Privacy
Use the minimum. Keep authority clear.
This policy describes the Runlight website, private owner app, customer-safe app, and plugin workflows. Runlight separates owner-private business context from customer-visible published information.
Information Runlight handles
Runlight may handle account identity, owner-authorized business context, approved workflow state, support correspondence, and technical security logs. Customer-safe workflows use owner-published business facts and minimize customer information.
Do not provide passwords, provider credentials, payment-card details, private messages, customer exports, or client photos unless Runlight has explicitly provided an appropriate authorized process.
How information is used
Information is used to provide and secure Runlight, maintain owner-approved business state, answer support requests, understand whether published services and products are being found and where customers encounter friction, and improve reliability. Observed public facts are treated as evidence, not proof of ownership or owner authority.
Customer workflows may record privacy-minimized invocation, intent, business-view, availability, preview, and completed-transaction events. These records use opaque references and bounded categories rather than customer identity, contact details, conversation transcripts, or sensitive intake. They do not automatically change owner-approved services, policies, or permissions.
Sharing and providers
Runlight uses service providers only as needed to operate the service, such as hosting, authentication, and approved connected capabilities. Provider credentials remain server-side. Runlight does not sell personal information.
Retention, export, and deletion
Privacy-minimized customer invocation and intent records are retained for up to 7 days, other privacy-minimized customer activity records for up to 30 days, and owner-visible aggregate trend records for up to 395 days. Authenticated owners can request an export or deletion of Runlight-held owner workspace data. Some minimal security, transaction, idempotency, or deletion-replay records may be retained where necessary for integrity, fraud prevention, or legal requirements.
Your choices
You may ask about access, correction, export, deletion, or withdrawal of consent by emailing hello@runlight.ca. Runlight will verify authority before acting on an account or business record.
Effective August 7, 2026. Questions: hello@runlight.ca