Legal

Privacy Policy

How Lomen handles your data, in language you can actually audit.

Last updated 17 August 2026

Pre-launch note — 17 August 2026

Lomen is pre-launch. The operator details above are placeholders and must be replaced with your real identity before publishing. The retention, deletion and EU/US data residency processes described below are the terms we commit to, and they take effect as the product grows into them.

Who is responsible for your data

Lomen is operated by [YOUR NAME], reachable at privacy@lomenanalytics.com and legal@lomenanalytics.com. [TODO: replace this paragraph with your full name, postal address and any business registration number before publishing.] For GDPR purposes, this person is the controller of data you provide to Lomen directly (your account, billing and support data). For traffic data collected from your website through the Lomen script, Lomen acts as a processor on your instructions, and you are the controller towards your own visitors.

What we collect

Account details (name, email, account settings), the website domains you choose to measure, the pageview data our script sends from your site, and standard product telemetry such as error traces. The tracking script sets no cookies, stores no IP addresses and builds no fingerprint, so we hold nothing that identifies your visitors.

How we use it

To operate the service: recording pageviews, computing metrics, generating insights, sending the alerts you configure and billing you correctly. We do not sell personal data, we do not run advertising, and we do not use your data to train models.

Legal bases

For customers in the EEA and UK we rely on contractual necessity for service delivery, legitimate interest for security and product telemetry, and consent for marketing email. You can withdraw marketing consent at any time from any email we send.

Subprocessors

Cloud hosting and managed database, transactional email delivery, error monitoring, Stripe for payments, and one language-model provider for AI insights. The current list with locations is available on request and published in our security overview.

Retention

Pageview data is retained for as long as your account is active, subject to your plan’s history window. Removing a site deletes its pageview history immediately. On account deletion, your data is destroyed within 30 days, including from backups on their normal expiry cycle. Invoices are retained as long as tax law requires.

Your rights

You may request access, correction, export or deletion of your personal data by emailing privacy@lomenanalytics.com. We respond within 30 days and do not charge for reasonable requests. You can also delete your site and its pageview history yourself at any time from the dashboard, or request deletion of your whole account by email.

International transfers

Workspaces are provisioned in the EU or the US and data stays in the chosen region. Where a subprocessor requires a transfer, we rely on Standard Contractual Clauses.

Cookies and storage on this site

Our own site uses a single first-party session cookie for authentication and stores your theme preference and cookie consent in localStorage. We do not run third-party advertising or cross-site tracking cookies. See our Cookie Policy for the full list.

Security and incidents

We maintain technical and organisational measures to protect your data. If we discover a personal data breach that affects your account, we will notify you without undue delay and report it to the relevant supervisory authority within 72 hours where required by law. Report vulnerabilities to security@lomenanalytics.com.

Changes to this policy

We will date and publish any material change to this page. For significant changes we will also notify you by email.

Questions?

Email legal@lomenanalytics.com and a human will answer.

Contact us