Privacy & Cookies Policy

Last updated: 26 August 2026

LimeLai Limited (company number 16486216, 86-90 Paul Street, London, EC2A 4NE) is the data controller for personal data we process to provide LimeOrigin. Contact: privacy@limeorigin.com.

What we collect and why

  • Account data — name, email, password (stored only as a salted hash). Legal basis: contract.
  • Workspace content — your Origin Session answers, Organisation Blueprint, website content and settings. Legal basis: contract.
  • Billing data — plan, subscription status and Stripe identifiers. Card details are held by Stripe, never by us. Legal basis: contract / legal obligation.
  • Activity records — an audit trail of actions in your workspace (including AI actions), used for security and support. Legal basis: legitimate interests.
  • Connected-service data — if you connect Google Search Console, Google Analytics, Google Business Profile, Google Ads or Bing Webmaster Tools, we store the metrics and account details those services return and your OAuth refresh token or API key, encrypted at rest. We use this only to show you your own performance data and, where you ask us to, to manage advertising campaigns in the account you connected. We never sell it, never use it for advertising of our own, and never use it to train AI models. Disconnecting deletes the credentials and revokes our access at Google. Legal basis: contract (at your request).
  • Visitor enquiries — messages submitted on websites we host for you are delivered to your workspace. For that content you are the controller and we are your processor.

Google user data

When you connect Google Search Console, Google Analytics, Google Business Profile or Google Ads, LimeOrigin’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:

  • We use Google data only to provide and improve the features you connected it for — showing you your own search, analytics, local-listing and advertising performance, and producing the recommendations and campaigns you ask us to produce.
  • We do not transfer Google data to anyone except the sub-processors listed below where that is needed to run those features, or where the law requires it. We never sell it and never share it with data brokers.
  • We do not use Google data for advertising of our own, and we never use it to target ads at you.
  • We do not use Google data to develop, improve or train generalised AI or machine-learning models. Where an AI feature you asked for processes this data — drafting SEO recommendations from your Search Console queries, for example, or proposing a campaign from your Analytics figures — it is sent to our AI providers for that one request, under contracts that forbid them training on it.
  • No human at LimeLai reads your Google data except where you have given specific consent (for instance, asking us to investigate a support issue), where it is necessary for security or to comply with the law, or where it has been aggregated and anonymised.
  • Your Google OAuth refresh token is stored encrypted at rest and is never sent to your browser. Disconnecting a service in Settings → Connections deletes the credential and revokes our access at Google.

AI processing

When AI features run, relevant workspace content is sent to our AI providers (Anthropic and/or OpenAI, and — for optional visibility sampling — Google and Perplexity) to generate the requested output. We do not permit these providers to use your content to train their models under our agreements with them. AI never publishes anything: output is drafted for your review and every AI action is recorded in your audit trail.

Who we share data with

Only sub-processors needed to run the Service: cloud hosting, Stripe (payments), Resend (transactional email), PostHog (product analytics — server-side only and keyed to your organisation, never to browsing behaviour, and it sets no cookies), Google (Google Analytics) for measuring how the LimeOrigin app itself is used — in your browser and only if you consent (see Cookies below), the AI providers above, and the search/data services you explicitly connect. We never sell personal data.

International transfers

Where sub-processors are outside the UK, transfers rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

Retention

  • Workspace data: for as long as your account exists.
  • Deleting your organisation from Settings permanently erases its workspace data. Billing records are kept as required by UK tax law (6 years).
  • Password-reset and verification tokens expire automatically and are single-use.

Your rights

Under UK GDPR you can access, correct, export, restrict, object to, or erase your personal data. Self-service: Settings → Data & privacy gives you a full machine-readable export and permanent deletion. Or email privacy@limeorigin.com. You can also complain to the ICO (ico.org.uk).

Cookies

Strictly necessary cookies (always on — no consent required, as they’re essential to the Service):

  • lo_session — keeps you signed in (30 days, httpOnly).
  • lo_oauth_state — protects the “Connect Google” flow against forgery (10 minutes).
  • lo_analytics_consent — remembers your analytics choice below (180 days).

Analytics cookies (only with your consent). We use Google Analytics 4 to understand how the LimeOrigin app is used and improve it. On your first visit a banner asks whether you consent; analytics cookies are set only if you accept. We use Google Consent Mode, so until you accept, Google Analytics stores nothing on your device and receives only aggregate, cookieless signals. If you accept, Google sets its _ga and _ga_<id> cookies (up to 2 years) to measure visits and usage. Legal basis: consent, which you can withdraw at any time by declining the banner or clearing the lo_analytics_consent cookie in your browser. Google acts as our processor; data may be transferred to the USA under the safeguards described above. We do not use Google Analytics for advertising, and ad-personalisation signals are disabled.

We set no advertising cookies, and no analytics cookies at all on customer websites we host — those use a separate, cookieless model described next.

Websites we host

Sites built on LimeOrigin can optionally enable a privacy-light, first-party analytics beacon (for conversion funnels and A/B tests). When a site owner turns it on, the beacon stores a session-scoped, pseudonymous key in the browser’s sessionStorage (cleared when the tab closes), records page views and whether a form/CTA was used, and stores no cookies, IP addresses, user-agents or personal data. It always honours Do-Not-Track and Global Privacy Control, and it is off by default. Because this storage is not strictly necessary, the owner of each hosted site is the data controller and is responsible for obtaining any consent their audience’s jurisdiction requires before enabling it.

Site owners may also connect their own Google Analytics to their published site. When they do, we load it behind a consent banner (no analytics cookies until the visitor accepts) and honour Do-Not-Track / Global Privacy Control — but the site owner is the data controller for that Google Analytics property and is responsible for disclosing it in their own privacy policy and for their chosen configuration. LimeOrigin never adds its own analytics to sites we host for you.

Security

Passwords are hashed (scrypt), session and reset tokens are stored hashed, connected-service credentials are encrypted (AES-256-GCM), access is role-based per organisation, and sensitive actions are rate limited and audit logged.

Changes

We will notify material changes in the product or by email. Continued use after the effective date means the updated policy applies.