LimeSpot Privacy Policy
Last Updated: October 8, 2026
LimeSpot Solutions Inc. ("LimeSpot", "we", "us", or "our") is committed to protecting the privacy of shoppers ("Shoppers") while providing personalized shopping experiences. We process personal information from our store clients' ("Store Clients") Shoppers to provide product recommendations and market intelligence. However, our output is restricted to aggregated, non-identifying data. We will not sell, rent, lease, or share Shopper information except as permitted by this Privacy Policy. This Privacy Policy is subject to and incorporated into our Customer Terms of Service.
This Privacy Policy also covers the LimeSpot browser extension. What it collects, where it is sent and how long we keep it are described in LimeSpot Browser Extension below.
This Privacy Policy is based on five key principles:
- Transparency: Store Clients must notify Shoppers that LimeSpot processes their data as described in this Privacy Policy.
- Consent: Store Clients must obtain informed Shopper consent for data processing by LimeSpot.
- Accountability: Store Clients must provide means for Shoppers to inquire about personal data and withdraw consent through LimeSpot or our Data Protection Officer.
- Security: LimeSpot maintains secure data storage and transfer methods.
- Breaches: LimeSpot notifies Store Clients of any security breaches or unauthorized processing.
Our Relationship to Our Clients and Their Shoppers
LimeSpot provides services to contracted Store Clients. We collect information at Shoppers' direction through Store Clients' platforms. LimeSpot relies on Store Clients to obtain informed consent and provide privacy policy access.
Shoppers may use third-party platforms (such as Facebook or Google) to access store sites. None of a Shopper's personal information is copied by or transferred to LimeSpot from any third-party platform in this circumstance.
LimeSpot cannot be held responsible if Store Clients fail to obtain proper consent or comply with data protection laws.
How We Collect Shopper Information
From Store Platforms: LimeSpot collects information through installed plugins or APIs as Shoppers interact with store sites, including product interests, order history, and browsing behavior.
Through Third-Party Platforms and CRM: Shoppers may authenticate using third-party services or store CRM systems. Information collected varies based on privacy settings with those platforms.
The Types of Information We May Collect
LimeSpot collects two categories of information:
Personally-Identifying Information ("PII"): Information uniquely associated with an identifiable Shopper, including age, gender, location, email, phone number, and sometimes IP address.
Non-Personally Identifying Information ("NPII"): Information not identifying specific Shoppers, such as store details, product collections, non-identifying order information, age ranges, geographical associations, shopping behavior, and aggregated or anonymized data derived from PII.
How We Use and Disclose Information
LimeSpot will not sell, rent, lease, share, or disclose information unless consent is provided, information is anonymized, or disclosure is legally required.
By accepting this policy, Shoppers authorize LimeSpot to use their information as follows:
Performance of Services: Use PII and NPII to fulfill stated purposes, assess shopping patterns, and create Shopper profiles. We may combine Shopper data across stores (without sharing PII between stores) and use information to improve our products and services.
Third-Party Platform Services: Push non-identifying shopping preference information to platforms like Facebook or Google for customized advertising. LimeSpot does not receive PII from these platforms. We also use authentication services provided by third parties.
Third-Party Service Providers: Engage other companies for data storage and analysis tasks. These providers access only necessary information for their functions. They include the AI model providers named in our Data Processing Agreement, which generate recommendations, content and analysis for our services under terms that do not allow them to use the information to train their models.
Business Transfer: In mergers, acquisitions, or asset sales, Shopper information transfers as a business asset but remains subject to this policy unless Shoppers consent otherwise.
How We Use Cookies and Other Technologies
LimeSpot and Store Clients use "cookies," pixel tags, and web beacons to track Shopper behavior, measure advertisement effectiveness, and generate recommendations. Personal information collected through these technologies is treated as PII under this policy.
We use cookies to remember personal information across visits, combine information across different stores (without sharing PII between stores), and improve services. For example, knowing a Shopper's country and language enables customized experiences, while knowing product interests helps deliver relevant advertising and recommendations.
How We Keep Your Information Secure
LimeSpot implements reasonable security measures both online and offline. Only employees with confidentiality obligations access Shopper PII.
Internet transmissions use SSL encryption. Shopper information is pseudonymized and rendered as NPII. We maintain redundant systems and conduct routine security assessments.
However, no method of transmission over the Internet, or method of electronic storage, is 100% secure.
LimeSpot notifies Store Clients of unauthorized access or disclosure. Store Clients must inform affected Shoppers as required by law.
