Privacy at Lowmark

A clear account of what the current Lowmark product stores and why.

What Lowmark receives

Account and staff details, business configuration, customer requests, operational records, website content, and images that a merchant chooses to upload.

How it is used

To authenticate users, keep each workspace separate, publish the merchant website, accept customer requests, run daily operations, and show first-party performance information.

Images

Lowmark validates and re-encodes uploaded images into optimized sizes. The uploaded original is not retained. Active website images are public because customers must be able to view them.

Analytics

Lowmark records first-party page and booking events with a one-way session hash. For merchant signup, session-scoped first-touch attribution records a referrer origin, a safe landing page, campaign labels, platform and locale. Authenticated product events record workspace milestones and feature use with workspace and user identifiers. Metadata excludes customer contact details, full URLs, IP addresses and precise location. Lowmark does not fingerprint users or use advertising trackers.

Sharing and providers

The current production foundation uses Hostinger for VPS hosting, GitHub for private source and deployment automation, and GoDaddy for DNS. Lowmark does not currently integrate an advertising tracker, payment processor, email sender, SMS sender, or AI provider.

Retention and control

Merchants can export customers, bookings, and inventory. Unused media and deletion requests use a 30-day recoverable period. Public-site analytics are configured for 90 days. Signup attribution and product event history are kept separately to measure business cohorts. Backup copies follow the documented operational retention period.

Contact

An in-app support request is available to signed-in merchants. A public privacy mailbox has not been configured yet.