Not open yet — signups haven't started. Join the list for the day they do.
Home/Legal/Privacy policy

Legal

Privacy Policy

Effective date: August 28, 2026 · Version 2026-08-28.1

This Privacy Policy explains how Analytix Media LLC, doing business as Lemonade Host and the current operator of the Lemonade Host service, collects, uses, discloses, retains, and protects personal information in connection with lemonadehost.com, the account dashboard, hosting platform, managed features, deployment tools, integrations, support channels, and related services. It also explains the distinction between information Lemonade Host uses for its own operations and information it processes on behalf of customers through customer Sites.

1. Scope and roles

For account administration, billing, security, fraud and abuse prevention, support, service operation, legal compliance, and our own business purposes, Analytix Media LLC generally determines why and how personal information is processed and acts as a controller or business, as those terms are used by applicable privacy laws. When Lemonade Host stores Customer Content or receives Visitor Data through a customer-configured Form, Booking, Commerce, or similar feature solely to provide the Service on the customer's instructions, the customer generally determines the purpose of the processing and acts as controller or business, while Lemonade Host generally acts as processor, service provider, or contractor.

This allocation depends on the actual circumstances and applicable law. A customer remains responsible for its Site, its visitor-facing notices, its lawful basis for collection, and its instructions to Lemonade Host. The Customer Data Processing Terms supplement this Policy for data we process on a customer's behalf. Questions and privacy requests concerning Lemonade Host account information may be sent to [email protected]. A request concerning data collected by a customer Site should ordinarily be directed to the owner or operator of that Site.

2. Summary of current practices

We collect the information reasonably needed to provide and secure a hosting service, process payments, connect authorized repositories and deployment tools, operate managed data features, respond to support requests, prevent abuse, and comply with law. We do not sell personal information and do not share personal information for cross-context behavioral advertising. We do not intend to run third-party advertising trackers at launch. We may use essential cookies, local storage, and similar technologies for login, session continuity, preferences, payment, fraud prevention, load balancing, diagnostics, and security.

Our primary application systems may operate on infrastructure owned or controlled by the Operator, together with third-party services for content delivery, network security, payments, repository connections, transactional email, monitoring, and optional backup storage. No method of collection, transmission, or storage is completely secure. Customers and visitors should not submit regulated or highly sensitive information unless an applicable feature is expressly designed and contracted for that purpose.

3. Information collected before and during account creation

Before paid accounts are available, a waitlist may collect an email address, signup date, source page, consent and delivery records, and ordinary request or security logs. A waitlist address is used to send the requested launch communication and related delivery or suppression processing. It is not automatically enrolled in an ongoing marketing newsletter unless the person separately opts in.

After launch, account and identity information may include an email address; account identifier; display name or organization name if provided; country, region, language, or time zone if supplied or reasonably inferred for service operation; account status, plans, Sites, permissions, and settings; acceptance records for legal terms and recurring-billing consent; and identity, authority, or ownership information supplied when resolving an account, payment, abuse, or ownership dispute.

4. Authentication and session information

Authentication may use magic links, one-time codes, passkeys, passwords, GitHub or another OAuth provider, or other methods we make available. Depending on the method, we may process hashed or otherwise protected authentication data; login-link issuance and expiration records; OAuth identifiers and authorization metadata; session identifiers and essential cookies; login time; IP address; browser, operating-system, or device information; failed attempts, revocations, and security events; and account-recovery or verification records.

We do not receive a user's GitHub password. If password authentication is offered, passwords are intended to be stored using a one-way password-hashing method rather than in readable form. Users are responsible for protecting the email account, device, credentials, passkeys, recovery methods, and third-party accounts used to authenticate.

5. Billing and transaction information

Stripe or another disclosed payment processor collects payment-card information directly and may process card details, billing address, tax information, device information, and fraud-prevention data under its own privacy terms. Lemonade Host generally receives and stores processor customer, subscription, invoice, payment, refund, dispute, and payment-method references; card brand, expiration information, last four digits, and payment status when made available; billing name, company name, country, postal code, and tax identifiers when needed; plan, Site, add-on, amount, currency, interval, discount, tax, renewal, and cancellation information; and correspondence concerning refunds, chargebacks, and billing support.

We do not intentionally store full payment-card numbers or card security codes on our own systems. Customers may not configure ordinary forms or booking notes to collect that information. If a payment interface is embedded within a Site, the payment fields should be hosted or tokenized by the authorized payment processor so the sensitive card data is transmitted directly to that provider.

