Updated 26 September 2026

Privacy

What Gridlap knows about you, why, and how to delete it – in plain English, no small print.

In short

Gridlap is a non-commercial fan project: the @gridlap_bot bot, a Mini App in Telegram and the gridlap.club website.

  • We keep only what Gridlap can’t work without: who you are on Telegram, your settings and what you do in games, predictions and ratings.
  • We don’t sell data and there are no ads. We share it only with Telegram – the bot and sign-in run through it – and with Yandex, if you allowed the Metrica counter on the website.
  • We count website visits with our own counter without cookies: it stores neither your IP address nor your browser.
  • You can delete your data at any time – just write to support.

What we keep

  • Your Telegram profile: account number, first and last name, username and language. Telegram passes them on when you open the bot or the Mini App and when you sign in on the website.
  • Settings: time zone, how many minutes ahead to remind you, time format, theme, favourite driver and team, whether reminders are on.
  • What you do in Gridlap: game results, predictions and leagues, race ratings and reviews, votes for ‘Driver of the Day’ and in polls, achievements, ‘My Season’ cards.
  • Support requests – whatever you wrote in them.
  • Donations: how many stars and when. Telegram handles the payment; we never see card details.
  • Service data: when you were last here, which reminders we sent and whether the bot is blocked.
  • The days you opened the Mini App, visited the website signed in or wrote to the bot – only the day and where you were, with no actions and no times.

What others see

  • A race review is visible to everyone together with your Telegram name.
  • In a predictions league, members see each other’s names, and predictions once entries close.
  • Votes for ‘Driver of the Day’ and in polls are anonymous: only the overall shares are shown.
  • There are no public profiles.

What the Gridlap owner sees

In the admin panel the owner sees the list of Gridlap people: Telegram profile, settings, activity days, games, ratings, support requests and donations. That’s needed to answer requests, handle complaints and understand what people use. Nobody but the owner has access to the admin panel.

Website cookies

The website sets its own cookies only for signing in, for games without signing in and for the language you picked – the site doesn’t work without them, so we don’t ask for consent:

  • __Host-gridlap_web – you’re signed in on the website; lasts 30 days unless you sign out.
  • __Host-gridlap_hint – a hint to the page that it’s worth asking the server who you are.
  • __Host-gridlap_login – while signing in with the bot, five minutes.
  • __Host-gridlap_guest – games without signing in, so today’s game doesn’t get lost.
  • __Host-gridlap_lang – the website language you picked with the ‘EN / RU’ switch; lasts a year. Until you pick, the site follows your browser’s language, which we read on each visit and don’t store.
  • The theme, the speed and position in a race replay, your choice on the cookie banner (the gl-consent entry) and ‘Stay’ on the Russian-version hint (the gl-lang-hint entry) are kept by your browser and never sent to us.

Our own website visit counter

We count how many people open the website ourselves – without cookies and without Yandex – so this counter works even if you didn’t allow Metrica.

From each page you open we take its address, the site you came from (just its name, not the full address), the device type – phone, tablet or computer – and a fingerprint of the day: your IP address and browser encrypted together. The fingerprint changes every day, so your visits on different days can’t be linked, and the IP address and browser themselves are not stored anywhere. We don’t count search engine robots or pages the browser preloads.

Day fingerprints are kept for 35 days; after that only the totals remain: how many people and page views there were.

Yandex Metrica

The Yandex Metrica counter turns on only if you pressed ‘Accept’ on the cookie banner. If you chose ‘Essential only’, the counter doesn’t start and nothing goes to Yandex.

If you allowed it, the counter sets its own cookies (_ym_uid, _ym_d and others) and collects statistics without names: which pages are opened, where people come from and on which devices.

Webvisor records how people use the pages – scrolling, clicks, mouse movement – so we can see where the site is awkward. It doesn’t record the name of a signed-in person or the contents of account pages.

Yandex processes this data under its own rules. Changed your mind? Press ‘Cookie settings’ at the bottom of any page and choose ‘Essential only’: the counter won’t start again and we’ll wipe its cookies. You can also block trackers in your browser – the site won’t break.

There’s no Metrica in the bot or the Mini App. There we only note the days you visited – see ‘What we keep’.

Signing in on the website with the bot

When you sign in on the website, we note which browser the request came from (for example, ‘Chrome · Windows’), and not your IP address itself but its encrypted fingerprint – to limit the number of attempts. Sign-in requests are deleted after 30 days, and games without signing in once nobody has come back to them for 30 days.

You can sign out on the website in your account, and ‘Sign out everywhere’ is also in the Mini App settings and in the bot’s sign-in message.

Who we share data with

  • Telegram – the bot and the Mini App run through it, and you sign in on the website through it.
  • Yandex – website statistics, if you allowed them; see the Metrica section.
  • Nobody else. The Formula 1 and weather data sources (OpenF1, f1db, Jolpica, MET Norway, OpenStreetMap) get only technical requests from our server, with no data about you.

Where and for how long

The data lives in a database on the project’s rented server. The database is backed up once a day, and the 14 latest copies are kept.

We keep data while you use Gridlap. Sign-in requests – 30 days, games without signing in – 30 days after the last visit, day fingerprints of our own visit counter – 35 days.

How to delete your data

Write to support: open the @gridlap_bot Mini App – ‘Account → Report a problem’, topic ‘Data’. We’ll delete everything linked to your account within 30 days; it will leave the backups within another 14 days.

You can turn reminders off in the settings, and if you block the bot, messages stop straight away.

If anything changes

If we start collecting something new, we’ll update this page and the date at the top.