Legal

Privacy policy

Draft of 1 August 2026. Not yet in force.

Draft for legal review. Do not publish yet.

This is a working draft written to be reviewed, not an outline. A qualified lawyer must approve it for every place Lanemi operates, including the GDPR in the EU and the UK, and India's DPDP Act, before it goes live.

Every highlighted item is a fact only Lanemi can supply, such as the legal entity, the hosting region, or a named supplier. A privacy policy that guesses at these is worse than one that is missing, because a wrong answer here is a false statement about how real people's data is handled. Nothing highlighted has been invented. Fill each one in, then have the whole thing reviewed.

In plain language

We collect what we need to run the service and nothing more. Your customers' data belongs to you. We process it on your behalf, and we cannot look at it unless you let us in, for a set time, with every action logged. We never sell data to anyone. You can ask us what we hold, correct it, or have it deleted, and the analytics on this website stay off until you say yes.

Contents

  1. Who we are
  2. What data we collect
  3. Controller and processor
  4. How we use data
  5. Legal bases
  6. Cookies and analytics
  7. Sharing and sub-processors
  8. International transfers
  9. Retention
  10. Your rights
  11. Security
  12. Children
  13. Changes
  14. Contact and complaints

1. Who we are

Lanemi is software for running a delivery round. This policy covers the Lanemi website at lanemi.com and the Lanemi product.

The company responsible for the data described here is registered legal entity name, at registered address, registered in country and company number.

You can reach us about anything on this page at hello@lanemi.com. Our representative in the EU is EU representative, or state that none is required and why, and in the UK UK representative, or state that none is required. Our Data Protection Officer is DPO name and contact, or state that none is required under GDPR Art. 37.

2. What data we collect

Six kinds of data, and they are not all the same. The difference matters for your rights, so it is worth reading which one applies to you.

Your account

Your name, your business name, your email address and phone number, your password stored as a hash and never in the clear, your role and permissions, and the hubs and rounds you work on. If you sign up, we need this to give you an account at all.

Billing

Your plan, your billing country, your tax registration number if you give us one, and the record of what you have paid. Card numbers are handled by our payment provider, named payment provider, and never touch our servers. We keep enough to know your plan is paid and to issue an invoice, and no more.

Your business data

The products you sell, your prices, your rounds, your delivery slots, your staff, and your financial ledger. This is the working record of your business.

Your customers' data

The households and businesses you deliver to: names, delivery addresses, phone numbers and email addresses, delivery notes and gate codes, subscription and pause history, wallet balances, payment and cash records, disputes and credits, and the consents they have given you for messages. We hold this because you asked us to. It is yours, not ours, and section 3 explains what that means in practice.

Support access

By default our staff cannot see your customers' personal or financial details. When you ask for help and grant access, that grant is time limited, and everything we do while it lasts is written to an audit log you can read. We keep the record of who was let in, when, and what they did.

This website

If you subscribe to the newsletter, we keep your email address until you leave. If you use the contact form or book a demo, we keep what you sent us so we can reply. If you agree to analytics, section 6 sets out exactly what is collected and what is not.

Our servers also write ordinary technical logs, which include IP addresses, for server log retention period. We use them to keep the service running and to investigate abuse, not to build a picture of you.

3. Controller and processor

We wear two hats, and which one we are wearing decides who you should ask about what.

For your account, your billing and this website, we are the controller. We decide what is collected and why, so questions and requests about that data come to us.

For your customers' data, you are the controller and we are the processor. You decide what to collect and why. We act on your instructions, and we do not use that data for our own purposes. Our Data Processing Addendum sets this out formally and forms part of your contract with us: link to the DPA, once it exists.

One practical consequence. If somebody you deliver to asks to see or delete their data, that request belongs to you, not to us. If it reaches us first, we will point them to you and tell you it arrived. We will not act on their data ourselves unless you tell us to.

4. How we use data

To run the service you signed up for: your rounds, your wallets, your ledger, your reminders, and the messages you send your customers by email, SMS and WhatsApp. To bill you and issue invoices. To answer you when you ask for help. To keep the service secure and to investigate abuse. To meet obligations the law puts on us, including tax and accounting records. To understand which parts of the product work, and which do not.

Some things we do not do, and would rather say plainly than leave you to assume. We do not sell personal data, to anyone, ever. We do not use your customers' data to advertise to them or to anyone else. We do not share your business data with your competitors, in any form.

Where we look at how the product is used to improve it, we work from aggregated and de-identified data. Confirm whether any customer data is used to train machine-learning models. If it is, say so here in plain words, say which data, and say how to opt out. If it is not, say that instead.

5. Legal bases

Under the GDPR we need a lawful basis for each thing we do. These are ours.

  • Performance of a contract (Art. 6(1)(b)) for your account, running the service, and billing you. Without this data there is no service to give you.
  • Legitimate interests (Art. 6(1)(f)) for keeping the service secure, preventing abuse, and improving the product. We have weighed these against your rights and can share that assessment on request.
  • Consent (Art. 6(1)(a)) for website analytics and for marketing email. You gave it freely, and you can take it back at any time without losing anything else.
  • Legal obligation (Art. 6(1)(c)) for keeping tax, accounting and financial records for as long as the law requires.

Under India's DPDP Act we rely on your consent, and on the legitimate uses the Act allows. Counsel to confirm the DPDP grounds, the notice wording the Act requires, and whether a Consent Manager applies.

6. Cookies and analytics

This website runs no advertising cookies and no cross-site tracking. There is nothing here selling your attention to anybody.