6. Site, plan, and operational metadata

We may process Site names and identifiers; Lemonade Host subdomains and custom domains; DNS and certificate status; plan, billing interval, add-ons, storage, bandwidth, request counts, file counts, deployment counts, and other resource measurements; settings, configuration, feature flags, and operational status; creation, modification, suspension, cancellation, and deletion dates; and backup, restore, migration, and protection metadata. We use this information to provide the Service, administer billing, enforce limits, diagnose problems, communicate with customers, and plan capacity.

7. Customer Content

We store and serve the files and content customers deploy, which may include HTML, CSS, JavaScript, images, fonts, text, code, configuration, media, and other site assets. Customer Content may contain information about customers, employees, contractors, clients, visitors, or other people. Customers control what they upload and are responsible for having authority and a lawful basis to use it.

We do not routinely read private Customer Content for advertising or unrelated marketing. We may access or automatically analyze Customer Content when reasonably necessary to provide the Service, respond to a customer request, detect malware or abuse, enforce policies, investigate an incident, maintain security, measure resource use, comply with law, or attempt a restore. Access may be performed by automated systems or authorized personnel and is limited according to the purpose and available controls.

8. Forms data

When a customer enables a managed Form, Lemonade Host may receive and store the fields configured by that customer, commonly a name, email address, telephone number, subject, and free-text message. To operate and protect the feature, we may also process submission time and status, the Site and page through which the form was submitted, referring page, browser or user-agent information, and a salted one-way hash or other privacy-reduced representation of an IP address for anti-abuse, rate-limiting, and security purposes. The customer decides which fields to request and how to use the submission.

The ordinary retention period for a form submission is up to 180 days after submission, unless the customer deletes it sooner, a different feature term is presented, or a longer period is reasonably necessary for security, abuse response, legal process, or a dispute. Customers should export information they need to retain and should not use a general-purpose form to collect medical or health information, full card data, government identifiers, account passwords, authentication secrets, or other highly sensitive information.

9. Bookings data

When a customer enables Bookings, Lemonade Host may receive and store a visitor's name, email address, telephone number, selected service, appointment date and time, stated price, status, and a free-text note, together with operational records needed to send a confirmation, calendar invite, reminder, rescheduling link, or cancellation link. A customer may receive and use the booking information through its dashboard and communications.

The ordinary retention period for a booking record is up to 24 months after the scheduled, completed, or canceled appointment unless the customer deletes it sooner, a different term is disclosed, or longer retention is reasonably necessary for a dispute, security incident, legal process, or another lawful purpose. The note field is not designed for medical histories, symptoms, diagnoses, treatment information, insurance information, or other regulated health data. A customer using the feature for a therapist, clinic, wellness provider, or similar business must configure the form so visitors are not invited to submit protected health information and must not represent that Lemonade Host provides HIPAA-compliant records or communications.

10. Commerce and order data

When a customer enables a managed Commerce feature, Lemonade Host may receive and store a purchaser's name, email address, telephone number if requested, billing or shipping address, items ordered, quantities, prices, discounts, taxes, shipping information, order status, fulfillment information, refunds, and related communications. Payment-card details are intended to be sent directly to Stripe or another authorized payment processor and not retained by Lemonade Host.

Commerce order records may be retained for up to seven years after the transaction because they may be relevant to tax, accounting, fraud, chargeback, warranty, fulfillment, and legal obligations. A customer may delete or request deletion sooner where available and lawful, but certain transaction metadata may remain in billing, fraud, security, processor, tax, backup, or legal-hold systems. Customers are responsible for determining the retention period appropriate for their business and for exporting records they need independently.

11. Server, request, device, and security logs

Our systems, Cloudflare, and other network or security providers may automatically process IP addresses; timestamps; requested hostnames, URLs, paths, methods, protocols, and response codes; user-agent, browser, operating-system, device, and referring-page information; network, routing, cache, TLS, DNS, firewall, bot, and security information; request and response sizes, latency, bandwidth, and error information; approximate geographic region derived from an IP address; and identifiers or patterns used to detect abuse, automated traffic, attacks, fraud, or security incidents.

Logs may relate to visitors to Lemonade Host pages, account users, API or MCP clients, and visitors to customer Sites. Ordinary request logs are generally kept for up to 30 days, but relevant records may be retained longer when needed for security, abuse, fraud, billing, incident response, legal process, or a dispute.

