Privacy

Last updated 4 August 2026

Logomark is operated by Lucro Limited, a company registered in Ireland, company number 811725. In this policy, "we" and "us" mean Lucro Limited, and "you" means the person or business using Logomark.

This is written to be read rather than to cover us. If anything here is unclear, email us and we will answer plainly.

Two kinds of data, two different roles

This distinction matters, so it comes first.

Your account data. We are the controller.

Your email address, company name, website, billing status. We decide how this is handled and this policy governs it.

Your customers' data. You are the controller, we are the processor.

When you connect Stripe, we read information about your customers. That data belongs to you and your relationship with them. We only process it to provide the service, and only on your instructions. You remain responsible for having a lawful basis to contact those people.

What we collect

Very little, and less than you would expect.

Your customers' data is not stored.

When you open the dashboard we read your customer list from Stripe, hold it in memory for that request, and discard it. Emails, names, plans and revenue figures are never written to disk. There is no copy of your customer list on our side.

What we keepWhy
The domainTo find and serve the right logo
The logo fileIt is what appears on your site
Whether they have been askedSo nobody is asked twice
The permission record: timestamp, IP, browser and a fingerprint of the approved fileTo prove the logo was approved. This is the point of the product
A Stripe reference idTo match a logo to the right customer. An opaque token, meaningless outside your own Stripe account

The domain and the logo are the two things you are publishing on your own homepage anyway.

Your account data. We are the controller.

WhatWhy
Your email addressTo create your account and send sign in links
Company name and websiteUsed in the approval pages your customers see
Your Stripe restricted keyEncrypted at rest. Read only. Verified read only before storing
Billing statusWhether your subscription is in trial, active or cancelled

Your Stripe connection

We accept restricted keys only. A full secret key is refused outright, because a key that can charge and refund is not one we want to hold. We do not use OAuth or Stripe Connect, so you create the key, you scope it, and you can revoke it at any time without telling us.

Before storing a key we attempt a write with it and confirm Stripe refuses. If the write succeeds, the key has permissions we did not ask for and we decline it.

We make four calls, all of them reads: customers, subscriptions, products and prices. Every call is logged and listed in your own Settings, recorded as it happens rather than described by us.

Disconnecting deletes everything. The key and every synced row are removed and overwritten on disk, not merely unlinked.

We do not track email opens. Open tracking is unreliable on modern mail clients and we would rather show nothing than show something wrong. We do not use advertising cookies, analytics trackers or third party pixels.

What we never do

Who else touches the data

We use a small number of providers to run the service. Each is bound by their own data processing terms.

ProviderWhat forWhere
HetznerApplication server and databaseEU (Germany or Finland)
CloudflareDNS, caching, and storage of published logo filesGlobal network
ResendSending sign in emailsEU and US
StripeOur own billing, and reading your customer listEU and US

Where data moves outside the EEA, it does so under the transfer safeguards those providers have in place, including Standard Contractual Clauses.

How long we keep it

Your rights

Under GDPR you can ask us to give you a copy of your data, correct it, delete it, or hand it to someone else in a portable format. Email us and we will do it within 30 days at no cost.

If a logo owner wants their logo removed, they do not need to email anyone. Every approval email carries a revoke link that works permanently and takes effect the same day.

You can complain to the Irish Data Protection Commission at dataprotection.ie if you think we have handled your data badly. We would rather you told us first.

Security

No system is perfect. If we ever have a breach affecting your data, we will tell you and the Data Protection Commission within 72 hours of becoming aware of it.

Cookies

One cookie, for keeping you signed in. It is strictly necessary, contains a random session identifier and nothing else, and expires after 30 days. No analytics, no advertising, no third parties.

Not affiliated with Stripe

Logomark is an independent product built by Lucro Limited. We are not affiliated with, endorsed by, sponsored by or otherwise connected to Stripe, Inc. Stripe is a trademark of Stripe, Inc. We use their publicly available API in the ordinary way any developer may.

Changes

If we change anything material here, we will email you before it takes effect rather than quietly updating the date at the top.

Contact

Lucro Limited, company number 811725, registered in Ireland.
hello@logomark.app