One thing is stored whatever you choose: your answer to the cookie question. It sits in your browser's local storage under the name lanemi.consent, holds your choice and the date you made it, and lasts 180 days. We keep it because it is the only way to honour a refusal. Storing it is what stops us asking again.

Beyond that, only analytics, and only if you say yes. We use Google Analytics to count visits and see which pages earn their place. Until you accept, nothing is requested from Google at all: the tag is not loaded, and no cookie is set. If you accept, Google Analytics sets _ga and _ga_<id>, which last up to two years and hold a randomly generated number that tells one browser from another. We use it to read visit counts and page popularity. We do not use it to work out who you are, and we do not join it to your account.

Closing the banner, or pressing Escape, counts as a refusal. It is never taken as a yes.

You can change your mind whenever you like. Open cookie settings, or use the same link in the footer of any page. We ask again after 180 days rather than treating one click as permanent.

Google is the recipient of analytics data and may process it outside your country. Confirm the Google Analytics data retention setting, whether IP anonymisation and Google signals are on or off, and the transfer mechanism relied on.

7. Sharing and sub-processors

We share data with the suppliers who help us run the service, and with nobody else, except where the law compels us. Every one of them is bound by contract to protect it and to use it only for what we have asked. We stay responsible for what they do.

  • Hosting and databases: named provider and region
  • Backups and file storage: named provider and region
  • Transactional and marketing email: named provider
  • SMS and WhatsApp messaging: named provider
  • Payments for your Lanemi plan: named provider
  • Error monitoring and uptime: named provider
  • Website analytics: Google Analytics, only with your consent

Note that the money your customers pay you runs through your own payment account, not ours. Those payment details are between you and your provider.

We keep the current list at link to a maintained sub-processor page and will tell you before we add anyone new, so you have time to object.

8. International transfers

Lanemi is used in many countries, so data sometimes moves across a border. Where it leaves the EEA, the UK or India, we rely on the transfer mechanism, such as Standard Contractual Clauses, the UK Addendum, or an adequacy decision, and we assess the destination country before we send anything.

Your data is stored in primary hosting region, and whether customers can choose a region. Confirm whether EU or India data residency is offered, since EU buyers ask this before signing and the answer belongs on the security page too.

9. Retention

We keep data for as long as you have an account, and after that only where we have a reason to.

  • Account and business data: deleted period after you close your account.
  • Financial and tax records: kept for period required by law in your jurisdiction, because we are required to.
  • Backups: overwritten on a backup rotation period cycle, so deleted data leaves backups within that window.
  • Support conversations: period.
  • Newsletter subscriptions: until you unsubscribe.
  • Server logs: period.

There is one part worth explaining properly, because it sounds like a contradiction. Your financial ledger is permanent by design: a correction is a new entry, never a rewrite, which is what lets your books be trusted years later. So when personal data has to be erased, we anonymise instead of deleting the row. The person becomes unidentifiable, and the money still adds up. The result is the same for the individual, and your accounts survive it.

10. Your rights

Wherever you are, you can ask us for the following, and we will not charge you or make it difficult.

  • See what we hold. A copy of your personal data and an explanation of what we do with it.
  • Correct it. If something is wrong, tell us and we will fix it.
  • Have it deleted. Subject to records the law makes us keep, and to the anonymisation in section 9.
  • Take it with you. Your data in a format another system can read. This is built into the product, so you do not have to ask us.
  • Object, or ask us to pause. Where we rely on legitimate interests, you can object, and we stop unless we have compelling grounds to continue.
  • Withdraw consent. For analytics, use cookie settings. For marketing email, use the unsubscribe link. Withdrawing is as easy as agreeing was, and costs you nothing else.
  • Complain. To us first, we hope, but you can go straight to a regulator. Section 14 says which.

Write to hello@lanemi.com and we will answer within response time, one month under GDPR Art. 12(3). We may need to check who you are first, which protects you rather than us.

If you are one of our customers' customers, and a delivery round holds your details, your request goes to that business, not to us. They decide what is held about you. If you contact us instead, we will tell you who to ask and let them know you asked.

11. Security

How we keep data safe is described in full on our security and trust page. In short: traffic runs over HTTPS, passwords are hashed and never stored in the clear, access is gated by permission, our staff cannot see your customers' details unless you grant it for a set time, and every sensitive action is written to an audit log. Backups are tested by actually restoring them, and your financial data can be restored to any moment in time.

If a breach puts your rights at risk, we will tell the regulator within 72 hours as the GDPR requires, and we will tell you without undue delay. Counsel to confirm the breach notification wording, and the equivalent DPDP timeline.

12. Children

Lanemi is a tool for running a business. It is not meant for children and we do not knowingly collect their data. If you believe a child's data has reached us, write to hello@lanemi.com and we will remove it.

India's DPDP Act sets specific duties around children's data, including verifiable parental consent and a ban on tracking or targeted advertising. Counsel to confirm how these apply, given a delivery round's customer list could include a household member under 18.

13. Changes

When this policy changes, we update the date at the top. If a change matters to you, we will email you before it takes effect rather than hoping you notice, and we will give you notice period to read it. Older versions are kept at link to a version archive, or remove this sentence.

14. Contact and complaints

Write to hello@lanemi.com, or by post to postal address. A person reads it.

If we have not put something right, you can complain to a regulator. In the EU that is the supervisory authority where you live or work, or ours, which is lead supervisory authority. In the UK it is the Information Commissioner's Office. In India it is the Data Protection Board, and our Grievance Officer is name and contact, which the DPDP Act requires you to publish.

We would rather hear from you first, and we would rather fix it than argue about it.

One good idea for your round, once a week.

Short, practical, and no filler. Leave any time.

Questions? Talk to a person.