Skip to content
Lithsted

Legal

Privacy Policy

Last updated: 13 August 2026

1. Who we are

The data controller is Lithsted Ltd, company number 17015657.

Registered office:

71-75 Shelton StreetCovent GardenLondonUnited KingdomWC2H 9JQ

Director: Jawad Hassan Ahmed

Lithsted Ltd is registered with the Information Commissioner’s Office under registration number ZC091660.

Privacy contact: support@lithsted.com

2. Scope

This Privacy Policy covers personal data processed in connection with:

  • visitors to https://lithsted.com;
  • users of https://app.lithsted.com;
  • Lithsted Partners;
  • Review Helper users;
  • purchasers of physical products;
  • referral programme participants; and
  • people who contact Lithsted for support.

3. Information we collect

Lithsted collects and stores the categories of information below where they are used to operate the service. Lithsted does not store full payment card numbers.

Account data

Name, email address, user or account ID, signup timestamps, and authentication or session information.

Billing

Stripe customer ID, subscription status, Stripe subscription and invoice identifiers, payment status, and relevant billing metadata. Card details are handled by Stripe.

Business records

Google Place ID, business name, address, Google category or type where stored, slug, and active state.

Review Helper records

Item or service, experience answer, ratings, customer notes, AI generated review, edited or final review, timestamps, and events such as generated, confirmed, copied or continued-to-Google, together with any reports, reasons or notes.

Application review-session records are intentionally designed not to store customer names, emails, phone numbers or Lithsted account identities for Review Helper respondents, where this remains accurate. Network infrastructure may still process IP addresses as part of ordinary hosting and security operations.

Orders

Items, quantities, Deck colour, sticker selections, delivery details, carrier or tracking information, payment and order status, and timestamps.

Referrals and commission

Lithsted may process referral and commission information needed to administer the programme, including referral codes, referring partner account ID, referred partner account ID, qualifying membership or payment records, commission amount, eligible unpaid balance, payout eligibility or status, payout amount, payout date or paid-at timestamp, and reconciliation or accounting records. Lithsted does not currently describe bank account or other payment-destination details as information stored for this purpose.

This information may be processed to administer the Lithsted partner referral programme, calculate qualifying commission, determine whether the £50 minimum threshold has been reached, administer the monthly payout process, reconcile payments, handle disputes or errors, meet accounting and tax compliance obligations, and prevent fraud. It is not a statement of commercial payout entitlements; those are set out in the Terms.

Community

Skool invite or access status, invite timestamps, and the account email used to deliver an invite.

Communications

Emails, support requests and related correspondence.

Technical and security data

IP or log information where processed by hosting or security infrastructure, browser or device information where generated by that infrastructure, session or security events, and necessary cookies or similar technologies.

4. How we collect data

We collect information:

  • directly from you when you create an account, order or contact us;
  • through use of the Lithsted application;
  • from Stripe in connection with billing;
  • from Google Places when a business profile is connected;
  • through referral links;
  • through support communications; and
  • through hosting and security infrastructure.

5. Purposes and lawful bases

The following table describes Lithsted’s current assessed position on why personal data is processed and the lawful basis relied upon. Final legal review is recommended before this matrix is treated as settled. Lithsted does not use consent for processing that is genuinely necessary to perform a contract.

PurposeTypical dataLawful basis
Partner account creation and administration where necessary to perform the agreementAccount data and authentication informationContract
Membership and subscription administrationAccount data, Stripe identifiers, subscription statusContract
Physical orders and fulfilmentOrder, delivery and payment-status dataContract
Billing and payment administrationStripe customer, subscription and invoice identifiers, payment statusContract
Customer support necessary to provide the contracted serviceAccount, order and correspondence dataContract
Administering the agreed partner referral programme, including calculating qualifying commission, determining whether the £50 minimum payout threshold has been reached, and administering the monthly payout processReferral codes, referring and referred partner account IDs, qualifying membership or payment records, commission amount, eligible unpaid balance, payout eligibility, payout amount and payout dateContract
Accounting and tax recordsBilling, order, commission, payout and relevant account recordsLegal obligation
Compliance with binding legal or regulatory requirementsRecords relevant to the requirementLegal obligation
Fraud prevention, account and platform security, and abuse preventionAccount, billing, referral, commission, technical and security dataLegitimate interests
Reconciling referral payments, correcting genuine commission or payout errors, handling disputes, and protecting Lithsted from referral abuseCommission, payout eligibility, unpaid balance and related account recordsLegitimate interests
Internal administrationLimited account, billing and operational recordsLegitimate interests
Service reliability and improvement using data that is appropriate and proportionateLimited account, usage and support information, without non-essential trackingLegitimate interests
Establishment, exercise or defence of legal claimsAccount, order, billing, correspondence and relevant logsLegitimate interests
Future optional direct marketing, if introduced and legally requiredName and email, if collected for that purposeConsent, where consent is legally required
Future non-essential cookies, analytics or advertising technology, if introduced and consent is requiredCookie or similar identifiersConsent, where consent is required

Where Lithsted relies on legitimate interests, it will assess and document those interests, including whether the processing is necessary and proportionate and whether it would override the interests or rights of the people concerned.

