Our Privacy Policy | Limecube

Privacy & Security Policy

Limecube take data privacy seriously and recognize your privacy is very important. The purpose of this Policy is inform you as to how we look after your personal data, including simply visiting our website, regardless of where you visit it from, whether you are logged in, or even have an account with Limecube. We have separated our privacy policy in an easy into clear sections and in plain language to make it clear and more user-friendly.

We will never sell your personal data to a third party

We provide this notice to explain our online information policy. To make this notice easy to find, we make it available on every page of our website. This privacy statement explains how data is handled whilst you browse and submit information through the website, and your options regarding the ways in which your data is used.

We provide this notice to explain our online information policy. To make this notice easy to find, we make it available on every page of our website. This privacy statement explains how data is handled whilst you browse and submit information through the website, and your options regarding the ways in which your data is used.

Limecube is owned by Smart Digital Group Pty Ltd ACN 611 319 647. By visiting Limecube you are accepting the practices described in this Privacy Policy.

The overall privacy experience

The data we collect is designed to provide us with an overview of how our clients use Limecube to continue to improve our product. It is not designed to focus on specific users. While we collect individual data when a user signs up, we only look at this personal information individually when a user specifically asks for help with their account at which time we need to access a level of this information such as name and email address.

Where we send general email updates or marketing updates, these are either sent to all users or based in the type of business or industry you selected when you signed up.

Information We Collect

Two types of information are collected:

  1. Personal, or "individually identifiable," information you provide to us;
    1. This will occur at signup, or
    2. If you create a support request and any information you provide in the support request
  2. And Standard web server/visitor traffic information, commonly referred to as "aggregate information," regarding overall website traffic patterns. Normally, web servers collect this type of basic information as part of their web log processes. We only use this information for statistical, reporting and website administration and maintenance purposes. It is not used in a way that individually identifies you, and we do not report on individual users.

    We use the following tools to capture anonymous data. Under each we have linked to their Privacy Policies to make it easy to see how they protect your data.
    - Google analytics
    - Hotjar.
    - Google Remarketing

If you use Limecube CRM, we also collect and process personal data through that product — including the contacts, bookings, form responses, quotes and call data that you and your customers enter. See the "Limecube CRM — Additional Privacy Terms" section below for full details.

Collection and use of Personal Data

Smart Digital Group Pty Ltd does not collect or record personal information, other than information you choose to provide through the online forms on this website. We only collect user details necessary for account creation and the management of your websites on Limecube. We do not collect unrelated personal information.

If you do submit online forms containing personal information, we will use that information to respond to your message and upon occasion for email marketing (covered below). The main purpose of collecting and using personal information submitted through our site is to respond to customer enquiries or feedback from this site. The information gathered will only be used to complete your request unless specifically stated on a particular form.

Information provided by you will be handled in accordance with Australian privacy laws, and, where applicable, the General Data Protection Regulation (GDPR) and other relevant international privacy regulations. We maintain strict privacy standards and procedures with a view to preventing unauthorised access to your data by anyone other than Smart Digital Group Pty Ltd.

Direct Marketing

Email addresses and any other contact details you provide may be used for email marketing upon occasion. Any email marketing we send includes a simple opt option to no longer receive direct marketing communications.

Third Party Information

We will not disclose your personal information to a third party without your consent, unless we are required or authorised to do so by law or other regulation. In the unlikely event of an investigation into suspected unlawful or improper activity, a law enforcement agency or government agency may exercise its legal authority to inspect the web server's records (eg. in relation to hacking or abusive messages).

The third-party services and cookies described in this section relate to the Limecube website builder. Limecube CRM uses a separate set of providers — see the sub-processor list in the "Limecube CRM — Additional Privacy Terms" section below. The CRM application itself uses only an essential sign-in session cookie, and no advertising or analytics cookies.

Cookies & Google Analytics

We use Cookies on our site for 3 purposes:

  1. To keep some types of users logged in. This Cookies captures a random string of characters which links back to a user account and is stored for 24 hours for each login session.
  2. For Google Remarketing as further mentioned below.
  3. We also use Cookies for collecting data in Google Analytics to help us understand traffic coming to our site for such things as total visits, unique and repeat visits, pages visited, demographic data and other general data. This data does not provide us with any identifiable information tied to any specific user. Further information about how Google keep your data safe is provided here.

For our clients, cookies are used within the login area to store session information.

A cookie is a block of data that is shared between a web server and a user's browser. Cookies give the server information about a user's identity and website visiting patterns and preferences. You can find more information about cookies on the Wikipedia website.

IP Addresses

We track IP addresses to maintain security on the site. IP addresses only link back to individual user accounts and are only looked at when there are any security concerns with the aim of protecting all user accounts on Limecube.

