Privacy Policy
Last updated 1 August 2026
LFG Ventures LLC (“LFG,” “we,” “us”) builds software and websites for businesses and operates the platform products We Know Restaurants, We Know Salons, and Local Site. This policy explains what we collect, why, and what you can do about it.
It covers lfgventures.io and the services we run. It does not cover the sites of businesses we build for — when you use a client’s website or booking page, that business decides how your information is used, and section 06 explains our role there.
01Information we collect
You give us
- Contact details — name, email, phone, business name — from our contact form, booking flow, or email
- Account information if you have a client portal login, including a securely hashed password
- Project material you send us: content, photos, brand assets, and business documents
- Billing details. Card numbers go directly to our payment processor; we never see or store them.
- Anything you write to us in a message, ticket, or booking note
Collected automatically
- IP address, browser and device type, pages viewed, and referring site
- Approximate location derived from IP, at city level
- Dates and times of logins and key actions in the portal, for security and support
We don’t buy personal information from data brokers, and we don’t run advertising trackers that follow you across other websites.
02How we use it
- To reply to enquiries and schedule calls
- To deliver, host, support, and improve the services you’ve engaged us for
- To bill you and keep financial records
- To send service messages — outages, changes, renewals, security notices
- To send occasional updates about our work, which you can unsubscribe from at any time
- To detect and prevent fraud, abuse, and security incidents
- To meet legal and tax obligations
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
03When we share it
We share information only in these situations:
- Service providers who run parts of our infrastructure under contract — hosting, database, email delivery, payments, scheduling, and analytics. They may only use it to provide their service to us.
- Professional advisers such as accountants and lawyers, where needed.
- Legal requirements — where we’re required by law, or to protect rights, safety, or property.
- Business transfer — if LFG is involved in a merger, acquisition, or sale of assets, with notice to you.
Our current providers include Supabase (database and file storage), Render (hosting), Square (payments), and Resend (email delivery). We’ll keep this list current as it changes.
04Cookies and analytics
We use a small number of cookies: ones required to keep you signed in and secure, and basic analytics to understand which pages get used. Session cookies are HTTP-only and expire.
You can block or delete cookies in your browser. Blocking the essential ones will break sign-in. We honour Global Privacy Control signals where your browser sends them.
05How long we keep it
- Enquiries that don’t become projects — up to 24 months, then deleted
- Client account and project data — for the life of the engagement and 12 months after, unless you ask us to delete it sooner
- Billing and tax records — seven years, as required
- Server and security logs — typically 90 days
When you end an engagement, we’ll provide an export of your data for 30 days before deletion begins.
06Data we handle for our clients
When we build and host a site or platform for a business, that business’s customers may give it personal information — a reservation, a booking, an order, a quote request. In that relationship the business is the controller of that data and LFG is the processor. We handle it on their instructions, we don’t use it for our own purposes, and we don’t sell it.
If you’re a customer of one of our clients and want your information accessed or deleted, contact that business directly. If you reach us instead, we’ll pass the request to them.
07Security
We take security seriously as a matter of engineering practice, not policy language:
- Encryption in transit (TLS) on every service we operate
- Passwords stored as bcrypt hashes, never in readable form
- Database access restricted to server-side code with authorization checked before every query
- Private file storage, served through short-lived signed links behind an access check
- Rate limiting on sign-in and other sensitive endpoints
No system is perfectly secure. If a breach affects your personal information, we’ll notify you and any required authority without undue delay.
08Your rights
Depending on where you live, you may have the right to:
- Know what personal information we hold and get a copy
- Correct information that’s wrong
- Delete information, subject to records we must legally keep
- Opt out of marketing email — every message has an unsubscribe link
- Object to or restrict certain processing
- Receive your data in a portable format
Email tony@lfgventures.io and we’ll respond within 30 days. We won’t discriminate against you for exercising any of these rights.
09Children
Our services are for businesses and aren’t directed at children under 13. We don’t knowingly collect their information. If you believe a child has given us personal information, contact us and we’ll delete it.
10International visitors
We operate in the United States and our providers process data there. If you’re outside the US, using our services means your information is transferred to and processed in the US, where privacy laws may differ from your own.
11Links to other sites
Our site links to sites we’ve built and to third-party tools. We aren’t responsible for their privacy practices, and we’d encourage reading their policies.
12Changes to this policy
We may update this policy. The date at the top always reflects the current version, and we’ll give notice by email or a site notice before any material change takes effect.
13Contact
Questions, requests, or complaints about privacy:
LFG Ventures LLC
New Jersey, United States