Legal
Security
Encryption, role-based access, backups, incident response and how to report a vulnerability.
1. How your data is protected
- All data in transit is encrypted (HTTPS/TLS).
- Access to your account data is controlled through Lighter’s role-based permission system: eight roles with server-enforced access, so team members only see what their role requires.
- Customer data is backed up daily, and backups are kept for 30 days.
2. Where your data is hosted
Data is hosted on servers located in India.
3. Who else touches your data
We use a small number of service providers to operate Lighter: cloud hosting, the Official WhatsApp Business API (Meta) for RSVP messaging, Google (only if you enable Calendar/Sheets sync), and a payment processor for billing. Each is bound by its own security and data-handling obligations.
4. What we do if something goes wrong
If we become aware of a security incident affecting your data, we will notify affected businesses and, where required by law, the Data Protection Board of India without undue delay, with a detailed report to the Board within 72 hours as required under the DPDP Rules, 2025.
5. Reporting a security issue
If you’ve found a vulnerability, tell us before you tell anyone else: support@lighteros.com. We’ll acknowledge reports promptly and won’t take action against good-faith researchers.
Last updated: 17 September 2026