Privacy Policy
This Master Privacy Policy explains how LVL DIGITAL VENTURES LTD ("we", "us", or "our") collects, uses, processes, stores, and protects personal information across all our business operations, commercial verticals, digital platforms, and consumer applications (collectively, the "Services").
LVL Digital Ventures Ltd operates as a venture studio and multi-discipline digital organization. To provide transparent data protection practices across all client touchpoints, customer journeys, and product ecosystems, this policy governs the following operational branches:
SaaS & Web Software
Cloud software platforms, web apps, automated venture systems (such as LVEL), API services, and team workspaces.
E-Commerce & Products
Direct-to-consumer and B2B online storefronts, digital product downloads, checkout gateways, and fulfillment pipelines.
Digital Agency & Consulting
Client design, engineering, marketing consultations, project deliverables, commercial contracts, and B2B communications.
Mobile Apps (iOS & Android)
Native applications distributed via the Apple App Store and Google Play Store, including device integrations and in-app features.
Regulatory & App Marketplace Governance:
This comprehensive policy satisfies the stringent requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the EU General Data Protection Regulation (EU GDPR), the Privacy and Electronic Communications Regulations (PECR), the California Consumer Privacy Act (CCPA/CPRA), as well as the developer mandates of the Apple App Store Review Guidelines (Guideline 5.1.1 & 5.1.1(v) Account Deletion) and the Google Play Developer Program Policy (User Data & Data Safety).
1. Who We Are (Data Controller)
LVL DIGITAL VENTURES LTD is the data controller responsible for the processing of your personal data under UK and EU data protection laws:
- Company Registration Number: 17436151 (Registered in England and Wales)
- Registered Office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
- Corporate Website: https://lvldigital.co.uk
- Data Protection Officer / Privacy Contact: contact@lvldigital.co.uk
2. Categories of Information We Collect
We collect only the data necessary to provide our services, operate our ventures, fulfill orders, and maintain software reliability. The types of data collected depend on the specific business vertical you engage with:
A. SaaS Platforms & Web Software Applications
- Account Profiles & Authentication: Name, work email address, encrypted authentication credentials, profile avatar, job title, and team workspace assignments.
- Workspace & Application Data: Files, assets, configuration schemas, project parameters, or system prompts uploaded or created within our software tools.
- Usage Analytics & API Logs: Feature interaction metrics, API endpoint call volumes, timestamped action logs, and usage quotas.
B. E-Commerce Storefronts & Digital Product Orders
- Customer & Order Information: Full name, billing address, physical shipping address (for physical merchandise), email address for order notifications, and contact telephone number (for courier dispatch).
- Transaction History: Ordered items, SKUs, order date and time, promotional codes redeemed, and digital license keys generated.
- Customer Support Inquiries: Order tracking tickets, refund requests, sizing/spec inquiries, and customer feedback.
C. Digital Agency Services & Commercial Client Engagements
- Client & Stakeholder Data: Business contact details (name, corporate email, phone number, company name, registered business address).
- Project & Contractual Information: Creative briefs, engineering specifications, non-disclosure agreements (NDAs), statement of work (SOW) documents, invoicing records, and project feedback.
- Collaborative Communications: Communications exchanged via email, video conference platforms, or project management boards.
D. Mobile Applications (iOS & Android)
- Device Identifiers & System Metadata: Operating system version (iOS, iPadOS, Android), hardware model, pseudonymous installation identifiers (e.g., Apple IDFV or Android App Set ID), IP address, locale, language preference, and time zone.
- Application Performance & Diagnostics: Crash logs, stack traces, latency benchmarks, memory diagnostics, and feature engagement logs collected pseudonymously to detect bugs and maintain system stability.
E. Mobile Device Permissions (Optional & User-Controlled)
Certain mobile features require explicit operating system permissions. You retain full control to enable, modify, or revoke permissions at any time in your device's native Settings:
- Push Notifications: Used strictly to transmit transactional notices, critical account alerts, or user-enabled product notifications via Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM).
- Camera & Photo Library: Only requested if an app explicitly requires media upload, avatar personalization, or visual scanning. Media is processed strictly for the requested in-app feature and never shared with third parties.
- Biometric Authentication (Face ID, Touch ID, Android Biometrics): Where supported, biometric unlocking is handled 100% locally by your device’s hardware secure enclave. Biometric data is never transmitted to, accessed by, or stored on LVL servers.
