LimeSpot Privacy Policy
Last Updated: October 9, 2026
LimeSpot Solutions Inc. ("LimeSpot", "we", "us", or "our") is committed to protecting the privacy of shoppers ("Shoppers") while providing personalized shopping experiences. We process personal information from our store clients' ("Store Clients") Shoppers to provide product recommendations and market intelligence. However, our output is restricted to aggregated, non-identifying data. We will not sell, rent, lease, or share Shopper information except as permitted by this Privacy Policy. This Privacy Policy is subject to and incorporated into our Customer Terms of Service.
This Privacy Policy also covers the LimeSpot browser extension. What it collects, where it is sent and how long we keep it are described in LimeSpot Browser Extension below.
This Privacy Policy is based on five key principles:
- Transparency: Store Clients must notify Shoppers that LimeSpot processes their data as described in this Privacy Policy.
- Consent: Store Clients must obtain informed Shopper consent for data processing by LimeSpot.
- Accountability: Store Clients must provide means for Shoppers to inquire about personal data and withdraw consent through LimeSpot or our Data Protection Officer.
- Security: LimeSpot maintains secure data storage and transfer methods.
- Breaches: LimeSpot notifies Store Clients of any security breaches or unauthorized processing.
Our Relationship to Our Clients and Their Shoppers
LimeSpot provides services to contracted Store Clients. We collect information at Shoppers' direction through Store Clients' platforms. LimeSpot relies on Store Clients to obtain informed consent and provide privacy policy access.
Shoppers may use third-party platforms (such as Facebook or Google) to access store sites. None of a Shopper's personal information is copied by or transferred to LimeSpot from any third-party platform in this circumstance.
LimeSpot cannot be held responsible if Store Clients fail to obtain proper consent or comply with data protection laws.
How We Collect Shopper Information
From Store Platforms: LimeSpot collects information through installed plugins or APIs as Shoppers interact with store sites, including product interests, order history, and browsing behavior.
Through Third-Party Platforms and CRM: Shoppers may authenticate using third-party services or store CRM systems. Information collected varies based on privacy settings with those platforms.
The Types of Information We May Collect
LimeSpot collects two categories of information:
Personally-Identifying Information ("PII"): Information uniquely associated with an identifiable Shopper, including age, gender, location, email, phone number, and sometimes IP address.
Non-Personally Identifying Information ("NPII"): Information not identifying specific Shoppers, such as store details, product collections, non-identifying order information, age ranges, geographical associations, shopping behavior, and aggregated or anonymized data derived from PII.
How We Use and Disclose Information
LimeSpot will not sell, rent, lease, share, or disclose information unless consent is provided, information is anonymized, or disclosure is legally required.
By accepting this policy, Shoppers authorize LimeSpot to use their information as follows:
Performance of Services: Use PII and NPII to fulfill stated purposes, assess shopping patterns, and create Shopper profiles. We may combine Shopper data across stores (without sharing PII between stores) and use information to improve our products and services.
Third-Party Platform Services: Push non-identifying shopping preference information to platforms like Facebook or Google for customized advertising. LimeSpot does not receive PII from these platforms. We also use authentication services provided by third parties.
Third-Party Service Providers: Engage other companies for data storage and analysis tasks. These providers access only necessary information for their functions. They include the AI model providers named in our Data Processing Agreement, which generate recommendations, content and analysis for our services under terms that do not allow them to use the information to train their models.
Business Transfer: In mergers, acquisitions, or asset sales, Shopper information transfers as a business asset but remains subject to this policy unless Shoppers consent otherwise.
How We Use Cookies and Other Technologies
LimeSpot and Store Clients use "cookies," pixel tags, and web beacons to track Shopper behavior, measure advertisement effectiveness, and generate recommendations. Personal information collected through these technologies is treated as PII under this policy.
We use cookies to remember personal information across visits, combine information across different stores (without sharing PII between stores), and improve services. For example, knowing a Shopper's country and language enables customized experiences, while knowing product interests helps deliver relevant advertising and recommendations.
How We Keep Your Information Secure
LimeSpot implements reasonable security measures both online and offline. Only employees with confidentiality obligations access Shopper PII.
Internet transmissions use SSL encryption. Shopper information is pseudonymized and rendered as NPII. We maintain redundant systems and conduct routine security assessments.
However, no method of transmission over the Internet, or method of electronic storage, is 100% secure.