12. Deployment, repository, API, CLI, and MCP information

For deployments and integrations, we may process deployment time, source, status, actor, commit, branch, file manifest, file hashes, error output, rollback or restore information; GitHub or other supported account, organization, repository, branch, installation, webhook, and commit metadata; App installation identifiers and, when needed, encrypted or otherwise protected integration credentials; webhook verification material; API and MCP token identifiers, names, scopes, creation dates, last-used dates, revocation dates, and audit records; one-way hashes of issued tokens; and commands, files, prompts, and instructions transmitted through an authorized deployment channel.

A raw token may be displayed only when it is created. After that, a properly implemented hashed token cannot be retrieved by us and must be replaced if lost. Audit records for authentication, deployments, APIs, CLI, and MCP use are generally retained for up to 30 days, with relevant records kept longer when needed to investigate compromise, abuse, billing, or a dispute.

13. Support and communications

We collect information provided in support tickets, emails, chat, feedback, abuse reports, privacy requests, legal notices, and other communications. This may include contact details, account information, screenshots, files, diagnostic information, and message contents. Do not send passwords, full card numbers, private keys, raw access tokens, repository secrets, or unnecessary sensitive information in an ordinary support message.

Support communications are generally retained for up to 24 months after the matter is closed, unless a shorter period is practical or longer retention is reasonably needed for security, abuse, legal, billing, fraud, quality review, or repeated issues. Transactional records documenting a cancellation, consent, refund, or legal request may be retained under the longer schedule applicable to that record.

We may collect and preserve reports, evidence, copies of content, logs, correspondence, ownership information, decisions, appeals, and other records associated with suspected phishing, malware, fraud, infringement, spam, attacks, policy violations, sanctions, payment disputes, legal requests, or account ownership disputes. We use this information to investigate, protect the Service and third parties, enforce agreements, comply with law, and establish, exercise, or defend legal claims. Retention depends on the nature and duration of the matter and may continue for as long as reasonably necessary.

15. Sources of personal information

We collect personal information from you when you join a waitlist, create an account, pay, configure a Site, deploy content, activate a feature, contact support, or exercise a right; from your organization, administrator, employee, contractor, client, or Authorized Agent; from a customer-authorized AI assistant, script, CLI, API, or MCP client; from GitHub and other integrations you connect; from Stripe and other service providers; automatically from browsers, devices, servers, networks, Cloudflare, and security systems; from visitors who access a customer Site or submit information through a managed feature; from abuse reporters, rights holders, courts, regulators, law-enforcement agencies, and other third parties; and from public sources where reasonably necessary to verify ownership, investigate abuse, or comply with law.

16. How we use personal information

We may use personal information to create, authenticate, administer, secure, and support accounts; process purchases, renewals, taxes, refunds, disputes, and chargebacks; host, store, cache, back up, restore, deploy, and serve Customer Content; operate Forms, Bookings, Commerce, and other customer-configured features; connect repositories and process authorized deployments; issue, verify, scope, rotate, and revoke tokens; configure domains, DNS, and certificates; provide transactional email, receipts, magic links, renewal notices, policy notices, and security alerts; measure storage, bandwidth, traffic, deployments, and other resource use; monitor availability and diagnose errors; provide support; detect and respond to fraud, abuse, malware, phishing, spam, attacks, and unauthorized access; enforce our policies and technical limits; protect customers, visitors, the public, our systems, and third parties; comply with contracts, tax obligations, sanctions, legal process, and other laws; establish, exercise, or defend legal claims; complete a financing, merger, reorganization, sale, assignment, or transfer of the Lemonade Host business; and perform another use disclosed at collection or authorized by the person or customer that controls the information.

We do not use Customer Content or Visitor Data to create advertising profiles. We do not intentionally use private Customer Content or Visitor Data to train a publicly available general-purpose artificial-intelligence model without a separate, clear opt-in from the party authorized to give it.

Where a privacy law requires a legal basis, we generally rely on performance of a contract to create and administer accounts, process purchases, host Sites, deploy files, and provide requested features; legitimate interests in securing and improving the Service, preventing fraud and abuse, measuring resource use, communicating about operations, and protecting legal rights, balanced against individual interests; compliance with legal obligations involving tax, accounting, sanctions, consumer protection, privacy, court orders, and regulatory requirements; consent for a waitlist, optional marketing, nonessential cookies or analytics, or another use for which consent is requested; and vital interests or public-interest grounds only in unusual circumstances where law permits.

