Legal
Privacy Policy
This policy explains how Lucidity collects, uses, stores, and shares personal information, including Google user data used for GA4 reporting.
Overview
Lucidity is a lead routing, tracking, and analytics platform for businesses and the agencies that serve them. This Privacy Policy describes the information Lucidity handles when you visit our website, request a demo, use the Lucidity application, or authorize a Google Connection.
Businesses using Lucidity may submit or capture information about their own Leads. Those businesses decide what Lead information is collected and where it is delivered. For that information, Lucidity acts as a service provider or processor on the business's behalf. A person seeking to exercise rights over a Lead record should normally contact the business that collected it first.
Information we collect
- Account and business information: names, email addresses, login information, Workspace membership, Business and Location details, preferences, and support communications.
- Lead and Delivery information: contact details, inquiry content, source and campaign context, validation results, routing instructions, and Delivery outcomes submitted by or for a Lucidity customer.
- Website and demo requests: the name, work email, phone number, website, message, source URL, and consent information you submit through our forms.
- Usage and device information: IP address, browser and device details, page URL, referrer, timestamps, product interactions, identifiers, and diagnostic or security events collected through logs, browser storage, and the Lucidity Tracking Pixel.
- Billing information: subscription and transaction records and limited payment metadata. Payment providers process full payment credentials under their own privacy terms.
- Google user data: the identity, authorization, property metadata, and GA4 report data described in the Google API Data section below.
How we use information
Lucidity uses information to:
- Provide, secure, maintain, and support the Lucidity service.
- Capture, validate, attribute, route, and record Delivery of Leads.
- Authenticate users and enforce Workspace, Business, and Location access.
- Provide analytics, reporting, and requested integrations.
- Process billing and administer subscriptions.
- Respond to inquiries and send requested service or marketing communications.
- Detect abuse, diagnose failures, and improve product reliability and usability.
- Comply with law and enforce our agreements.
Google API Data
This section explains how Lucidity accesses, uses, stores, and shares Google user
data. A Workspace administrator can choose to connect Lucidity to Google Analytics
through Google OAuth. Lucidity requests the minimum access used by the current
integration: openid, email, and
https://www.googleapis.com/auth/analytics.readonly. The Analytics scope
is read-only. Lucidity cannot use it to change a user's Google Analytics
configuration.
How Lucidity accesses Google user data
After an administrator grants consent, Lucidity accesses:
- A stable Google account identifier and email address used to identify and display the Google Connection.
- Google Analytics account and property metadata available to the connected identity, including account and property identifiers, display names, time zones, and currency codes.
- Read-only GA4 reports for a property the administrator selects, including report date, traffic source, medium, campaign, default channel group, landing page, device category, sessions, users, engaged sessions, key events, and advertiser ad cost when available.
How Lucidity uses Google user data
Lucidity uses this data only to let authorized Workspace users connect and select a GA4 property, keep that connection working, import GA4 traffic and campaign context, and display that context alongside Lucidity's first-party Lead and Delivery facts. If an authorized user asks Lucidity Assistant about analytics, Lucidity may send the relevant GA4 metrics and the user's prompt through OpenRouter to a selected AI inference provider solely to generate the requested answer. Those calls are configured to use providers with zero data retention and to deny provider data collection, so the providers may not retain the data or use it to train models.
Lucidity does not use Google user data for advertising, sell it, use it to determine creditworthiness, or use it to train general-purpose artificial intelligence models.
How Lucidity stores Google user data
Lucidity stores the Google account identifier and email, granted scopes, selected account and property metadata, connection status, encrypted OAuth access and refresh tokens, and imported daily GA4 report rows. Access and refresh tokens are encrypted at rest and are not exposed through Lucidity's customer APIs. Access is limited by Lucidity Workspace permissions.
How Lucidity shares Google user data
Google user data is shown to authorized users in the Workspace that established the connection and may be included in reports sent to external email recipients configured by an authorized customer user. Lucidity may disclose it to service providers that host, secure, monitor, or support Lucidity, but only as needed to provide the user-facing service and subject to confidentiality and data protection obligations. Lucidity does not sell Google user data or share it with data brokers or advertisers. We may disclose data if required by law or to protect users, Lucidity, or the public from fraud, abuse, or security threats.
Google data retention and controls
Lucidity retains connection records and imported GA4 report data while needed to provide the service, maintain required business records, resolve disputes, or meet legal and security obligations. Disabling a Google Connection stops future access and synchronization but does not automatically delete data already imported into Lucidity.
An administrator can disable the connection in Lucidity or revoke Lucidity's access from the Google Account connections page. You may request deletion of stored Google user data and imported GA4 data by using our website contact form. We will delete or de-identify the requested data unless we must retain it for a legal, security, fraud prevention, or dispute resolution purpose.
Lucidity's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we share information
Lucidity may share information with:
- Authorized customer users: people permitted to use the relevant Workspace, Business, Client Group, or Location.
- Configured Destinations: CRMs, webhooks, email recipients, and other systems a customer directs Lucidity to deliver Lead information to.
- Service providers: vendors that provide hosting, databases, monitoring, communications, billing, security, and customer support.
- Legal and safety recipients: authorities or other parties when required by law or reasonably necessary to protect rights, safety, and service integrity.
- Corporate transaction recipients: parties involved in a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections. This category does not include Google user data unless the user gives explicit prior consent.
Lucidity does not sell personal information.
Retention and security
We retain information for as long as needed to provide the service, follow customer instructions, satisfy legal and accounting obligations, enforce agreements, and protect the service. Retention varies by record type and contract. For example, raw Tracking Pixel events are scheduled for deletion after 14 months, while account, Lead, Delivery, reporting, billing, security, and audit records may follow different periods.
Lucidity uses administrative, technical, and organizational safeguards designed to protect information, including access controls and encryption for sensitive Google OAuth credentials. No system is completely secure, and we cannot guarantee absolute security.
Your choices and rights
Depending on where you live and how Lucidity handles your information, you may have rights to request access, correction, deletion, restriction, or a copy of your personal information, or to object to certain uses. You may unsubscribe from marketing emails through the link in the message and opt out of text messages by replying STOP.
To make a privacy request, use our website contact form and identify the relevant Lucidity Workspace or Business. We may need to verify your identity and authority. If a Lucidity customer controls the information, we may direct your request to that customer or assist it in responding.
Children
Lucidity is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13 through our own website or application.
Changes to this policy
We may update this Privacy Policy as the service or legal requirements change. We will post the revised policy here and change the last updated date. We will provide additional notice when required by law or when a material change affects how Lucidity uses Google user data.
Contact us
For questions, privacy requests, or Google user data deletion requests, contact Lucidity through the website form.