Privacy Policy

Effective: 7 September 2026 Who we are: Lath LLC ("Lath", "we"), 3348 Snowy Butte Ln, Central Point, OR 97502. Contact: privacy@trylath.com.

1. What Lath is, and the two kinds of people this policy covers

Lath is a platform that lets software companies ("Customers") add sign-in, email and SMS to their products. Because of that, we handle personal data in two roles:

2. Data we collect from account holders

Category Examples Why
Account identity email address, name, the business name you give us to create and secure your account
Authentication data sign-in codes and links (hashed, short-lived), session identifiers, device and browser type to sign you in and keep you signed in
Business identity, when you register for SMS sending legal name, tax identifier, business address, website, authorized contact required by telecommunications carriers to register your messaging identity
Usage and billing operations performed, messages sent, numbers held, invoices, payment status to run the service, bill you and prevent abuse. Card details are handled by our payment processor and never stored by us
Technical IP address, request timestamps, API key identifiers security, rate limiting, fraud prevention, and the activity log you can read
Support what you send us when you contact support to help you

We do not buy data about you and we do not use your data to build advertising profiles.

3. Data we process for Customers about their end users

Only what the Customer sends us or asks us to collect: email addresses, phone numbers, names and profile details returned by an identity provider the end user chose (such as Google or Microsoft), message content and delivery events, consent records, and technical data such as IP address and device type at sign-in. We hold this in an environment isolated to that Customer.

4. Lawful bases (GDPR and UK GDPR)

5. Who receives data

We use service providers in these categories. Each acts on our instructions under a written agreement, and we do not sell personal data.

Category Purpose
Cloud infrastructure hosting, databases, encryption key management
Email delivery transmitting email you or your Customers send
Telecommunications carriers and messaging aggregators transmitting SMS, and carrier registration of sending identities
Identity providers when an end user chooses to sign in with Google, Microsoft or GitHub, that provider processes the sign-in under its own policy
Payment processing card payments and invoicing
Error and performance monitoring diagnosing faults
Professional advisers legal, accounting, where required

A current list of subprocessors by name is available on request to privacy@trylath.com and to Customers under their data processing terms. We may also disclose data when the law requires it, to protect the rights or safety of any person, or in a merger or acquisition, with notice.

6. International transfers

We are based in the United States and store data there. Where data about people in the EEA, UK or Switzerland is transferred to us, we rely on standard contractual clauses or an equivalent recognised mechanism.

7. Retention

Data Kept
Account data for the life of the account, then deleted within 30 days of closure, except as below
Activity and event logs 13 months, then deleted or anonymised
Message content 30 days after delivery for transactional email and SMS unless the Customer configures a shorter or longer period; delivery metadata for 13 months
Consent and suppression records for as long as needed to honour the choice, which may be indefinite for an opt-out
Carrier registration data as long as the registration is active plus the period the carrier requires
Billing records 7 years, as tax law requires
Security logs 13 months

8. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing, to port your data, and to withdraw consent. Write to privacy@trylath.com. We will respond within 30 days, or sooner if the law requires. We will not discriminate against you for exercising a right. If you are in the EEA or UK you may also complain to your supervisory authority.

California residents: you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, and to opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not use or disclose sensitive personal information other than to provide the service. You may exercise rights through privacy@trylath.com or an authorised agent; we will verify your identity through your account email.

9. Security

Data is encrypted in transit and at rest. Customer environments are isolated at the database layer with row-level security. Secrets are encrypted with keys we do not hold in plaintext. API keys are stored hashed. Access to production is limited to named staff with multi-factor authentication and is logged. If a breach affects you, we will notify you and any regulator as the law requires.

10. If you are a Customer's end user

We process your data for the Customer whose product you used. To access, correct or delete your data, or to stop receiving messages, contact that Customer; their contact details are in the message you received or in their product. Every marketing email we deliver contains an unsubscribe link, and replying STOP to any SMS stops further messages from that sender. If you cannot reach the Customer, write to privacy@trylath.com and we will help route your request.

11. Children

Lath is not directed at children under 13, and Customers may not use Lath to collect personal information from children under 13 (or under 16 where that is the local age) without the consent the law requires.

12. Changes

We will post changes here and, for material changes, email account holders at least 14 days before they take effect.

13. Contact

privacy@trylath.com · Lath LLC, 3348 Snowy Butte Ln, Central Point, OR 97502