How LANDING AI collects, stores and uses personal data for accounts, published sites and visitors of this platform.
The platform operator is the controller (see company details in settings / contact). We process data to provide the service: accounts, site generation and hosting, leads, payments and support.
For a data request use the contact form. Do not send passwords in tickets or email.
Account: name, email, hashed password, language, registration and login times.
Sites: copy, photos, logo, phone and address you upload or generate; a domain if you connect one.
Leads from your visitors: name, email, phone and the form message.
Technical: IP, user agent, session/CSRF cookies, security logs, daily analytics events with a visitor hash — no third-party ad pixels.
Payments: amount, plan, status, last digits where the processor returns them. We do not store full card numbers, CVC or PIN.
Contract — so the account, site, inbox and paid plan work.
Legitimate interest — security, abuse prevention, product improvement, basic visits without ad profiling.
Legal duty — invoices and bookkeeping where the law requires it.
Consent — only if you opt in to marketing email. You can unsubscribe at any time.
Account and sites: while the profile is active and a short period after closure (usually up to 30 days), unless the law requires longer.
Invoices and payments: typically up to 5 years under Bulgarian accounting rules.
Security logs: usually up to 12 months.
Leads in your inbox: until you keep the site / delete the row, plus a short backup window.
Hosting, SMTP, the payment processor and Cloudflare Workers AI for text generation. They receive only what that request needs.
We do not sell personal data. Public is only what you publish on a site.
When you generate or rewrite, the business description and selected fields go to the AI provider to return a draft. Do not put other people’s personal data in the brief without a basis. You must review generated copy before publish.
Necessary only: login session, language (lai_locale) and CSRF. No marketing cookies from us. Customer-site analytics are first-party events without an ad pixel.
Access, rectification, restriction, portability and erasure (GDPR). Export or delete from the profile. You may complain to the Bulgarian CPDP (KZLD).
For visitors of sites you publish, you are the controller of their leads; we are the processor storing them in your inbox.
Passwords are hashed. HTTPS where the domain is set up. Admin access is limited. No system is perfectly safe — we act under the law if an incident happens.
Material changes update the date above. Continued use means you have seen the new version.
Online · The LANDING AI dog
How was the chat?