PRIVACY POLICY

Last updated: July 6, 2026

This Privacy Policy explains how Lasso Inc. (“Lasso,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information about Merchants, Merchant personnel, website visitors, and End-Customers who interact with Lasso-powered checkout, post-purchase, and related flows.

Who We Are; Scope

Lasso provides checkout, payment orchestration, hosted checkout components, post-purchase flows, optional identity resolution, optional offer network and monetization features, analytics, integrations, APIs, SDKs, and related services for merchants globally.

Merchants use Lasso to operate checkout and post-purchase experiences for their customers. This Privacy Policy applies to information processed through Lasso’s website, dashboard, Services, checkout pages, post-purchase pages, embedded components, APIs, SDKs, integrations, and related services.

Roles

For End-Customer personal information processed by Lasso to provide the Services to a Merchant, the Merchant is generally the controller or business, and Lasso is generally the processor, service provider, or contractor.

For Merchant account information, admin user information, billing information, security signals, service telemetry, fraud and abuse prevention, product analytics, aggregated or de-identified analytics, and Lasso’s own business operations, Lasso acts as an independent controller or business.

Some optional integrations involve third-party providers that may act as independent controllers, businesses, or third parties for their own services. This includes identity resolution providers that maintain independent identity graphs and offer network partners that select, deliver, measure, or monetize third-party offers.

Information We Process

We may process the following categories of information.

Merchant account, admin, and business verification information: name, email, phone, profile photo, role, partner affiliation, company details, legal business name, tax ID, business address, payout method, bank account details, W-9 forms, date of birth, SSN, account credentials, dashboard settings, authorized users, authentication information, support communications, usage information, and logs.

End-Customer transaction metadata: order details, product information, cart contents, order value, billing and shipping addresses, contact information, checkout events, post-purchase events, session information, device and network identifiers, token identifiers, aliases from provider-hosted components, and related transaction context.

Payment-related information: payment token references, payment aliases, transaction metadata, authorization status, payment provider response information, and payment routing information. We do not store raw card PAN or sensitive authentication data.

Identity resolution and matching data: if a Merchant enables identity resolution features, we and our identity resolution providers may process device identifiers, IP address, browser and session information, event data, page interaction data, hashed or pseudonymous identifiers, checkout context, and other signals used to help match anonymous or pseudonymous visitors with known or inferred identities.

Offer network and monetization data: if a Merchant enables offer network or post-purchase monetization features, we may process and disclose shopper and transaction context, including product category, cart contents, order value, checkout context, transaction metadata, device and session data, approximate location derived from IP address, hashed or pseudonymous identifiers, and offer engagement data.

Support and communications: messages, attachments, files, feedback, and other communications sent to us.

Automatically collected information: diagnostics, crash logs, performance logs, security signals, device information, browser information, IP address, access logs, telemetry, and analytics.

Aggregated and de-identified information: information that has been aggregated or de-identified so it does not identify a person and is not reasonably capable of being associated with a person.

AI and content generation data: merchant-supplied prompts, product copy, URLs, extracted web content, generated content, and related observability data used for AI-assisted store and content generation features.

Sources of Information

We collect information:

  • directly from Merchants and Merchant personnel;

  • from End-Customer interactions with checkout, post-purchase, and related flows;

  • from Merchant websites, integrations, APIs, SDKs, tags, scripts, and embedded components;

  • from Designated Providers and integration partners;

  • from payment processors, commerce platforms, identity resolution providers, offer network partners, and other third-party providers;

  • from our infrastructure, security, analytics, support, and monitoring tools.

How We Use Information

We use information to:

  • provide, operate, secure, support, maintain, monitor, troubleshoot, and improve the Services;

  • render checkout pages, post-purchase pages, hosted components, and related user experiences;

  • orchestrate payments and payment routing;

  • sync orders with commerce platforms;

  • provide optional identity resolution features enabled by Merchants;

  • provide optional offer network, recommendation, post-purchase monetization, personalization, attribution, reporting, and revenue share features enabled by Merchants;

  • help Merchants configure checkout, post-purchase, payment, identity, offer, analytics, and integration features;

  • prevent, detect, and investigate fraud, abuse, security incidents, policy violations, and unlawful activity;

  • communicate with Merchants and provide support;

  • create aggregated or de-identified analytics for product improvement, service monitoring, and business operations;

  • comply with applicable law, legal process, regulatory requests, and contractual obligations;

  • provide AI-assisted store generation, content generation, product copy generation, content extraction, observability, debugging, and related features;

  • enforce our terms and protect rights, safety, and security.

