1. Introduction
Lithi Technologies ("Lithi," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our account-based marketing platform and services (the "Services").
By using our Services, you consent to the data practices described in this policy. If you do not agree with this policy, please discontinue use of our Services immediately.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you provide when you:
- Create an account: Name, email address, company name, phone number, billing information
- Complete the onboarding quiz: Business type, industry, geographic preferences, budget, service radius
- Use our Services: Campaign details, target account lists, message templates, contact information
- Contact us: Name, email, company, message content, support inquiries
- Subscribe to updates: Email address for newsletters and product updates
2.2 Information Collected Automatically
When you access our Services, we automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Information: Pages viewed, time spent on pages, clicks, navigation paths
- Session Information: Session ID, company slug, event sequences, funnel stages
- Location Information: Geographic location based on IP address
- Cookies and Tracking: Session cookies, analytics cookies, preference cookies
2.3 Information from Third-Party Sources
We may collect information from:
- Business Databases: Publicly available company information, contact details
- Analytics Providers: Google Analytics, Supabase Analytics
- Payment Processors: Stripe or other payment service providers
- Social Media: LinkedIn, Twitter (if you connect your accounts)
3. How We Use Your Information
We use your information to:
- Provide Services: Deliver account-based marketing campaigns, territory mapping, outreach services
- Personalization: Customize content, recommendations, and campaign strategies
- Communication: Send transactional emails, campaign updates, support responses
- Analytics: Track campaign performance, user behavior, funnel conversion rates
- Improvement: Enhance our platform, develop new features, optimize user experience
- Compliance: Meet legal obligations, prevent fraud, enforce our Terms of Service
- Marketing: Send promotional emails (with your consent), product updates, newsletters
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your personal data based on:
- Contract Performance: Processing necessary to fulfill our Services to you
- Legitimate Interests: Improving our Services, fraud prevention, direct marketing
- Consent: Analytics cookies, marketing emails (you can withdraw consent anytime)
- Legal Obligation: Compliance with laws, responding to legal requests
5. Data Sharing and Disclosure
We may share your information with:
5.1 Service Providers
- Cloud Hosting: Vercel, Supabase (data storage and hosting)
- Analytics: Google Analytics, Supabase Analytics
- Payment Processing: Stripe (we do not store credit card information)
- Communication: Email service providers, SMS providers
- AI Services: OpenAI, Anthropic (for content generation and personalization)
5.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety.
5.3 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5.4 With Your Consent
We may share your information with third parties when you explicitly consent to such sharing.
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: TLS/SSL encryption for data in transit, AES-256 encryption for data at rest
- Access Controls: Role-based access control, multi-factor authentication
- Regular Audits: Security audits, vulnerability assessments, penetration testing
- Employee Training: Data protection and security awareness training
- Incident Response: Procedures for detecting and responding to security breaches
However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as necessary to provide Services and fulfill the purposes outlined in this policy:
- Account Data: Retained while your account is active, plus 90 days after termination
- Campaign Data: Retained for 2 years for analytics and compliance purposes
- Financial Records: Retained for 7 years to comply with tax and accounting regulations
- Support Tickets: Retained for 3 years for quality assurance and legal compliance
- Analytics Data: Aggregated and anonymized data may be retained indefinitely
8. Your Privacy Rights
Depending on your location, you may have the following rights:
8.1 GDPR Rights (EEA Users)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit processing of your data
- Data Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for marketing communications
8.2 CCPA Rights (California Users)
- Know: Request information about data we collect, use, and share
- Delete: Request deletion of your personal data
- Opt-Out: Opt-out of sale of personal information (we do not sell data)
- Non-Discrimination: Exercise rights without facing discrimination
8.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@lithi.ai. We will respond within 30 days.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
- Essential Cookies: Required for basic functionality (e.g., session management)
- Analytics Cookies: Track usage patterns to improve our Services
- Preference Cookies: Remember your settings and preferences
- Marketing Cookies: Deliver relevant advertisements (with your consent)
You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our Services.
10. Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
11. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@lithi.ai.
12. International Data Transfers
Your information may be transferred to and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from your country.
For EEA users, we ensure that data transfers comply with GDPR through Standard Contractual Clauses or other approved mechanisms.
13. Do Not Track Signals
Some browsers support "Do Not Track" (DNT) signals. Currently, we do not respond to DNT signals, as there is no industry standard for how to interpret them. We will update this policy if we implement DNT support in the future.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting a notice on our website
- Sending an email to your registered email address
- Updating the "Last Updated" date at the top of this policy
Your continued use of the Services after such notice constitutes acceptance of the updated policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
16. Compliance Statement
Lithi Technologies is committed to compliance with:
- GDPR: General Data Protection Regulation (EU)
- CCPA: California Consumer Privacy Act
- CAN-SPAM Act: Controlling the Assault of Non-Solicited Pornography And Marketing Act
- TCPA: Telephone Consumer Protection Act
- SOC 2 Type II: Security and availability controls (certification in progress)