Contact: [email protected]
Storage and Transfer of Your Information
Shopper information may be transferred to, stored, and processed in the United States, Europe, or Canada. LimeSpot uses Microsoft's Azure platform data centers. Canada provides adequate data protection recognition. Transfers from the EU and UK to providers in the United States rest on the provider's Data Privacy Framework certification or on Standard Contractual Clauses with the UK Addendum; copies are available from [email protected]. Information stored outside Canada may be accessible to the authorities of the country where it is stored under that country's laws.
Storage Duration for PII:
LimeSpot removes Shopper PII upon:
- Shopper request via the Shopper Rights Access Portal
- Store Client request or Shopper consent withdrawal notice
- Shopper objection to PII processing received in writing
- Discovery of unlawful PII collection
- Request from supervisory or legal authorities with proper authorization
Storage for NPII not identifying Shoppers is indefinite.
Shoppers' Rights
Transparency: Full disclosure of information processing and purposes through this policy.
Accountability and DPO: Shoppers may contact our Data Protection Officer ([email protected]) regarding information collected by LimeSpot through Store Clients. LimeSpot may forward concerns to relevant Store Clients. Shoppers may lodge complaints with applicable supervisory authorities. For Shopper information LimeSpot acts as a processor for Store Clients, who are responsible for any European or UK representative the law requires of them.
Access, Rectification, and Deletion: Shoppers may request PII erasure through Store Clients or directly via [email protected]. Rectification requests should also be directed to [email protected].
Breaches: LimeSpot notifies Store Clients of breaches involving PII, providing details on breach nature, the DPO contact, possible consequences, and mitigation measures taken.
LimeSpot Browser Extension
This section applies to merchants and other people ("Users") who use the LimeSpot browser extension (the "Extension"), and to people who receive a report from it by email ("Recipients"). The Extension may offer different functionality over time, such as auditing an online store a User names and writing a report on where it could personalize (an "Audit" and its "Audit Report"), a chat about that report, and emailing the report to people the User chooses. The Extension collects information only from the one store a User activates an Audit for, and only after they activate it. It does not collect or transmit information from any other website, and it uses no third-party analytics or tracking. When the Extension is installed it opens a LimeSpot welcome page, to which the website parts of this policy apply; we record the campaign it came from, for 90 days, only if the User then submits the activation form. If a Studio sign-in is held, removing the Extension opens a LimeSpot page that revokes it. The Extension asks the browser for access to all websites so that it can run on whichever store the User names; it collects nothing from a page and sends nothing off the browser until the User activates an Audit there.
LimeSpot's use and transfer of information received through the Extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that information only to provide and improve the Audit and the Extension's own features, we do not sell it or use it for advertising, and no person at LimeSpot reads it except with the User's permission, to keep the service secure, or to comply with law.
Activating an Audit
What we collect: To activate an Audit, a User submits a form on limespot.com with their name, email address, store address, store platform and annual revenue range, ticks a box to agree to our Terms of Service and this Privacy Policy, and may choose to receive LimeSpot marketing email. We record that agreement with the version of its wording and when it was given. We also record how they reached the form (campaign tags, referring page and ad click identifier), their browser and Extension version, when their activation link was sent and used, and when their Audit runs start and finish. The form is checked with Cloudflare Turnstile. Rate limits use keyed one-way hashes of the email address and network address; we do not store raw IP addresses.
How we use it: We email the User a single-use activation link through SendGrid, activate the Audit for their store only, limit how many runs each store receives, and send a copy of the request to the LimeSpot team. If the User opts in to marketing email, we record that consent and may add their name and email address to our customer messaging service, Intercom.
Auditing the Store
When a User runs an Audit, the Extension opens pages of the activated store, such as its home, collection, product, cart and search pages, through LimeSpot's page proxies (limespot.app and lsproxy.app) so they can be shown inside the Extension. A storefront password typed into a proxied page passes through the proxy to the store. The Extension captures screenshots of those pages at desktop and mobile widths, together with their text, structure and selected page markup, and sends them with the store's address to LimeSpot's AI service (app-ai.personalizer.io). That service uses our AI model providers to analyze them and write the Audit Report.
Our AI model providers, named with their locations and retention periods in our Data Processing Agreement, process this content as our service providers under terms that do not allow them to use it to train their models. Each keeps what it receives through its API only to monitor for abuse, for the period listed there (at most 55 days), and then deletes it. An Audit session lasts up to 30 days. The screenshots and page captures uploaded for a run are deleted shortly after its session expires or is replaced by a new activation, and within 30 days of upload in any case.
