Privacy Policy
Laurel holds two kinds of people's information, and they arrive very differently. Organizers sign up. Finishers are uploaded by their club and may never have heard of us. This page is mostly about the second.
Last updated 16 August 2026
1Who we are, and who this covers
Laurel is a service run by Manika Anand Thilakan that turns an event’s results into personalized finisher certificates. This policy covers getlaurel.co and everything on it.
Two groups of people appear in what follows:
- Organizers — the club or event that signs up, uploads a list, and pays. They chose Laurel.
- Finishers — the people who took part. Their details reach Laurel because their club uploaded them. They did not sign up and have no account.
For finisher information, the club is the one who decides what is collected and why. Laurel holds and processes it on their instruction. If you finished an event and want your details removed, the fastest route is your club — but you can write to us directly at support@getlaurel.co and we will act on it.
2What we collect from an organizer
- An email address, to create the account and sign in. Laurel uses emailed sign-in links and password reset, so the address is the account.
- The club and event details you type — club name, event name, date, venue, a website address, the wording that appears on the certificate.
- Any logo you upload, and the colors we read out of it.
- A record of what you paid — the amount, how many finishers it covered, and the reference Stripe gives the payment.
We never see your card. Payment happens on Stripe’s own checkout page. Laurel stores the amount and a reference number, and no card number, expiry or security code ever reaches our systems.
3What a club gives us about a finisher
When a club uploads its results, each row can carry the following. Only the first three are required:
- First and last name, as it should be printed on the certificate.
- An email address, which is what a finisher enters to find themselves and where their certificate is sent.
- An award or category line — division, age group, route — if the club included one.
- A detail line — usually a finish time or a distance — if the club included one.
From those, Laurel works out a few things of its own: a simplified version of the name used for searching, a one-way fingerprint of the email address (see below), and a random code that identifies the certificate without naming anybody.
We ask clubs not to upload anything else, and the importer ignores columns it does not recognize. Nothing on this list is bought, scraped, or obtained from anywhere except the club’s own upload.
4The fingerprint, and why the address goes but it stays
Alongside each address, Laurel stores a SHA-256 hash of it — a fixed-length string of characters produced from the address by a one-way calculation. It cannot be turned back into the address. It can only be compared: if you type your address into the lookup, we hash what you typed and see whether it matches.
That is what lets the useful parts of Laurel keep working after the address itself is deleted. Looking someone up, counting how many finishers collected their certificate, and honoring an unsubscribe all run on the fingerprint. None of them ever needed the address.
The address exists so we can send to it, so it dies when sending ends. The fingerprint outlives it, and cannot be read backwards.
5How long any of it is kept
Everything is measured from the day an event is published — not the day it was created. A club that builds an event in March and publishes it in July gets its full window from July.
- Day 0
- The club publishes. Finishers can look themselves up, and Laurel can email them.
- Day 30
- The lookup window closes. The event stops being searchable and is archived — still held, no longer public. Certificates already downloaded are unaffected.
- Day 50
- We email the club 10 days before deletion, so nobody is surprised by it.
- Day 60
- Names, email addresses, fingerprints and certificate codes for that event are deleted permanently. We keep no copy to search.
The gap between closing and deletion is deliberate. A finisher’s email address is held for the whole 60 days, not wiped at the 30-day close, because the 30 days after a window closes are when an organizer is still helping the handful of people who wrote in late. An organizer cannot help somebody whose address was deleted a month earlier.
What survives deletion
Three things, and none of them is a person:
- Counts. How many finished, how many collected a certificate, how many files were served, what was paid. These are totals for the event, kept indefinitely so a club can see its own history. They contain no names and no addresses, and they were never linked to individual people in the first place — the download log records an event, a certificate code and a file format, with no address, no IP address and no browser details.
- The event’s own details — its name, date, and which club ran it.
- The do-not-email list, as fingerprints only. See below.
6Email, and the do-not-email list
Laurel sends the certificate emails, not the club. Every one carries an unsubscribe link, and unsubscribing is permanent.
Three things put someone on the do-not-email list: they clicked unsubscribe, their address bounced, or they marked an email as spam. The list holds fingerprints only, never addresses, and two consequences follow from that:
- It is global. It applies to every club on Laurel, not just the one whose email prompted it. A person who has said stop has said stop.
- It cannot be read back. Laurel can refuse to send to you. Laurel cannot tell your club that you opted out, or produce a list of who did. That is not a limitation we have worked around; it is the point.
A finisher is emailed once when their certificate is ready, and at most once more as a reminder. Never more than that.
Laurel also sends organizers the emails an account needs — sign-in links, receipts, and the notice before an event’s data is deleted. Those are not marketing and cannot be unsubscribed from, because the deletion notice is the only warning a club gets.
7Verification after the data is gone
Every certificate carries a code. Scanning it tells you whether the certificate is genuine — and that check does not look anything up. The proof is carried inside the code itself, signed by Laurel, so it keeps working years later, long after the event’s list has been deleted.
That means a certificate a finisher has already downloaded continues to verify after we have deleted everything about the event. It also means verification does not require us to keep anybody’s details in order to work — which is the reason the deletion above can be as complete as it is.
The other way in, the check-a-name form, does search the club’s list, so it only works while that list exists.
9Who else sees any of this
Laurel is a small product built on other people’s infrastructure. These are every company that handles data on our behalf. There are no others, and we do not sell data to anyone, ever.
- Supabase
- Database, sign-in, and logo file storage · United States
- Vercel
- Hosting and request logs · United States
- Resend
- Delivering email to finishers and organizers · United States
- Stripe
- Card payment. Stripe sees the card; Laurel never does. · United States
- Cloudflare
- DNS and network protection for getlaurel.co · Global
Laurel is run from the United States and its data is stored there. If you are outside the US, using Laurel means your information is processed there.
10Your choices
If you finished an event: you can unsubscribe from the link in any email we send you, which stops all Laurel email permanently. You can ask your club to remove you from its list, or write to us at support@getlaurel.co and we will delete your row. You can also simply wait — everything about you goes on day 60 whether anyone asks or not.
If you are an organizer: you can see and change everything about your events in your workspace, delete an event yourself, or ask us to close your account and remove it all.
Depending on where you live you may have specific rights — to access what we hold, correct it, delete it, or object to how it is used. Write to support@getlaurel.co and we will answer within one month. We will not charge you for it or treat you differently for asking.
One thing we genuinely cannot do is tell you whether a particular address is on the do-not-email list, or take it off on request from somebody else. The list holds fingerprints, not addresses, so there is nothing to look up.
11Children
Laurel accounts are for adults running events. We do not knowingly create accounts for anyone under 13.
A finisher, on the other hand, may well be a child — junior races are common. Laurel receives only what the club uploads about them: a name, an address the club already holds, and their result. If a parent or guardian wants that removed before the automatic deletion, write to support@getlaurel.co and we will do it.
12Security
Everything travels over encrypted connections and is stored encrypted at rest by our hosting providers. One club cannot read another club’s finishers — that separation is enforced by the database itself rather than by application code, so a mistake in a single screen cannot expose someone else’s list.
No system is perfect. What limits the damage here is how little is held and for how long: an event’s finisher list exists for 60 days and then does not exist at all.
13Changes, and how to reach us
If this policy changes in a way that matters, we will change the date at the top and, where the change affects organizers, email them. We will not apply a materially different policy to information already collected without saying so.
Questions, requests, or anything that looks wrong on this page: support@getlaurel.co, or Manika Anand Thilakan, 1700 Pacific Ave, Ste 1800, Dallas, TX 75201.