LimeSpot notifies Store Clients of unauthorized access or disclosure. Store Clients must inform affected Shoppers as required by law.
Contact: [email protected]
Storage and Transfer of Your Information
Shopper information may be transferred to, stored, and processed in the United States, Europe, or Canada. LimeSpot uses Microsoft's Azure platform data centers. Canada provides adequate data protection recognition. Transfers from the EU and UK to providers in the United States rest on the provider's Data Privacy Framework certification or on Standard Contractual Clauses with the UK Addendum; copies are available from [email protected]. Information stored outside Canada may be accessible to the authorities of the country where it is stored under that country's laws.
Storage Duration for PII:
LimeSpot removes Shopper PII upon:
- Shopper request via the Shopper Rights Access Portal
- Store Client request or Shopper consent withdrawal notice
- Shopper objection to PII processing received in writing
- Discovery of unlawful PII collection
- Request from supervisory or legal authorities with proper authorization
Storage for NPII not identifying Shoppers is indefinite.
Shoppers' Rights
Transparency: Full disclosure of information processing and purposes through this policy.
Accountability and DPO: Shoppers may contact our Data Protection Officer ([email protected]) regarding information collected by LimeSpot through Store Clients. LimeSpot may forward concerns to relevant Store Clients. Shoppers may lodge complaints with applicable supervisory authorities. For Shopper information LimeSpot acts as a processor for Store Clients, who are responsible for any European or UK representative the law requires of them.
Access, Rectification, and Deletion: Shoppers may request PII erasure through Store Clients or directly via [email protected]. Rectification requests should also be directed to [email protected].
Breaches: LimeSpot notifies Store Clients of breaches involving PII, providing details on breach nature, the DPO contact, possible consequences, and mitigation measures taken.
LimeSpot Browser Extension
This section applies to people who use the LimeSpot browser extension (the "Extension", its "Users") and to people who receive a report from it by email ("Recipients"). The Extension may audit an online store a User names and write a report on where it could personalize (an "Audit" and its "Audit Report"), offer a chat about that report, and email the report to people the User chooses; it may offer other functionality over time. It asks the browser for access to all websites so that it can run on whichever store the User names, but it collects nothing from a page and sends nothing off the browser until the User activates an Audit there, and then only from that store. It uses no third-party analytics or tracking. The website parts of this policy apply to the LimeSpot pages it opens.
LimeSpot's use and transfer of information received through the Extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that information only to provide and improve the Audit and the Extension's own features, we do not sell it or use it for advertising, and no person at LimeSpot reads it except with the User's permission, to keep the service secure, or to comply with law.
What We Collect and How We Use It
Activation details. To activate an Audit, a User gives us their name, email address and store details, agrees to our Terms of Service and this Privacy Policy, and may opt in to LimeSpot marketing email. We record those choices with the wording shown and when they were made, how the User reached us, their browser and Extension version, and when their activation and Audit runs happen. We use these to verify the User's email address, to activate the Audit for their store only, to limit runs per store, and to let our team follow up. A User who opts in to marketing email may be added to our customer messaging service, Intercom.
Store pages. When a User runs an Audit, the Extension loads pages of the activated store through LimeSpot's proxies and captures screenshots of them with their text, structure and selected page markup. A storefront password a User types into a proxied page passes through the proxy to the store. The captures go to LimeSpot's AI service, which uses the AI model providers named in our Data Processing Agreement to write the Audit Report. Those providers may not train their models on this content and keep it only to monitor for abuse, for the period listed there.
Chat. Questions a User asks about the Audit Report go, with the conversation and the Audit Report, to LimeSpot's AI service and its AI model providers to answer. The service does not store the questions; it keeps each answer briefly so that a repeated request gets the same answer.
Emailing the Audit Report. A User may ask us to email the Audit Report to themselves and to Recipients they choose, with an optional personal note. Before a copy goes to anyone else, the User gives their full name and confirms a personal or business relationship with each Recipient. We send from our own domain through SendGrid. A Recipient's copy names the User, by full name and email address, as the person who shared it, says it was sent as a result of their referral, carries no LimeSpot offer, and adds the Recipient to no mailing list; each Recipient receives at most one Audit Report email per store, and none if they have unsubscribed. We keep a record of each send and each referral, not the Audit Report or the note.
