Privacy Policy

Last updated: June 6, 2026

1. Overview

Lugano Automation ("we," "us," or "our") provides AI-powered lead follow-up software for automotive dealerships. This Privacy Policy explains how we collect, use, and protect information in connection with our Service at luganoautomation.com and app.luganoautomation.com.

2. Information We Collect

Information you provide directly:

  • Account information: Name, email address, password when you register
  • Dealership information: Business name, phone number, website URLs
  • Lead data: Customer names, email addresses, phone numbers, vehicle interests, and notes that you enter into the Service
  • Payment information: Processed by our payment provider; we do not store full card numbers

Information collected automatically:

  • Usage data: Pages visited, features used, actions taken within the Service
  • Log data: IP addresses, browser type, timestamps
  • Email interaction data: Whether emails sent through the Service were opened or replied to (where trackable)

Information from third parties:

  • Gmail / Outlook: If you connect your inbox, we access email metadata to detect customer replies and stop follow-up sequences. We read only the minimum necessary data and do not store email body content beyond what you explicitly authorize
  • Scheduling tools: If you connect Calendly or Acuity, we receive appointment booking data

3. How We Use Information

  • Providing and operating the Service
  • Sending automated follow-up emails on behalf of your dealership
  • Monitoring connected email inboxes for customer replies (with your authorization)
  • Generating AI-assisted email content using third-party AI providers
  • Sending you service updates, security notices, and support communications
  • Improving the Service and developing new features
  • Complying with legal obligations

We do not sell your data or your customers' data to third parties. We do not use your Customer Data to train AI models without your explicit consent.

4. Data Sharing

We share data only with:

  • Supabase — database and authentication infrastructure
  • Resend — email delivery service
  • Anthropic — AI provider for email content generation (prompt data is sent; we do not share customer PII beyond what is necessary for generation)
  • Google / Microsoft — only when you authorize Gmail or Outlook connection
  • Vercel — hosting infrastructure
  • Law enforcement or legal process — when required by law

5. Data Retention

We retain your account data and Customer Data for as long as your account is active. After termination, we retain data for up to 90 days before deletion, unless a longer period is required by law or you request earlier deletion.

Email logs and usage records may be retained for up to 12 months for billing and dispute resolution purposes.

6. Security

We implement industry-standard security measures including:

  • Encryption in transit (HTTPS/TLS) and at rest
  • Row-level security on all database tables
  • Access controls limiting employee access to Customer Data
  • OAuth tokens stored securely, not in plain text

No method of transmission over the internet is 100% secure. We will notify you of any breach affecting your data as required by law.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and data
  • Export your Customer Data
  • Disconnect third-party integrations (Gmail, Outlook, etc.) at any time

To exercise these rights, contact us at support@luganoautomation.com.

8. Your Customers' Data

You are the data controller for the customer information you enter into the Service. You are responsible for ensuring your collection and use of that data complies with all applicable privacy laws, including obtaining any required consents before sending automated email communications.

Every email sent through the Service includes an unsubscribe link. When a customer unsubscribes, the Service automatically stops all further email sequences to that customer.

9. Cookies

The Service uses essential cookies for authentication and session management. We do not use third-party tracking or advertising cookies. The landing page at luganoautomation.com does not use analytics tracking by default.

10. Children

The Service is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us at support@luganoautomation.com.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or a notice within the Service at least 7 days before the change takes effect.

12. Contact

For privacy questions or requests:
Lugano Automation
Email: support@luganoautomation.com