6. Review Helper and OpenAI

Customer-provided Review Helper information may be sent to OpenAI through an API so that a review draft can be generated. The AI is assisting with language drafting. The output is returned to the customer, who retains control and the editing decision. Lithsted does not make a solely automated legal or similarly significant decision through this process.

Lithsted does not make unsupported promises about OpenAI’s retention or training practices. Those practices are governed by OpenAI’s own terms and privacy information.

7. Data sharing / processors

Lithsted uses service providers who receive only the data appropriate to their role:

  • Supabase — database and authentication;
  • Vercel — hosting and infrastructure;
  • Stripe — billing and payment;
  • OpenAI — AI generation;
  • Google — Places or business data and as the destination a customer may choose for a review;
  • Resend — transactional email;
  • Skool — partner community;
  • delivery or carrier providers — shipping fulfilment;
  • professional advisers, such as accountants or lawyers, where required; and
  • public authorities, where legally required.

8. International transfers

Some service providers may process data outside the United Kingdom. Where required, Lithsted will use legally recognised safeguards, such as applicable adequacy regulations, contractual safeguards or other permitted mechanisms. Lithsted does not currently publish provider-specific transfer mechanisms until that review is complete.

[LEGAL REVIEW REQUIRED: COMPLETE PROVIDER TRANSFER REVIEW]

9. Retention

Lithsted keeps personal data only for as long as needed for the purposes described in this policy, including legal, accounting or dispute-related obligations. Retention may be shorter where the data is no longer needed, and may be longer where the law requires it.

The following is a provisional operational retention schedule. It is subject to final legal and accounting review and is not a confirmed statutory timetable.

CategoryProvisional retention
Account dataFor the duration of the account and up to 2 years after closure where reasonably required for administration, disputes, fraud prevention or legal claims, unless a longer period is legally required.
Billing and accounting recordsRetained for the period required by applicable UK tax and accounting law. Lithsted does not currently state a specific number of years pending confirmation against the applicable statutory requirement.
Review Helper session recordsTarget retention: 24 months after the session, unless earlier deletion is appropriate or longer retention is reasonably required for a report, dispute, security investigation or legal obligation.
Order and fulfilment recordsRetained for the applicable accounting and tax period and as reasonably necessary for fulfilment, returns, warranty issues, disputes and legal claims.
Referral and commission recordsRetained for the applicable accounting and tax period and as reasonably necessary to administer commissions and resolve disputes.
Support correspondenceTarget retention: 2 years after the matter is resolved, unless longer retention is reasonably required for a dispute or legal obligation.
Security and application logsNormally retained for no longer than 180 days, unless required for an active security investigation, fraud investigation or legal obligation.

[LEGAL REVIEW REQUIRED: CONFIRM RETENTION SCHEDULE WITH LEGAL AND ACCOUNTING REVIEW]

10. Security

Lithsted uses reasonable measures appropriate to the service, including HTTPS, authentication, server-side secrets, restricted admin access, database row-level security where implemented in the application, and other access controls. No method of transmission or storage is perfectly secure.

11. Cookies and similar technologies

Lithsted currently uses necessary technologies required for website and application operation, authentication and security where applicable. Lithsted currently does not intentionally use analytics or advertising cookies or pixels.

The current public marketing website does not include an analytics SDK, advertising SDK, gtag, advertising pixels, PostHog, Plausible, Hotjar, Mixpanel or Clarity, third-party tracking embeds, or first-party localStorage, sessionStorage or document.cookie usage. Fonts are self-hosted at build time. Hosting or security infrastructure may still process technical data such as IP addresses, or set strictly necessary cookies, as part of ordinary delivery. This description covers the current marketing website technology only and does not cover every future integration.

A cookie consent banner has not been added, because this marketing website does not currently use non-essential cookies that would require one. If non-essential cookies, analytics or advertising technology are introduced later, Lithsted will update this policy and obtain any consent then required.

12. Marketing communications

Lithsted does not currently operate general promotional email marketing campaigns. Current emails are primarily transactional or service communications, such as account verification, password resets, billing or service messages, order updates, community invitations and support communications.

If Lithsted introduces direct marketing in future, it will implement the appropriate lawful basis, PECR compliance, preference controls and unsubscribe functionality before doing so. Direct marketing must be reassessed before any such campaign is launched.

13. Children

Lithsted is a commercial partner programme and business service. It is not intended for children.

14. Automated decision-making

Lithsted does not currently use personal data for solely automated decisions producing legal or similarly significant effects. AI review generation is a drafting function controlled by the customer.

15. Data protection rights

Under UK data protection law, you may have rights of access, correction, erasure, restriction, objection, data portability, withdrawal of consent, and qualifying automated-decision rights. These rights depend on the circumstances and are not always absolute.

To exercise a right, contact support@lithsted.com.

16. Information Commissioner's Office

Lithsted Ltd is registered with the Information Commissioner’s Office under registration number ZC091660. If you have concerns about how personal data is handled, you may complain to the ICO. You can find the ICO at ico.org.uk. You do not have to contact Lithsted first, although we welcome the chance to resolve concerns directly.

18. Changes

Lithsted may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do.

19. Contact

Lithsted Ltd

71-75 Shelton StreetCovent GardenLondonUnited KingdomWC2H 9JQ

support@lithsted.com

Company number: 17015657

ICO registration: ZC091660