LimeSpot's AI service also keeps a record for each store, holding how many chat questions its run has left and the details it needs to manage the store's sessions. It deletes that record 30 days after the store's latest session ends, so at most about 60 days after the Audit was last activated for that store.
Chat About the Report
A User may ask questions about the finished Audit Report. Each question is sent, with the conversation so far and the Audit Report, to LimeSpot's AI service and its AI model providers to answer it, and each store's run includes a limited number of questions. LimeSpot's AI service does not store the questions a User types. It keeps each answer, with one-way fingerprints of the conversation and of the reply from which their text cannot be read, for 30 days after that answer, so that a repeated request receives the same answer, and then deletes them. To enforce daily limits it uses a keyed hash of the User's network address that changes every day; the address itself is not stored.
Emailing the Audit Report
A User may email the finished Audit Report to themselves and to other people, up to five copies of each Audit Report in total, with an optional personal note of up to 500 characters for the Recipients. Before the Audit Report goes to anyone besides themselves, the User gives their full name and confirms that they have a personal or business relationship with each Recipient and that each would expect the email. Until December 1, 2026, Audit Reports sent from earlier Extension versions identify the User by the name given at activation, or by email address where none was given, and carry no such confirmation. The Extension sends the email addresses the User types, their name, that confirmation, the note and the Audit Report to limespot.com, which emails the Audit Report through SendGrid.
A Recipient's copy identifies the User as the person who shared it, by full name and email address, or, until December 1, 2026 for earlier Extension versions, by the name given at activation, or, where none was given, by email address alone or as the person who ran the Audit on that store where the address cannot be shown, and says it was sent by LimeSpot Solutions Inc. as a result of a referral by that User; replies go to the User. It carries no LimeSpot offer, only one link that explains what the Audit is. Each Recipient receives at most one Audit Report email per store, and receiving it does not add them to any mailing list.
Every copy, the User's own included, carries a link to unsubscribe and a one-click unsubscribe that mail apps can offer, which stops all LimeSpot marketing email. Unsubscribe links do not expire. The unsubscribe page offers two choices: stop Audit Reports that others share, or stop all LimeSpot marketing email; either choice withdraws any marketing consent, and the address goes, as a keyed hash, on our own unsubscribe list, which every email sent from limespot.com is checked against. Account and service emails, such as password resets, invoices and payment notices, are not marketing and are sent regardless, as is anything a person asks for themselves, such as an Audit Report, an activation link or a guide they download. Messages from our customer messaging service carry their own unsubscribe link. Before an Audit Report is emailed to a Recipient, we check that they have not unsubscribed. Anything a person asks for themselves, such as an Audit Report, an activation link or a guide they download, is still delivered after they unsubscribe, because they requested it.
We keep a record of each send (the store, the addresses it went to, when it was sent and whether it was delivered) for 90 days. We do not keep the Audit Report or the note after sending, only a one-way digest of the request so that a repeated request is not sent twice. To keep the one-email-per-person promise, we keep a keyed one-way hash of each Recipient's address and store, from which the address cannot be read without our key, for three years. As the record of each referral, we keep the User's name, the version of the confirmation they gave, when they gave it and keyed hashes of the Recipients' addresses for three years, even if the User's activation details are deleted sooner. To honor unsubscribes, we keep a keyed one-way hash of each address that unsubscribed, rather than the address itself (a few earlier entries remain as addresses until converted), until that address subscribes again. When someone subscribes or unsubscribes, we keep a record of that choice that holds their email address as they entered it, the choice they made, the wording they saw and keyed hashes of their network address and browser, for three years after their last change or while an activation request still holds that address, whichever is later.
Why We Process Extension Information
Where the law asks us to name a legal basis for each use of personal information, these are ours. We process a User's activation details, the store they name, their Audit Report, their chat and the copy of the Audit Report they ask us to send them because they asked for the Audit and we are delivering it (performance of a contract). We read the pages of the store a User names, including any names or reviews shown on them, and we send an Audit Report to the Recipients a User names, on the User's referral, because the User has a legitimate interest in reviewing and sharing an Audit Report on their own store and LimeSpot has a legitimate interest in offering Audits; we have assessed those interests against the effect on the people concerned and limited what we do accordingly, and anyone may object at any time as described under Users' and Recipients' Choices. We add an address to a mailing list only with that person's consent, which they may withdraw at any time. We keep referral records, the unsubscribe list and consent records to meet our obligations under anti-spam and privacy law and to honor the choices people have made. We use Cloudflare Turnstile and keyed hashes of network addresses to keep the service secure, in our legitimate interest in preventing abuse.
