LatticeSpotPublic service recordPrivacy · coordinate P-02
Policy directory01Terms02Privacy03Refunds04Content rules05Contact

Privacy notice

Your data, in plain view.

This notice describes the personal data used to provide LatticeSpot, what becomes public, and how to contact us about your information.

Effective
17 September 2026
Controller
Drelavi Studio
Contact
support@latticespot.com

What we collect

  • Account and authentication identifiers, including verified email and account status.
  • Profile, Creative, destination, category, coordinates and Placement history.
  • Order status, consent version and payment-provider references. Stripe processes billing details and card data; LatticeSpot does not store full card numbers or security codes.
  • Support, report, moderation, security and audit records needed to investigate issues.
  • Technical logs and security signals such as timestamps, IP addresses, device or request information that may be processed by us or our providers.

Why we use it

We use data to authenticate Members, publish and maintain Placements, fulfil and reconcile payments, operate Explore, prevent abuse, respond to requests, secure and back up the service, meet legal obligations and resolve payment or content disputes.

When enabled, outbound click statistics count destination-link activations on Canvas, Info, Explore and Placement pages. A cumulative click count is public beside the display time on eligible Placement records, including records of replaced Placements. Paid Refresh does not reset it. Only the owning Member can view daily trends and source breakdowns. Counts are not unique visitors, successful destination loads, sales or return on investment. We do not provide behavioural advertising profiles or impression analytics.

Daily counts by Placement and source are retained for 90 days. The cumulative public total is kept with the Placement record and is not reduced when daily data expires. Random event identifiers suppress duplicate requests; they expire after ten minutes and are removed by the next minute’s cleanup while the service runs, or on restart. This feature does not store visitor IP addresses, user agents or browser fingerprints, or set analytics cookies. Basic automated-request filtering is applied in memory. We honor Do Not Track and Global Privacy Control for these events. Blocking scripts or connection failures may prevent a click from being counted. Existing infrastructure security logs are separate.

What is public

Canvas images, Handles, listing text, categories, destination links, coordinates, dates, Pixel counts and Placement history can be public and shared by visitors.

Replacement does not automatically make a record private. Do not place sensitive information in a Creative or listing. Private billing details, account email, Stripe identifiers and investigation material are not intended for public display.

Providers and disclosure

We use service providers where needed to run the product: Clerk for authentication, Stripe for payments, Hostinger for hosting and email, Cloudflare R2 for private encrypted recovery material, and UptimeRobot for availability monitoring. Those providers may process technical or account information under their own terms and locations.

We may disclose relevant information where required by law or after assessing a payment, security, safety or rights complaint. Member destination sites are independent and have their own privacy practices.

Storage and retention

The Canvas remembers camera preferences in local browser storage and may use essential session mechanisms for sign-in. You can clear local browser data, although doing so may reset preferences or sign you out.

We retain information only while needed for the purposes above and applicable legal, accounting, security and dispute requirements. Public content can be hidden or de-identified where appropriate; necessary payment, audit, backup and factual Placement records may remain longer. Backups are access-restricted and expire under operational retention procedures.

Your choices and rights

Email support@latticespot.com to request access, correction, deletion, restriction, portability or withdrawal where available under applicable law. We may need to verify your identity and may retain information where law or legitimate operational requirements permit. Do not send identity documents through ordinary email unless we agree on a suitable process.

You may also contact Malaysia's Personal Data Protection Commissioner where applicable.

First-party acquisition counts

When enabled, we count visible homepage loads to understand use of the free pixel entry point. These are page loads, not unique visitors or advertising impressions. We do not send these events to a third-party analytics provider or store visitor IP addresses, user agents, full URLs, referrers or browser fingerprints in this feature. It sets no analytics cookies or browser storage. Do Not Track and Global Privacy Control are honored. Basic automated-request filtering is performed in memory.

Anonymous daily homepage counts are retained for 90 days. Random event identifiers prevent duplicate event retries for ten minutes; expired data is cleaned up each minute while the service runs and on startup. Existing infrastructure security logs are separate. Owner-only reports also aggregate existing free-claim and fulfilled-order records. These business records follow their existing retention rules. Test orders are reported separately. Independent period totals do not identify a visitor’s browsing journey.

Drelavi Studio · CA0426527-M
CanvasTermsRefundsContent rulesContactReport content