Legal Bases for EEA, UK, and Similar Jurisdictions

Where GDPR, UK GDPR, or similar laws apply and Lasso acts as an independent controller, we rely on the following legal bases:

  • performance of a contract to provide Merchant accounts, dashboard access, support, billing, and Services;

  • legitimate interests to secure, monitor, improve, analyze, and protect the Services; prevent fraud and abuse; communicate with Merchants; and operate our business;

  • legal obligations to comply with law, regulatory obligations, accounting, tax, sanctions, and legal process;

  • consent where required, such as for certain cookies, tracking technologies, marketing communications, or optional features.

For End-Customer personal information processed by Lasso on behalf of a Merchant, the Merchant determines the lawful basis. Merchants are responsible for providing required notices and obtaining required consents or other lawful bases for their use of the Services.

How We Disclose Information

We disclose information to the following categories of recipients.

Service providers and sub-processors. Providers that help us host, deliver, secure, monitor, support, analyze, and operate the Services.

Payment processors, gateways, orchestration providers, acquirers, payment networks, and fraud providers. Providers used at the Merchant’s direction or as needed to provide payment-related features.

Commerce platforms and integration partners. Providers used at the Merchant’s direction for order sync, fulfillment, analytics, and related integrations.

Identity resolution providers. If the Merchant enables identity resolution features, we disclose relevant identifiers, device signals, network signals, session data, and checkout context to identity resolution providers. These providers may process information on our behalf for the Services and may independently maintain their own identity graphs, data graphs, or proprietary datasets under their own terms and privacy notices.

Offer network partners. If the Merchant enables offer network or post-purchase monetization features, we disclose shopper and transaction context to offer network partners to select, personalize, serve, measure, attribute, optimize, and monetize third-party offers. These disclosures may constitute a sale, sharing, targeted advertising, or similar regulated disclosure under some privacy laws.

Professional advisors, legal, safety, and compliance recipients. Recipients used to comply with law, enforce terms, protect rights, prevent fraud or abuse, or protect security.

Business transaction recipients. Recipients involved in an actual or potential merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.

AI, content generation, and observability providers. We may disclose merchant-supplied prompts, product copy, URLs, extracted web content, generated content, and related observability data to providers that support AI-assisted store and content generation, web content extraction, and LLM observability.

Merchant-Controlled Environments

Most End-Customer interactions with Lasso occur in Merchant-controlled environments, including Merchant websites, checkout flows, post-purchase flows, storefronts, consent banners, cookie banners, tag managers, scripts, pixels, SDKs, product pages, and customer communications.

Merchants control which optional features they enable, including identity resolution, offer network, advertising, analytics, and marketing integrations. Merchants are responsible for providing required notices, obtaining required consents, honoring privacy rights, honoring opt-outs, honoring opt-out preference signals, and configuring privacy controls for those environments and features.

Lasso processes End-Customer personal information in accordance with Merchant instructions and the Terms of Service when acting as Merchant’s processor, service provider, or contractor.

Service Provider, Contractor, and Processor Commitments

For End-Customer personal information we process on behalf of Merchants, we process the information in accordance with our Terms of Service, including the embedded data processing terms.

We do not sell or share Customer Personal Data when processing solely as a service provider, contractor, or processor unless the Merchant enables and authorizes an optional feature involving an independent third-party provider, such as identity resolution or offer network services.

Merchant Responsibilities

Merchants are responsible for:

  • providing privacy notices, cookie notices, and other legally required disclosures to End-Customers;

  • obtaining and maintaining required consents, opt-ins, lawful bases, and authorizations;

  • honoring End-Customer rights, opt-outs, consent withdrawals, objection rights, opt-out preference signals, Global Privacy Control signals, and similar choices;

  • configuring consent banners, cookie controls, tag controls, “Do Not Sell or Share” links, and similar mechanisms;

  • determining whether to enable identity resolution, offer network, advertising, analytics, and similar optional features;

  • making required disclosures about revenue share, sponsored offers, advertising, profiling, or monetization where applicable.

