Legal · v0.1 · last updated 03 May 2026
Privacy policy.
Limelight is built and operated by Limelight Pty Ltd in Sydney, Australia. This page is a plain-language summary; see your DPA for the contractual terms.
What we collect
- Account details (your email, business name, vertical).
- Customer records pulled from connected tools (Cliniko, ServiceM8): names, phone numbers, appointment / job metadata, marketing-consent flags.
- Reviews and replies from Google Business Profile and ProductReview.com.au.
- Outbound SMS metadata (delivery status, cost, opt-outs).
Where it lives
AWS ap-southeast-2 (Sydney). Encrypted at rest. Integration credentials sealed with AES-256-GCM.
What we don't do
- We don’t sell your data, ever.
- We don’t train AI models on your reviews or replies.
- We don’t expose photos with detected people on any public surface.
- We don’t route negative reviews away from public platforms.
Your rights (Privacy Act 1988)
Access, correction, deletion. Email privacy@findlimelight.com and we respond within 30 days.
Subprocessors
- AWS (Sydney) — data hosting
- Supabase (AU region) — auth + Postgres
- Vercel — application hosting
- Cellcast / ClickSend — SMS delivery (AU-owned)
- Resend — transactional email
- Anthropic — AI reply generation
- OpenAI — text embeddings only (voice match)
- Stripe — billing