Legal

Privacy Policy

Effective 15 September 2026 · Version 2026-09-15

This Privacy Policy explains how Zachary Tyler Lehmann trading as LTNA (ABN 80 226 912 105) (“LTNA”, “we”, “us”) collects, uses, shares and protects personal information when you use LTNA Hosting, including ltnahosting.com, the dashboard, and the LTNA account you sign in with.

It is written to meet the Australian Privacy Principles in the Privacy Act 1988 and, where they apply, the EU and UK General Data Protection Regulation and US state privacy laws.

In short: we collect what we need to run your account and projects. We don’t sell personal information or use it for advertising, and our own site uses no third-party trackers. Your data is stored in Australia, and some of our providers process it overseas.

1. Who we are

Zachary Tyler Lehmann trading as LTNA (ABN 80 226 912 105), an Australian sole trader based in Victoria, operates LTNA Hosting and is responsible for your personal information under this policy. Contact us about privacy at [email protected].

2. What this policy covers

This policy covers people who use LTNA Hosting: account holders, people they give access to, and people who contact us.

It does not cover visitors to websites our customers host on LTNA Hosting. Each customer is responsible for their own site’s privacy practices, and we process their visitors’ information on the customer’s behalf under our Data Processing Addendum. If you visited a site hosted on LTNA and have a question about your information, contact that site’s owner.

Other LTNA products, such as LTNA Hub and LTNA Mail, are not covered by this policy.

3. Information we collect

Information you give us

  • Account details: your name, email address and user identifier from the LTNA account you sign in with.
  • Billing details: your name, email, billing address and payment information, which Stripe collects and processes. We don’t receive or store full card numbers.
  • Project information: repository links, project settings, build and start commands, custom domains, firewall rules and outbound allowlists.
  • Secrets: environment variables and database connection strings you add, which may contain personal information.
  • Communications: messages you send us for support or other reasons.

Information we collect automatically

  • Activity: deployments, build and runtime logs, notifications, and a record of actions taken in your account.
  • Technical information: IP address, browser type and request details when you use the dashboard, processed by our servers and by Cloudflare to deliver and protect the site.
  • Terms acceptance: which version of our Terms of Service and this policy you accepted, and when.
  • Cookies: only those strictly necessary to sign you in and keep your session secure, as described in our Cookie Policy.

Information from services you connect

When you connect an integration, we receive information from that provider:

  • GitHub: your GitHub account name, the installation identifier, and access to the repositories you choose, so we can build and deploy them.
  • Cloudflare: an access token for the zone you authorise, the zone name and your Cloudflare account email, so we can manage DNS records on your instructions.
  • Supabase: an access token for your Supabase organisation, and the projects it can manage.
  • Firebase: a read-only access token for your Firebase projects, and your Google account email.
  • Google Analytics and Google Search Console: a read-only access token.
  • Bing Webmaster Tools: a read-only access token.

4. How we use your information

PurposeInformation usedLegal basis where GDPR applies
Provide the Services: sign you in, build and run your projects, and show logs, analytics and performance dataAccount, project, activity, technical and connected-service informationPerforming our contract with you
Operate the integrations you connectConnected-service informationPerforming our contract; your consent when you connect
Bill you and manage your subscriptionAccount and billing detailsPerforming our contract; legal obligations
Keep the Services secure, prevent abuse and enforce our termsAccount, activity and technical information, and logsLegitimate interests in protecting LTNA, our customers and the public
Provide support and send service messagesAccount details and communicationsPerforming our contract; legitimate interests
Comply with the law and respond to lawful requestsAny information neededLegal obligations
Improve the ServicesAggregated activity informationLegitimate interests in improving our product

We don’t sell personal information, share it for targeted advertising, or use it to train machine learning models.

We send marketing emails only if you have agreed to receive them, and every marketing email lets you unsubscribe.

5. Connected Google accounts

If you connect Google Analytics or Google Search Console, we request read-only access and use it only to show your own reports inside your LTNA dashboard.

We store only the OAuth tokens needed to keep the connection working. Reports are fetched from Google when you open the page and are not stored, copied, sold, shared with third parties, used for advertising, or used to train any model. Because the data is not stored, it is not available for LTNA staff to read.

LTNA’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google at any time from Account Settings or the Analytics tab, which removes our stored tokens and revokes our access. You can also revoke access yourself at myaccount.google.com/permissions.

6. Connected Supabase projects

If you connect Supabase, you can manage your Supabase projects from the LTNA dashboard, including running SQL and managing users, files, extensions and functions. These actions run on your instructions against your own project.

