Legal
Privacy Policy
Last updated: May 13, 2026
This policy explains how GHLThemer ("we", "our", "us") collects, uses, and protects information when you use our service at ghlthemer.com.
1. Overview
GHLThemer is a B2B SaaS platform that allows marketing professionals to apply custom CSS themes to GoHighLevel pages. We take your privacy seriously and collect only the data necessary to provide and improve our service.
By using GHLThemer, you agree to the collection and use of information as described in this policy. Our Terms of Service are a separate document and also apply to your use of the service.
2. Data We Collect
We collect the following categories of information:
| Data | Why |
|---|---|
| Name & email address | Account creation and communication |
| Country | Routing to the correct payment gateway |
| Account type & plan | Enforcing feature access limits |
| Theme settings (colors, fonts, CSS) | Delivering your custom themes to GHL pages |
| Client and site names | Organising your workspace |
| Support ticket content | Resolving your support requests |
| Billing information | Processed by LemonSqueezy or Safepay — we never store card data |
| Usage analytics (page views, clicks) | Product improvement — only with your consent |
4. How We Use Your Data
- Provide and operate the GHLThemer service
- Deliver your CSS theme to your GoHighLevel pages via our embed script
- Send transactional emails (account verification, billing, support replies)
- Send trial reminder emails (3 emails in the last 3 days of your trial)
- Enforce plan limits and feature access
- Respond to support tickets
- Detect and prevent abuse or fraud
- Improve our product (only with analytics consent)
We do not sell your data. We do not use your data to serve third-party advertising. We do not share your client data with any party outside the service providers listed below.
5. Third-Party Services
We share limited data with the following providers to operate the service:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database & authentication | All account and theme data |
| Vercel | Hosting & edge delivery | Request logs (IP, user agent) |
| Resend | Transactional email | Name, email, ticket content |
| LemonSqueezy | Payments (non-PK users) | Name, email, plan selection |
| Safepay | Payments (Pakistan users) | Name, email, plan selection |
| OpenAI | AI color suggestions | Industry + vibe selection only (no PII) |
| Google Analytics | Usage analytics (consent-only) | Anonymised page views |
| Microsoft Clarity | Heatmaps (consent-only) | Anonymised session data |
| Cloudflare R2 | Video hosting | None — public CDN reads only |
Each provider has their own privacy policy. For links, search "[provider name] privacy policy".
6. Data Retention
- Account data is retained while your account is active
- Theme history snapshots are kept for the last 10 saves per theme
- Analytics events are automatically deleted after 90 days
- Support tickets and replies are retained for 2 years
- After account deletion, all personal data is removed within 30 days
To request account deletion, email support@ghlthemer.com.
7. Your Rights (GDPR / CCPA)
If you are in the European Economic Area (EEA), UK, or California, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Portability — receive your data in a machine-readable format
- Objection — object to processing of your data for analytics
- Restrict processing — request limited processing of your data
- Withdraw consent — for analytics cookies, at any time (see Section 3)
To exercise any of these rights, email support@ghlthemer.com with your request. We will respond within 30 days.
For CCPA: we do not sell personal information. You have the right to know what data we collect and to request deletion.
8. Security
We take reasonable technical and organisational measures to protect your data:
- All data transmitted over HTTPS (TLS)
- Database rows protected by Supabase Row Level Security (RLS) policies
- Authentication handled by Supabase Auth (bcrypt-hashed passwords)
- Payment card data never touches our servers — handled entirely by LemonSqueezy/Safepay
- API keys and secrets stored as environment variables, never in source code
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it responsibly to support@ghlthemer.com.
9. Children's Privacy
GHLThemer is a business tool intended for adults (18+). We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify active users by email.
Continued use of GHLThemer after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
For any privacy-related questions, requests, or concerns: