Privacy Policy

Effective date: July 26, 2026

EN

This Privacy Policy explains how Lapas ("Platform", "we", "our", "us") collects, uses, and stores personal data when you use:

  • public business pages (business cards)
  • booking pages
  • business dashboard

The Platform is available at lapas.tech and its subdomains (including dashboard.lapas.tech, booking.lapas.tech, card.lapas.tech).

We operate from Lithuania (European Union) and process data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).


1. Data Controller

Maksim Možeiko (individual activity) Individual activity certificate No. 1457771 Address: Zarasai, Lithuania Email: privacy@lapas.tech


2. What data we collect

2.1 Business accounts (dashboard)

  • email address
  • password (stored securely as a hashed value)

2.2 Business profile data

  • business name and description
  • address and map link
  • contact details (phone, email, social links)
  • language, timezone, currency
  • images (such as logo or service photos)
  • public page URL (slug)

2.3 Booking data (customers)

  • name
  • email address
  • phone number (optional)
  • booking notes or answers
  • appointment details (time, selected service, status)

2.4 Feedback and communication

  • message content
  • account or business reference (if applicable)

2.5 Technical and security data

We process limited technical data (such as IP address) to:

  • prevent abuse
  • apply rate limiting
  • protect the Platform

This data is not used for tracking or analytics.

2.6 Subscription and billing data

This section applies only to business users who subscribe to our paid Pro plan.

Stored by us:

  • your subscription plan and status
  • Stripe customer, subscription, and price identifiers
  • the end date of your current billing period
  • whether a discount applies to your account

We also send your internal business identifier to Stripe so that payments can be matched to the correct account.

Collected and stored by Stripe, not by us:

  • billing name, address, and country
  • Tax ID / VAT number, if you provide one
  • payment card details
  • invoice and transaction history

We never receive or store full payment card numbers. Card details are entered on a checkout page hosted by Stripe and never pass through our systems.


3. Why we use your data

We use personal data to:

  • provide booking and business profile functionality
  • authenticate users and manage accounts
  • process and manage bookings
  • send booking-related communications
  • process subscription payments and issue invoices
  • maintain accounting and tax records
  • provide support
  • ensure Platform security and prevent abuse and payment fraud

Legal basis for processing:

  • performance of a contract (providing the Platform and managing your subscription)
  • legitimate interests (security, fraud prevention, and platform operation)
  • legal obligations (in particular accounting and tax record-keeping)
  • consent (where explicitly provided, if applicable)

4. Where your data is stored

Your data may be stored using trusted service providers:

  • Database (PostgreSQL via Neon) — accounts, bookings, business data
  • Cloudflare R2 — images (logos, service images)
  • Resend — email delivery (booking notifications)
  • Stripe — subscription payments, billing, and invoices

Stripe

Payments for the Pro plan are processed by Stripe Payments Europe, Limited and Stripe Technology Europe, Limited (Ireland). Stripe processes personal data on our behalf under Stripe's Data Processing Agreement, which forms part of our Stripe Services Agreement.

To provide its services, Stripe transfers personal data to Stripe, LLC in the United States. Stripe is certified under the EU–U.S. Data Privacy Framework; where an additional transfer mechanism is required, Stripe's Data Transfers Addendum (incorporating the EU Standard Contractual Clauses) applies.

Stripe's own privacy policy is available at stripe.com/privacy.

Other providers

Some providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards (e.g. standard contractual clauses).


5. Cookies and local storage

We use cookies for essential functionality and user preferences. In the business dashboard only, our authentication library also uses a small amount of browser local storage to keep your session synchronized across tabs (see "Local storage (dashboard only)" below).

Essential cookies

These cookies are strictly necessary for the operation of the Platform and cannot be disabled.

CookiePurposeDuration
__Secure-next-auth.session-tokenMaintains your authenticated session across lapas.tech subdomains (required for login and API access)30 days
__Host-next-auth.csrf-tokenCSRF protection for the sign-in processSession
__Secure-next-auth.callback-urlStores the redirect URL used after authenticationSession

Preference cookies

These cookies improve your experience but are not used for tracking.

CookiePurposeDuration
lapas-languageStores your selected interface language1 year
lapas-sidebar-stateStores dashboard sidebar layout preference1 year

Local storage (dashboard only)

When you sign in to the Lapas dashboard, our authentication library (NextAuth) writes a short technical message to your browser's local storage under the key nextauth.message. It is used only to keep your session state synchronized across open browser tabs — for example, so that signing out in one tab also signs you out in others.

Storage keyPurposeData storedDuration
nextauth.messageSynchronizes sign-in, sign-out, and session updates across browser tabsTechnical event type and timestamp only — no password, personal data, or session tokenOverwritten on each sign-in/sign-out/session-update event; not used as long-term storage

This is strictly necessary for providing the authentication service you requested and is treated the same way as our session cookies. It is only present while using the business dashboard; our public business pages and booking pages do not use browser local storage.

Payment pages

We do not embed Stripe scripts and do not set Stripe cookies on our own domains. When you proceed to pay for the Pro plan, you are redirected to a checkout page hosted by Stripe, where Stripe's own cookie and privacy policies apply.

Additional notes

  • Cookies may be shared across lapas.tech subdomains to enable authentication between services
  • We do not use analytics, advertising, or tracking cookies, and local storage is not used for tracking

6. Data sharing

We do not sell your data. We only share data with service providers necessary to operate the Platform:

  • database hosting
  • email delivery
  • file storage
  • payment processing

7. Data retention

We retain data only as long as necessary:

  • accounts — until deleted by the user (see below)
  • bookings — retained for up to 3 years or as required by legal obligations
  • feedback — retained for support purposes
  • uploaded content — until removed by the business
  • billing and accounting records — retained for 10 years from the date of the relevant invoice, as required by Lithuanian accounting and tax law

Account deletion

When you request account deletion and confirm it by email, your account is frozen for 14 days. During this period you can sign in and restore it. After 14 days your account, business profile, services, bookings, and uploaded files are permanently deleted.

At that point any active subscription is cancelled and your saved payment methods are detached at Stripe. Your Stripe customer record is retained in an archived state, and invoices already issued are kept, solely to meet the accounting and tax retention obligations described above.


8. Your rights (EU/EEA)

You have the right to:

  • access your data
  • correct inaccurate data
  • request deletion
  • restrict processing
  • request data portability
  • object to processing

To exercise your rights, contact: privacy@lapas.tech

Please note that we cannot delete records we are legally required to retain, such as issued invoices.

You also have the right to lodge a complaint with a supervisory authority.


9. Security

We apply reasonable technical and organizational measures, including:

  • password hashing
  • access control
  • secure booking management
  • keeping payment card data entirely outside our systems

10. Changes

We may update this Privacy Policy from time to time. The latest version will always be available on this page. For significant changes — such as adding a new provider that processes your data — we will also notify business users by email.