Luton Labs
  • Solutions ⌄
    AssetNexa AI Asset Tracking & Analytics Benevanta AI Not-for-Profit CRM ProVanta AI For-Profit CRM CountNexa AI Inventory Management ReturnNexa Lost & Found Management MusterKey Personnel Data Integration Platform ORVANTA GTM AI Go-to-Market Engine
  • About
  • Contact
Sign In Get Started

Privacy Policy

Effective 9 September 2026. Last updated 9 September 2026. This policy applies to Luton Labs LLC and to every application listed in section 2.

Contents
  1. Who we are
  2. What this covers
  3. Controller and processor
  4. Information we collect
  5. How we use it
  6. Legal bases
  7. Artificial intelligence
  8. Sharing and sub-processors
  9. Third-party platform data
  10. International transfers
  11. Retention and deletion
  12. Your rights
  13. US state privacy rights
  14. Security
  15. Cookies and tracking
  16. Children
  17. Changes
  18. Contact us

1. Who we are

Luton Labs LLC (“Luton Labs”, “we”, “us”) is a Delaware limited liability company with its principal place of business in Texas. We build and operate a family of business applications delivered as software as a service, and we are the entity responsible for the platform described in this policy.

For any privacy question, request or complaint, write to privacy@lutonlabs.com. We answer privacy requests at that address and nowhere else, so please use it rather than a support channel.

2. What this policy covers

This policy covers our public website at lutonlabs.com, our account portal at app.lutonlabs.com, and these applications:

  • AssetNexa — asset tracking
  • Benevanta — nonprofit fundraising and constituent management
  • CountNexa — inventory counting
  • GovNexa — government contracting pipeline
  • MusterKey — personnel and readiness data
  • ORVANTA GTM — go-to-market execution
  • ProVanta — client and practice management
  • ReturnNexa — lost property and claims

It does not cover any third-party site or service we link to. Those have their own policies and we do not control them.

3. Controller and processor — the distinction matters

We handle personal information in two different capacities, and your rights differ depending on which applies.

CapacityWhose informationWho decides how it is used
Controller Our own customers: the people who create an account, sign in, and are billed. Also visitors to our public website. We do. This policy governs it.
Processor Information our customers put into the applications — their donors, employees, claimants, contacts and clients. Our customer does. We act on their instructions.

If you are a donor, employee, claimant or contact of an organisation that uses our software, that organisation — not Luton Labs — decides what is held about you and why. Contact them first. If you cannot reach them, write to us and we will help you identify them and pass your request on.

4. Information we collect

4.1 Account information (we are the controller)

  • Name, email address, and where you provide one, a telephone number
  • Organisation name, city and postal code
  • Whether your email address and telephone number have been verified
  • Authentication data, including multi-factor authentication settings and recovery codes
  • Billing and subscription records. We never see or store your card number — payment details are entered directly with our payment provider (see section 8)

4.2 Information you put into the applications (we are the processor)

What is held depends entirely on which application your organisation uses and what it chooses to enter. Across the platform this can include names, postal and email addresses, telephone numbers, dates of birth, employment or membership details, donation and payment history, correspondence, and notes your organisation records.

We do not require, and do not ask for, government identifiers such as social security numbers. Some applications hold information that may be sensitive in context — for example a charitable giving history, or personnel readiness data. Your organisation decides what to enter.

4.3 Technical information

  • IP address, and the date and time of requests
  • Browser and device information sent by your browser
  • Pages requested, recorded in server logs
  • Session cookies needed to keep you signed in

We do not use advertising trackers, and we do not run third-party analytics that profile you across other websites.

5. How we use information

  • To provide the service — authenticating you, storing and returning your organisation's data, and running the features you use
  • To keep it working — monitoring, diagnosing faults, backups, and recovering from them
  • To keep it secure — detecting and investigating abuse, fraud and unauthorised access
  • To bill you and to keep the financial records the law requires
  • To support you — answering the questions you send us
  • To tell you about the service — changes, outages, and security notices. These are operational and you cannot opt out of them while you hold an account

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use the data our customers put into the applications to train artificial-intelligence models, ours or anybody else's.