Where We Store Extension Information
limespot.com and LimeSpot's AI service run on Cloudflare, and the Extension information they keep is stored with Cloudflare in the United States (western North America). Email is sent through SendGrid, and AI analysis is performed by the AI model providers named in our Data Processing Agreement, as described above. Transfers from the EU and UK to these providers rest on the provider's Data Privacy Framework certification or on Standard Contractual Clauses with the UK Addendum, available from [email protected]. Information stored in the United States may be accessible to United States authorities under United States law.
What the Extension Stores in the Browser
The Extension keeps each store's Audit Report, the User's chat about it and the Audit session in the browser's extension storage, so that returning to the store reopens them. They are deleted when the session ends, after at most 30 days, or earlier if LimeSpot ends the run. The single-use activation token is kept in the browser's session storage for at most 15 minutes, and stores the User activated are listed for up to 30 days. If the User's store subscribes to LimeSpot, the Extension also keeps a Studio sign-in for that store, which it validates and revokes with LimeSpot's servers at personalizer.io and removes when it expires or the User logs out. The Extension never receives the User's LimeSpot password.
How Long We Keep Extension Information
- Activation details, including the record of agreement to our Terms of Service and this Privacy Policy: 180 days after the request was last updated. Deleting them also deletes the store's run, activation, status and send records linked to them.
- Activation links: stored only as one-way hashes and deleted 7 days after they expire. Activation records: deleted 30 days after they expire.
- Attribution records and run-status events: 90 days.
- Audit Report send records, which hold the addresses an Audit Report went to: 90 days.
- Audit Report Recipient hashes (keyed): three years.
- Referral records (the User's name, confirmation version and time, and keyed Recipient hashes): three years.
- Unsubscribe list (keyed hashes): until the address subscribes again. Account and service email is sent separately and is not affected.
- Audit Report email consent records, which hold the email address, the choice made and the wording shown: three years after the last change, or while an activation request still holds the address, whichever is later.
- Chat answers, and the conversation and reply fingerprints, held by LimeSpot's AI service: 30 days after each answer.
- Each store's record held by LimeSpot's AI service (chat allowance and session details): 30 days after the store's latest session ends, at most about 60 days after the last activation.
- Audit session, and the Audit Report, chat and session kept in the Extension: up to 30 days.
- Screenshots and page captures uploaded for a run: deleted shortly after its session ends or is replaced, and within 30 days of upload in any case.
- Content sent to our AI model providers, for abuse monitoring only: the period listed for each provider in our Data Processing Agreement, at most 55 days.
Users' and Recipients' Choices
- Emailing the Audit Report and the chat are optional; an Audit produces its Audit Report without them.
- Anyone who receives an Audit Report email can unsubscribe at any time with the link in that email, from shared Audit Reports or from all LimeSpot marketing email.
- Users and Recipients may complain about how LimeSpot handles their information to the Office of the Privacy Commissioner of Canada, to the Office of the Information and Privacy Commissioner for British Columbia, or, in the EU and UK, to their local data protection authority.
- Anyone can object at any time, free of charge, to LimeSpot using their information for direct marketing, by unsubscribing or by writing to [email protected]. We then stop, and we keep only what we need to honor that objection.
- A User can delete the stored Audit Reports, chats, sessions, activated stores and sign-ins at any time with Manage sessions, then Disconnect and forget, in the Extension's popup, or by removing the Extension.
- To see or delete the Extension information we hold about an email address, including send records, Recipient hashes, the unsubscribe list and consent records, contact [email protected]. After a deletion we keep only the keyed unsubscribe entry, so we do not email that address again, and referral records for the rest of their three years.
Changes to this Privacy Policy
LimeSpot may update this policy. Each version shows its date at the top. Before a material change takes effect, we give notice: to Store Clients by email, to Users with a current Audit activation by email or in the Extension, and to everyone on this page. We do not use information we already hold for a new purpose that needs consent without first asking for it. Store Clients and Shoppers should review the policy periodically. The current policy applies to all PII about Shoppers using LimeSpot-enabled platforms unless otherwise stated.
Questions and Concerns
This policy is subject to British Columbia provincial law and applicable Canadian federal law.
For privacy concerns: [email protected]
For policy questions: [email protected]
Related Documents: Terms of Service | Acceptable Use Policy