Privacy Policy
Effective: 7 September 2026 Who we are: Lath LLC ("Lath", "we"), 3348 Snowy Butte Ln, Central Point, OR 97502. Contact: privacy@trylath.com.
1. What Lath is, and the two kinds of people this policy covers
Lath is a platform that lets software companies ("Customers") add sign-in, email and SMS to their products. Because of that, we handle personal data in two roles:
- For Customers' account holders, the developers and team members who sign up to Lath, we are the controller. Sections 2 to 9 apply to you directly.
- For Customers' end users, the people who sign in to a Customer's product or receive a message from it, our Customer is the controller and we are their processor. We handle your data only on the Customer's instructions. Section 10 explains what that means and how to exercise your rights, which you do through the Customer.
2. Data we collect from account holders
| Category | Examples | Why |
|---|---|---|
| Account identity | email address, name, the business name you give us | to create and secure your account |
| Authentication data | sign-in codes and links (hashed, short-lived), session identifiers, device and browser type | to sign you in and keep you signed in |
| Business identity, when you register for SMS sending | legal name, tax identifier, business address, website, authorized contact | required by telecommunications carriers to register your messaging identity |
| Usage and billing | operations performed, messages sent, numbers held, invoices, payment status | to run the service, bill you and prevent abuse. Card details are handled by our payment processor and never stored by us |
| Technical | IP address, request timestamps, API key identifiers | security, rate limiting, fraud prevention, and the activity log you can read |
| Support | what you send us when you contact support | to help you |
We do not buy data about you and we do not use your data to build advertising profiles.
3. Data we process for Customers about their end users
Only what the Customer sends us or asks us to collect: email addresses, phone numbers, names and profile details returned by an identity provider the end user chose (such as Google or Microsoft), message content and delivery events, consent records, and technical data such as IP address and device type at sign-in. We hold this in an environment isolated to that Customer.
4. Lawful bases (GDPR and UK GDPR)
- Contract: almost everything in section 2, because we cannot provide the service otherwise.
- Legal obligation: carrier registration data, tax and accounting records.
- Legitimate interests: security logging, fraud and abuse prevention, service analytics that do not profile individuals. You may object; see section 8.
- Consent: only where we ask for it explicitly, such as optional product emails to account holders. Withdraw at any time.
5. Who receives data
We use service providers in these categories. Each acts on our instructions under a written agreement, and we do not sell personal data.
| Category | Purpose |
|---|---|
| Cloud infrastructure | hosting, databases, encryption key management |
| Email delivery | transmitting email you or your Customers send |
| Telecommunications carriers and messaging aggregators | transmitting SMS, and carrier registration of sending identities |
| Identity providers | when an end user chooses to sign in with Google, Microsoft or GitHub, that provider processes the sign-in under its own policy |
| Payment processing | card payments and invoicing |
| Error and performance monitoring | diagnosing faults |
| Professional advisers | legal, accounting, where required |
A current list of subprocessors by name is available on request to privacy@trylath.com and to Customers under their data processing terms. We may also disclose data when the law requires it, to protect the rights or safety of any person, or in a merger or acquisition, with notice.
6. International transfers
We are based in the United States and store data there. Where data about people in the EEA, UK or Switzerland is transferred to us, we rely on standard contractual clauses or an equivalent recognised mechanism.
7. Retention
| Data | Kept |
|---|---|
| Account data | for the life of the account, then deleted within 30 days of closure, except as below |
| Activity and event logs | 13 months, then deleted or anonymised |
| Message content | 30 days after delivery for transactional email and SMS unless the Customer configures a shorter or longer period; delivery metadata for 13 months |
| Consent and suppression records | for as long as needed to honour the choice, which may be indefinite for an opt-out |
| Carrier registration data | as long as the registration is active plus the period the carrier requires |
| Billing records | 7 years, as tax law requires |
| Security logs | 13 months |
8. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing, to port your data, and to withdraw consent. Write to privacy@trylath.com. We will respond within 30 days, or sooner if the law requires. We will not discriminate against you for exercising a right. If you are in the EEA or UK you may also complain to your supervisory authority.
California residents: you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, and to opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not use or disclose sensitive personal information other than to provide the service. You may exercise rights through privacy@trylath.com or an authorised agent; we will verify your identity through your account email.
9. Security
Data is encrypted in transit and at rest. Customer environments are isolated at the database layer with row-level security. Secrets are encrypted with keys we do not hold in plaintext. API keys are stored hashed. Access to production is limited to named staff with multi-factor authentication and is logged. If a breach affects you, we will notify you and any regulator as the law requires.
10. If you are a Customer's end user
We process your data for the Customer whose product you used. To access, correct or delete your data, or to stop receiving messages, contact that Customer; their contact details are in the message you received or in their product. Every marketing email we deliver contains an unsubscribe link, and replying STOP to any SMS stops further messages from that sender. If you cannot reach the Customer, write to privacy@trylath.com and we will help route your request.
11. Children
Lath is not directed at children under 13, and Customers may not use Lath to collect personal information from children under 13 (or under 16 where that is the local age) without the consent the law requires.
12. Changes
We will post changes here and, for material changes, email account holders at least 14 days before they take effect.
13. Contact
privacy@trylath.com · Lath LLC, 3348 Snowy Butte Ln, Central Point, OR 97502