Amend/update information

If you believe that any information held by us about you is incorrect or incomplete you can update or delete your personal information and websites anytime from your account dashboard. If for some reason you cannot do this yourself due to technical issues, please contact us, and we’ll assist you promptly.

Access Rights

You have the right to access personal data that is held about you. To obtain a copy of your personal information we hold, please call us or fill in our form at the bottom of this page and we will attempt to provide this to you within a reasonable timeframe.

There are exceptions to providing access to this information:

  1. We reasonably believe that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety; or
  2. giving access would have an unreasonable impact on the privacy of other individuals; or
  3. the request for access is frivolous or vexatious; or
  4. the information relates to existing or anticipated legal proceedings between the We and the individual, and would not be accessible by the process of discovery in those proceedings; or
  5. giving access would reveal the intentions of We in relation to negotiations with the individual in such a way as to prejudice those negotiations; or
  6. giving access would be unlawful; or
  7. denying access is required or authorised by or under an Australian law or a court/tribunal order; or
  8. both of the following apply: We has reason to suspect that unlawful activity, or misconduct of a serious nature, that relates to the We's functions or activities has been, is being or may be engaged in;
  9. giving access would be likely to prejudice the taking of appropriate action in relation to the matter; or
  10. giving access would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or
  11. giving access would reveal evaluative information generated within We in connection with a commercially sensitive decision-making process.

Your Rights under GDPR (if applicable)

If you are located in the European Union, United Kingdom, or jurisdictions offering equivalent data protection, you have the following rights regarding your personal data:

  • Right of Access, Rectification, and Deletion: You can access, update, or delete the personal data we hold—namely, the details necessary to operate your Limecube account and websites. This can be done directly through your account dashboard.
  • Right to Object or Restrict Processing: You may object to or restrict our processing of your data. Please note that because the data we process is essential for operating your websites, restricting processing effectively means that the services will no longer be available unless the data is deleted (i.e., by deleting your websites and account).
  • Right to Withdraw Consent: If you have provided explicit consent—for example, via marketing communications—you may withdraw that consent at any time (e.g. by unsubscribing). This right does not apply to processing that is necessary to provide the Limecube service (such as account operation), which is based on contract.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format. In our case, as we only hold basic account information (like name, email), you can access and update this information yourself via your account dashboard—thus meeting the portability requirement without needing a formal export from us.

California residents (CCPA/CPRA): you have the right to know, delete and correct your personal information and to opt out of its "sale" or "sharing" — we do not sell or share personal information as those terms are defined. Note that for personal data you store in Limecube CRM about your own contacts and customers, you are the controller and we act as your processor; requests from those individuals should be directed to the business that collected their data, and we will assist that business as its processor.

Notification of changes to the Privacy Statement

Smart Digital Group Pty Ltd may change the content or services found on our website at any time without notice; consequently our Privacy Statement may change at any time also without notice.

If you do not agree with any changes to this Privacy Notice, you will need to stop using our Services, delete your account and if required contact us to remove any information we collect as outlined on this page.

Security of your Personal Data

The transfer of information across any medium may involve a degree of risk, and the Internet is no different. However the protection of personal privacy is a priority of Smart Digital Group Pty Ltd. We use a range of technologies and internal policies to prevent unauthorised access or disclosure, to maintain data accuracy, and to ensure the appropriate use of information, we secure sensitive data by: including firewalls, access controls, restrictions and appropriate physical, electronic, internal processes and management processes and procedures to safeguard and secure the information we collect online and offline. For highly sensitive information and documentation this is held by senior management, and viewed only by relevant personnel. This helps ensure that your data is secured not only from access and visibility but also from unauthorised alteration or erasure.

This website does not provide facilities that guarantee secure transmission of information over the internet. You should be aware that there are risks in transmitting information across the internet, including online forms and email. If you are concerned about conveying sensitive or personal material to Smart Digital Group Pty Ltd over the internet, contact us by telephone to discuss the matter.

For Limecube CRM specifically: account passwords are hashed (bcrypt) and never stored in plain text; third-party access tokens and API keys are encrypted at rest (AES-256-GCM); all traffic to external services is encrypted in transit (TLS); each account's data is isolated from other accounts; and sensitive endpoints such as sign-in and password reset are rate-limited.

Data Deletion & User Responsibility

How You Can Request Deletion of Your Data

Limecube only stores personal information required for your account and the operation of your websites on the platform. We do not retain any unnecessary or unrelated information.

If you no longer wish to use Limecube, you can delete your websites at any time from your account dashboard. Once all websites associated with your account have been deleted, your data will be completely removed. Limecube does not retain your personal data.

  • Self-service deletion: Users can log in and delete their websites directly from their account dashboard.
  • Full data removal: When you delete all your websites, your associated personal data is automatically removed from our systems.
  • Your responsibility: It is your responsibility to delete your websites if you wish to remove your data from Limecube.
  • Alternative request: If you are unable to delete your websites for any technical reason, you may request assistance by contacting us via the form below, using the account holder email address, and we will process your request in accordance with applicable laws, including GDPR.

