the business dashboard only, our authentication library also uses a small amount of browser local storage to keep your session synchronized across tabs (see "Local storage (dashboard only)" below).
Essential cookies
These cookies are strictly necessary for the operation of the Platform and cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
| __Secure-next-auth.session-token | Maintains your authenticated session across lapas.tech subdomains (required for login and API access) | 30 days |
| __Host-next-auth.csrf-token | CSRF protection for the sign-in process | Session |
| __Secure-next-auth.callback-url | Stores the redirect URL used after authentication | Session |
Preference cookies
These cookies improve your experience but are not used for tracking.
| Cookie | Purpose | Duration |
|---|---|---|
| lapas-language | Stores your selected interface language | 1 year |
| lapas-sidebar-state | Stores dashboard sidebar layout preference | 1 year |
Local storage (dashboard only)
When you sign in to the Lapas dashboard, our authentication library (NextAuth) writes a short technical message to your browser's local storage under the key nextauth.message. It is used only to keep your session state synchronized across open browser tabs — for example, so that signing out in one tab also signs you out in others.
| Storage key | Purpose | Data stored | Duration |
|---|---|---|---|
| nextauth.message | Synchronizes sign-in, sign-out, and session updates across browser tabs | Technical event type and timestamp only — no password, personal data, or session token | Overwritten on each sign-in/sign-out/session-update event; not used as long-term storage |
This is strictly necessary for providing the authentication service you requested and is treated the same way as our session cookies. It is only present while using the business dashboard; our public business pages and booking pages do not use browser local storage.
Payment pages
We do not embed Stripe scripts and do not set Stripe cookies on our own domains. When you proceed to pay for the Pro plan, you are redirected to a checkout page hosted by Stripe, where Stripe's own cookie and privacy policies apply.
Additional notes
- Cookies may be shared across lapas.tech subdomains to enable authentication between services
- We do not use analytics, advertising, or tracking cookies, and local storage is not used for tracking
6. Data sharing
We do not sell your data. We only share data with service providers necessary to operate the Platform:
- database hosting
- email delivery
- file storage
- payment processing
7. Data retention
We retain data only as long as necessary:
- accounts — until deleted by the user (see below)
- bookings — retained for up to 3 years or as required by legal obligations
- feedback — retained for support purposes
- uploaded content — until removed by the business
- billing and accounting records — retained for 10 years from the date of the relevant invoice, as required by Lithuanian accounting and tax law
Account deletion
When you request account deletion and confirm it by email, your account is frozen for 14 days. During this period you can sign in and restore it. After 14 days your account, business profile, services, bookings, and uploaded files are permanently deleted.
At that point any active subscription is cancelled and your saved payment methods are detached at Stripe. Your Stripe customer record is retained in an archived state, and invoices already issued are kept, solely to meet the accounting and tax retention obligations described above.
8. Your rights (EU/EEA)
You have the right to:
- access your data
- correct inaccurate data
- request deletion
- restrict processing
- request data portability
- object to processing
To exercise your rights, contact: privacy@lapas.tech
Please note that we cannot delete records we are legally required to retain, such as issued invoices.
You also have the right to lodge a complaint with a supervisory authority.
9. Security
We apply reasonable technical and organizational measures, including:
- password hashing
- access control
- secure booking management
- keeping payment card data entirely outside our systems
10. Changes
We may update this Privacy Policy from time to time. The latest version will always be available on this page. For significant changes — such as adding a new provider that processes your data — we will also notify business users by email.