6. Legal bases (UK and EU users)

PurposeBasis
Providing the service to an account holderPerformance of a contract
Billing, and keeping financial recordsLegal obligation, and legitimate interests
Security, fraud prevention, service integrityLegitimate interests
Operational notices to account holdersLegitimate interests
Optional integrations you switch onConsent, which you may withdraw
Information our customers enter about other peopleDetermined by that customer as controller; we process it under their instructions

7. Artificial intelligence

Several features use large language models. Being precise about this matters, so:

  • AI features are used when your organisation chooses to use them. They are individually switchable and are off unless enabled.
  • Where an AI feature runs, the relevant content is sent to a model provider to produce the answer. That may include personal information contained in the records the feature is working on.
  • Your organisation may supply its own provider credentials at app.lutonlabs.com, in which case the request goes to the provider your organisation chose, under your organisation's own agreement with them. Where no credentials are supplied, the request goes to a provider we hold an account with.
  • We instruct providers not to train on this content and use them under terms that provide for that. We do not train models on customer data ourselves.
  • Automated agents. Some applications offer assistants that read your organisation's records to answer questions. They read; they do not change records through conversation. Anything that would alter a record is proposed for a person to approve.

Model providers we may route to are listed in section 8. No AI feature makes a decision that produces a legal or similarly significant effect on anyone without a person reviewing it.

8. Sharing, and who processes data for us

We share personal information only as set out here. We never sell it.

8.1 Sub-processors

CategoryProvidersWhat reaches them
Hosting and infrastructure Hostinger International Everything stored by the platform, hosted in their facilities
AI model providers Anthropic, OpenAI, Google, xAI, Mistral, Cohere Only the content of an AI request your organisation initiated
Payment processing Stripe, PayPal, Square, Authorize.Net Payment details, entered directly with them; we receive a confirmation and a token, never a card number
Donation platforms
(Benevanta only, if connected)
Donorbox, Givebutter, CharityEngine Donation and donor records exchanged with a platform your organisation already uses
Address validation United States Postal Service A postal address being checked for deliverability
Email delivery Our mail provider; Mailchimp where a customer connects it Recipient address and message content
Bot protection Cloudflare (Turnstile) Signals from your browser on forms, to tell people from automated abuse

Each is bound by contract to process information only on our instructions and to protect it. We review this list as it changes; the version on this page is the current one.

8.2 Between our customers

One customer's records are not visible to another. Each organisation's data is separated and access is enforced on every request.

One deliberate exception, and its limits: Benevanta contributes and reads organisation-level research information — details about companies, foundations and grant-makers — to and from a shared reference database. That database holds information about organisations, not individuals. Personal records of an organisation's donors or contacts are never contributed to it, and the software refuses rather than filters if asked to.

8.3 Otherwise

  • To comply with the law, a court order or a lawful request, where we are satisfied it is valid
  • To establish, exercise or defend legal claims
  • To protect the rights and safety of people or the security of the service
  • To a successor if the business or part of it is transferred, subject to this policy

9. Data from third-party platforms you connect

Some features let your organisation connect an external account — for example a professional network, an email provider, or a donation platform — so that the application can work with information held there.

  • The connection is made by your organisation, deliberately, and can be disconnected at any time
  • We request only the permissions the feature needs
  • Information retrieved is used only to provide that feature to the organisation that connected it. It is not sold, not shared with other customers, and not used to train models
  • It is stored in that organisation's own workspace, subject to the retention rules in section 11
  • Disconnecting stops further retrieval. Information already retrieved is deleted on request under section 12, and is deleted with the workspace when an account is closed
  • We comply with the terms of the platform providing the data, including any requirement to delete it on request or when access is revoked

10. International transfers

Our infrastructure is operated in the United States and the European Union. Some sub-processors in section 8 are located in the United States. Where personal information of people in the United Kingdom or European Economic Area is transferred, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with the measures in section 14.

