Privacy Policy
Last Updated: May 19, 2026
This Privacy Notice for Ghostlemon ("we", "us", or "our") describes how and why we may access, collect, store, use, and/or share ("process") your personal information when you use our Services, including when you visit our website, create an account, or engage with us in sales, marketing, or events.
Summary of Key Points
- We only collect information necessary to deliver the Service (account, prospecting, billing).
- We do not process sensitive personal information as defined by the GDPR.
- We do not sell your data and only share it with subprocessors required to operate the Service.
- Your GDPR rights (access, rectification, deletion, objection, portability, restriction) are guaranteed.
- To exercise these rights, contact us at support@ghostlemon.com.
1. What Information Do We Collect?
Personal Information You Disclose To Us
We collect personal information that you voluntarily provide to us when you register on the Services, express interest in our products and Services, or when you contact us. This information may include:
- Names and email addresses
- Social media account information provided via third-party authentication (e.g. Google)
- Profile and post data associated with the accounts you connect to Ghostlemon (e.g. via Unipile)
- Payment information securely processed by Stripe
We do not process sensitive information. All personal information you provide must be true, complete, and accurate.
Information Automatically Collected
Some information — such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, and usage data — is collected automatically for security, operations, and internal analytics. This includes:
- Log and Usage Data
- Device Data (model, configuration, technical identifiers)
- Location Data (derived from your IP address)
2. How Do We Process Your Information?
We process your information to:
- Create and manage your account
- Provide, operate, and improve the Service (including your prospecting automations, sequences, and leads)
- Process payments and manage subscriptions via Stripe
- Send you service or support communications
- Prevent fraud and protect platform security
- Comply with our legal and regulatory obligations
3. Legal Bases for Processing (GDPR)
In accordance with the General Data Protection Regulation (GDPR), we process your information on the following legal bases:
- Contract performance: to deliver the Service you signed up for
- Consent: for processing where you have given us permission (revocable at any time)
- Legitimate interests: for security, fraud prevention, or service improvement
- Legal obligations: to meet accounting, tax, and regulatory duties
4. When And With Whom Do We Share Your Information?
We do not sell your data. We only share it with contractually-bound subprocessors that are necessary to operate the Service:
- Supabase (database hosting and authentication)
- Vercel (web app hosting)
- Stripe (payment processing)
- Unipile (technical connection to third-party platforms, including professional and social networks)
- Resend & Loops.so (transactional and marketing emails)
- Anthropic & OpenAI (AI models for post generation and ICP scoring)
- PostHog (internal product analytics)
We may share or transfer your information in connection with a merger, sale of company assets, financing, or acquisition.
5. Do We Use Cookies and Tracking Technologies?
We use cookies and similar tracking technologies to secure your session, remember preferences, measure usage, and support core functionality. You can configure your browser to reject some or all cookies. Some analytics cookies can be opted out of via the provider (e.g. https://tools.google.com/dlpage/gaoptout for Google Analytics).
6. How Do We Handle Your Social Logins?
If you register or log in using a third-party social media account (e.g. Google), we receive certain profile information from that provider (name, email, profile picture). We only use this information for the purposes described in this Privacy Notice. We do not control any other uses of your personal information by your third-party provider — please review their privacy policy.
7. How Long Do We Keep Your Information?
We retain your personal information only as long as necessary to fulfill the purposes set out in this Privacy Notice, unless a longer retention period is required by law (notably accounting and tax obligations). Account data is deleted or anonymized upon your request or when your account is closed.
8. How Do We Keep Your Information Safe?
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS) and at rest
- Secure authentication and access management
- Regular security audits and updates
However, no electronic transmission or storage technology can be guaranteed to be 100% secure; you acknowledge the residual risks involved in using the Service.
9. Do We Collect Information From Minors?
We do not knowingly collect data from, or market to, individuals under the age of 18. If you become aware of any data we may have collected from a minor, please contact us so we can delete it.
10. Your Privacy Rights
Under the GDPR and French data protection rules, you have the following rights:
- Right of access to your data and to receive a copy
- Right to rectification
- Right to erasure (the "right to be forgotten")
- Right to restrict processing
- Right to object
- Right to data portability
- Right to withdraw consent at any time
- Right to define post-mortem instructions for your data
To exercise these rights, contact us at support@ghostlemon.com. If you believe your rights are not respected, you can lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris.
11. Do-Not-Track Signals
No uniform technology standard for recognizing and implementing Do-Not-Track signals has been finalized. We do not currently respond to DNT browser signals or any other equivalent mechanism. If an industry standard is adopted, we will update this Privacy Notice accordingly.
12. Updates to This Notice
We may update this Privacy Notice from time to time to remain compliant with applicable laws. The updated version will be indicated by a revised date at the top of this document. For material changes, we may notify you directly or via a banner on the site.
13. Third-Party Trademarks and Connected Platforms
Ghostlemon allows you to connect the Service to various third-party professional and social platforms. LinkedIn is a registered trademark of LinkedIn Corporation. Ghostlemon is not affiliated with, endorsed by, or officially connected to LinkedIn or any other third-party platform referenced on this site. Trademarks, service marks, and logos associated with those platforms remain the property of their respective holders and are used for identification purposes only.
14. Contact Us
For any question regarding this Privacy Notice or to exercise your rights, contact us at:
Email : support@ghostlemon.com