Effective 9 September 2026. Last updated 9 September 2026. This policy applies to Luton Labs LLC and to every application listed in section 2.
Luton Labs LLC (“Luton Labs”, “we”, “us”) is a Delaware limited liability company with its principal place of business in Texas. We build and operate a family of business applications delivered as software as a service, and we are the entity responsible for the platform described in this policy.
For any privacy question, request or complaint, write to privacy@lutonlabs.com. We answer privacy requests at that address and nowhere else, so please use it rather than a support channel.
This policy covers our public website at lutonlabs.com, our account portal at app.lutonlabs.com, and these applications:
It does not cover any third-party site or service we link to. Those have their own policies and we do not control them.
We handle personal information in two different capacities, and your rights differ depending on which applies.
| Capacity | Whose information | Who decides how it is used |
|---|---|---|
| Controller | Our own customers: the people who create an account, sign in, and are billed. Also visitors to our public website. | We do. This policy governs it. |
| Processor | Information our customers put into the applications — their donors, employees, claimants, contacts and clients. | Our customer does. We act on their instructions. |
If you are a donor, employee, claimant or contact of an organisation that uses our software, that organisation — not Luton Labs — decides what is held about you and why. Contact them first. If you cannot reach them, write to us and we will help you identify them and pass your request on.
What is held depends entirely on which application your organisation uses and what it chooses to enter. Across the platform this can include names, postal and email addresses, telephone numbers, dates of birth, employment or membership details, donation and payment history, correspondence, and notes your organisation records.
We do not require, and do not ask for, government identifiers such as social security numbers. Some applications hold information that may be sensitive in context — for example a charitable giving history, or personnel readiness data. Your organisation decides what to enter.
We do not use advertising trackers, and we do not run third-party analytics that profile you across other websites.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use the data our customers put into the applications to train artificial-intelligence models, ours or anybody else's.
| Purpose | Basis |
|---|---|
| Providing the service to an account holder | Performance of a contract |
| Billing, and keeping financial records | Legal obligation, and legitimate interests |
| Security, fraud prevention, service integrity | Legitimate interests |
| Operational notices to account holders | Legitimate interests |
| Optional integrations you switch on | Consent, which you may withdraw |
| Information our customers enter about other people | Determined by that customer as controller; we process it under their instructions |
Several features use large language models. Being precise about this matters, so:
Model providers we may route to are listed in section 8. No AI feature makes a decision that produces a legal or similarly significant effect on anyone without a person reviewing it.
We share personal information only as set out here. We never sell it.
| Category | Providers | What reaches them |
|---|---|---|
| Hosting and infrastructure | Hostinger International | Everything stored by the platform, hosted in their facilities |
| AI model providers | Anthropic, OpenAI, Google, xAI, Mistral, Cohere | Only the content of an AI request your organisation initiated |
| Payment processing | Stripe, PayPal, Square, Authorize.Net | Payment details, entered directly with them; we receive a confirmation and a token, never a card number |
| Donation platforms (Benevanta only, if connected) |
Donorbox, Givebutter, CharityEngine | Donation and donor records exchanged with a platform your organisation already uses |
| Address validation | United States Postal Service | A postal address being checked for deliverability |
| Email delivery | Our mail provider; Mailchimp where a customer connects it | Recipient address and message content |
| Bot protection | Cloudflare (Turnstile) | Signals from your browser on forms, to tell people from automated abuse |
Each is bound by contract to process information only on our instructions and to protect it. We review this list as it changes; the version on this page is the current one.
One customer's records are not visible to another. Each organisation's data is separated and access is enforced on every request.
One deliberate exception, and its limits: Benevanta contributes and reads organisation-level research information — details about companies, foundations and grant-makers — to and from a shared reference database. That database holds information about organisations, not individuals. Personal records of an organisation's donors or contacts are never contributed to it, and the software refuses rather than filters if asked to.
Some features let your organisation connect an external account — for example a professional network, an email provider, or a donation platform — so that the application can work with information held there.
Our infrastructure is operated in the United States and the European Union. Some sub-processors in section 8 are located in the United States. Where personal information of people in the United Kingdom or European Economic Area is transferred, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with the measures in section 14.
| Information | Kept |
|---|---|
| Account and profile | While the account is open, then 90 days, then deleted |
| Data your organisation entered | Until your organisation deletes it, or 90 days after the account closes |
| Billing and financial records | Seven years, as tax law requires |
| Server and security logs | Up to 12 months |
| Backups | Up to 35 days, after which they are overwritten |
Two things we want to state plainly rather than leave you to assume.
Deletion from live systems is immediate on request. Copies inside encrypted backups persist until those backups rotate, within the period above; we do not restore deleted records from them.
Where an application offers a configurable retention period, that setting governs the records it names. Some scheduled deletion is still being brought into service across the platform; until it is, deletion in those applications happens when you ask us, which we do promptly and within the times in section 12. We would rather say that than imply an automation that is not yet running everywhere.
Depending on where you live, you have some or all of these rights:
Write to privacy@lutonlabs.com. We acknowledge within 7 days and respond within 30 days, extendable by a further 60 where a request is complex, in which case we will tell you why. We verify who you are before acting, and we do not charge for a reasonable request.
If your information was entered by an organisation that uses our software, that organisation is the controller and we will refer your request to them, and assist them in answering it.
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas or another state with comprehensive privacy legislation, you have the rights in section 12, and additionally the right not to be discriminated against for exercising them.
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months, and we do not do so. We do not process personal information for targeted advertising or for profiling that produces legal or similarly significant effects.
Categories collected, and the purposes, are in sections 4 and 5; the categories disclosed to service providers are in section 8. Exercise any of these rights at privacy@lutonlabs.com. You may use an authorised agent; we will ask for proof of their authority.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, without undue delay.
We use cookies that are strictly necessary: a session cookie to keep you signed in, and a security token to protect forms from cross-site request forgery. Bot protection on public forms is provided by Cloudflare Turnstile, which reads signals from your browser to tell a person from an automated script.
We do not use advertising cookies, and we do not track you across other websites. Because we set only strictly necessary cookies, no consent banner is required; blocking them in your browser will stop you signing in.
Our applications are business tools, are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, write to privacy@lutonlabs.com and we will delete it. Where a customer's own records concern minors, that customer is the controller and is responsible for the lawful basis for holding them.
When we change this policy we update the date at the top. If a change materially affects how we use personal information we will notify account holders by email at least 30 days before it takes effect, and where the law requires it we will ask for your consent.
Luton Labs LLC — a Delaware limited liability company,
principal place of business in Texas.
Privacy enquiries and requests: privacy@lutonlabs.com
General support: support@lutonlabs.com
If you are in the UK or EEA and are dissatisfied with our response, you may complain to your supervisory authority. We would prefer the chance to put it right first.