When we process Visitor Data solely on a customer's documented instructions, the customer is responsible for identifying and maintaining its legal basis and for providing required notices. Withdrawing consent affects future processing and does not make prior lawful processing unlawful.

18. Cookies and similar technologies

We may use cookies, local storage, session identifiers, and similar technologies that are necessary or reasonably useful for login, session continuity, magic-link, OAuth, and passkey flows; security, fraud detection, load balancing, and abuse prevention; language, interface, and consent preferences; checkout and payment processing; and essential technical performance. These technologies may be set by Lemonade Host or by providers such as Cloudflare, Stripe, or an authentication provider.

We do not intend to use third-party advertising cookies or pixels at launch. If we add nonessential analytics, advertising, or another materially different tracking practice, we will update this Policy and provide a consent or opt-out mechanism where required. A browser's "Do Not Track" signal is not a uniform legal or technical standard, and we do not treat it as a separate request when we are not tracking activity over time across unrelated services for advertising. Where applicable law requires recognition of a legally valid opt-out preference signal, such as Global Privacy Control for activities to which it applies, we will honor it. Because we do not sell or share personal information for cross-context behavioral advertising, an advertising sale-or-share opt-out should not be necessary for our current practices.

Third parties may collect information about activity over time and across services when a person directly interacts with a third-party payment page, repository provider, embedded service, or customer-selected script. Those parties operate under their own terms. Lemonade Host does not authorize unrelated cross-site advertising tracking through its own marketing pages at launch.

19. Service providers, subprocessors, and other recipients

We disclose personal information to providers that perform functions for Lemonade Host, subject to contracts, instructions, and applicable law. Provider categories may include payment processors such as Stripe; content-delivery, DNS, caching, certificate, tunnel, bot-management, and security providers such as Cloudflare; repository and authentication providers such as GitHub; transactional email providers; monitoring and diagnostic providers; optional off-site backup providers such as Backblaze B2; hosting, infrastructure, and internet providers; customer-support and, if enabled, AI-assistance providers; and accountants, attorneys, insurers, security consultants, and other professional or operational advisers.

We may change providers as the Service evolves. We use provider categories in this Policy so ordinary substitutions do not require a complete rewrite, but we will update the Policy or provide notice when a change materially affects the purposes, categories, or risks of processing or when law requires identification. The Customer Data Processing Terms govern subprocessors used for Customer Personal Data.

We may also disclose information to an account owner, organization administrator, or Authorized Agent consistent with permissions; at your direction or with consent; to investigate abuse, fraud, infringement, security incidents, ownership disputes, or policy violations; to comply with law, regulation, subpoena, warrant, court order, sanctions, or other valid process; to protect rights, safety, property, users, visitors, the public, or the Service; to establish, exercise, or defend legal claims; or in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale, assignment, or transfer of all or part of the business.

We may use and disclose aggregated or deidentified information that cannot reasonably be linked to an individual. We will not attempt to reidentify information that applicable law requires us to maintain as deidentified.

20. Customer-connected AI assistants and external tools

A customer may connect an external AI coding assistant, agent, editor, script, or other tool to our MCP server or API using a scoped credential. The customer selects, instructs, and controls that external tool. Lemonade Host processes the command, files, credential identifier, scope, logs, and related metadata needed to perform and secure the requested action. The external provider processes information under its own terms and privacy policy and is not our subprocessor merely because the customer instructed it to connect.

Customers are responsible for deciding what information to provide to an external tool and whether its use is lawful and secure. They should not place raw MCP tokens, passwords, secrets, regulated personal information, or confidential content into an AI prompt unless they understand and accept the external provider's handling of that information.

21. AI-assisted Lemonade Host support

If Lemonade Host offers AI-assisted support, we may send the support message and limited relevant account or diagnostic context to an AI provider to help generate, summarize, classify, or route a response. Before enabling such a feature, we intend to identify the use of AI at the point of interaction, limit the information sent, avoid transmitting passwords, private keys, full card data, or raw access tokens, use available business-data controls, prohibit use of submitted content to train a public model unless the user separately opts in, and configure an appropriate retention period.

AI-generated support may be incomplete or incorrect and should not be treated as legal, security, financial, medical, or other professional advice. A person should review material account, billing, security, or compliance decisions.

