This policy explains what personal information LatticeKit LLC ("LatticeKit", "we", "us") collects when you visit latticekit.tech, create an account on latticekit.app, or use the LatticeKit platform (the "Service"), how we use and share it, and the choices you have. It applies to the businesses that use the Service and the people who operate those accounts. Where a business puts its own customers' information into the Service, that business decides why and how it is used; we process it on the business's behalf, and section 4 explains what that means for you if you are one of those customers.
1. What we collect
- Account information. Your name, email address, business name, business address, the role you hold in the account, and the version of the terms you accepted and when.
- Billing information. A card is collected and held by our payment processor on a page it hosts. We never receive the card number. We store a reference to the card, its brand, its last four digits and expiry, and your plan, invoices and usage.
- Sign-in and security information. Credentials in hashed form, passkeys, one-time codes, session identifiers, API keys in hashed form, the IP address and device details of sign-ins and API calls, and the audit trail of actions taken in the account.
- Usage information. Which features and endpoints are used, how much, and the metered usage that drives billing. We record errors and performance to keep the Service working.
- Content you give us. Messages you send us, feedback, and anything you upload to the Service.
- Waitlist and marketing. If you join the waitlist we keep the name, email and business details you submit.
2. How we use it
- To provide, secure and support the Service: creating and running your account, signing you in, sending the emails the Service needs to send (verification links, invitations, receipts, security notices), billing you, and answering your questions.
- To operate the AI features you use. Prompts and the information the AI operator reads to answer them are sent to the AI provider we use to generate the response; we record how much was used so it can be metered and capped.
- To keep the Service reliable: monitoring, debugging, capacity planning, and defending against abuse and fraud. Rate limits are keyed on the address a request comes from.
- To tell you about the Service: product updates and, if you joined the waitlist, an invitation when there is one. You can opt out of marketing email at any time; we still send the messages the Service needs to operate.
- To meet legal duties and enforce our terms.
3. Who we share it with
- Processors that help us run the Service, under contracts that limit them to our instructions: hosting and infrastructure, the payment processor, email and text delivery, error monitoring, and the AI provider that generates responses. They receive only what their role needs.
- Third parties you connect through the Service — a payment processor for your own customers, a calendar or channel partner, a sign-in provider — receive what the connection requires, under their own terms.
- The businesses you deal with. If you are a customer or staff member of a business on the Service, that business sees the information you give it and the record of your dealings with it.
- When the law requires it, or to protect the rights, safety or property of LatticeKit, our users or the public, and in a merger, acquisition or sale of the business, with notice.
We do not sell personal information and we do not use it for advertising.
4. Information a business puts into the Service
Businesses use the Service to run bookings, sales, memberships, staff schedules and messaging. The people in those records — customers, members, employees — are the business's people, not ours. The business decides what it collects and why; we hold and process it only to run the Service for that business and on its instructions. If you are one of those people and want to see, correct or delete your information, contact the business; we will help it respond. Messages the Service sends on a business's behalf go only to people who have consented to hear from that business through that channel.
5. Cookies
latticekit.app uses cookies that the Service needs: a session cookie to keep you signed in, a short-lived cookie that carries a signup through its steps, and a cookie for a staff member acting on a tenant's behalf. latticekit.tech, this site, sets no cookies of its own. We do not use advertising or cross-site tracking cookies.
6. Retention
We keep account information for as long as the account is open and for 30 days after it closes, so it can be exported, then delete it from active systems; backups expire on their own schedule. We keep billing records, audit trails and security logs for as long as the law or a dispute requires. Waitlist entries are kept until you are invited or ask to be removed. A signup that is never completed expires and is deleted.
7. Security
Personal information is encrypted in transit and at rest. Card numbers never touch our systems. Credentials and API keys are stored hashed. Access to production data is limited to the people who need it to run the Service, is logged, and is protected by strong authentication. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the authorities as the law requires.
8. Your choices and rights
- You can see and change your account information in the console, and export your business's data at any time.
- You can ask us to access, correct, delete or export the personal information we hold about you, or to restrict or object to how we use it, by writing to hello@latticekit.app. We answer within 30 days. Some requests are limited where we must keep information by law or to run your account.
- You can opt out of marketing email through the link in any such email.
- If you are in a jurisdiction with a data-protection authority, you may complain to it; we would rather hear from you first.
9. Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16 as an account holder. A business that records information about minors — a family membership, a junior class — does so under its own responsibility and with the consents it needs.
10. Where information is processed
We are based in the United States and process information there. If you use the Service from elsewhere, your information is transferred to and processed in the United States, and we rely on the contractual safeguards our processors provide.
11. Changes to this policy
We may update this policy. Material changes are announced to account owners and posted here with a new effective date before they take effect.
12. Contact
LatticeKit LLC, a Michigan limited liability company · hello@latticekit.app