To do this we use your access token, and fetch your project’s service key only at the moment it is needed. We never store the service key or send it to your browser.

Information from your Supabase project that appears in the dashboard is shown to you and not stored by LTNA, except where you choose to import connection details into your project’s environment variables.

7. Analytics

Our own website and dashboard don’t use third-party analytics or advertising trackers.

The website analytics LTNA provides to customers don’t use cookies. We count unique visitors using a one-way hash of the visitor’s IP address and browser details, which is held in memory for a few hours and never stored. Stored analytics contain only aggregated counts, such as page views by page, referrer, country and device.

8. How we share information

We share personal information only in these cases:

  • Service providers who help us run LTNA Hosting, listed on our Sub-processors page, under obligations to protect it.
  • Services you connect, when you ask us to act on them.
  • Legal and safety reasons, where we reasonably believe the law, a court order or a lawful government request requires it, or it is needed to protect people, prevent fraud or abuse, or enforce our terms.
  • Business changes, if our business is incorporated, sold or restructured, to the new owner or entity, which must protect it under this policy.
  • With your consent, in any other case.

9. Where your information is stored and sent

We store account and project information in Australia, with our database provider in Sydney, and run your builds and applications on our own servers in Victoria.

Some information is disclosed to recipients overseas:

  • United States: Stripe, GitHub, Google and Microsoft, when you pay us or connect those services.
  • Malaysia: a hosting provider whose server runs the edge that receives traffic to customers’ root domains.
  • Worldwide: Cloudflare, whose network delivers and protects our site and customer sites from locations around the world.

Where the GDPR or UK GDPR applies, we rely on appropriate safeguards for these transfers, such as standard contractual clauses or the provider’s certification under a recognised data transfer framework.

10. How long we keep information

InformationHow long we keep it
Account details and terms acceptance recordsWhile your account is open, then removed within 30 days of closure unless the law requires us to keep them
Projects, domains, settings, environment variables and connected-service credentialsUntil you remove them or close your account
Build logs30 days
Runtime logs from your applications7 days
Build workspaces holding your source code7 days
Uptime checks90 days
Deployment history, notifications, account activity records, analytics and performance dataWhile your account is open
Billing recordsAs long as tax and accounting laws require, generally five years
Support communicationsUp to two years after the conversation ends

When information is no longer needed, we remove it or make it anonymous.

11. How we protect information

We protect personal information with measures including:

  • encryption of secrets and connected-service credentials in a managed vault;
  • encryption in transit between your browser, our edge and our servers;
  • access controls so each account can reach only its own records;
  • isolated containers with restricted privileges and network controls for customer workloads; and
  • rate limiting, activity logging and restricted administrative access.

No system is completely secure, and we can’t guarantee the security of information sent over the internet.

12. Data breaches

If a data breach is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. We follow that scheme even where the Privacy Act’s small business exemption might apply to us. Where the GDPR or UK GDPR applies, we notify the relevant supervisory authority within 72 hours where feasible.

13. Your choices and rights

You can ask us to:

  • give you access to the personal information we hold about you, and a copy in a portable format;
  • correct information that is inaccurate or out of date;
  • remove your information, subject to what the law requires us to keep;
  • restrict or object to certain uses of it; and
  • stop processing that relies on your consent, for example by disconnecting an integration. This doesn’t affect processing that happened before.

Email [email protected] to make a request. We will confirm your identity, respond within 30 days, and won’t charge a fee unless a request is clearly excessive. If we refuse a request, we will explain why.

European Economic Area and United Kingdom. You have the rights above under the GDPR and UK GDPR, and the right to complain to your local data protection authority.

United States. Depending on your state, you may have rights to know, access, correct and remove your personal information, and to opt out of its sale, its sharing for targeted advertising, or profiling. We don’t sell or share personal information for those purposes, and we won’t discriminate against you for exercising your rights.

14. Complaints

If you have a concern about how we handle your personal information, contact us first at [email protected]. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner, or to your local data protection authority if you are in the EU or UK.

15. Children

LTNA Hosting is not intended for anyone under 18, and we don’t knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will remove it.

16. Changes to this policy

We may update this policy. For material changes we will tell you by email or in the dashboard before they take effect, and ask you to review the updated policy the next time you use the dashboard. The version and effective date are shown at the top of this page.

17. Contact

Zachary Tyler Lehmann trading as LTNA (ABN 80 226 912 105), Victoria, Australia.

This is version 2026-09-15. Earlier versions are available on request from [email protected].