11. How long we keep information

InformationKept
Account and profileWhile the account is open, then 90 days, then deleted
Data your organisation enteredUntil your organisation deletes it, or 90 days after the account closes
Billing and financial recordsSeven years, as tax law requires
Server and security logsUp to 12 months
BackupsUp to 35 days, after which they are overwritten

Two things we want to state plainly rather than leave you to assume.

Deletion from live systems is immediate on request. Copies inside encrypted backups persist until those backups rotate, within the period above; we do not restore deleted records from them.

Where an application offers a configurable retention period, that setting governs the records it names. Some scheduled deletion is still being brought into service across the platform; until it is, deletion in those applications happens when you ask us, which we do promptly and within the times in section 12. We would rather say that than imply an automation that is not yet running everywhere.

12. Your rights

Depending on where you live, you have some or all of these rights:

  • Access — a copy of the personal information we hold about you
  • Correction — to have inaccurate information put right
  • Deletion — to have it erased, where no legal duty requires us to keep it
  • Portability — a machine-readable copy of information you gave us
  • Restriction and objection — to limit or object to a use, including any based on legitimate interests
  • Withdraw consent — at any time, without affecting what was done before
  • Complain — to your data protection authority. In the UK that is the Information Commissioner's Office; in the EEA, your national authority

Write to privacy@lutonlabs.com. We acknowledge within 7 days and respond within 30 days, extendable by a further 60 where a request is complex, in which case we will tell you why. We verify who you are before acting, and we do not charge for a reasonable request.

If your information was entered by an organisation that uses our software, that organisation is the controller and we will refer your request to them, and assist them in answering it.

13. United States state privacy rights

If you live in California, Colorado, Connecticut, Virginia, Utah, Texas or another state with comprehensive privacy legislation, you have the rights in section 12, and additionally the right not to be discriminated against for exercising them.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months, and we do not do so. We do not process personal information for targeted advertising or for profiling that produces legal or similarly significant effects.

Categories collected, and the purposes, are in sections 4 and 5; the categories disclosed to service providers are in section 8. Exercise any of these rights at privacy@lutonlabs.com. You may use an authorised agent; we will ask for proof of their authority.

14. Security

  • Encryption in transit using TLS for every connection
  • Encryption of stored credentials and integration secrets
  • Database connections authenticated with client certificates
  • Multi-factor authentication available, and required for administrative access
  • Access separated per organisation and enforced on every request
  • Role-based permissions your organisation controls
  • Regular backups, held encrypted
  • Administrative access limited to named people, and logged

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, without undue delay.

15. Cookies and similar technologies

We use cookies that are strictly necessary: a session cookie to keep you signed in, and a security token to protect forms from cross-site request forgery. Bot protection on public forms is provided by Cloudflare Turnstile, which reads signals from your browser to tell a person from an automated script.

We do not use advertising cookies, and we do not track you across other websites. Because we set only strictly necessary cookies, no consent banner is required; blocking them in your browser will stop you signing in.

16. Children

Our applications are business tools, are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, write to privacy@lutonlabs.com and we will delete it. Where a customer's own records concern minors, that customer is the controller and is responsible for the lawful basis for holding them.

17. Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we use personal information we will notify account holders by email at least 30 days before it takes effect, and where the law requires it we will ask for your consent.

18. Contact us

Luton Labs LLC — a Delaware limited liability company, principal place of business in Texas.
Privacy enquiries and requests: privacy@lutonlabs.com
General support: support@lutonlabs.com

If you are in the UK or EEA and are dissatisfied with our response, you may complain to your supervisory authority. We would prefer the chance to put it right first.

Luton Labs

Practical AI-powered SaaS applications for teams that need real results.

Solutions
  • AssetNexa
  • Benevanta
  • ProVanta
  • CountNexa
  • ReturnNexa
  • MusterKey
  • ORVANTA GTM
Platform
  • Sign In
  • Get Started
  • About
  • Contact

© 2026 Luton Labs LLC. All rights reserved. · Privacy Policy · Terms of Service