Skip to content
Edge LabSign in

Legal

Privacy policy

What we collect, where it lives, how long we keep it, and how you stay in charge of it.

Last updated 11 October 2026

Who we are

Edge Lab (edgelab.ski) is a small independent project run from Australia. We handle your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Questions about any of this: hello@edgelab.ski.

What we collect

  • Your lift ticket. Weight, the ski and length you ride, how your boots fit and the snow you usually ski. It lives in your browser (local storage and the edgelab-ticket cookie) so pages can use it. It holds no name or email, and we do not keep a copy on our servers unless you make an account and save a setup.
  • Your account,if you make one. Email address, a display name, a password (stored only as a salted hash), your units, and the setups and gear you choose to save. If you continue with Google, Apple or Facebook instead, we read only your name and email address from them, keep that provider’s anonymous id for your account so we can recognise you next time, and never post to or read anything else from your account there.
  • Symptom reports. If you save what you feel on the hill (for example sore quads or skis that lock up), that is health information. The Privacy Act treats health information as sensitive information, so we only keep it with your explicit consent, it is private to you by default, and you can export it or delete it at any time. Edge Lab records what people feel; it never gives medical advice. See not medical advice.
  • Your consents. A row for each choice you make at sign-up or later (terms, health information, marketing email, research use of anonymised data): what you chose, when, and which version of the wording you saw. Withdrawing a consent adds a new row; it does not rewrite history.
  • Emails you ask for.When you ask for something by email (your setup as a link, a boot fitter report, a ski comparison, a pre-trip checklist, or to hear when the app or early access opens) we keep a record: your email address, which thing you asked for, the page you asked on, the symptom, ski or setup numbers that went into it, the date of your trip if you gave one, whether you ticked “occasional notes from Darren” (notes are only sent after you confirm from the email), and the campaign tag on the link that brought you (such as utm_source=reddit). We never keep anything you typed about your health. Every email has an unsubscribe link, which stops the notes. To have the record deleted, reply to any of those emails or use the unsubscribe link and ask; we delete it within 30 days.
  • Analytics.We use PostHog to count visits and which parts of the site get used. Events are named actions such as “opened a run” or “picked a symptom” with a slug, never free text, never your email and never the contents of a form. We do not build a profile of you. Analytics does not start at all if your browser sends Do Not Track or Global Privacy Control, and it is off in any environment where we have not switched it on.
  • Referral click logs. When you follow a link to a shop or boot fitter through Edge Lab, we log that a click happened: which offer and shop, which kind of page and position it came from, and the country from your request. We do not log your IP address, browser details, cookies or account.
  • Server logs. Our host keeps short-lived technical logs (IP address, request path, time) to run and secure the service.

Why we use it

To run the tools you ask for (the Lab, Feel and Skis pages), to keep your account and saved setups, to answer you, to keep the service secure, and to understand which parts of the site help people. If you agreed to marketing email we send it; you can stop at any time. If you agreed to research use, anonymised and aggregated data may be used to improve the model. We do not sell personal information.

Where it is stored

Account data and saved setups are stored in a Postgres database hosted by Neon. The database region is to be confirmed before launch and this page will name it. The site runs on Vercel, email goes through Resend and analytics through PostHog. Those providers may process data outside Australia; we choose providers that publish security and privacy terms, and we send them no more than the job needs.

How long we keep it

  • Usage events (counts such as referral clicks and interest in early access) are deleted after 400 days. At 90 days any link to an account is removed, so older events are anonymous.
  • Account data, setups and symptom reports are kept until you delete them or your account.
  • Deleting your account removes your profile, gear, setups, symptom reports, comparisons and consent history.

Your rights

You can, at any time:

  • Export a copy of everything we hold about you, from Account, Privacy when you are signed in.
  • Delete your account and everything attached to it, from the same page.
  • Withdraw a consent (health information, marketing email, research use) from the same page. Withdrawing the health-information consent stops us keeping new symptom reports.
  • Ask us to correct something, or ask a question about how we handle your information: hello@edgelab.ski. We will reply within 30 days.

If you are not happy with our answer you can complain to the Office of the Australian Information Commissioner (OAIC).

Cookies and local storage

  • payload-token: keeps you signed in. Set only when you sign in. Needed for the account area.
  • edgelab-ticket: a copy of your lift ticket (weight, ski, boots, snow) so pages can show results for your setup. No name or email in it.
  • PostHog: if analytics is running, PostHog stores an anonymous identifier in local storage and a cookie. It does not run for browsers that send Do Not Track or Global Privacy Control.

Changes

If we change this page in a way that matters, we will say so on the site and, where you gave a consent that the change affects, ask again.