// Privacy
Privacy Policy
Last updated August 17, 2026
This policy covers lucive.co and the client portal at lucive.co/portal. It says what we collect, why, who else touches it, and how to make us delete it. It is written to be read, not to be skimmed past.
The Camp app has its own policy, published at camp.lucive.co. This page does not cover it.
Who we are
Lucive LLC, a company registered in North Carolina, United States. We are the ones who decide how the information described here is handled.
Lucive LLC301 S McDowell Street, STE 125-1028
Charlotte, NC 28204
hello@lucive.co
What we collect
Only what a given part of the site needs to work. Nothing is gathered in the background while you read.
When you send an inquiry
The three fields you fill in: your name, your email address, and your message. There are no hidden fields. We do not fingerprint your browser or record what you looked at before you wrote to us.
When you have a portal account
Your email address, and the one-time codes we send to it. Portal accounts are invite-only and passwordless, so there is no password to store. Codes are short-lived and single use.
When you sign a proposal
The name you type, the time you signed, the IP address the signature came from, and the version of the document that was on screen. That record is frozen once written and cannot be edited afterwards, by you or by us. That permanence is the point of it: it is what makes the signature worth anything later.
When you are invoiced or pay
Line items, amounts, dates, and status, plus the confirmation Stripe sends back when a payment succeeds. Card numbers are entered on Stripe's own hosted page and never reach our servers or our database.
When you subscribe to anything we send
Your email address, and only if you asked us for it.
While the site runs
Our host keeps standard server logs. Errors are reported to Sentry so we can fix them, which can include the page you were on and a technical stack trace. Form submissions are rate limited by IP address, and those counters expire within minutes. We also keep an append-only audit log of actions taken inside the admin panel and portal, which records who did what and when.
What we do not collect
- No analytics, no advertising pixels, no session recording, no heatmaps.
- No tracking of you across other websites.
- No personal information bought or received from data brokers.
- No sensitive categories: no health, biometric, precise location, or similar data.
Why we collect it
- To answer you when you write to us.
- To run projects we have been hired for, and to show you their status.
- To send proposals and invoices, and to take payment.
- To keep the site standing: blocking spam and abusive traffic.
- To keep the records that tax, accounting, and contract law require us to keep.
We do not use your information to build a profile of you, and we do not use it to train machine learning models.
Who else handles it
We run a small stack and each piece of it does one job. These are the only companies that process information on our behalf:
- Supabase for the database and account sign-in.
- Vercel for hosting and server logs.
- Resend for the email we send you.
- Stripe for payments, including all card handling.
- Cloudinary for images published on the site.
- Sentry for error reports.
- hCaptcha to keep automated spam off the inquiry form.
- Upstash for the rate-limit counters.
We do not sell personal information, and we do not share it for advertising or any other company's marketing. We will hand information to law enforcement only when a valid legal process requires it.
Cookies
Only the ones the site cannot work without. Signing in to the admin panel or the portal sets a session cookie so the next page knows it is still you. There are no analytics cookies and no advertising cookies on this site today. hCaptcha may set a cookie of its own when a challenge runs on the inquiry form.
If we ever add analytics, this page changes before it ships, and anything requiring consent gets a consent control rather than a quiet switch-on.
How long we keep it
Client records, signed proposals, invoices, and payment records are kept for as long as the working relationship lasts and afterwards for as long as tax, accounting, and contract law require. Inquiries are kept while they are still useful to us. Rate-limit counters expire within minutes. Error reports age out on a short schedule.
We do not run an automatic deletion schedule beyond that. If you want your information gone, ask, and we will delete everything we are not legally required to keep.
How we protect it
- Every table enforces row-level security in the database, so access is checked at the data layer rather than trusted from the application.
- Clients have no direct write access to any table. Every change a client makes goes through a specific, reviewed database function that does one thing.
- Internal accounts require a password plus a time-based one-time code.
- Actions inside the admin panel and portal are written to an append-only audit log.
- Files in the portal are stored in private buckets and served through expiring links.
No system is perfectly secure, and we are not going to claim otherwise. If we ever discover a breach affecting your information, we will tell you.
Your rights
Email hello@lucive.co and you can ask us to show you what we hold about you, correct it, send you a copy, or delete it. We will answer within 30 days. We will not charge you, and we will not treat you differently for asking.
Depending on where you live, including California, Colorado, Connecticut, Virginia, and a number of other states, the law grants you specific versions of those rights. Rather than sort you by state, we apply the same process to everyone who asks. Since we do not sell personal information or share it for targeted advertising, there is no such sale for you to opt out of.
Marketing email carries an unsubscribe link in every message. Unsubscribing does not stop messages you need in order to use the portal, such as sign-in codes and invoices.
Browsers send Do Not Track signals in inconsistent ways and there is no agreed standard for honoring them, so we do not respond to them. We do not track you across sites in the first place.
Children
This is a business site and it is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has sent us something, write to hello@lucive.co and we will delete it.
Where your information is held
Our providers are United States companies and the information is processed in the United States. If you write to us from outside the US, you are sending it here.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects how we handle information belonging to portal clients, we will email them rather than rely on you noticing.
Contact
Questions about this policy, or any request about your information, go to hello@lucive.co, or by post to Lucive LLC, 301 S McDowell Street, STE 125-1028, Charlotte, NC 28204. You can also use the contact form.