Sub-processors

We maintain a Sub-processor Appendix at https://www.lassocart.com/subprocessor-appendix with service categories, vendor names, processing purposes, locations, and transfer information. We may update the Sub-processor Appendix from time to time in accordance with the notice and objection process described in the Terms of Service.

Security

We use administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of information we process. These measures may include encryption in transit, encryption at rest where we store personal data, access controls, logging, monitoring, vulnerability management, and incident response.

No method of transmission or storage is completely secure.

Retention

We retain personal information for as long as needed to provide the Services, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and operate our business.

Certain operational records, including customer data, cart sessions, attribution identifiers, and webhook payloads, may be retained until removed through manual, operational, or out-of-band processes. Short-lived operational tokens, such as password-reset and verification codes, expire on shorter schedules.

Application request logs may be retained at the load-balancer level for up to five years and may contain identifiable information such as IP addresses, emails, and session identifiers.

For Customer Personal Data processed on behalf of Merchants, retention is governed by the Terms of Service, Merchant instructions, applicable law, and Lasso’s operational deletion processes.

International Transfers

Lasso is based in the United States, and we and our providers may process personal information in the United States and other countries.

Where required for personal information subject to GDPR, UK GDPR, Swiss FADP, or similar transfer laws, we use appropriate transfer safeguards, such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the UK International Data Transfer Agreement, Swiss adaptations, or other lawful transfer mechanisms.

Cookies, Device Identifiers, and Similar Technologies

We and our providers may use cookies, pixels, tags, scripts, SDKs, device identifiers, local storage, and similar technologies to operate, secure, analyze, and improve the Services.

If a Merchant enables identity resolution, offer network, advertising, analytics, or similar optional features, additional identifiers and signals may be processed through Merchant checkout, post-purchase, and related flows.

Merchants are responsible for providing required notices and controls for cookies, pixels, tags, identity resolution, offer network, advertising, analytics, and similar technologies used in Merchant-controlled environments.

Privacy Choices and Rights

Merchants may manage account information and feature settings in the dashboard or by contacting us.

End-Customers should direct requests to access, delete, correct, restrict, object, opt out, withdraw consent, or exercise other privacy rights to the Merchant that operates the checkout or post-purchase flow. We will assist the Merchant as described in our Terms of Service.

If you are an End-Customer, the Merchant operating the checkout or post-purchase flow is usually the controller or business responsible for responding to your privacy request. Please contact the Merchant directly.

If you contact Lasso directly about Customer Personal Data that we process on behalf of a Merchant, we may direct you to the Merchant or forward your request to the Merchant where appropriate.

Lasso does not currently provide a self-service portal for End-Customer access, export, or deletion requests. Where Lasso processes Customer Personal Data on behalf of a Merchant, Lasso will support the Merchant through operational processes as described in the Terms of Service.

California and U.S. State Privacy Disclosures

Depending on how a Merchant configures the Services and whether optional features are enabled, disclosures to identity resolution providers or offer network partners may constitute a sale, sharing, targeted advertising, or similar disclosure under applicable U.S. state privacy laws.

Merchants are responsible for determining whether their use of these features triggers such obligations and for providing required notices and opt-out mechanisms.

Lasso does not sell or share Customer Personal Data when processing solely as a service provider, contractor, or processor. Lasso may disclose Customer Personal Data to independent third parties when Merchant enables and authorizes optional features, including Identity Resolution Services or Offer Network Services.

Children

The Services are not directed to children. Merchants may not use the Services to collect or process children’s personal information unless expressly permitted by law and by Lasso in writing.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be posted on our site, in the dashboard, by email, or through other reasonable notice. Continued use of the Services after the effective date means the updated Privacy Policy applies.

Contact

Lasso Inc.
Legal/Privacy: admin@lassocart.com
Address: 24A Trolley Square #1339, Wilmington, DE 19806

Lasso powers your entire checkout flow. From global payment methods to individual consumer insights, get the tools and analytics you need to make better decisions. One checkout, every channel.

Lasso powers your entire checkout flow. From global payment methods to individual consumer insights, get the tools and analytics you need to make better decisions. One checkout, every channel.