Legal

Privacy Policy

Last updated: April 13, 2026

Lapas is operated by Pro Sistemos, MB, a company registered in Lithuania ("we", "us", "our"). This Privacy Policy describes what information we collect when you use lapas.io, how we use it, and the choices you have. It applies to all users worldwide, including residents of the United States and the European Union.

1. Who we are

Company: Pro Sistemos, MB
Service: Lapas — browser-based 2D nesting software (lapas.io)
Contact: hello@lapas.io

2. Information we collect

Information you provide

  • Account registration: email address and password (stored as a cryptographic hash)
  • Billing: payment is processed by Stripe — we never see or store your card number
  • Support: any information you include when contacting us

Information collected automatically

  • Usage data: nesting jobs run, features used, session duration, error events
  • Log data: IP address, browser type and version, pages visited, referring URL, timestamps
  • Cookies: session cookies to keep you logged in; a preference cookie to remember your settings. We do not use advertising cookies or cross-site trackers.

Files you upload

DXF and SVG files you upload are processed in-session to perform nesting. Files are not stored beyond your session unless you explicitly save a project. We do not use your design files to train AI models or share them with any third party.

3. How we use your information

  • To create and maintain your account
  • To perform nesting calculations and return results to you
  • To process payments and manage your subscription
  • To send transactional emails (account confirmation, password reset, billing receipts)
  • To respond to support requests
  • To monitor for abuse, security threats, and service errors
  • To improve the product using aggregated, de-identified usage patterns

We do not sell your personal information. We do not share it with third parties for their marketing purposes.

4. Information sharing

We share information only in these limited circumstances:

  • Service providers: Stripe (payments), transactional email provider, cloud hosting — each bound by data processing agreements
  • Legal compliance: when required by law, court order, or to protect the rights and safety of users or the public
  • Business transfer: if Pro Sistemos, MB is acquired or merges, your data may transfer as part of that transaction — we will notify you in advance

5. Data retention

We retain account information for as long as your account is active. If you delete your account we remove your personal data within 30 days, except where retention is required by law (e.g., financial records). Free-plan session files are not retained after the session ends.

6. Security

We use HTTPS for all data in transit, bcrypt-hashed passwords, and access controls on our infrastructure. No system is completely secure — if you believe your account has been compromised, contact us immediately at hello@lapas.io.

7. Children

Lapas is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

8. Your privacy rights

All users

Regardless of where you are located, you can:

  • Access and update your account information at any time from your account settings
  • Delete your account by emailing hello@lapas.io
  • Opt out of any marketing emails using the unsubscribe link in those emails

California residents (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell
  • Delete personal information we hold about you (subject to certain exceptions)
  • Correct inaccurate personal information
  • Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising
  • Limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA
  • Non-discrimination — we will not discriminate against you for exercising any of these rights

To exercise your California rights, email hello@lapas.io with the subject line "California Privacy Request." We will respond within 45 days. You may designate an authorized agent to submit requests on your behalf.

Categories of personal information collected in the past 12 months: identifiers (email, IP address), internet or other network activity (usage data, log data), and commercial information (subscription plan, transaction history). We do not sell or share any of these categories.

EU / EEA residents (GDPR)

If you are located in the EU or EEA, Pro Sistemos, MB is the data controller. Our legal bases for processing are: contract performance (to provide the service), legitimate interests (security, product improvement), legal obligation (financial records), and consent (marketing emails). You have the right to:

  • Access, rectify, or erase your personal data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with your national supervisory authority or the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt)

To exercise GDPR rights, email hello@lapas.io. We respond within 30 days.

9. International data transfers

Our infrastructure is hosted within the EU. Where we use third-party processors outside the EU (such as Stripe), we rely on Standard Contractual Clauses or adequacy decisions approved by the European Commission to ensure your data is protected.

10. Cookies

We use strictly necessary cookies (session management, login state) and functional cookies (user preferences). We do not use advertising, analytics, or tracking cookies from third parties. You can disable cookies in your browser settings, but doing so may prevent login from working.

11. Changes to this policy

We will post changes to this page and update the "last updated" date. For material changes we will notify you by email at least 14 days in advance. Continued use of the service after the effective date constitutes acceptance.

12. Contact us

For any privacy questions, rights requests, or concerns:
Pro Sistemos, MB
Email: hello@lapas.io