Legal · v0.1 · last updated 03 May 2026

Privacy policy.

Limelight is built and operated by Limelight Pty Ltd in Sydney, Australia. This page is a plain-language summary; see your DPA for the contractual terms.

What we collect

  • Account details (your email, business name, vertical).
  • Customer records pulled from connected tools (Cliniko, ServiceM8): names, phone numbers, appointment / job metadata, marketing-consent flags.
  • Reviews and replies from Google Business Profile and ProductReview.com.au.
  • Outbound SMS metadata (delivery status, cost, opt-outs).

Where it lives

AWS ap-southeast-2 (Sydney). Encrypted at rest. Integration credentials sealed with AES-256-GCM.

What we don't do

  • We don’t sell your data, ever.
  • We don’t train AI models on your reviews or replies.
  • We don’t expose photos with detected people on any public surface.
  • We don’t route negative reviews away from public platforms.

Your rights (Privacy Act 1988)

Access, correction, deletion. Email privacy@findlimelight.com and we respond within 30 days.

Subprocessors

  • AWS (Sydney) — data hosting
  • Supabase (AU region) — auth + Postgres
  • Vercel — application hosting
  • Cellcast / ClickSend — SMS delivery (AU-owned)
  • Resend — transactional email
  • Anthropic — AI reply generation
  • OpenAI — text embeddings only (voice match)
  • Stripe — billing