Unsubscribing. Every copy carries an unsubscribe link, which does not expire, and a one-click unsubscribe that mail apps can offer. A person may stop Audit Reports that others share with them or stop all LimeSpot marketing email; either withdraws any marketing consent and puts the address, as a keyed one-way hash, on our unsubscribe list, which every email sent from limespot.com is checked against. Account and service emails, and anything a person asks for themselves, are not marketing and are sent regardless. Messages from our customer messaging service carry their own unsubscribe link.
Legal Basis
Where the law asks us to name a legal basis, these are ours. We process a User's activation details, store pages, Audit Report, chat and own copy of the Audit Report to deliver the Audit they asked for (contract). We read the store's pages, including any names or reviews shown on them, and email Recipients on the User's referral, in the User's legitimate interest in reviewing and sharing a report on their own store and LimeSpot's in offering Audits; we have weighed those interests against the effect on the people concerned, and anyone may object at any time. Marketing email rests on consent, which may be withdrawn at any time. We keep referral, unsubscribe and consent records to meet anti-spam and privacy law, and we protect the service with Cloudflare Turnstile and rate limits keyed to one-way hashes of email and network addresses, in our legitimate interest in preventing abuse; we do not store raw IP addresses.
Where We Store Extension Information
limespot.com and LimeSpot's AI service run on Cloudflare, and the Extension information they keep is stored with Cloudflare in the United States. Email is sent through SendGrid, and AI analysis is performed by the AI model providers named in our Data Processing Agreement. Transfers from the EU and UK to these providers rest on the provider's Data Privacy Framework certification, including its UK Extension for UK data, or on Standard Contractual Clauses with the UK Addendum, available from [email protected]. Information stored in the United States may be accessible to United States authorities under United States law.
What the Extension Keeps in the Browser
The Extension keeps each store's Audit Report, chat and Audit session in the browser's extension storage until the session ends. If the User's store subscribes to LimeSpot, it also keeps a Studio sign-in for that store, validated and revoked with LimeSpot's servers; it never receives the User's LimeSpot password. A User can delete everything it keeps from within the Extension or by removing it, which also revokes any Studio sign-in.
How Long We Keep Extension Information
- Audit sessions, the captures uploaded for a run, and everything the Extension keeps in the browser: up to 30 days, sooner when the session ends.
- Chat answers and the per-store records LimeSpot's AI service keeps: 30 days after the latest answer or session. Content sent to our AI model providers: the period listed in our Data Processing Agreement.
- Activation details, including the record of agreement to our Terms of Service and this Privacy Policy: up to 180 days after the request was last updated.
- Send records, which hold the addresses an Audit Report went to: 90 days.
- Referral records (the User's name, their confirmation and keyed hashes of the Recipients' addresses), keyed Recipient hashes, and subscribe and unsubscribe choices with the wording shown: three years, or while an activation request still holds the address, whichever is later.
- Unsubscribe list (keyed hashes): until the address subscribes again.
Your Choices
- Emailing the Audit Report and the chat are optional; an Audit produces its Audit Report without them.
- Anyone can unsubscribe with the link in any Audit Report email, and anyone can object, free of charge, to LimeSpot using their information for direct marketing by writing to [email protected]; we then stop and keep only what we need to honor that objection.
- Users and Recipients may ask us to see, correct, restrict or delete the information we hold about their email address, to receive what they gave us in a portable form, and to object to any use we base on our legitimate interests, at [email protected]. After a deletion we keep only the keyed unsubscribe entry, so we do not email that address again, and referral records for the rest of their retention period.
- Complaints may go to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner for British Columbia, or, in the EU and UK, the local data protection authority.
Changes to this Privacy Policy
LimeSpot may update this policy. Each version shows its date at the top. Before a material change takes effect, we give notice: to Store Clients by email, to Users with a current Audit activation by email or in the Extension, and to everyone on this page. We do not use information we already hold for a new purpose that needs consent without first asking for it. Store Clients and Shoppers should review the policy periodically. The current policy applies to all PII about Shoppers using LimeSpot-enabled platforms unless otherwise stated.
Questions and Concerns
This policy is subject to British Columbia provincial law and applicable Canadian federal law.
LimeSpot Solutions Inc., 302-8 Bastion Square, Victoria, British Columbia V8W 1H9, Canada.
For privacy concerns: [email protected]
For policy questions: [email protected]
Related Documents: Terms of Service | Acceptable Use Policy