Last updated 3 October 2026.
1. Who we are
The Greatest Lap ("we", "us") organises Edition One, the first ever relay run around the world. This policy explains how we handle personal data when you use thegreatestlap.com. The controller responsible for your data is The Greatest Lap AG (in formation). Until the company is entered in the commercial register and takes over this role, the controller is its founder, Wilhelm Tear. For anything about your data, email makehistory@thegreatestlap.com.
We are based in Switzerland and handle personal data in line with the Swiss Federal Act on Data Protection (FADP). Where the EU or UK General Data Protection Regulation applies to you, you have the rights it gives you as well.
2. What we collect, and why
We only collect what we need for the thing you are doing on the site.
- Runner profile and leg reservation. How you signed in (Google, Apple or email link), your name, email address, profile photo (uploaded by you or taken from your Google account if you sign in with Google), run club if you give one, the leg you choose, your reservation status and its history, and your choice about public display. We use this to review and manage reservations, contact you about your leg and the event, and run your account. We also keep short internal notes and tags on reservations to help us organise the relay.
- Running club blocks. The club name and the legs requested, linked to the profile of the person making the request.
- Partner enquiries. Your name, company, email address and message, so we can reply.
- Shop and training updates. Your email address and, for the shop, your name, country and the items you are interested in, so we can tell you when they launch. We only email you about what you signed up for.
- Emails we send. Confirmation and decision emails about your reservation (with a calendar file for your leg). Our email provider records whether a message was delivered.
- Technical data. When you load a page, our hosting and content providers receive your IP address and basic browser information and keep short-lived logs to deliver and protect the site.
We count visits with Cloudflare Web Analytics, which uses no cookies and does not identify or follow you across sites; we only see totals such as pages viewed, countries and referring websites. We do not use advertising cookies or tracking pixels, and we never sell your data.
3. Our legal basis
- To provide what you asked for: your account, your reservation and replies to your enquiries.
- Our legitimate interests: organising the event, keeping the site secure and working, and responding to business enquiries.
- Your consent: launch emails for the shop and training programmes, and showing your name and photo publicly on your leg. You can withdraw consent at any time.
4. Public display is your choice
Your name and photo appear publicly on your leg only if you opt in. It is off by default and you can change it at any time in your profile. Run club names may be shown on legs reserved for that club.
5. Who processes your data for us
We use a small number of service providers who process data only on our instructions:
- Supabase: database, sign-in, sign-in emails and private photo storage, hosted in Frankfurt, Germany.
- Netlify: website hosting and enquiry forms (United States).
- Resend: sending our emails (United States).
- Cloudflare: cookie-free visitor statistics (United States). It receives your IP address and the page you load, and reports only aggregated totals to us.
- Google: "Sign in with Google", if you choose it, and web fonts loaded from Google's servers.
- Apple: "Sign in with Apple", if you choose it. Apple may let you hide your real email address from us.
- Content delivery networks (jsDelivr, Amazon CloudFront, Unsplash): deliver scripts and images, and receive your IP address when they do.
Links to our social media accounts only send data to those platforms if you click them.
6. International transfers
Some providers are in the United States. Where a country is not recognised as offering adequate protection, we rely on the Swiss–US or EU–US Data Privacy Framework where the provider is certified, or on standard contractual clauses.
7. Cookies and local storage
We do not use cookies for advertising or analytics. Our visitor statistics (see section 5) work without cookies or browser storage. The site keeps a few small items in your browser's storage so it works properly:
- Sign-in session: keeps you signed in. Removed when you sign out.
- Leg you were choosing and where to return after sign-in: so you land back on the same leg or panel after signing in. Cleared once used, and deleted when you close the tab.
- Shop currency: remembers the currency you picked in the shop.
None of these are shared with anyone. They are strictly necessary for features you ask for, so we do not ask for consent. You can clear them at any time in your browser settings.
8. How long we keep it
- Profile and reservation data: until you delete your account, and no later than 12 months after the Edition One finale.
- Partner enquiries: up to 24 months after our last contact.
- Shop and training sign-ups: until we have sent the launch email or you unsubscribe, and no longer than 24 months.
- Technical logs: kept by our providers for a short period, typically no more than 30 days.
- Visitor statistics: aggregated totals only, with no record that identifies you.
9. Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, take it with you, and withdraw consent at any time. Withdrawing your reservation releases your leg, and deleting your account removes your profile. Email makehistory@thegreatestlap.com and we will reply within 30 days. If you are unhappy with how we handle your data, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), the data protection authority where you live in the EU, or the UK Information Commissioner's Office.
10. Children
The site is not aimed at children under 16 and we do not knowingly collect their data. If you think a child has given us data, contact us and we will delete it.
11. Security
Data is encrypted in transit, and access to reservation data is limited to our team through role-based controls. Profile photos are stored privately: only you and our team can see yours, unless you choose to show it on your leg. You sign in with Google, Apple or a one-time link sent to your email, so we never store passwords.
12. Changes
We may update this policy as the event develops. The current version always lives on this page, with the date it was last updated. See also our Reservation Terms.