Legal

Privacy policy

What we collect, why, and who we share it with - as an account holder, and as a visitor to a page one of our customers is testing.

Draft for legal review. This page describes LiftLander's data practices as of the date below but has not yet been reviewed by counsel. Bracketed fields are placeholders pending confirmation. Do not publish until reviewed. Questions: legal@liftlander.com

1. Who this applies to

This policy covers two different relationships, and they are not the same thing:

If you have a LiftLander account (or are a visitor to liftlander.com), LiftLander is the data controller for your account, billing, and usage data. This policy tells you what we collect and your rights over it.

If you're a visitor to a page one of our customers is running a test on, LiftLander is a data processor acting on that customer's instructions, not the controller. We collect test-assignment and interaction data (which variant you saw, whether you converted) under the customer's direction and their own privacy policy, not this one. Direct questions about a specific site's data practices to that site, not LiftLander.

2. Data controller

Entity[Legal entity name - pending formation/confirmation]
Address[Registered business address]
Contactlegal@liftlander.com
Data Protection Officer[DPO name/contact, if appointed - required if processing at scale under GDPR Art. 37]

3. What we collect

Account data. Name, work email, company, password (hashed), role, collected when you sign up or are invited to a workspace.

Billing data. Plan, billing address, and payment details. Payment card numbers are handled by our payment processor directly; LiftLander does not store full card numbers.

Usage data. Tests created, pages connected, features used, login timestamps, IP address, and browser/device information, collected automatically to operate and secure the product.

Test data (as processor). When you run a test on your site, our tracking snippet collects variant assignment, page interaction events, and conversion events from your site's visitors. We process this on your behalf and under your instructions as the controller for that data.

Content you provide. Page copy, images, and translation glossaries you upload for testing or AI generation.

4. How we use it, and why we're allowed to

Provide the serviceRun tests, compute probability-to-win, generate AI copy/creative, necessary to perform our contract with you.
BillingCalculate usage-based charges (tested visitors, active sites), necessary to perform our contract with you.
Security & fraud preventionDetect abuse, unauthorized access, bot traffic, legitimate interest.
Product improvementAggregated, de-identified usage patterns, legitimate interest.
Service communicationsTrial expiry, billing, incident notices, necessary to perform our contract with you.
Marketing (optional)Product updates you can opt out of at any time, consent.

5. AI features

Copy variants, creative generation, and winner analysis are produced by AI models we license from third-party inference providers (see Section 7). Content you submit for AI generation is sent to those providers to produce a result; we do not permit those providers to use your content to train their own models outside of serving your request, per our agreements with them. Review AI-generated output before publishing. It is a starting point, not a guarantee of accuracy or compliance with any law applicable to your business.

6. Cookies

liftlander.com uses cookies for login sessions, security, and (with your consent) analytics. Full detail, including what each cookie does and how to opt out, is in the Cookie policy.

7. Who we share data with

We don't sell personal data. We share it with the following categories of subprocessor, each bound by a data processing agreement:

Cloud infrastructureAWS - hosting, storage, compute.
AI inference providers[Provider names] - copy/creative generation, winner analysis.
Email delivery[Provider name] - transactional and account emails.
Payment processing[Provider name] - billing and subscription management.
Analytics (optional)[Provider name] - product usage analytics, only if you consent.

Full subprocessor list with legal entity names and DPA status is available on request. See Security.

8. International transfers

Data may be processed in the United States and other countries where our subprocessors operate. Where we transfer personal data out of the EEA/UK, we rely on Standard Contractual Clauses or an equivalent safeguard recognized under GDPR Chapter V.

9. How long we keep it

Account data is kept for the life of your subscription plus [X days] after closure, for billing records and legal obligations. Test data is retained per your plan's data retention setting, or deleted within [X days] of test archival if you have no active retention setting. We delete or anonymize data once it's no longer needed for the purpose it was collected for.

10. Your rights

If you're in the EEA/UK (GDPR): you can request access, correction, deletion, or a portable copy of your data, restrict or object to processing, and withdraw consent at any time. Contact legal@liftlander.com. We'll respond within one month. You can also lodge a complaint with your local supervisory authority.

If you're a California resident (CCPA/CPRA): you have the right to know what we collect, delete it, correct inaccuracies, limit use of sensitive personal information, and opt out of sale or sharing. We do not sell personal information, and we honor Global Privacy Control signals as a valid opt-out.

To exercise any of these, email legal@liftlander.com from the address on your account. We may ask you to verify your identity first.

11. Security

Data is encrypted in transit (TLS) and at rest. Access to production data is role-based and logged. See the role matrix on our Security page. No system is perfectly secure; if we experience a breach affecting your data, we'll notify you as required by applicable law.

12. Children's privacy

LiftLander is a business tool, not directed at children. We do not knowingly collect personal data from anyone under 16.

13. Changes to this policy

We'll post material changes here and update the date below. For significant changes, we'll notify account holders by email.

Last updated: August 2026 · Document ID: privacy · Version 0.1 (draft)

Related: Privacy policy · Terms of service · Cookie policy · Security