22. Customer Sites and visitor rights requests

Each customer is responsible for publishing an accurate privacy notice for its Site; identifying itself as the party responsible for Visitor Data; obtaining required consent for forms, cookies, communications, and analytics; limiting collection and retention; selecting and governing third-party tools; avoiding regulated data the Service is not designed to handle; and responding to visitor rights requests. A customer should notify us when our assistance is reasonably needed to fulfill a lawful request concerning data we process on its behalf.

If a visitor asks Lemonade Host to access, correct, or delete Visitor Data controlled by a customer, we may request the Site and transaction details needed to locate the customer, direct the visitor to the customer, forward the request, preserve the request for security, or act on verified customer instructions. We do not ordinarily decide whether the customer's purpose or refusal is lawful. We may act directly where applicable law requires us to do so, where the customer no longer exists or cannot be reached and action is legally appropriate, or where the data is also used for Lemonade Host's independent security, billing, or legal purposes.

23. International processing and transfers

Lemonade Host is operated from the United States, and primary systems are intended to be located in the United States. Information may be transferred to and processed in the United States and other countries where service providers operate. Those countries may have privacy laws different from the laws where the individual resides.

The Service is presently designed primarily for United States customers and does not, by this Policy alone, represent that every requirement for an EEA, United Kingdom, Swiss, or other restricted international transfer has been completed. A customer that intentionally offers services to people in those jurisdictions or processes their personal data is responsible for determining whether it needs a data processing addendum, transfer impact assessment, standard contractual clauses, representative, local storage, consent mechanism, or another compliance measure. Contact us before using the Service for a workload that requires a specific transfer instrument; we may agree to additional terms or decline the use.

24. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, customer instructions, security, dispute resolution, tax, accounting, legal compliance, and enforcement. Actual retention may vary based on account status, feature settings, backup cycles, legal holds, investigations, and technical constraints.

Our intended baselines are: waitlist addresses until the launch notice is sent or deletion is requested, ordinarily no more than 30 days afterward except for suppression records; ordinary request logs up to 30 days; authentication, deployment, API, CLI, and MCP audit logs up to 30 days; active account information while the account is active and ordinarily up to 30 days after closure; active Customer Content while the Site is active and ordinarily up to 30 days after deletion on primary systems; standard backup copies until the applicable cycle expires, ordinarily within 30 days; retrievable integration credentials until revoked or no longer needed, followed by prompt removal from active systems and later expiration from backups; token hashes until revoked, expired, deleted, or the account closes; form submissions up to 180 days; booking records up to 24 months after the appointment; commerce order records up to seven years; billing, invoice, tax, refund, and dispute records for the period reasonably advisable under payment, tax, accounting, and legal rules; recurring-billing consent and legal-acceptance records for at least three years or one year after the contract ends, whichever is longer; support communications ordinarily up to 24 months after closure; and abuse, security, legal-hold, and litigation records for as long as reasonably necessary.

Deletion from active systems does not always mean immediate deletion from immutable logs, encrypted backups, fraud systems, provider records, or records we are legally permitted or required to retain. We may retain a minimal suppression record to honor an unsubscribe or prevent a deleted account from being recreated through fraud.

25. Security

We use administrative, technical, and physical safeguards intended to protect personal information. Depending on the feature, safeguards may include access controls, network filtering, encryption in transit, encryption at rest for retrievable credentials, one-way hashing for issued tokens, scoped permissions, secret rotation, logging, backups, and security monitoring. GitHub App private keys and other retrievable integration secrets are intended to be encrypted at rest; short-lived access tokens are intended to expire through their normal lifecycle; issued API and MCP tokens are intended to be hashed at rest and displayed only once; and dashboard controls are intended to support revocation.

No security measure is perfect. We cannot guarantee that unauthorized access, loss, alteration, disclosure, hardware failure, software defects, attacks, or other incidents will never occur. Customers remain responsible for their own devices, email, repositories, code, credentials, Authorized Agents, Site configuration, visitor notices, and independent backups.

26. Privacy rights and requests

Depending on residence and applicable law, an individual may have rights to know or access personal information; receive information about categories, sources, purposes, and recipients; correct inaccurate information; delete information subject to exceptions; obtain a portable copy; restrict or object to certain processing; withdraw consent for future processing; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive information; appeal a denied request; and complain to a privacy authority.

