Privacy

Privacy policy

How we handle the data on this website and the data your team shares with us while we build workflow automations for you.

Last updated · 22 July 2026

01

Who this policy is from

LimeDock (“LimeDock”, “we”, “us”) is a studio that designs and ships custom workflow automations for SaaS teams. This privacy policy applies to visitors of limedock.com and to the business contacts we work with during an engagement.

Client end-user data (your customers, your users, your prospects) never reaches LimeDock in production — that data is processed by the automations we build, which run inside your own cloud account. The privacy notice your customers rely on is yours to write and publish.

02

What we collect on limedock.com

The marketing site collects a small, standard set of data:

  • Analytics. We use Google Analytics to understand what pages people read and where they arrive from. It captures page views, referrers, approximate location by IP, device type, and browser. IP addresses are processed by Google’s standard controls.
  • Booking. When you book a workflow call, Cal.com collects your name, email address, and selected time. That information is used to hold the meeting and follow up.
  • Email. When you email us at ranjeet@limedock.com, we keep the thread in Google Workspace for as long as we’re still in touch.
  • Cookies. Essential cookies for the site to work, plus Google Analytics’ own cookies. You can block them with your browser or use an ad blocker.

We do not sell visitor data. We do not run advertising retargeting off this site.

03

What we collect during an engagement

When we scope and build a workflow automation for you, we collect only what we need to do the job:

  • Business context — your workflow map, team structure, tool inventory, and success criteria, gathered in interviews and shared docs.
  • Sample data — anonymised or masked CRM exports, ticket samples, or product data used to test a workflow before it goes live. We ask you to strip real personal data before it reaches us wherever possible.
  • Temporary access — where a build requires it, short-lived credentials or a sandbox environment inside your systems. We do not store your production credentials on our machines and we work through your password manager or an SSO invite where you have one.
04

Where the automations run

This is the core of how LimeDock treats data differently. The workflow automations we build are deployed into your cloud account or on-prem environment. Prompts, integrations, and configuration ship into your Git organisation as versioned code.

As a result, your day-to-day customer and business data flows between the systems you already control (Slack, CRM, product database, internal platform) — not through servers operated by LimeDock. LimeDock has no continuous access to production data after handover, and any ongoing access during an operate retainer is scoped and logged.

05

AI providers and your API keys

The automations call model providers such as OpenAI, Anthropic, or others you choose. Those calls are made with your API keys, from your infrastructure, against the provider’s endpoints directly. LimeDock does not proxy your model traffic.

Each provider has its own privacy and data-retention policy that applies to the requests you make. We help you configure zero data-retention, enterprise agreements, or private deployments where the provider supports them.

06

Sub-processors we use

For the marketing site and internal delivery, we rely on a small set of tools:

  • Vercel — marketing-site hosting and analytics.
  • Google Analytics — traffic measurement.
  • Cal.com — meeting booking.
  • Google Workspace — email, docs, and shared drives for engagement materials.
  • GitHub — source control and code review.
  • Slack — shared channels invited by clients for engagement communication.

We do not appoint additional sub-processors to touch your engagement data without telling you first.

07

How long we keep things

  • Website analytics. Rolled up after 26 months following Google Analytics defaults.
  • Booking + email. Kept for as long as we’re in active conversation, then archived for 24 months so we can pick up threads.
  • Engagement materials. Kept for the duration of the engagement plus 12 months, or as required by the SOW. Sample data we asked you to share is deleted within 30 days of a workflow going live unless we’ve agreed otherwise for eval reasons.
08

Your rights

If you’re a visitor or a client contact, you can ask us to see, correct, export, or delete the personal information we hold about you. If you’re in the EEA, the UK, or a jurisdiction with comparable rules, you also have the right to object to processing and to lodge a complaint with your local data protection authority.

Email ranjeet@limedock.com with the request. We respond within 30 days.

09

Security

Engagement materials sit in Google Workspace and GitHub with two-factor authentication required. Client credentials are never committed to code, and secrets are stored in the client’s own secret manager rather than on our laptops. Devices used for engagements have full-disk encryption and auto-locking.

10

International transfers

The tools listed in section 6 may process data in the United States, the European Union, or India. Where personal data of EEA or UK residents is transferred, we rely on the standard contractual clauses those providers publish and on your prior agreement in the SOW.

11

Children

LimeDock’s services are aimed at businesses. The marketing site is not directed at anyone under 16 and we do not knowingly collect information from children.

12

Changes to this policy

When we make a material change, we’ll update the “last updated” date at the top of this page and — for existing clients — send a note over the shared Slack or email.

13

Contact

Questions or requests: ranjeet@limedock.com. If you’d rather see our terms of service, they live at /terms.