Privacy Policy

Last updated: 25 June 2025

Welcome to Lettice ( https://lettice.uk ), a collection of casual word-games published under the Lighthouse Labs brand of Lighthouse Policy Design Ltd("we", "us", "our"). Your privacy matters; this notice explains what personal data we collect, why we collect it, and the choices you have.


1. Who we are

  • Controller: Lighthouse Policy Design Ltd
  • Brand: Lighthouse Labs (games)
  • Contact: support@lettice.uk

2. The data we collect

Account creation & sign-in

  • Email address (for email + password users)
  • Display name and avatar (if provided by Google, Apple, Facebook or LinkedIn)
  • Provider-specific user ID

Gameplay

  • Puzzle attempts, moves, scores and streaks
  • Device/browser information (to sync progress and debug issues)

Payments

  • Billing email and Stripe payment token (we never see full card details)

Site analytics & ads

  • IP-derived country/region
  • Pages visited, time on site, ad impressions/clicks

Support requests

  • Any information you choose to share in emails

3. How we use your data

  1. Run the game – authenticate you, sync progress across devices, show leader-boards.
  2. Improve features – analyse aggregated usage to balance puzzles and fix bugs.
  3. Service & marketing emails – send password resets, receipts, release notes (you can opt out of marketing).
  4. Ads (free tier only) – personalise and measure adverts via Google AdSense unless you subscribe to the ad-free tier or opt out.
  5. Legal & safety – prevent fraud, enforce our Terms and comply with UK law.

4. Legal bases (UK GDPR & DPA 2018)

  • Contract: providing the game you requested
  • Legitimate interests: analytics, limited personalisation, security
  • Consent: marketing emails and non-essential cookies
  • Legal obligation: accounting, tax and fraud-prevention records

5. How long we keep it

  • Game logs: while your account is active; deleted after 24 months of inactivity
  • Payment records: 7 years (HMRC requirement)
  • Aggregated, anonymised statistics may be kept indefinitely

6. Sharing & processors

We use a small number of trusted service providers:

  • Supabase (EU) – authentication, database and file storage
  • Resend (US) – transactional email delivery
  • Stripe (EU/US) – payment processing (PCI-DSS compliant)
  • Google AdSense (EU/US) – advertising
  • Vercel Analytics (US) – site analytics and performance monitoring

Transfers outside the UK/EEA rely on Standard Contractual Clauses plus the UK International Data Transfer Addendum. We do not sell your data.


7. International transfers

Where data leaves the UK/EEA (e.g., to the US), we rely on the safeguards mentioned above.


8. Your rights

You may at any time: access, correct, erase, restrict, object, port your data, or withdraw consent. Email admin@lighthousepolicydesign.co.uk. Unresolved concerns? Complain to the UK ICO.


9. Children

Lettice is not directed at children under 13. If we learn we've collected data from a child, we will delete it promptly.


10. Security

All traffic is HTTPS-encrypted; credentials are salted & hashed. Production data access is limited to vetted staff using MFA.


11. Changes to this notice

We'll post updates here and email registered users if changes are significant. Continued use after the effective date means you accept the updated policy.


Questions? Drop us a line at support@lettice.uk – we're happy to help.

Back to home