Submit a request concerning Lemonade Host account or operational information to [email protected] and identify the account email and right requested. We may verify identity and authority through access to the account email, account authentication, transaction information, or other proportionate steps. An authorized agent may submit a request where law permits, but we may require proof of authorization and direct verification with the individual. We may deny or limit a request where permitted, including when identity cannot be verified, the information belongs to another person, deletion would impair security or legal rights, retention is required, or the request is fraudulent, excessive, manifestly unfounded, or outside applicable law. We will not unlawfully discriminate against a person for exercising a privacy right.

A request concerning Visitor Data controlled by a customer should ordinarily be sent to that customer. We will assist as described in Section 22 and the Customer Data Processing Terms.

27. California privacy information

California's comprehensive privacy law applies only when statutory criteria and relationships are met. To the extent it applies, this Policy describes categories of personal information, sources, business purposes, categories of recipients, retention, and a request method. We do not sell personal information, do not share personal information for cross-context behavioral advertising, and do not knowingly sell or share the personal information of people under sixteen. Even where a particular statutory right does not apply, we may choose to honor a reasonable access, correction, or deletion request when doing so is feasible, secure, and consistent with our obligations.

For Customer Personal Data processed on behalf of a customer, the Customer Data Processing Terms restrict our use to specified business purposes, prohibit sale and cross-context behavioral advertising, require a comparable level of privacy protection to the extent applicable, and provide a process for assistance and remediation.

28. EEA, United Kingdom, and Swiss information

Where applicable, individuals in the EEA, United Kingdom, or Switzerland may have rights to access, correction, deletion, portability, restriction, objection, and withdrawal of consent and may complain to a competent supervisory authority. If we rely on legitimate interests, an individual may request information about the applicable interests. If we rely on consent, withdrawal applies prospectively.

If Lemonade Host actively targets or materially expands service to these jurisdictions, additional organizational and contractual measures may be required. This Policy and the Customer Data Processing Terms provide a general allocation of controller and processor responsibilities, but they do not by themselves include the European Commission's standard contractual clauses, the United Kingdom International Data Transfer Addendum, a local representative appointment, or every enterprise-specific requirement.

29. Automated processing

We may use automated systems to detect spam, attacks, malware, abnormal resource use, payment risk, or policy violations; prioritize support; route reports; and identify technical errors. These systems may temporarily block a request, deployment, Site, payment, or login. Where applicable law grants a right relating to a decision based solely on automated processing that produces a legal or similarly significant effect, a person may request information or human review by contacting [email protected].

We do not intend to use the Service to make employment, credit, housing, insurance, medical, or similarly high-impact decisions about individuals. Customers may not use the Service for a regulated automated-decision workload unless an applicable feature is expressly approved and all required notices, assessments, contracts, and rights mechanisms are in place.

30. Children

The Service is not directed to children or minors, and account holders must be at least eighteen. We do not knowingly collect personal information directly from a person under thirteen through a Lemonade Host account. If we learn that a minor created an account or submitted account information without valid authorization, we may suspend the account and delete the information, subject to security and legal exceptions.

Customers may not intentionally use the Service to collect children's personal information unless they independently satisfy applicable parental-consent, notice, security, and other requirements and the applicable Lemonade Host feature is expressly approved for that use. The base Service and managed features are not designed for children's regulated data.

31. Changes to this Policy

We may update this Policy as the Service, providers, features, laws, or business structure change. The effective date identifies the current version. If a change materially affects how active account information is used, we will provide notice as required by law, which may be by email, account notice, or another appropriate method. A provider-name update that does not materially change the purpose or category of processing may be made by updating the provider description and effective date.

If the Lemonade Host business is transferred, this Policy may be updated to identify the successor controller or business and resulting changes to contacts, locations, and providers.

32. Contact

Privacy questions and requests may be sent to [email protected]. For account security, do not include passwords, full card numbers, private keys, raw access tokens, or other secrets in ordinary email.

Related

The rest of the legal pages

Terms of service

Billing, renewal, deployments, and what happens if something goes wrong.

Acceptable use policy

The limits and rules that keep a 99¢ site healthy for everyone.

Refund and cancellation policy

The 30-day guarantee on a new site, and how billing disputes are handled.

Customer data processing terms

How we handle the visitor data your site collects through Forms, Bookings and Commerce.

Copyright complaints

Where to send a DMCA notice, what it must contain, and how counter-notices work.

Pricing

Every plan, every interval, on one page.

Get on the list

Join the list and we'll email you just once — that's the only thing we use your address for.

Join the list