For Limecube CRM, deleting your account permanently and irreversibly erases all of your CRM records and the files held with our storage providers (database, AWS S3 and Vercel Blob). You can also delete individual records — contacts, bookings, quotes, files and call logs — at any time from within the CRM.

Limecube CRM — Additional Privacy Terms

These additional terms apply when you use Limecube CRM. Limecube CRM is operated by Smart Digital Group Pty Ltd (ACN 611 319 647), trading as Limecube. Where they differ from the general policy above, these terms govern your use of the CRM.

1. Our role: controller and processor

Limecube CRM involves two different relationships, and our privacy responsibilities differ for each:

  • As a controller — for the personal data of our direct customers (the account holder and their team members): your name, email, phone, login records, billing identifiers and account settings. We decide how this data is used to provide and bill for the service.
  • As a processor — for the personal data you load into or capture through the CRM about your own contacts, leads, customers, booking guests, form respondents, quote recipients and callers. For this data you are the controller and we act only on your instructions. You are responsible for having a lawful basis to collect it, for honouring the rights of those individuals, and for any required privacy notices on your own forms, booking pages and call flows. We make a Data Processing Agreement (DPA) available to govern this relationship (see section 10 below).

2. Personal data we process through the CRM

Account and team data (we are controller): name, email, phone, hashed password, business name, company contact details, locale, login timestamps and IP address, subscription/plan status and Stripe customer/subscription identifiers.

Customer data you store (we are processor): contacts and companies (names, emails, phone numbers, postal addresses, websites, notes, tags, status), deals and pipeline notes, tasks (including notes, comments and file attachments), quotes (client name/email/phone/company/address, line items, electronic signature image and the IP address used to sign), time-tracking entries, and activity-log notes and call logs you record.

Data captured from your visitors (we are processor):

  • Booking widget — guest name, email, phone, notes and any custom fields, plus booking times.
  • Public forms & surveys — respondent name, email, phone, custom field answers, and the IP address and browser user-agent of the submission.
  • Inbound email & inbox/webhook submissions — sender name and address, recipients, subject, message body, and the raw payload/headers of third-party form webhooks.

AI voice agent (we are processor): caller phone number and name, call recordings (held in your ElevenLabs account), transcripts, AI-generated summaries, sentiment and matched intent.

Calendar data (we are processor): OAuth access/refresh tokens for the calendar you connect (Google or Microsoft), the connected account email, your calendar busy-time periods, and the events the CRM creates for bookings.

Accounting data (we are processor): Xero OAuth tokens, organisation name, and contact/invoice data synced between Xero and the CRM.

Knowledge base content: business knowledge entries and voice-interview transcripts you create.

Files: attachments and documents you upload (task files, logos, quote PDFs, form uploads).

3. How we use this data and our legal bases (GDPR / UK GDPR)

Purpose Legal basis
Providing the CRM to you (account, contacts, pipeline, bookings, quotes, etc.) Performance of our contract with you
Processing the customer/visitor data you load in Processed on your documented instructions as processor; you determine the legal basis
Securing the service, preventing abuse, rate-limiting, audit logging Our legitimate interests
Billing and tax records Performance of contract; legal obligation
Optional booking-widget analytics (Google Analytics 4) Consent (you enable it and are responsible for obtaining visitor consent)
Product updates and B2B marketing to account holders Legitimate interests / consent, with opt-out

We do not sell your personal data. Anthropic (Claude) does not use your content to train its models. The ElevenLabs voice agent runs on your own ElevenLabs account, so under ElevenLabs' standard (non-enterprise) terms it may, by default, use voice and conversation data to improve its AI models — you can opt out and control how long call data is kept in your ElevenLabs account settings (see section 4 below).

4. Artificial intelligence features

The CRM's AI features run on AI accounts that you connect yourself: you supply your own Anthropic (Claude) API key for text features (form-response summaries, inbox auto-reply drafting, quote cover-page generation, knowledge-base interviews and campaign content) and your own ElevenLabs account for the AI voice agent (speech and call handling). Because you set these up directly and accept each provider's terms yourself, your relationship with them — including how they may use your data — is governed by your own agreement with that provider, not by us. The CRM simply sends content to, and receives results from, the account you connected, over an encrypted connection.

For your awareness: Anthropic does not use your content to train its models. ElevenLabs, by default on its standard (non-enterprise) plans, may use voice and conversation data to improve its AI models — you can opt out via the "Data use" setting under "Terms and Privacy" in your ElevenLabs account, and you control how long ElevenLabs keeps call transcripts and audio (2 years by default, down to immediate deletion).

