1 — Controller and scope
Lainstack Ltd, company number 17243799, is the controller for the processing described in this notice. Our registered office is 128 City Road, London, United Kingdom, EC1V 2NX. Contact us at [email protected].
This notice covers the Lainstack website, business enquiries, product updates, accounts, support, security, and subscriptions. When we process personal data in customer content on a customer's behalf, that customer is the controller and our Data Processing Addendum applies.
2 — Data, purposes, and legal bases
- Website delivery and security. We process IP addresses, request and device information, timestamps, and security signals to deliver and protect the website. Our legal basis is our legitimate interest in operating a secure and reliable service.
- Optional website analytics. With your consent, our self-hosted Umami service collects page paths, performance, browser and device information, coarse location, referring source, selected interactions, heatmaps, and sampled session replay. Contact and early-access forms are excluded from replay. If you submit an enquiry, its random request ID may link the enquiry to the same analytics session. We use this data to understand and improve the public website. Our legal basis is consent.
- Privacy-minimised server traffic measurement. Independently of optional browser analytics, the marketing server records a normalised page path, response status, controlled source and campaign categories, and recognised search-crawler classification for HTML requests. The event does not contain an IP address, cookie, raw user agent, referrer hostname or URL, raw query string, or visitor identifier. We use aggregate counts to understand which public pages and sources receive requests and to improve the website. Our legal basis is our legitimate interest in measuring and improving the public website with privacy-minimised server telemetry.
- Enquiries and product updates. We process the contact details and information you submit to respond to enquiries and manage customer relationships. Our legal basis is our legitimate interest in doing so. We send product updates only with your consent.
- Accounts, support, and subscriptions. We process business contact details, account and access information, service usage, support and security records, and subscription and transaction information to provide, secure, support, and administer the service. We receive this data from you, your organisation, its identity provider, and Paddle. Our legal bases are performance of a contract, our legitimate interests in operating the service, and our legal obligations, including tax and accounting requirements, as applicable.
Required form and account fields are identified when collected. Without them, we may be unable to respond to an enquiry or provide and administer an account.
For essential browser error reporting, GlitchTip receives redacted technical errors with the page pathname, browser and operating-system context, release, and environment; it does not receive IP addresses, cookies, query strings, referrers, or form contents.
3 — Browser storage and analytics controls
Analytics, heatmaps, and replay load only after you accept. You can withdraw consent at any time through “Analytics choices” in the footer. Your choice is stored in your browser for 180 days. The website also uses storage needed for security and your display preference. Details are in our Cookie and Analytics Notice.
Contact forms use Cloudflare Turnstile to assess abuse and return a verification result.
4 — Recipients and international transfers
We use service providers for hosting, storage, website security, customer relationship management, and transactional email. Providers that process customer personal data are listed in our Subprocessor Register. We may also disclose data to professional advisers or public authorities where necessary to protect legal rights or comply with law.
Paddle is our merchant of record and acts as an independent controller for checkout and payment data under its own privacy notice. We receive the transaction and subscription information needed to administer the service.
Where personal data is transferred outside the UK or EEA, we use an applicable adequacy decision or approved contractual safeguards. Contact us for information about the safeguard relevant to a transfer.
5 — Retention
- Website analytics events and sessions are retained for up to 180 days.
- Replay and heatmap data are retained for up to 30 days.
- Privacy-minimised server traffic events are retained for up to 30 days.
- Enquiries, account, support, security, and subscription records are kept for as long as needed for the purposes above and applicable legal, accounting, security, or dispute requirements.
- Customer content is retained and deleted under the customer agreement and Data Processing Addendum.
6 — Your rights
Depending on the law that applies, you may have rights to access, correct, erase, restrict, object to processing, and receive your personal data. You may withdraw consent at any time without affecting earlier processing. Contact [email protected] to exercise a right.
Right to object. You may object to processing based on our legitimate interests and to the use of your personal data for direct marketing.
Data protection complaints may be sent to [email protected]. We will acknowledge complaints within 30 days, investigate them, keep you informed where appropriate, and communicate the outcome without undue delay.
If your request concerns data controlled by a Lainstack customer, we may refer the request to that customer. You may complain to the UK Information Commissioner's Office or your local supervisory authority.