Privacy Policy

Last updated: June 5, 2026

Lightarch is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard your information. We comply with GDPR (EU), CCPA/CPRA (US), POPIA (South Africa), PIPEDA (Canada), PDPA (Singapore), LGPD (Brazil), and other applicable laws.

1. Information We Collect

1.1 Information You Provide

  • Account registration: Name, email address
  • Payment: Billing details processed by Lemon Squeezy — we do not store card numbers
  • Support: Messages, feedback, and support tickets

1.2 Your Data (Telemetry)

"Your Data" is any information you submit to the Service: application traces, log records, metrics data, and associated attributes. Lightarch does not use Your Data for any purpose other than providing the Service. We do not sell, rent, or share Your Data with third parties.

1.3 Automatically Collected

  • IP address, browser type, and version
  • Device information and operating system
  • Pages visited and time spent on the Service
  • Crash reports and error logs
  • Authentication session data

2. How We Use Your Information

  • Service delivery: Processing and storing Your Data, providing dashboards, queries, and alerts
  • Communication: Transactional emails, alert notifications, support responses
  • Service improvement: Anonymised usage analysis, debugging, new feature development
  • Security: Fraud detection, access control, audit trails
  • Marketing (with consent): Product updates, feature announcements — opt out any time

3. Data Storage and Security

3.1 Storage Architecture

  • Hot Storage (0–48 hours): Per-tenant SQLite database (D1) on Cloudflare's edge network for real-time queries
  • Cold Storage (48+ hours): Your Data archived to your own R2 bucket — you own and control this data
  • Region control: Enterprise plan users may specify their preferred R2 region for data localisation (GDPR, LGPD compliance)

3.2 Security Measures

  • Encryption in transit: TLS 1.2+ for all data
  • Encryption at rest: Cloudflare R2 server-side encryption
  • Role-based access control (Owner, Admin, Member, Viewer)
  • Unique DSN tokens for data ingestion authentication
  • PBKDF2 password hashing

4. Data Retention and Deletion

  • Hot storage: 48 hours (automatic deletion)
  • Cold storage: Indefinite — in your R2 bucket under your control
  • User-initiated deletion: Delete Your Data from the dashboard at any time
  • Account deletion: Hot storage deleted immediately; account metadata retained 90 days for billing/legal

5. Third-Party Sub-processors

  • Cloudflare: Infrastructure, DDoS protection, edge computing
  • Lemon Squeezy: Payment processing (global multi-currency)
  • Resend: Transactional email delivery

We notify users 30 days in advance of any new sub-processor additions.

6. Your Rights

Depending on your jurisdiction, you have the right to:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your personal information ("right to be forgotten")
  • Portability: Receive your data in a portable format
  • Object: Object to certain processing activities
  • Restrict: Request restriction of processing in certain circumstances

To exercise any of these rights, contact us at [email protected]. We respond within 30 days.

7. Multi-Jurisdictional Compliance

  • GDPR (EU/EEA): Lawful basis for processing, data subject rights, 72-hour breach notification, Standard Contractual Clauses for international transfers
  • CCPA/CPRA (California): Right to know, delete, correct, opt-out; no sale of personal information
  • POPIA (South Africa): Accountability, purpose limitation, information quality, breach notification to Information Regulator
  • PIPEDA (Canada): Consent-based collection, security safeguards, individual access
  • PDPA (Singapore): Collection, use, and disclosure obligations
  • LGPD (Brazil): Data processing on lawful basis, data subject rights

8. Data Breach Notification

In the event of a data breach affecting your personal information, we will:

  • Notify affected users within 72 hours of discovery (GDPR) or 24 hours for high-risk breaches
  • Notify relevant regulatory authorities as required by applicable law
  • Notify the South African Information Regulator as required by POPIA
  • Provide details of the breach, data affected, and remediation steps

9. Cookies

We use cookies and similar tracking technologies. See our Cookie Policy for details.

10. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email 30 days before taking effect. Continued use of the Service after changes constitutes acceptance.

Questions about this policy?