F. Corporate Website & General Inquiries
- Contact Inquiries: Name, email address, message body, and IP address submitted through contact forms on
lvldigital.co.uk. - Standard Server Logs: Standard HTTP server telemetry including browser user-agent, referring URL, requesting IP address, and request timestamps.
3. Payments & Financial Information
We maintain strict security separation for all commercial payment transactions across our web, e-commerce, SaaS, and mobile channels:
- Web, SaaS & E-Commerce Transactions: Payments made on our websites and SaaS platforms are processed securely by Tier-1, PCI-DSS Level 1 certified processors (including Stripe, PayPal, and Shopify Payments). LVL Digital Ventures Ltd never collects, processes, or stores your full credit/debit card numbers or security CVV codes. We only receive encrypted payment tokens, masked card digits (e.g., last 4), and settlement receipts.
- Mobile In-App Purchases & Subscriptions: In-app purchases, digital unlocks, and mobile subscriptions in our iOS and Android applications are handled exclusively through Apple Inc. (App Store In-App Purchases) or Google LLC (Google Play In-App Billing). We receive only pseudonymous purchase receipts and entitlement tokens to activate your purchase.
4. Lawful Bases for Processing (UK & EU GDPR)
We process personal data only when an established lawful basis exists under Article 6 of the UK GDPR and EU GDPR:
- Performance of a Contract (Art. 6(1)(b)): To deliver SaaS services, fulfill e-commerce orders, dispatch physical products, execute agency consulting deliverables, manage client contracts, and operate mobile applications.
- Legitimate Interests (Art. 6(1)(f)): To safeguard infrastructure security, detect and prevent fraud, optimize app and website performance, diagnose software crashes, and administer commercial relationships.
- Legal Obligation (Art. 6(1)(c)): To comply with statutory UK corporate tax accounting (HMRC), VAT regulations, company filings, and lawful regulatory directives.
- Consent (Art. 6(1)(a)): For optional mobile push notifications, non-essential cookies, or opt-in marketing newsletters. Consent may be withdrawn at any time.
5. Zero Sale of Data & Tracking Safeguards
- Zero Data Brokerage: We do not sell, rent, lease, trade, or commercialize your personal information to third parties, data brokers, or advertising networks under any circumstances.
- Apple App Tracking Transparency (ATT): In strict compliance with Apple guidelines, our mobile apps do not track you across third-party websites or apps for targeted advertising without your explicit affirmative opt-in consent.
- Direct Marketing & Unsubscribe: We send promotional updates only with your prior consent or legitimate commercial relationship in accordance with the UK PECR and US CAN-SPAM Act. Every marketing communication contains a clear, one-click unsubscribe mechanism.
6. Third-Party Infrastructure & Sub-processors
We work exclusively with vetted enterprise infrastructure providers bound by rigorous Data Processing Agreements (DPAs) and industry security certifications (SOC 2 Type II, ISO 27001):
- Cloud Hosting & Server Infrastructure: Amazon Web Services (AWS), Cloudflare, Supabase, and Vercel (providing enterprise encrypted hosting, global edge routing, and secure databases).
- Payment & Billing Processors: Stripe, PayPal, Shopify Payments, Apple In-App Purchases, and Google Play In-App Billing.
- E-Commerce Logistics & Dispatch: Shopify, Royal Mail, DPD, DHL, or partner courier APIs strictly for order delivery fulfillment.
- Application Diagnostics & Telemetry: Sentry and Google Firebase (configured with IP anonymization for software stability and crash diagnostics).
7. Account & Personal Data Deletion Requests
We provide comprehensive data autonomy across all our digital products, ensuring strict compliance with Apple App Store Guideline 5.1.1(v) and the Google Play Data Deletion Policy:
Universal Account & Data Deletion Instructions:
1. In-App Mobile Account Deletion: Within any LVL mobile application supporting account creation, you can delete your account directly inside the app by going to Settings > Account > Delete Account. This permanently removes your credentials and associated application data.
2. SaaS & Web Platform Deletion: In our SaaS platforms, workspace administrators or individual account holders can initiate complete profile and workspace deletion via the Account / Organization Settings dashboard.
