Privacy
Last updated 4 August 2026
Logomark is operated by Lucro Limited, a company registered in Ireland, company number 811725. In this policy, "we" and "us" mean Lucro Limited, and "you" means the person or business using Logomark.
This is written to be read rather than to cover us. If anything here is unclear, email us and we will answer plainly.
Two kinds of data, two different roles
This distinction matters, so it comes first.
Your account data. We are the controller.
Your email address, company name, website, billing status. We decide how this is handled and this policy governs it.
Your customers' data. You are the controller, we are the processor.
When you connect Stripe, we read information about your customers. That data belongs to you and your relationship with them. We only process it to provide the service, and only on your instructions. You remain responsible for having a lawful basis to contact those people.
What we collect
| What | Why |
|---|---|
| Your email address | To create your account and send sign in links |
| Company name and website | Used in the approval pages your customers see |
| Your Stripe restricted key | Encrypted at rest. Read only. Used to list your customers |
| Your customers' names, email addresses, domains, plan and subscription dates | To decide who qualifies and who to ask |
| Logo files | Fetched from your customer's own public website, or uploaded by them |
| Consent records: timestamp, IP address, browser, and a fingerprint of the approved file | To prove a logo was approved. This is the point of the product |
| Billing status | Whether your subscription is in trial, active or cancelled |
What we never do
- Sell or rent your data, or your customers' data, to anyone
- Use your customer list to market to those people ourselves
- Use one customer's data to benefit another customer
- Store card numbers or bank details. Stripe handles all of that and we never see it
- Take write access to your Stripe account. The key we accept is read only
Who else touches the data
We use a small number of providers to run the service. Each is bound by their own data processing terms.
| Provider | What for | Where |
|---|---|---|
| Hetzner | Application server and database | EU (Germany or Finland) |
| Cloudflare | DNS, caching, and storage of published logo files | Global network |
| Resend | Sending sign in emails | EU and US |
| Stripe | Our own billing, and reading your customer list | EU and US |
Where data moves outside the EEA, it does so under the transfer safeguards those providers have in place, including Standard Contractual Clauses.
How long we keep it
- Account data: while your account is open, then 30 days after you close it
- Your customers' data: deleted within 30 days of you disconnecting Stripe or closing your account
- Consent records: kept for as long as the logo is published, plus six years afterwards. A consent record with no retention is worthless, since its whole purpose is to show that permission was given at a point in time
- Logo files: removed from public serving immediately on revocation. The stored copy is kept with the consent record
Your rights
Under GDPR you can ask us to give you a copy of your data, correct it, delete it, or hand it to someone else in a portable format. Email us and we will do it within 30 days at no cost.
If a logo owner wants their logo removed, they do not need to email anyone. Every approval email carries a revoke link that works permanently and takes effect the same day.
You can complain to the Irish Data Protection Commission at dataprotection.ie if you think we have handled your data badly. We would rather you told us first.
Security
- Stripe keys are encrypted at rest with AES-256-GCM and are never sent to a browser
- We only accept restricted, read only Stripe keys
- Sign in is by one time link. We do not store passwords because we do not use them
- The administrative interface is not reachable from the public internet
- All traffic is over HTTPS
No system is perfect. If we ever have a breach affecting your data, we will tell you and the Data Protection Commission within 72 hours of becoming aware of it.
Cookies
One cookie, for keeping you signed in. It is strictly necessary, contains a random session identifier and nothing else, and expires after 30 days. No analytics, no advertising, no third parties.
Not affiliated with Stripe
Logomark is an independent product built by Lucro Limited. We are not affiliated with, endorsed by, sponsored by or otherwise connected to Stripe, Inc. Stripe is a trademark of Stripe, Inc. We use their publicly available API in the ordinary way any developer may.
Changes
If we change anything material here, we will email you before it takes effect rather than quietly updating the date at the top.
Contact
Lucro Limited, company number 811725, registered in Ireland.
hello@logomark.app