5. Call recording and transcription

When the AI voice agent is enabled, inbound calls are recorded and transcribed. Where you operate this feature you are the controller and are responsible for complying with call-recording and consent laws in your and your callers' jurisdictions (some require all-party consent), including informing callers that the call is recorded.

6. Sub-processors and third-party integrations

(a) Sub-processors we engage. We use the following providers to run the core CRM. We contract with each, and they receive only the data needed for their function:

Sub-processor Function Data location
Supabase (PostgreSQL) Primary database Sydney, Australia
Vercel Application hosting & file (Blob) storage Sydney (compute, syd1); Blob is globally distributed
Amazon Web Services (S3) Storage for larger file uploads Sydney (ap-southeast-2)
Stripe Subscription billing & card processing United States
Mailgun Transactional & inbound email (unless you connect your own) United States
Google (Maps/Places) Address autocomplete Global

We keep this list current as our sub-processors change, and will give affected customers reasonable advance notice of material changes so they can object where they have the right to.

(b) Optional integrations you connect. The features below run on third-party accounts that you set up and connect yourself (via your own API key or by authorising access). You accept each provider's terms directly, so they act as your vendor — your relationship with them, including their data use and retention, is governed by your agreement with them, not by us. The CRM transmits data to and from the account you connect:

Integration Function Provider
ElevenLabs AI voice agent (your own account/key) ElevenLabs (US)
Anthropic (Claude) AI text features (your own API key) Anthropic (US)
Xero Accounting / contact & invoice sync (your OAuth) Xero
Google Calendar Calendar availability & event sync (your OAuth) Google
Microsoft / Outlook Calendar Calendar availability & event sync (your OAuth) Microsoft
Mailchimp Email campaigns (your own API key) Mailchimp (US)

7. International data transfers

Your core CRM data is stored in Sydney, Australia. Several sub-processors in section 6 are located overseas (including the United States), so using those features involves transferring personal data internationally. Where required, these transfers are protected by appropriate safeguards such as Standard Contractual Clauses. For example, our email provider Mailgun processes email in the United States.

8. Data retention

We retain account and customer data for as long as your account is active. When an account owner deletes the account, all associated data is permanently and irreversibly erased, including records in our database and files held with our storage providers. You may also delete individual records (contacts, bookings, etc.) at any time from within the CRM. Apart from the CRM itself — and the main Limecube website, where your billing may be set up — we do not keep separate identifiable billing or tax records; payment card processing is handled by Stripe under its own terms.

9. Your privacy rights

Depending on where you live, you have rights over your personal data:

  • GDPR / UK GDPR (EU/EEA/UK): access, rectification, erasure, restriction, data portability, objection, and the right to lodge a complaint with your supervisory authority (the ICO in the UK).
  • Australian Privacy Act (APPs): access and correction, and to complain to the OAIC.
  • CCPA/CPRA (California): to know, delete and correct your personal information, and to opt out of "sale"/"sharing" — we do not sell or share personal information as those terms are defined.

For data we control, you can access and correct most details in your account dashboard, delete your account from Settings, and export your contacts to CSV. For other requests, contact us using the form on this page. If your request concerns data a Limecube CRM customer holds about you (for example, you filled in a business's booking form), that business is the controller — contact them directly, and we will assist them as their processor.

We respond to access and portability requests: you can already export your contacts to CSV in the CRM, and on request we will provide a copy of other personal data we hold in a structured, commonly used, machine-readable format within the statutory timeframe (one month under GDPR). The first request is free; for requests that are manifestly unfounded, excessive or repetitive — or for additional copies — we may charge a reasonable fee based on our administrative costs, or decline the request, to the extent permitted by law.

10. Data Processing Agreement

If you use the CRM to process personal data about individuals in the EEA/UK (or otherwise need a DPA), we make a Data Processing Agreement available that incorporates the required processing terms and the sub-processor list in section 6. Request one using the form on this page.

11. Cookies and tracking in the CRM

The CRM application itself uses only essential cookies required to keep you securely signed in (a session cookie and related security tokens). It does not use advertising or third-party tracking cookies. The booking widget can optionally load Google Analytics 4 only if you, the account holder, configure a Measurement ID — in that case you are responsible for the cookie consent shown to your visitors.

Questions or concerns

If you have any questions or concerns regarding this Privacy Policy, please complete this form below and we will try to resolve any concerns.

Why Limecube?

Limecube offers everything you need to build a professional-looking website, even without prior experience. Use our AI Website Builder to have AI create your site and write your content or start from scratch. Perfect for small businesses, entrepreneurs, and creatives, Limecube provides flexible design options and an easy-to-use drag-and-drop builder.

Whether you’re launching a new business or revamping an existing site, Limecube has you covered.

Let's Get Started!

Now that you know how easy it is to create a website with Limecube’s AI website builder, get started today!