Legal · Privacy
Privacy Policy
Lithi Privacy Policy: how we collect, use, disclose, and safeguard information when you use our Services.
On this page
Privacy and data practices
Last Updated: August 12, 2026
Battery Department LLC, trading as Lithi Technologies ("Lithi," "we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our account-based marketing platform and services (the "Services"). By using our Services, you consent to the data practices described in this policy. If you do not agree with this policy, please discontinue use of our Services immediately.
Contents
- Information we collect
- CMS platform data handling
- AI-generated content and conversations
- How we use information
- SMS, voice, and AI communications
- Legal basis, sharing, security, and retention
- Your privacy rights
- Cookies, international data, and changes
- Contact and compliance
- Reconciliation status
- Primary action
Reconciliation status
| Field | Record |
|---|---|
| Scope | This public Privacy Policy source and the products, providers, data practices, and rights it describes. |
| Status | Predecessor terminology remains; legal reconciliation is required before publication. |
| Owner | Lithi legal and privacy |
| Evidence | The current policy source, product authority, provider register, and applicable executed terms. |
| Last reviewed | 2026-08-11 |
| Limitation | This source is noindex and does not establish current live processing or customer-specific legal advice. |
1. Information We Collect
Information You Provide Directly
We collect information you provide when you:
- Create an account: Name, email address, company name, phone number, billing information.
- Complete the onboarding quiz: Business type, industry, geographic preferences, budget, service radius.
- Use our Services: Campaign details, target account lists, message templates, contact information.
- Contact us: Name, email, company, message content, support inquiries.
- Subscribe to updates: Email address for newsletters and product updates.
Information Collected Automatically
When you access our Services, we automatically collect device information (IP address, browser type, operating system, and device identifiers), usage information (pages viewed, time spent, clicks, and navigation paths), session information (session ID, company slug, event sequences, and funnel stages), geographic location based on IP address, and session, analytics, and preference cookies.
Information from Third-Party Sources
We may collect publicly available company information and contact details from business databases, analytics information from Google Analytics and Supabase Analytics, payment information from Stripe or other payment service providers, and information from LinkedIn or Twitter if you connect those accounts.
2. CMS Platform Data Handling
- WordPress: Application Password (encrypted at rest and used solely to publish content), site URL, and site title. Data is revoked immediately upon plugin deactivation or disconnection.
- Wix: OAuth2 Instance ID used to generate short-lived access tokens on demand; no passwords or long-lived tokens are stored. Site URL and display name are used for connection identification.
- Shopify: OAuth2 Access Token (stored encrypted), shop domain, and store name. We comply with Shopify GDPR mandatory webhooks, and all data is deleted within 48 hours of app uninstallation per Shopify requirements.
- Squarespace and Webflow: A manual copy-paste embed code is provided in the admin portal. No OAuth connection or credential storage is involved.
- HubSpot: When connected via OAuth2, Lithi pushes chatbot-captured leads (name, email, phone, and conversation summary) to HubSpot as new contacts. We store the HubSpot hub ID and encrypted OAuth tokens, which are revoked immediately upon disconnection. HubSpot is a CRM integration only.
3. AI-Generated Blog Content and Chatbot Conversation Data
Blog ideas and posts are generated using AI models trained on your business knowledge base. Generated content is stored in our database and published to your connected CMS platform only with your authorization. Content is fact-checked against your knowledge base, but you are responsible for reviewing before publication, and blog content can be deleted at any time via the admin portal.
Conversations are stored in our database for quality improvement and analytics. Lead information (name, email, and phone) is captured only when voluntarily provided by visitors. Conversation data is retained for 12 months and then automatically anonymized. You can request deletion of specific conversations via the admin portal.
4. How We Use Your Information
We use your information to provide account-based marketing campaigns, territory mapping, and outreach services; personalize content, recommendations, and campaign strategies; send transactional emails, campaign updates, and support responses; track campaign performance, user behavior, and funnel conversion rates; enhance our platform and user experience; meet legal obligations, prevent fraud, and enforce our Terms of Service; and send promotional emails, product updates, and newsletters with your consent.
5. SMS, Voice, and AI Communications
SMS messages may include service notifications, campaign updates, lead responses, and promotional messages. Voice calls may include AI-powered outreach, follow-up, and customer service calls. Automated voice agents identify themselves as AI assistants. Consent may be express written consent, verbal consent, reply opt-in (such as “START”), or a B2B exemption for communications to publicly listed business phone numbers. Message frequency varies by campaign settings and service usage; standard message and data rates may apply. Carriers are not liable for delayed or undelivered messages. Reply STOP, UNSUBSCRIBE, CANCEL, END, or QUIT to SMS, request removal during a voice call, contact optout@lithi.ai, or update preferences in your account settings.
6. Legal Basis, Sharing, Security, and Retention
Our legal bases include contract performance, legitimate interests, consent, and legal obligation. We may share information with service providers including Vercel, Supabase, Google Analytics, Stripe, Mercury, QuickBooks Payments, email and SMS providers (including Twilio), Anthropic PBC, Merge.dev, ElevenLabs Inc., and Mapbox Inc., as described in the predecessor Privacy Policy.
Payment processors receive name, billing address, email, plan or invoice amount, line-item descriptions, and transaction or invoice identifiers. Lithi does not store full credit card numbers, CVV/security codes, bank account numbers, or Apple Pay tokens. Public pricing and Trust pages do not start Checkout, create an invoice, or collect payment credentials.
Security measures include TLS/SSL encryption in transit, AES-256 encryption at rest, role-based access control, multi-factor authentication, security audits, vulnerability assessments, penetration testing, employee training, and incident response procedures. Account data is retained while active plus 90 days after termination; campaign data for 2 years; financial and invoice/payment records for 7 years; payment disputes for the dispute plus 2 years; support tickets for 3 years; and aggregated anonymized analytics may be retained indefinitely.
7. Your Privacy Rights
EEA users may request access, rectification, erasure, restriction, data portability, objection to legitimate-interest processing, or withdrawal of consent. California users may request to know, delete, or opt out of sale of personal information (we do not sell data), and exercise rights without discrimination. Contact privacy@lithi.ai to exercise your rights. We will respond within 30 days.
8. Cookies, International Data, and Changes
We use essential cookies for basic functionality, analytics cookies to track usage patterns, and preference cookies to remember settings. The embedded chatbot widget does not set cookies: it uses localStorage for conversation persistence in the lithi.ai iframe origin and does not access or modify merchant storefront cookies. Analytics cookies and marketing emails require consent, which you can withdraw at any time; this policy does not grant a general marketing-cookie permission. We recognize the United States as our primary jurisdiction, and address GDPR, UK GDPR, and Australia Privacy Act 1988 considerations in the applicable processing arrangements. We do not respond to Do Not Track signals. We may update this policy by posting a website notice, emailing registered users, and updating the Last Updated date.
9. Contact and Compliance
Battery Department LLC, trading as Lithi Technologies — Data Protection Officer. Email privacy@lithi.ai. The predecessor policy identifies GDPR, CCPA, CAN-SPAM Act, TCPA, TSR, the National Do Not Call Registry, 10DLC, and inherited SOC 2 Type II statements; those statements remain subject to their stated scope and limitations.