Privacy Policy
Last updated 2026-10-09
LeadLamp (“we”) is operated by an independent developer. This policy explains what we collect when you use leadlamp.app, why, and what you can do about it. We’ve written it to match what the software actually does.
Questions or requests: hello@leadlamp.app.
What we collect
- Account: your email address, your language preference, and the accounts and stores you belong to.
- Store settings: store name, report recipients’ email addresses, time zone, send time, and reorder settings.
- Inventory data you give us: SKUs, product and supplier names, stock on hand, stock on order, lead times, safety stock, pack sizes and units sold over 14 or 28 days. We keep the parsed rows from CSV imports and the file name, not the original file.
- Platform credentials, if you connect a store: a WooCommerce REST API key and secret, or a Shopify app’s client ID and secret (or an older Admin API token). Slack webhook URLs, if you add one. These are encrypted before they’re stored.
- Weekly reports: a snapshot of each report we generate, and the time each report link or tracking image was opened. We don’t record IP addresses or devices for these events.
- Billing, if you upgrade: your Stripe customer and subscription IDs, plan and renewal date. Card details go to Stripe and never reach us.
- Abuse prevention: when someone requests a sign-in email or opens the demo, we record a keyed one-way hash of their IP address (not the address itself) so we can limit repeated requests.
What we read from Shopify and WooCommerce
Connections are read-only. We read product and variant SKUs, names and stock levels, and, from recent orders, only the order ID and its line items, of which we keep just the SKU and quantity to count units sold. We don’t request or store customer names, addresses, emails or payment details.
If you turn on WooCommerce threshold write-back, we write each product’s low-stock threshold and nothing else.
How we use it
- To compute reorder points and send your weekly report by email (and to Slack, if you set it up).
- To sign you in: we email a one-time link and code.
- To run the service: preventing abuse, fixing problems and enforcing plan limits.
We don’t sell your data, use it for advertising, or train AI models on it. We don’t look at your store data except to fix a problem you’ve reported, or when the law requires it.
Cookies
- ll_session — keeps you signed in. HttpOnly, expires after 30 days or when you sign out.
- ll_locale — remembers English or Chinese. Expires after one year.
We don’t use advertising or cross-site tracking cookies.
Who processes data for us
- Cloudflare — hosting, database (Cloudflare D1, primary location in the Asia-Pacific region) and sending email. Cloudflare keeps short-term request logs to operate its network.
- Stripe — payments, only if you upgrade.
- Google Fonts — our pages load fonts from Google, which receives your IP address when your browser fetches them.
- Shopify, WooCommerce and Slack — only when you connect them, and only at your direction.
How long we keep it
- Your account and store data: until you delete the store or ask us to delete your account.
- Weekly reports: 4 weeks on the Free plan; kept on paid plans until you delete the store.
- Demo workspaces: deleted automatically after 24 hours.
- Sign-in sessions are deleted when they expire; sign-in codes are deleted 7 days after they expire.
- Abuse-prevention records (hashed IP addresses): deleted after 48 hours.
- When you ask us to delete your account, we delete it within 30 days.
Your choices and rights
You can edit or delete your SKUs and stores in the app at any time. To get a copy of your data, correct something you can’t edit, or delete your whole account, email hello@leadlamp.app from the address on your account. We’ll reply within 30 days.
Depending on where you live (for example under the GDPR or CCPA), you may have additional rights to access, correct, delete or port your data, or to object to processing. Contact us and we’ll help.
Security
Everything is served over HTTPS. Platform credentials and Slack webhooks are encrypted at rest with AES-GCM. Sign-in links and codes are stored only as hashes and expire after 20 minutes (invitation links after 7 days). No system is perfectly secure; if we learn of a breach that affects your data, we’ll tell you.
Children
LeadLamp is a business tool and isn’t meant for anyone under 16.
Changes
If we change this policy, we’ll update the date above. If a change affects how we use data you’ve already given us, we’ll email account owners before it takes effect.