3. Direct Email Deletion Request: You can submit an omnibus deletion request across any of our services (SaaS, e-commerce records, agency contacts, mobile apps) at any time by emailing our Data Protection Team at contact@lvldigital.co.uk with the subject "Data Deletion Request".
4. Processing & Verification: Verified deletion requests are executed across our active production systems within 30 days. Where applicable, statutory financial and tax transaction records (such as completed e-commerce sales receipts) are retained strictly as required by UK tax law (HMRC statutory retention) and then automatically purged.
8. Children’s Privacy Protection (COPPA, GDPR-K, Google Play Families)
Our platforms, digital products, e-commerce storefronts, agency services, and mobile applications are directed at general audiences and professionals. We do not knowingly collect, solicit, or maintain personal information from children under the age of 13 (or under 16 for residents of the UK and European Economic Area). If we learn that personal data of a child has been collected without verified parental consent, we take immediate action to permanently erase the information. Parents or guardians may direct inquiries or deletion requests to contact@lvldigital.co.uk.
9. Your Statutory Rights (UK GDPR, EU GDPR & CCPA/CPRA)
Under applicable international data protection legislation, you hold specific enforceable rights:
- Right of Access: Request confirmation of whether we process your data and receive a readable copy.
- Right to Rectification: Request correction of inaccurate, outdated, or incomplete personal data.
- Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your personal data across all LVL systems.
- Right to Restrict Processing: Request temporary or permanent limitation on the processing of your data.
- Right to Data Portability: Obtain your personal data in a structured, commonly used, and machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing at any time.
- Right to Withdraw Consent: Withdraw previously granted consent without affecting lawful prior processing.
- Non-Discrimination: We will never discriminate against you (in pricing, service quality, or availability) for exercising your privacy rights.
To exercise any statutory right, contact our team at contact@lvldigital.co.uk. We respond to all verified requests within 30 days without charge.
10. Data Security & Encryption Standards
We deploy rigorous technical, operational, and physical controls to safeguard your data against unauthorized access, loss, or alteration:
- Encryption in Transit: All data transmitted between your device and our web servers, SaaS APIs, and mobile backends is encrypted using TLS 1.3.
- Encryption at Rest: Database tables, customer files, and server backups are encrypted using AES-256 standard encryption.
- Access Controls: Production data is accessible only by authorized personnel bound by confidentiality agreements, enforced through multi-factor authentication (MFA) and least-privilege role-based access.
11. International Data Transfers
Where personal data is transferred or hosted outside the United Kingdom or the European Economic Area (EEA), we ensure appropriate safeguards are implemented. Transfers are governed by the UK International Data Transfer Agreement (IDTA), the UK Addendum, or the European Commission’s Standard Contractual Clauses (SCCs), guaranteeing that recipient entities uphold equivalent data protection levels.
12. Data Retention Schedules
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected:
- SaaS & Mobile Accounts: Retained for the duration of your active account, and permanently purged within 30 days following an account deletion request.
- E-Commerce & Commercial Transaction Records: Retained for up to 6 years following transaction completion to satisfy UK HMRC statutory accounting, VAT, and corporate tax compliance.
- Agency Client Deliverables & Inquiries: Inquiries without contract execution are purged after 12 months; active client records are maintained for the contract lifecycle plus any statutory liability limitation period.
13. Product-Specific Terms & Ancillary Notices
Individual digital products, specialized SaaS platforms (such as LVEL), or specific mobile applications developed by LVL Digital Ventures Ltd may display supplemental in-product terms or documentation detailing feature-specific data flows. Any such notices supplement and operate alongside this overarching Master Privacy Policy.
14. Changes to This Master Privacy Policy
We may periodically update this Master Privacy Policy to reflect technological improvements, new product launches across our venture studio, or regulatory changes. Any modifications will be posted to this page with an updated Effective Date. For material changes impacting active mobile app or SaaS users, we will provide conspicuous notice via in-app alerts, dashboard banners, or direct email notifications.
15. Contact Us & Regulatory Supervision
If you have any questions, concerns, or requests regarding this Master Privacy Policy or our data protection practices, please contact our Data Protection Team:
- Company: LVL DIGITAL VENTURES LTD (Company No. 17436151)
- Email: contact@lvldigital.co.uk
- Registered Office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
If you are a resident of the United Kingdom and believe your personal data has not been processed in accordance with the law, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.